Fix HIGH findings from 2026-09-24 maintenance review
- nginx: resolve real client IP through Cloudflare -> NPM so rate limits
are per client instead of shared across all users
- Bump vulnerable Python deps (PyJWT auth bypass, anyio, starlette via
fastapi 0.141.1, cryptography, python-multipart, Mako); pin PyMySQL
1.1.2 since 1.2.x breaks SQLAlchemy 2.0.35's aiomysql ping
- Backend: python 3.12.14-slim, apt-get upgrade, drop unneeded build deps
- Frontend: nginx 1.30.5-alpine (stable) + apk upgrade
- MySQL 8.0.40 (EOL) -> 8.4.11 LTS; add healthcheck start_period so
slow startups (e.g. data upgrades) don't abort dependent services
- Add maintenance review report
Co-Authored-By: Claude Opus 5.5 <[email protected]>