Run frontend in production mode instead of exposed npm run dev
next dev bound to 0.0.0.0:3000 with the host source dir bind-mounted rw was the entry point malware kept getting dropped through (see prior commit). Now builds and runs `next start`; the bind mount is gone so a compromised container can no longer write onto host disk. Also bumps next to 15.1.11, patching CVE-2025-66478 (critical RCE via the RSC Next-Action header) and the follow-up CVE-2025-67779/55184/ 55183 batch — the installed 15.1.6 was vulnerable to all of them and is the likely actual initial-access vector. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Gh2UXUQUVBWroWEnn1FLFG
This commit is contained in:
1 parent
ee4562530a
commit
2cb2bc0729
3 files changed
+10
-7
No files matched your search
@@ -34,10 +34,6 @@ services:
|
|||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
env_file:
|
env_file:
|
||||||
- ./frontend/.env.local
|
- ./frontend/.env.local
|
||||||
volumes:
|
|
||||||
- ./frontend:/app
|
|
||||||
- /app/node_modules
|
|
||||||
- /app/.next
|
|
||||||
ports:
|
ports:
|
||||||
- "3000:3000"
|
- "3000:3000"
|
||||||
depends_on:
|
depends_on:
|
||||||
|
|||||||
+8
-1
@@ -2,10 +2,17 @@ FROM node:22-bookworm-slim
|
|||||||
|
|
||||||
WORKDIR /app
|
WORKDIR /app
|
||||||
|
|
||||||
|
# registry.npmjs.org resolves to Cloudflare's IPv6-only records here, and
|
||||||
|
# Docker's default bridge network has flaky IPv6 egress — Node's Happy
|
||||||
|
# Eyeballs then hangs on IPv6 before timing out instead of falling back to
|
||||||
|
# IPv4 quickly, causing intermittent ETIMEDOUT mid-install.
|
||||||
|
ENV NODE_OPTIONS=--dns-result-order=ipv4first
|
||||||
|
|
||||||
COPY package.json package-lock.json* ./
|
COPY package.json package-lock.json* ./
|
||||||
RUN npm install
|
RUN npm install
|
||||||
|
|
||||||
COPY . .
|
COPY . .
|
||||||
|
RUN npm run build
|
||||||
|
|
||||||
CMD ["npm", "run", "dev", "--", "--hostname", "0.0.0.0"]
|
CMD ["npm", "start", "--", "--hostname", "0.0.0.0"]
|
||||||
|
|
||||||
@@ -10,7 +10,7 @@
|
|||||||
},
|
},
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"lucide-react": "^0.469.0",
|
"lucide-react": "^0.469.0",
|
||||||
"next": "15.1.6",
|
"next": "15.1.11",
|
||||||
"react": "19.0.0",
|
"react": "19.0.0",
|
||||||
"react-dom": "19.0.0"
|
"react-dom": "19.0.0"
|
||||||
},
|
},
|
||||||
@@ -19,7 +19,7 @@
|
|||||||
"@types/react": "^19.0.2",
|
"@types/react": "^19.0.2",
|
||||||
"@types/react-dom": "^19.0.2",
|
"@types/react-dom": "^19.0.2",
|
||||||
"eslint": "^9.17.0",
|
"eslint": "^9.17.0",
|
||||||
"eslint-config-next": "15.1.6",
|
"eslint-config-next": "15.1.11",
|
||||||
"typescript": "^5.7.2"
|
"typescript": "^5.7.2"
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in new issue
Block a user