Fix HIGH findings from 2026-09-24 maintenance review
- nginx: resolve real client IP through Cloudflare -> NPM so rate limits are per client instead of shared across all users - Bump vulnerable Python deps (PyJWT auth bypass, anyio, starlette via fastapi 0.141.1, cryptography, python-multipart, Mako); pin PyMySQL 1.1.2 since 1.2.x breaks SQLAlchemy 2.0.35's aiomysql ping - Backend: python 3.12.14-slim, apt-get upgrade, drop unneeded build deps - Frontend: nginx 1.30.5-alpine (stable) + apk upgrade - MySQL 8.0.40 (EOL) -> 8.4.11 LTS; add healthcheck start_period so slow startups (e.g. data upgrades) don't abort dependent services - Add maintenance review report Co-Authored-By: Claude Opus 5.5 <[email protected]>
This commit is contained in:
1 parent
8e92ae6073
commit
3170c7f4eb
6 files changed
+260
-10
No files matched your search
+2
-1
@@ -1,6 +1,6 @@
|
||||
services:
|
||||
db:
|
||||
image: mysql:8.0.40
|
||||
image: mysql:8.4.11
|
||||
container_name: homeschool_db
|
||||
restart: unless-stopped
|
||||
environment:
|
||||
@@ -17,6 +17,7 @@ services:
|
||||
interval: 10s
|
||||
timeout: 5s
|
||||
retries: 5
|
||||
start_period: 180s
|
||||
mem_limit: 512m
|
||||
cpus: 1.0
|
||||
|
||||
|
||||
Reference in new issue
Block a user