Run frontend in production mode instead of exposed npm run dev
next dev bound to 0.0.0.0:3000 with the host source dir bind-mounted rw was the entry point malware kept getting dropped through (see prior commit). Now builds and runs `next start`; the bind mount is gone so a compromised container can no longer write onto host disk. Also bumps next to 15.1.11, patching CVE-2025-66478 (critical RCE via the RSC Next-Action header) and the follow-up CVE-2025-67779/55184/ 55183 batch — the installed 15.1.6 was vulnerable to all of them and is the likely actual initial-access vector. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Gh2UXUQUVBWroWEnn1FLFG
This commit is contained in:
1 parent
ee4562530a
commit
2cb2bc0729
3 files changed
+10
-7
No files matched your search
@@ -34,10 +34,6 @@ services:
|
||||
restart: unless-stopped
|
||||
env_file:
|
||||
- ./frontend/.env.local
|
||||
volumes:
|
||||
- ./frontend:/app
|
||||
- /app/node_modules
|
||||
- /app/.next
|
||||
ports:
|
||||
- "3000:3000"
|
||||
depends_on:
|
||||
|
||||
Reference in new issue
Block a user