From 7a75328c49a03ff6b2d4ec118f13eb6a66c8e3b6 Mon Sep 17 00:00:00 2001 From: ammnt Date: Fri, 18 Sep 2026 08:15:54 +0300 Subject: [PATCH 01/14] Update base version and hash in .env and Dockerfile.template; add NJS module with QuickJS-NG support in README --- .env | 4 +-- Dockerfile.template | 61 +++++++++++++++++++++++++++++++++++++++------ README.md | 4 +-- 3 files changed, 56 insertions(+), 13 deletions(-) diff --git a/.env b/.env index 3148b18..6718e5c 100644 --- a/.env +++ b/.env @@ -1,4 +1,4 @@ -BASE_VERSION=3.24.1 -BASE_HASH=bec4ccd3817e7c824eb0388971a0b83fab111d586285511ba0266b77e8dc65a9 +BASE_VERSION=3.24.2 +BASE_HASH=31b6477333eb8257db9e5d7c3a7264fd0467928756f0bbcc27d35bea5d28cdbd OPENSSL_VERSION=4.0.2 APP_VERSION=1.31.4 diff --git a/Dockerfile.template b/Dockerfile.template index 1149918..4d71ac1 100644 --- a/Dockerfile.template +++ b/Dockerfile.template @@ -1,6 +1,6 @@ # Build arguments for version pinning and reproducibility -ARG BASE_VERSION=3.24.1 -ARG BASE_HASH=bec4ccd3817e7c824eb0388971a0b83fab111d586285511ba0266b77e8dc65a9 +ARG BASE_VERSION=3.24.2 +ARG BASE_HASH=31b6477333eb8257db9e5d7c3a7264fd0467928756f0bbcc27d35bea5d28cdbd FROM alpine:${BASE_VERSION}@sha256:${BASE_HASH} AS builder ARG OPENSSL_VERSION ARG APP_VERSION @@ -26,7 +26,7 @@ RUN addgroup --system --gid "10001" freenginx && adduser --disabled-password --s git=2.54.0-r0 \ mimalloc2-dev=2.2.7-r0 \ build-base=0.5-r4 \ - ca-certificates=20260611-r0 \ + ca-certificates=20260909-r0 \ linux-headers=7.0.0-r1 \ upx=5.2.0-r0 \ perl=5.42.2-r0 \ @@ -36,12 +36,20 @@ RUN addgroup --system --gid "10001" freenginx && adduser --disabled-password --s brotli-dev=1.2.0-r1 \ brotli-static=1.2.0-r1 \ curl=8.22.0-r0 \ + autoconf=2.73-r0 \ + automake=1.18.1-r1 \ + libtool=2.6.0-r1 \ + python3-dev=3.14.7-r1 \ # Update CA certificates for SSL verification && update-ca-certificates \ && git config --global advice.detachedHead false \ && PCRE_VERSION=$(curl -sSfL "https://api.github.com/repos/PCRE2Project/pcre2/releases/latest" | grep '"tag_name":' | sed -E 's/.*"pcre2\-([^"]+)".*/\1/') \ && ZLIB_VERSION=$(curl -sSfL "https://api.github.com/repos/zlib-ng/zlib-ng/releases/latest" | grep '"tag_name":' | sed -E 's/.*"([^"]+)".*/\1/') \ && ZSTD_VERSION=$(curl -sSfL "https://api.github.com/repos/tokers/zstd-nginx-module/releases/latest" | grep '"tag_name":' | sed -E 's/.*"([^"]+)".*/\1/') \ + && NJS_VERSION=$(curl -sSfL "https://api.github.com/repos/nginx/njs/releases/latest" | grep '"tag_name":' | sed -E 's/.*"([^"]+)".*/\1/') \ + && QJS_VERSION=$(curl -sSfL "https://api.github.com/repos/quickjs-ng/quickjs/releases/latest" | grep '"tag_name":' | sed -E 's/.*"([^"]+)".*/\1/') \ + && LIBXML2_VERSION=$(git ls-remote --tags --refs https://github.com/GNOME/libxml2 'v*' | sed 's|.*/||' | grep -v -- '-' | sort -V | tail -1) \ + && LIBXSLT_VERSION=$(git ls-remote --tags --refs https://github.com/GNOME/libxslt 'v*' | sed 's|.