Fix HIGH findings from 2026-09-24 maintenance review

- nginx: resolve real client IP through Cloudflare -> NPM so rate limits
  are per client instead of shared across all users
- Bump vulnerable Python deps (PyJWT auth bypass, anyio, starlette via
  fastapi 0.141.1, cryptography, python-multipart, Mako); pin PyMySQL
  1.1.2 since 1.2.x breaks SQLAlchemy 2.0.35's aiomysql ping
- Backend: python 3.12.14-slim, apt-get upgrade, drop unneeded build deps
- Frontend: nginx 1.30.5-alpine (stable) + apk upgrade
- MySQL 8.0.40 (EOL) -> 8.4.11 LTS; add healthcheck start_period so
  slow startups (e.g. data upgrades) don't abort dependent services
- Add maintenance review report

Co-Authored-By: Claude Opus 5.5 <[email protected]>
This commit is contained in:
derekcandClaude Opus 5.5 committed 2026-09-24 23:38:16 -07:00
1 parent 8e92ae6073
commit 3170c7f4eb
6 files changed
+260 -10

No files matched your search

+9 -5
View File
@@ -1,13 +1,17 @@
fastapi==0.115.0
fastapi==0.141.1
starlette==1.7.0
anyio==4.15.1
uvicorn[standard]==0.30.6
sqlalchemy[asyncio]==2.0.35
aiomysql==0.3.0
PyJWT==2.12.0
cryptography==46.0.5
PyMySQL==1.1.2
PyJWT==2.15.0
cryptography==50.0.1
passlib[bcrypt]==1.7.4
bcrypt==3.2.2
pydantic-settings==2.5.2
alembic==1.13.3
python-multipart==0.0.22
alembic==1.20.0
Mako==1.4.3
python-multipart==0.0.32
email-validator==2.2.0
httpx==0.27.2