chore: upgrade app nginx to 1.31.6 #8

Closed
autonomic-bot wants to merge 1 commits from upgrade-4e5976f into main
Owner

Bumps the nginx app image 1.31.5 → 1.31.6 (nginx mainline, 15 Sep 2026 — a security patch release).

Image tags

service image current new
app nginx 1.31.5 1.31.6

Sidecars unchanged: alpine/git v2.54.0 (latest per abra), linuxserver/openssh-server latest (intended floating tag).

Why

  • Security — CVE-2026-90439: a heap memory buffer overflow might occur in a worker process under certain configurations when using HTTP/3 with OpenSSL 3.5.0 and earlier (F5 advisory K000162604: Medium, CVSS v3.1 6.5 / v4.0 6.9; NGINX Open Source 1.29.2–1.31.5 vulnerable, fixed in 1.31.6). Not exploitable in this recipe's shape (plain HTTP/1.1 static serving on :80 behind traefik, no HTTP/3/QUIC listener) — but the bump ships the fix.
  • Change: the QUIC transport parameters extension received in an SSL connection is now always ignored.
  • Bugfixes: binary upgrade with control API socket + perl module; predicate-location evaluation error no longer ignored; nested location lookup with regex/predicate locations; segfault reading config with geo + ranges and a corrupted binary base file.

Advisory scan (deterministic + adjudicated): 1 CVE fixed by this window — CVE-2026-90439 (the release notes name no other).

Upstream release notes: app nginx 1.31.5→1.31.6: https://nginx.org/en/CHANGES

Operator action required

None. Tag-only bump; no config/env/volume/label changes; no migrations. None of the 1.31.6 changes touch this recipe's config surface (static file serving, no HTTP/3, no proxy upstreams, no perl/geo/predicate locations).

Release

The coop-cloud.${STACK_NAME}.version label (1.14.0+1.31.5) is intentionally NOT bumped in this PR; it is set at release time. After this merges:

abra recipe release custom-html -z

Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review.

cc @trav @notplants

Bumps the **nginx** app image 1.31.5 → 1.31.6 (nginx mainline, 15 Sep 2026 — a security patch release). ## Image tags | service | image | current | new | |---------|-------|---------|-----| | app | nginx | 1.31.5 | 1.31.6 | Sidecars unchanged: `alpine/git v2.54.0` (latest per abra), `linuxserver/openssh-server` `latest` (intended floating tag). ## Why - **Security — CVE-2026-90439**: a heap memory buffer overflow might occur in a worker process under certain configurations when using HTTP/3 with OpenSSL 3.5.0 and earlier (F5 advisory K000162604: Medium, CVSS v3.1 6.5 / v4.0 6.9; NGINX Open Source 1.29.2–1.31.5 vulnerable, fixed in 1.31.6). Not exploitable in this recipe's shape (plain HTTP/1.1 static serving on :80 behind traefik, no HTTP/3/QUIC listener) — but the bump ships the fix. - Change: the QUIC transport parameters extension received in an SSL connection is now always ignored. - Bugfixes: binary upgrade with control API socket + perl module; predicate-location evaluation error no longer ignored; nested location lookup with regex/predicate locations; segfault reading config with `geo` + `ranges` and a corrupted binary base file. Advisory scan (deterministic + adjudicated): **1 CVE fixed by this window** — CVE-2026-90439 (the release notes name no other). **Upstream release notes:** app nginx 1.31.5→1.31.6: https://nginx.org/en/CHANGES ## Operator action required **None.** Tag-only bump; no config/env/volume/label changes; no migrations. None of the 1.31.6 changes touch this recipe's config surface (static file serving, no HTTP/3, no proxy upstreams, no perl/geo/predicate locations). ## Release The `coop-cloud.${STACK_NAME}.version` label (1.14.0+1.31.5) is intentionally NOT bumped in this PR; it is set at release time. After this merges: abra recipe release custom-html -z Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review. cc @trav @notplants
autonomic-bot added 1 commit 2026-09-18 02:16:57 +00:00
autonomic-bot requested review from trav 2026-09-18 02:16:57 +00:00
autonomic-bot requested review from notplants 2026-09-18 02:16:57 +00:00
Author
Owner

!testme

!testme
Author
Owner

🌻 cc-ci — custom-html @ 4e5976f6 ✅ passed

cc-ci result card

level

full logs · dashboard

<!-- cc-ci:testme --> 🌻 **cc-ci** — `custom-html` @ `4e5976f6` ✅ **passed** [![cc-ci result card](https://ci.commoninternet.net/runs/1361/summary.png)](https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/1361) [![level](https://ci.commoninternet.net/runs/1361/badge.svg)](https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/1361) [full logs](https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/1361) · [dashboard](https://ci.commoninternet.net/)
Author
Owner

Auto-closed by cc-ci canonical sweep: its changes are already in upstream main (merged upstream); mirror main re-synced

Auto-closed by cc-ci canonical sweep: its changes are already in upstream main (merged upstream); mirror main re-synced
autonomic-bot closed this pull request 2026-09-20 03:12:46 +00:00

Pull request closed

Please reopen this pull request to perform a merge.
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: recipe-maintainers/custom-html#8