*/||' | grep -v -- '-' | sort -V | tail -1) \ # Clone FreeNGINX webserver and remove documentation && git clone -q --depth 1 --recursive -j8 --single-branch -b "release-${APP_VERSION}" https://github.com/freenginx/nginx freenginx && rm -rf /tmp/freenginx/docs/html/* \ # Clone OpenSSL with HTTP/3 and QUIC support @@ -54,6 +62,14 @@ RUN addgroup --system --gid "10001" freenginx && adduser --disabled-password --s && git clone -q --depth 1 --recurse-submodules -j8 https://github.com/google/ngx_brotli \ # Clone ZSTD compression module && git clone -q --depth 1 --recursive -j8 --single-branch -b "${ZSTD_VERSION}" https://github.com/tokers/zstd-nginx-module \ + # Clone NJS module + && git clone -q --depth 1 --recursive -j8 --single-branch -b "${NJS_VERSION}" https://github.com/nginx/njs \ + # Clone QuickJS-NG engine + && git clone -q --depth 1 --recursive -j8 --single-branch -b "${QJS_VERSION}" https://github.com/quickjs-ng/quickjs.git \ + # Clone libxml2 for NJS + && git clone -q --depth 1 --recursive -j8 --single-branch -b "${LIBXML2_VERSION}" https://github.com/GNOME/libxml2 \ + # Clone libxslt for NJS + && git clone -q --depth 1 --recursive -j8 --single-branch -b "${LIBXSLT_VERSION}" https://github.com/GNOME/libxslt \ # Remove Server header from HTTP responses (HTTP/1.1, HTTP/2, HTTP/3) && sed -ie 's@r->headers_out.server == NULL@0@g' \ /tmp/freenginx/src/http/ngx_http_header_filter_module.c \ @@ -62,6 +78,32 @@ RUN addgroup --system --gid "10001" freenginx && adduser --disabled-password --s # Remove default footer from error pages && sed -ie 's@
freenginx
@@g' /tmp/freenginx/src/http/ngx_http_special_response.c +# Build QuickJS-NG library +WORKDIR /tmp/quickjs +RUN make -s -j "$(nproc)" \ + && cp ./build/libqjs.a ./libquickjs.a + +# Build libxml2 library +WORKDIR /tmp/libxml2 +RUN ./autogen.sh \ + && CFLAGS="-fPIC -O3 -march=x86-64 -fstack-protector-strong -fcf-protection=full \ + -fvisibility=hidden -flto=full" \ + ./configure \ + --disable-shared \ + --enable-static \ + && make -s -j "$(nproc)" && make -s install && make -s clean + +# Build libxslt library +WORKDIR /tmp/libxslt +RUN ./autogen.sh \ + && CFLAGS="-fPIC -O3 -march=x86-64 -fstack-protector-strong -fcf-protection=full \ + -fvisibility=hidden -flto=full" \ + ./configure \ + --disable-shared \ + --enable-static \ + --with-libxml-src=/tmp/libxml2 \ + && make -s -j "$(nproc)" && make -s install && make -s clean + # Build zlib-ng and Brotli compression libraries with optimizations WORKDIR /tmp/zlib-ng RUN mkdir -p /tmp/ngx_brotli/deps/brotli/out \ @@ -102,6 +144,7 @@ RUN ./auto/configure \ --with-zlib="/tmp/zlib-ng" \ # Compilation flags --with-cc-opt="-fPIE -O3 -march=x86-64 -flto=full \ + -I/tmp/quickjs -I/usr/local/include \ -Wall -Wextra -Wformat=2 -Wimplicit-fallthrough \ -Werror=format-security -Werror=return-type -Wno-deprecated-declarations \ -Wno-unused-parameter -Wno-implicit-fallthrough -Wno-sign-compare \ @@ -109,9 +152,9 @@ RUN ./auto/configure \ -fstrict-flex-arrays=3 -fstack-clash-protection -fstack-protector-strong \ -fcf-protection=full -ftrivial-auto-var-init=pattern \ -fno-delete-null-pointer-checks -fno-strict-overflow \ - -fasynchronous-unwind-tables -fomit-frame-pointer \ - -DTCP_FASTOPEN=23" \ - --with-ld-opt="-fuse-ld=lld -flto=full -lmimalloc -L/usr/local/lib -lz -static-pie \ + -fasynchronous-unwind-tables -fomit-frame-pointer -DTCP_FASTOPEN=23" \ + --with-ld-opt="-fuse-ld=lld -flto=full -L/tmp/quickjs -L/usr/local/lib \ + -lmimalloc -lxml2 -lxslt -lexslt -lz -lm -static-pie \ -Wl,-z,nodlopen -Wl,-z,noexecstack -Wl,-z,relro -Wl,-z,now \ -Wl,-z,separate-code -Wl,-z,shstk -Wl,-z,force-ibt -Wl,--no-warnings \ -Wl,--as-needed -Wl,--no-copy-dt-needed-entries" \ @@ -152,10 +195,12 @@ RUN ./auto/configure \ # Third-party modules --add-module="/tmp/ngx_brotli" \ --add-module="/tmp/zstd-nginx-module" \ + --add-module="/tmp/njs/nginx" \ # Build and install FreeNGINX - && make -s -j "$(nproc)" && make -s install && make -s clean \ + && make -s -j "$(nproc)" && make -s install \ + && file objs/src/http/ngx_http.o objs/src/core/nginx.o | grep -i 'LLVM IR bitcode' && make -s clean \ # Security hardening: strip debug symbols and compress binary - && strings /usr/sbin/freenginx | grep -iE "zlib-ng/zlib.h|mimalloc_version" \ + && strings /usr/sbin/freenginx | grep -iE "zlib-ng/zlib.h|mimalloc_version|quickjs/quickjs.h" \ && llvm-strip --strip-all /usr/sbin/freenginx \ && upx -qq --best --lzma /usr/sbin/freenginx \ && ls -lash /usr/sbin/freenginx \ diff --git a/README.md b/README.md index fda9384..1872cb6 100644 --- a/README.md +++ b/README.md @@ -13,9 +13,6 @@ > [!IMPORTANT] > The QuicTLS is now deprecated. I use OpenSSL, since this library natively supports OCSP, PQC, ECH and QUICโš ๏ธ -> [!IMPORTANT] -> NJS module has been removed due to security vulnerabilities in libxml2/libxslt dependenciesโš ๏ธ - > [!TIP] > You can find an example [configuration file](example.conf) in the repository for successfully configuring HTTP/3, ECH and PQC๐Ÿ’ก @@ -173,6 +170,7 @@ freenginx/ ### **Performance Features** - **zlib-ng** with modern compression algorithms (RFC 1950, RFC 1951, RFC 1952) - **PCRE2 with JIT** compilation for regex performance +- **NJS with QuickJS-NG** - JavaScript scripting support with modern engine - **Thread pool support** for async I/O operations - **TCP Fast Open** and **SSL session resumption** (RFC 7413, RFC 8446) - **Graceful shutdown** - SIGQUIT handling for proper connection draining (RFC 7230) From c2f37e28374be91920e174311211eecf31bd6f85 Mon Sep 17 00:00:00 2001 From: ammnt Date: Sun, 20 Sep 2026 21:12:44 +0300 Subject: [PATCH 02/14] Set no-fail to true in hadolint configuration for stricter linting enforcement --- hadolint.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/hadolint.yaml b/hadolint.yaml index aeabe0a..34e91da 100644 --- a/hadolint.yaml +++ b/hadolint.yaml @@ -1,6 +1,6 @@ failure-threshold: warning no-color: false -no-fail: false +no-fail: true trustedRegistries: - docker.io - ghcr.io From 0e5478ec997372d96c1cc4cb1b909fae30594d3c Mon Sep 17 00:00:00 2001 From: ammnt Date: Tue, 22 Sep 2026 23:29:12 +0300 Subject: [PATCH 03/14] Refactor Dockerfile.template to streamline dependency installation and update