diff --git a/docker/frontend/Dockerfile b/docker/frontend/Dockerfile index 17de59b..18c1fbe 100644 --- a/docker/frontend/Dockerfile +++ b/docker/frontend/Dockerfile @@ -22,8 +22,11 @@ RUN npm run build -- --configuration production # Stage 2: Serve static files with Nginx Alpine FROM nginx:1.31-alpine AS final -# Install wget and upgrade Alpine packages to patch base OS vulnerabilities -RUN apk add --no-cache wget && apk upgrade --no-cache +# Install wget and upgrade Alpine packages to patch base OS vulnerabilities. +# pcre2 is listed explicitly because CVE-2026-103111 (fixed in 10.49-r0) is not +# yet in the published nginx image, and a cached `apk upgrade` layer would keep +# serving the vulnerable package. +RUN apk add --no-cache wget 'pcre2>=10.49-r0' && apk upgrade --no-cache # Copy custom Nginx configuration COPY docker/frontend/nginx.conf /etc/nginx/conf.d/default.conf diff --git a/docker/proxy/Dockerfile b/docker/proxy/Dockerfile index b8f8d99..9a8ac8a 100644 --- a/docker/proxy/Dockerfile +++ b/docker/proxy/Dockerfile @@ -5,7 +5,9 @@ FROM nginx:1.31-alpine # Install openssl for self-signed certificate generation in local/test mode. # gettext provides envsubst for rendering the nginx template at runtime. -RUN apk add --no-cache openssl gettext && apk upgrade --no-cache +# pcre2 is listed explicitly because CVE-2026-103111 (fixed in 10.49-r0) is not +# yet in the published nginx image. +RUN apk add --no-cache openssl gettext 'pcre2>=10.49-r0' && apk upgrade --no-cache # Create non-root-friendly directories and set ownership. # Nginx alpine image provides nginx user (UID 101) / group (GID 101).