Fix security vulnerabilities detected by Trivy

- CVE-2025-64756: glob CLI command injection - added override to use glob ^11.1.0
- CVE-2025-13466: body-parser DoS - added override to use body-parser ^2.2.1
- CVE-2025-64718: js-yaml prototype pollution - updated to js-yaml ^4.1.1
- BusyBox vulnerabilities (netstat, tar) - added apk upgrade to all Dockerfiles

Changes:
- backend/package.json: Updated js-yaml, added overrides for glob, body-parser
- frontend/package.json: Added overrides for glob, js-yaml
- All Dockerfiles: Added 'apk upgrade --no-cache' to get latest security patches
- backend/Dockerfile.dev: Updated from node:18-alpine to node:20-alpine
This commit is contained in:
Claude
2025-11-25 20:35:59 +00:00
parent e85d1bf72a
commit 14c4bc17f3
7 changed files with 25 additions and 3 deletions
+3
View File
@@ -30,6 +30,9 @@ RUN npm run build
# Production stage
FROM nginx:alpine
# Upgrade all packages to fix security vulnerabilities (BusyBox CVEs)
RUN apk upgrade --no-cache
# Install runtime dependencies
RUN apk add --no-cache curl
+3
View File
@@ -3,6 +3,9 @@ FROM node:20-alpine
WORKDIR /app
# Upgrade all packages to fix security vulnerabilities (BusyBox CVEs)
RUN apk upgrade --no-cache
# Copy package files
COPY package*.json ./
+3
View File
@@ -25,6 +25,9 @@ RUN npm run build
# Production stage
FROM nginx:alpine
# Upgrade all packages to fix security vulnerabilities (BusyBox CVEs)
RUN apk upgrade --no-cache
# Install runtime dependencies
RUN apk add --no-cache curl
+4
View File
@@ -65,5 +65,9 @@
},
"optionalDependencies": {
"@rollup/rollup-linux-x64-gnu": "^4.45.1"
},
"overrides": {
"glob": "^11.1.0",
"js-yaml": "^4.1.1"
}
}