12a9d963f5
Trivy flagged nginx 1.28.3-r1 in the frontend image (alerts #371-374): - CVE-2026-42055 (HIGH) HTTP/2 heap overflow - CVE-2026-49975 (HIGH) HTTP/2 DoS - CVE-2026-9256 (HIGH) rewrite_module code exec / DoS - CVE-2026-48142 (MED) charset_module memory disclosure All fixed in nginx 1.28.3-r4. The Dockerfile already ran 'apk upgrade --no-cache', but the pushed image predated the fixed package and the layer was cached on r1. Add an explicit nginx upgrade to force the layer to rebuild against the current Alpine repos (which now carry r4).