version retrieval methods --- Dockerfile.template | 21 ++++++++------------- 1 file changed, 8 insertions(+), 13 deletions(-) diff --git a/Dockerfile.template b/Dockerfile.template index 4d71ac1..19b295b 100644 --- a/Dockerfile.template +++ b/Dockerfile.template @@ -26,7 +26,6 @@ RUN addgroup --system --gid "10001" freenginx && adduser --disabled-password --s git=2.54.0-r0 \ mimalloc2-dev=2.2.7-r0 \ build-base=0.5-r4 \ - ca-certificates=20260909-r0 \ linux-headers=7.0.0-r1 \ upx=5.2.0-r0 \ perl=5.42.2-r0 \ @@ -35,27 +34,23 @@ RUN addgroup --system --gid "10001" freenginx && adduser --disabled-password --s zstd-static=1.5.7-r2 \ brotli-dev=1.2.0-r1 \ brotli-static=1.2.0-r1 \ - curl=8.22.0-r0 \ autoconf=2.73-r0 \ automake=1.18.1-r1 \ libtool=2.6.0-r1 \ python3-dev=3.14.7-r1 \ - # Update CA certificates for SSL verification - && update-ca-certificates \ - && git config --global advice.detachedHead false \ - && PCRE_VERSION=$(curl -sSfL "https://api.github.com/repos/PCRE2Project/pcre2/releases/latest" | grep '"tag_name":' | sed -E 's/.*"pcre2\-([^"]+)".*/\1/') \ - && ZLIB_VERSION=$(curl -sSfL "https://api.github.com/repos/zlib-ng/zlib-ng/releases/latest" | grep '"tag_name":' | sed -E 's/.*"([^"]+)".*/\1/') \ - && ZSTD_VERSION=$(curl -sSfL "https://api.github.com/repos/tokers/zstd-nginx-module/releases/latest" | grep '"tag_name":' | sed -E 's/.*"([^"]+)".*/\1/') \ - && NJS_VERSION=$(curl -sSfL "https://api.github.com/repos/nginx/njs/releases/latest" | grep '"tag_name":' | sed -E 's/.*"([^"]+)".*/\1/') \ - && QJS_VERSION=$(curl -sSfL "https://api.github.com/repos/quickjs-ng/quickjs/releases/latest" | grep '"tag_name":' | sed -E 's/.*"([^"]+)".*/\1/') \ - && LIBXML2_VERSION=$(git ls-remote --tags --refs https://github.com/GNOME/libxml2 'v*' | sed 's|.*/||' | grep -v -- '-' | sort -V | tail -1) \ - && LIBXSLT_VERSION=$(git ls-remote --tags --refs https://github.com/GNOME/libxslt 'v*' | sed 's|.*/||' | grep -v -- '-' | sort -V | tail -1) \ + && PCRE_VERSION=$(git ls-remote --tags --refs https://github.com/PCRE2Project/pcre2 'pcre2-*' | grep -v -- '-RC' | sed 's|.*/||' | tail -1) \ + && ZLIB_VERSION=$(git ls-remote --tags --refs https://github.com/zlib-ng/zlib-ng | sed 's|.*/||' | sed 's/^v//' | sort -V | tail -1) \ + && ZSTD_VERSION=$(git ls-remote --tags --refs https://github.com/tokers/zstd-nginx-module | sed 's|.*/||' | sort -V | tail -1) \ + && NJS_VERSION=$(git ls-remote --tags --refs https://github.com/nginx/njs '[0-9]*' | sed 's|.*/||' | sort -V | tail -1) \ + && QJS_VERSION=$(git ls-remote --tags --refs https://github.com/quickjs-ng/quickjs 'v*' | sed 's|.*/||' | sort -V | tail -1) \ + && LIBXML2_VERSION=$(git ls-remote --tags --refs https://github.com/GNOME/libxml2 'v*' | sed 's|.*/||' | sort -V | tail -1) \ + && LIBXSLT_VERSION=$(git ls-remote --tags --refs https://github.com/GNOME/libxslt 'v*' | sed 's|.