next dev bound to 0.0.0.0:3000 with the host source dir bind-mounted rw was the entry point malware kept getting dropped through (see prior commit). Now builds and runs `next start`; the bind mount is gone so a compromised container can no longer write onto host disk. Also bumps next to 15.1.11, patching CVE-2025-66478 (critical RCE via the RSC Next-Action header) and the follow-up CVE-2025-67779/55184/ 55183 batch — the installed 15.1.6 was vulnerable to all of them and is the likely actual initial-access vector. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Gh2UXUQUVBWroWEnn1FLFG
44 lines
770 B
YAML
44 lines
770 B
YAML
name: kkpab-site-old
|
|
|
|
services:
|
|
db:
|
|
image: postgres:16-alpine
|
|
environment:
|
|
POSTGRES_DB: kkpab
|
|
POSTGRES_USER: postgres
|
|
POSTGRES_PASSWORD: postgres
|
|
restart: unless-stopped
|
|
volumes:
|
|
- postgres_data:/var/lib/postgresql/data
|
|
ports:
|
|
- "5433:5432"
|
|
|
|
backend:
|
|
build:
|
|
context: ./backend
|
|
dockerfile: Dockerfile
|
|
restart: unless-stopped
|
|
env_file:
|
|
- ./backend/.env
|
|
volumes:
|
|
- ./backend:/app
|
|
ports:
|
|
- "7788:8000"
|
|
depends_on:
|
|
- db
|
|
|
|
frontend:
|
|
build:
|
|
context: ./frontend
|
|
dockerfile: Dockerfile
|
|
restart: unless-stopped
|
|
env_file:
|
|
- ./frontend/.env.local
|
|
ports:
|
|
- "3000:3000"
|
|
depends_on:
|
|
- backend
|
|
|
|
volumes:
|
|
postgres_data:
|