From 1aa97f0af0da6a32de7710f1ed09acfdff138322 Mon Sep 17 00:00:00 2001 From: Bastien Chanot Date: Sun, 5 Jul 2026 22:41:58 +0200 Subject: [PATCH] =?UTF-8?q?fix(security):=20bump=20base=20to=20nginx-unpri?= =?UTF-8?q?vileged=201.30-alpine=20=E2=80=94=20CVE-2026-42945=20(tour=20SE?= =?UTF-8?q?C-1)?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit 1.28 stable branch retired; 2026-05-13 nginx security batch (rewrite-module buffer overflow, fixed 1.30.1+) never backported to 1.28.x. New digest pin carries nginx/1.30.3. Verified: build, nginx -t, uid 101, hardened run, 5/5 security headers + HTTP 200 on /, .html, .pdf, favicon. --- Dockerfile | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Dockerfile b/Dockerfile index 93c7cf1..70a2313 100644 --- a/Dockerfile +++ b/Dockerfile @@ -2,7 +2,7 @@ # nginx-unprivileged serves index.html + CV (HTML + PDF) as uid 101 — # no root master process in the container (tag + digest pinned). -FROM nginxinc/nginx-unprivileged:1.28-alpine@sha256:209331cfcaec00da781f5b8a38e0d1c0abd00cb2b51e6ad385a30abbbdb04e15 +FROM nginxinc/nginx-unprivileged:1.30-alpine@sha256:fd3314e343bad2de4e1127ef58be122abbfa7e09572fa46ae62fcddb6b3f21c5 # Custom nginx config (gzip, cache, security headers). COPY nginx.conf /etc/nginx/conf.d/default.conf