*/||' | sort -V | tail -1) \ # Clone FreeNGINX webserver and remove documentation && git clone -q --depth 1 --recursive -j8 --single-branch -b "release-${APP_VERSION}" https://github.com/freenginx/nginx freenginx && rm -rf /tmp/freenginx/docs/html/* \ # Clone OpenSSL with HTTP/3 and QUIC support && git clone -q --depth 1 --recursive -j8 --single-branch -b "openssl-${OPENSSL_VERSION}" https://github.com/openssl/openssl \ # Clone PCRE2 for regex with JIT support - && git clone -q --depth 1 --recursive -j8 --single-branch -b "pcre2-${PCRE_VERSION}" https://github.com/PCRE2Project/pcre2 \ + && git clone -q --depth 1 --recursive -j8 --single-branch -b "${PCRE_VERSION}" https://github.com/PCRE2Project/pcre2 \ # Clone zlib-ng for modern compression performance && git clone -q --depth 1 --recursive -j8 --single-branch -b "${ZLIB_VERSION}" https://github.com/zlib-ng/zlib-ng \ # Clone Brotli compression module From 82fcad356dbf6a31d049b37f05730989fa97a7a0 Mon Sep 17 00:00:00 2001 From: ammnt Date: Wed, 23 Sep 2026 08:19:17 +0300 Subject: [PATCH 04/14] Remove .env file and update Dockerfile.template to set default values for OPENSSL_VERSION and APP_VERSION; update README to reflect removal of .env --- .env | 4 ---- .github/workflows/build.yml | 7 ------- Dockerfile.template | 6 +++--- README.md | 1 - 4 files changed, 3 insertions(+), 15 deletions(-) delete mode 100644 .env diff --git a/.env b/.env deleted file mode 100644 index 6718e5c..0000000 --- a/.env +++ /dev/null @@ -1,4 +0,0 @@ -BASE_VERSION=3.24.2 -BASE_HASH=31b6477333eb8257db9e5d7c3a7264fd0467928756f0bbcc27d35bea5d28cdbd -OPENSSL_VERSION=4.0.2 -APP_VERSION=1.31.4 diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index a623db0..c3d5c83 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -40,13 +40,6 @@ jobs: - name: Load .env variablesโ˜๏ธ id: load_env run: | - while IFS= read -r line; do - if [[ ! "$line" =~ ^# ]] && [[ -n "$line" ]]; then - key="${line%%=*}" - value="${line#*=}" - echo "$key=$value" >> $GITHUB_OUTPUT - fi - done < .env echo "BUILD_DATE=$(date -u +'%Y-%m-%dT%H:%M:%S')" >> $GITHUB_OUTPUT echo "VCS_REF=$(git rev-parse HEAD)" >> $GITHUB_OUTPUT diff --git a/Dockerfile.template b/Dockerfile.template index 19b295b..1aecf5c 100644 --- a/Dockerfile.template +++ b/Dockerfile.template @@ -2,8 +2,8 @@ ARG BASE_VERSION=3.24.2 ARG BASE_HASH=31b6477333eb8257db9e5d7c3a7264fd0467928756f0bbcc27d35bea5d28cdbd FROM alpine:${BASE_VERSION}@sha256:${BASE_HASH} AS builder -ARG OPENSSL_VERSION -ARG APP_VERSION +ARG OPENSSL_VERSION=4.0.2 +ARG APP_VERSION=1.31.4 SHELL ["/bin/ash", "-euo", "pipefail", "-c"] ENV CC=clang \ @@ -213,7 +213,7 @@ RUN ./auto/configure \ # Final distroless image FROM scratch -ARG APP_VERSION +ARG APP_VERSION=1.31.4 ARG BUILD_DATE ARG VCS_REF diff --git a/README.md b/README.md index 1872cb6..78d4caf 100644 --- a/README.md +++ b/README.md @@ -102,7 +102,6 @@ freenginx/ โ”œโ”€โ”€ ๐Ÿณ Dockerfile.template # Dockerfile template (dynamic generation) โ”œโ”€โ”€ ๐Ÿ™ˆ .dockerignore # Files to exclude from Docker build context โ”œโ”€โ”€ โš™๏ธ .editorconfig # EditorConfig for consistent coding styles -โ”œโ”€โ”€ ๐Ÿ”ง .env # Environment variables configuration โ”œโ”€โ”€ ๐Ÿ“„ example.conf # Example FreeNGINX configuration