diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index b9d48f9..4f6f561 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -63,7 +63,7 @@ jobs: run: | docker run --rm \ -v "$PWD/web/nginx.conf:/etc/nginx/conf.d/default.conf:ro" \ - nginxinc/nginx-unprivileged:1.27-alpine \ + nginxinc/nginx-unprivileged:1.30-alpine \ nginx -t - name: Validate the edge proxy config @@ -71,7 +71,7 @@ jobs: docker run --rm \ -v "$PWD/nginx/nginx.conf:/etc/nginx/conf.d/default.conf:ro" \ --add-host web:127.0.0.1 \ - nginxinc/nginx-unprivileged:1.27-alpine \ + nginxinc/nginx-unprivileged:1.30-alpine \ nginx -t compose-config-check: diff --git a/memory-bank/progress.md b/memory-bank/progress.md index d8c7f0b..1eab4d7 100644 --- a/memory-bank/progress.md +++ b/memory-bank/progress.md @@ -37,7 +37,7 @@ Site is live at `clock.taylormadetech.net`. - Edge-cached homepage can lag up to 2 h behind a deploy (expected; judge freshness via `/healthz` or a query-string cache-bust, which works). - CI actions pinned to Node-20-runtime majors (HK-2 — fix in progress). -- `nginxinc/nginx-unprivileged:1.27-alpine` is an EOL mainline branch +- `nginxinc/nginx-unprivileged:1.30-alpine` is an EOL mainline branch (HK-5 candidate: re-pin to current stable + digest). - npm minor drift: eslint/prettier/lint-staged/TS patch bumps available; vite 7+/vitest 5 majors deliberately deferred (not housekeeping). diff --git a/memory-bank/techContext.md b/memory-bank/techContext.md index bc21546..5fb4322 100644 --- a/memory-bank/techContext.md +++ b/memory-bank/techContext.md @@ -6,7 +6,7 @@ (`web/.nvmrc`: 22). - **Vitest 4 + jsdom** for tests; `@vitest/coverage-v8` for coverage. - ESLint (flat config, `web/eslint.config.js`), Prettier, husky + lint-staged. -- Containers: `node:22-alpine`, `nginxinc/nginx-unprivileged:1.27-alpine` +- Containers: `node:22-alpine`, `nginxinc/nginx-unprivileged:1.30-alpine` (EOL mainline branch — see backlog HK-5), `golang:1.24-alpine`, `alpine:3.21` — all digest-pinned (ADR 0005). Deployer: `github.com/adnanh/webhook` pseudo-version pin. diff --git a/nginx/Dockerfile b/nginx/Dockerfile index e9bab31..324d4dd 100644 --- a/nginx/Dockerfile +++ b/nginx/Dockerfile @@ -3,7 +3,7 @@ # Built on nginxinc/nginx-unprivileged: the process runs as a non-root user and # listens on 8080, so the container needs no capabilities at all # (docker-compose*.yml drops every cap). -FROM nginxinc/nginx-unprivileged:1.27-alpine@sha256:65e3e85dbaed8ba248841d9d58a899b6197106c23cb0ff1a132b7bfe0547e4c0 +FROM nginxinc/nginx-unprivileged:1.30-alpine@sha256:adf5042a17f4ecdd200c595fa9ffd1be37efb18f89a830bd1a00e4ab4d59d42c COPY nginx.conf /etc/nginx/conf.d/default.conf diff --git a/web/Dockerfile.prod b/web/Dockerfile.prod index b0f120e..ab0bfc0 100644 --- a/web/Dockerfile.prod +++ b/web/Dockerfile.prod @@ -20,7 +20,7 @@ RUN npm run build # ── Runtime stage ───────────────────────────────────────────────── # nginxinc/nginx-unprivileged runs as a non-root user and listens on 8080, # which is why the edge proxy targets web:8080 in every environment. -FROM nginxinc/nginx-unprivileged:1.27-alpine@sha256:65e3e85dbaed8ba248841d9d58a899b6197106c23cb0ff1a132b7bfe0547e4c0 AS runtime +FROM nginxinc/nginx-unprivileged:1.30-alpine@sha256:adf5042a17f4ecdd200c595fa9ffd1be37efb18f89a830bd1a00e4ab4d59d42c AS runtime COPY nginx.conf /etc/nginx/conf.d/default.conf COPY --from=builder /app/dist /usr/share/nginx/html