Fix LOW findings from 2026-09-24 maintenance review
- Frontend on nginx-unprivileged (non-root, container port 8080) - Replace unmaintained passlib with bcrypt 5.0.0 (hash-compatible) - Pass DOCS_ENABLED through to the backend container - Raise db mem_limit to 768m for MySQL 8.4 Co-Authored-By: Claude Opus 5.5 <[email protected]>
This commit is contained in:
1 parent
f74bc1a1ff
commit
eed5a8fb12
6 files changed
+30
-12
No files matched your search
@@ -35,3 +35,12 @@ Maintenance release from the 2026-09-24 review (`reports/maintenance-2026-09-24.
|
||||
### Known / accepted
|
||||
- npm audit: vite ≤6.4.2 and esbuild advisories affect only the **dev server**, which production never runs (it serves the static build). Fixing them fully needs Vite 6.4+/7.
|
||||
- mysql:8.4.11 has upstream findings in Oracle's image: curl, bundled Python tools, and gosu's Go stdlib.
|
||||
|
||||
## v1.1.1 — 2026-09-25
|
||||
|
||||
Low-severity items from the 2026-09-24 review.
|
||||
|
||||
- Frontend runs as non-root: `nginxinc/nginx-unprivileged:1.30.5-alpine`, listening on **8080** in the container. Host port 8054 is unchanged, so NPM needs no change.
|
||||
- Replaced unmaintained `passlib` with `bcrypt` 5.0.0 directly. Existing `$2b$` hashes still verify; passwords are truncated to 72 bytes as before. A malformed hash now fails verification instead of raising.
|
||||
- `DOCS_ENABLED` is now passed to the backend container (default `false`), so the README instructions work.
|
||||
- db `mem_limit` 512m → 768m (MySQL 8.4 was at ~86% of 512m).
|
||||
Reference in new issue
Block a user