for HTTP/3 โ”œโ”€โ”€ ๐Ÿš€ freenginx.conf # Main FreeNGINX configuration file โ”œโ”€โ”€ ๐Ÿ›ก๏ธ freenginx-seccomp.json # Seccomp profile for FreeNGINX security From 03b864e185b967d7300a4e92269f676146c0702d Mon Sep 17 00:00:00 2001 From: ammnt Date: Wed, 23 Sep 2026 08:24:52 +0300 Subject: [PATCH 05/14] Revert "Remove .env file and update Dockerfile.template to set default values for OPENSSL_VERSION and APP_VERSION; update README to reflect removal of .env" This reverts commit 82fcad356dbf6a31d049b37f05730989fa97a7a0. --- .env | 4 ++++ .github/workflows/build.yml | 7 +++++++ Dockerfile.template | 6 +++--- README.md | 1 + 4 files changed, 15 insertions(+), 3 deletions(-) create mode 100644 .env diff --git a/.env b/.env new file mode 100644 index 0000000..6718e5c --- /dev/null +++ b/.env @@ -0,0 +1,4 @@ +BASE_VERSION=3.24.2 +BASE_HASH=31b6477333eb8257db9e5d7c3a7264fd0467928756f0bbcc27d35bea5d28cdbd +OPENSSL_VERSION=4.0.2 +APP_VERSION=1.31.4 diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index c3d5c83..a623db0 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -40,6 +40,13 @@ jobs: - name: Load .env variablesโ˜๏ธ id: load_env run: | + while IFS= read -r line; do + if [[ ! "$line" =~ ^# ]] && [[ -n "$line" ]]; then + key="${line%%=*}" + value="${line#*=}" + echo "$key=$value" >> $GITHUB_OUTPUT + fi + done < .env echo "BUILD_DATE=$(date -u +'%Y-%m-%dT%H:%M:%S')" >> $GITHUB_OUTPUT echo "VCS_REF=$(git rev-parse HEAD)" >> $GITHUB_OUTPUT diff --git a/Dockerfile.template b/Dockerfile.template index 1aecf5c..19b295b 100644 --- a/Dockerfile.template +++ b/Dockerfile.template @@ -2,8 +2,8 @@ ARG BASE_VERSION=3.24.2 ARG BASE_HASH=31b6477333eb8257db9e5d7c3a7264fd0467928756f0bbcc27d35bea5d28cdbd FROM alpine:${BASE_VERSION}@sha256:${BASE_HASH} AS builder -ARG OPENSSL_VERSION=4.0.2 -ARG APP_VERSION=1.31.4 +ARG OPENSSL_VERSION +ARG APP_VERSION SHELL ["/bin/ash", "-euo", "pipefail", "-c"] ENV CC=clang \ @@ -213,7 +213,7 @@ RUN ./auto/configure \ # Final distroless image FROM scratch -ARG APP_VERSION=1.31.4 +ARG APP_VERSION ARG BUILD_DATE ARG VCS_REF diff --git a/README.md b/README.md index 78d4caf..1872cb6 100644 --- a/README.md +++ b/README.md @@ -102,6 +102,7 @@ freenginx/ โ”œโ”€โ”€ ๐Ÿณ Dockerfile.template # Dockerfile template (dynamic generation) โ”œโ”€โ”€ ๐Ÿ™ˆ .dockerignore # Files to exclude from Docker build context โ”œโ”€โ”€ โš™๏ธ .editorconfig # EditorConfig for consistent coding styles +โ”œโ”€โ”€ ๐Ÿ”ง .env # Environment variables configuration โ”œโ”€โ”€ ๐Ÿ“„ example.conf # Example FreeNGINX configuration for HTTP/3 โ”œโ”€โ”€ ๐Ÿš€ freenginx.conf # Main FreeNGINX configuration file โ”œโ”€โ”€ ๐Ÿ›ก๏ธ freenginx-seccomp.json # Seccomp profile for FreeNGINX security From 30012d198e4c452fcb6b076e4203ce29cd198984 Mon Sep 17 00:00:00 2001 From: ammnt Date: Thu, 24 Sep 2026 19:37:17 +0300 Subject: [PATCH 06/14] fixed: ER0006 and ER0015 - dockerlinter warnings --- Dockerfile.template | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/Dockerfile.template b/Dockerfile.template index 19b295b..cebee9c 