382f9bec6b6bd60ad6467ea08209549c2cf11d6e
Apply all available OS security updates in the runtime image stage to pull in openssl 3.5.5-1~deb13u2 (fixes CVE-2026-31789 heap buffer overflow). Three CVEs with no upstream fix (Mesa will_not_fix, perl-base affected) documented and suppressed in .trivyignore with rationale. Trivy rescan exits 0 (D-10 gate passes). Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
feat(06-04): multi-stage Dockerfile with appuser + docker-compose runtime hardening (D-07/D-08/D-09)
Description
No description provided
8.1 MiB
Languages
Python
57.2%
JavaScript
16.5%
HTML
14.2%
Vue
12%