fix(security): bump base to nginx-unprivileged 1.30-alpine — CVE-2026-42945 (tour SEC-1)

1.28 stable branch retired; 2026-05-13 nginx security batch (rewrite-module
buffer overflow, fixed 1.30.1+) never backported to 1.28.x. New digest pin
carries nginx/1.30.3. Verified: build, nginx -t, uid 101, hardened run,
5/5 security headers + HTTP 200 on /, .html, .pdf, favicon.
This commit is contained in:
Bastien Chanot
2026-07-05 22:41:58 +02:00
parent 7967afff08
commit 1aa97f0af0
+1 -1
View File
@@ -2,7 +2,7 @@
# nginx-unprivileged serves index.html + CV (HTML + PDF) as uid 101 —
# no root master process in the container (tag + digest pinned).
FROM nginxinc/nginx-unprivileged:1.28-alpine@sha256:209331cfcaec00da781f5b8a38e0d1c0abd00cb2b51e6ad385a30abbbdb04e15
FROM nginxinc/nginx-unprivileged:1.30-alpine@sha256:fd3314e343bad2de4e1127ef58be122abbfa7e09572fa46ae62fcddb6b3f21c5
# Custom nginx config (gzip, cache, security headers).
COPY nginx.conf /etc/nginx/conf.d/default.conf