100644 --- a/Dockerfile.template +++ b/Dockerfile.template @@ -17,8 +17,8 @@ ENV CC=clang \ WORKDIR /tmp # System setup and dependency installation RUN addgroup --system --gid "10001" freenginx && adduser --disabled-password --shell /bin/false --ingroup freenginx --uid "10001" --no-create-home freenginx \ - # Update system and install build dependencies - && apk -U -q upgrade && apk add -q --no-cache \ + # Install build dependencies + && apk add -q --no-cache \ clang22=22.1.3-r2 \ lld22=22.1.3-r0 \ llvm=22-r0 \ @@ -32,7 +32,7 @@ RUN addgroup --system --gid "10001" freenginx && adduser --disabled-password --s cmake=4.2.3-r0 \ zstd-dev=1.5.7-r2 \ zstd-static=1.5.7-r2 \ - brotli-dev=1.2.0-r1 \ + brotli-dev=1.2.0-r1 \ brotli-static=1.2.0-r1 \ autoconf=2.73-r0 \ automake=1.18.1-r1 \ From 938ca6a74180f80f2a0467fb6753c8f5521f6d94 Mon Sep 17 00:00:00 2001 From: ammnt Date: Thu, 24 Sep 2026 20:35:49 +0300 Subject: [PATCH 07/14] Fix ssl_ecdh_curve syntax in example.conf for improved compatibility --- example.conf | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/example.conf b/example.conf index 3ee185f..c6740a2 100644 --- a/example.conf +++ b/example.conf @@ -47,11 +47,11 @@ http { ssl_session_timeout 1440m; ssl_buffer_size 4k; # ssl_protocols TLSv1.3; - # ssl_ecdh_curve X25519MLKEM768:X25519; + # ssl_ecdh_curve ?X25519MLKEM768:X25519; # ssl_ciphers TLS_CHACHA20_POLY1305_SHA256:TLS_AES_256_GCM_SHA384:ECDHE:!COMPLEMENTOFDEFAULT; # ssl_conf_command Ciphersuites TLS_CHACHA20_POLY1305_SHA256:TLS_AES_256_GCM_SHA384; ssl_protocols TLSv1.3 TLSv1.2; - ssl_ecdh_curve X25519MLKEM768:X25519:SecP384r1MLKEM1024:SecP256r1MLKEM768:secp521r1:secp384r1; + ssl_ecdh_curve ?X25519MLKEM768:X25519:?SecP384r1MLKEM1024:?SecP256r1MLKEM768:secp521r1:secp384r1; ssl_ciphers TLS_CHACHA20_POLY1305_SHA256:TLS_AES_256_GCM_SHA384:ECDH+AESGCM+AES256:ECDH+CHACHA20; ssl_conf_command Options ServerPreference,PrioritizeChaCha; ssl_conf_command Ciphersuites TLS_CHACHA20_POLY1305_SHA256:TLS_AES_256_GCM_SHA384:ECDH+AESGCM+AES256:ECDH+CHACHA20; From d2aa3f98dc4b73f49dfd9de60b405947b0952056 Mon Sep 17 00:00:00 2001 From: ammnt Date: Sat, 26 Sep 2026 19:34:14 +0300 Subject: [PATCH 08/14] Update perl version in Dockerfile.template and configure git to suppress detached head advice --- Dockerfile.template | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/Dockerfile.template b/Dockerfile.template index cebee9c..ebb0eed 100644 --- a/Dockerfile.template +++ b/Dockerfile.template @@ -28,7 +28,7 @@ RUN addgroup --system --gid "10001" freenginx && adduser --disabled-password --s build-base=0.5-r4 \ linux-headers=7.0.0-r1 \ upx=5.2.0-r0 \ - perl=5.42.2-r0 \ + perl=5.42.2-r1 \ cmake=4.2.3-r0 \ zstd-dev=1.5.7-r2 \ zstd-static=1.5.7-r2 \ @@ -38,6 +38,7 @@ RUN addgroup --system --gid "10001" freenginx && adduser --disabled-password --s automake=1.18.1-r1 \ libtool=2.6.0-r1 \ python3-dev=3.14.7-r1 \ + && git config --global advice.detachedHead false \ && PCRE_VERSION=$(git ls-remote --tags --refs https://github.com/PCRE2Project/pcre2 'pcre2-*' | grep -v -- '-RC' | sed 's|.