🔒️(frontend) upgrade tiff to fix CVE-2026-4775

Trivy flags tiff 4.7.1-r0 (HIGH) in the nginx alpine 3.24 base
of the frontend images. Force the upgrade to 4.7.2-r0.
This commit is contained in:
lebaudantoine
2026-10-08 20:27:01 +02:00
committed by aleb_the_flash
parent cee2109726
commit 811540c85f
3 changed files with 3 additions and 2 deletions
+1
View File
@@ -16,6 +16,7 @@ and this project adheres to
### Fixed
- 🔒️(backend) prevent editing client id and secret in Django admin
- 🔒️(frontend) upgrade tiff to fix CVE-2026-4775
## [1.34.0] - 2026-10-07
+1 -1
View File
@@ -58,7 +58,7 @@ FROM nginxinc/nginx-unprivileged:1.30.4-alpine3.24 AS frontend-production
USER root
RUN apk upgrade --no-cache libexpat && \
apk add --no-cache --upgrade 'pcre2>=10.49-r0' && \
apk add --no-cache --upgrade 'pcre2>=10.49-r0' 'tiff>=4.7.2-r0' && \
apk del curl
USER nginx
+1 -1
View File
@@ -49,7 +49,7 @@ FROM nginxinc/nginx-unprivileged:1.30.4-alpine3.24 AS frontend-production
USER root
RUN apk upgrade --no-cache libexpat && \
apk add --no-cache --upgrade 'pcre2>=10.49-r0' && \
apk add --no-cache --upgrade 'pcre2>=10.49-r0' 'tiff>=4.7.2-r0' && \
apk del curl
USER nginx