M46: refresh web runtime base
MobilityOps acceptance / backend (push) Failing after 18s
MobilityOps acceptance / frontend (push) Successful in 27s
MobilityOps acceptance / e2e (push) Skipped

This commit is contained in:
NuklearRabbit
2026-08-21 18:46:10 +02:00
parent ec02aca0fd
commit 95c91797fa
2 changed files with 11 additions and 1 deletions
+10
View File
@@ -1,5 +1,15 @@
# Project state
## M46 — refresh vulnerable web runtime base (2026-08-21)
- The production image gate found fixed HIGH/CRITICAL Alpine vulnerabilities in the
previously pinned Nginx 1.27 runtime, after all functional production checks passed.
- Refreshed the official runtime to Nginx 1.30.4 on Alpine 3.24.1 and pinned its immutable
multi-platform digest `sha256:97d490c12ba55b4946b01546d1c3ed324e8d41ab1c9fcb2a616aa470620e5b46`.
Trivy 0.70 reports zero fixed HIGH/CRITICAL findings for that base.
- Exact next action: build and scan the complete web image, commit and push M46, deploy
the exact revision, then repeat production image and browser acceptance gates.
## M45 — authenticate production metrics scraping (2026-08-21)
- Pre-deployment inspection confirmed production protects `/metrics` with a non-empty