*/||' | tail -1) \ && ZLIB_VERSION=$(git ls-remote --tags --refs https://github.com/zlib-ng/zlib-ng | sed 's|.*/||' | sed 's/^v//' | sort -V | tail -1) \ && ZSTD_VERSION=$(git ls-remote --tags --refs https://github.com/tokers/zstd-nginx-module | sed 's|.*/||' | sort -V | tail -1) \ From ac405560e3d824c10b1326a46276cd920ffaee14 Mon Sep 17 00:00:00 2001 From: ammnt Date: Tue, 29 Sep 2026 20:09:24 +0300 Subject: [PATCH 09/14] Update OPENSSL_VERSION to 4.0.3 in .env file --- .env | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.env b/.env index 6718e5c..4e5e116 100644 --- a/.env +++ b/.env @@ -1,4 +1,4 @@ BASE_VERSION=3.24.2 BASE_HASH=31b6477333eb8257db9e5d7c3a7264fd0467928756f0bbcc27d35bea5d28cdbd -OPENSSL_VERSION=4.0.2 +OPENSSL_VERSION=4.0.3 APP_VERSION=1.31.4 From e740a172875fb22df15f14a6c2ee1f2145df8467 Mon Sep 17 00:00:00 2001 From: ammnt Date: Sat, 3 Oct 2026 12:06:50 +0300 Subject: [PATCH 10/14] Update build environment to use Ubuntu 26.04 and upgrade python3-dev to version 3.14.8 --- .github/workflows/build.yml | 2 +- Dockerfile.template | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index a623db0..02aa8c6 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -18,7 +18,7 @@ env: jobs: build-and-publish: if: github.actor == 'ammnt' - runs-on: ubuntu-24.04 + runs-on: ubuntu-26.04 permissions: contents: read packages: write diff --git a/Dockerfile.template b/Dockerfile.template index ebb0eed..eb1856a 100644 --- a/Dockerfile.template +++ b/Dockerfile.template @@ -37,7 +37,7 @@ RUN addgroup --system --gid "10001" freenginx && adduser --disabled-password --s autoconf=2.73-r0 \ automake=1.18.1-r1 \ libtool=2.6.0-r1 \ - python3-dev=3.14.7-r1 \ + python3-dev=3.14.8-r0 \ && git config --global advice.detachedHead false \ && PCRE_VERSION=$(git ls-remote --tags --refs https://github.com/PCRE2Project/pcre2 'pcre2-*' | grep -v -- '-RC' | sed 's|.*/||' | tail -1) \ && ZLIB_VERSION=$(git ls-remote --tags --refs https://github.com/zlib-ng/zlib-ng | sed 's|.*/||' | sed 's/^v//' | sort -V | tail -1) \ From 3d685f84edaa9976e32bb6a478adfd04f1cb574f Mon Sep 17 00:00:00 2001 From: ammnt Date: Sun, 4 Oct 2026 12:56:20 +0300 Subject: [PATCH 11/14] Update CI/CD workflows to use Ubuntu 26.04 and adjust failure thresholds in hadolint configuration --- .github/workflows/build.yml | 17 +++++------------ hadolint.yaml | 2 +- 2 files changed, 6 insertions(+), 13 deletions(-) diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index 02aa8c6..62f0833 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -156,7 +156,7 @@ jobs: security-scans: needs: build-and-publish - runs-on: ubuntu-24.04 + runs-on: ubuntu-26.04 permissions: contents: read security-events: write @@ -185,7 +185,7 @@ jobs: curl -sSfLO "https://github.com/bridgecrewio/checkov/releases/latest/download/checkov_linux_X86_64.zip" unzip -q ./checkov_linux_X86_64.zip ./dist/checkov \ - --quiet \ + --quiet -s \ --output sarif \ --output-file-path results \ --framework dockerfile \ @@ -199,8 +199,6 @@ jobs: with: image: ghcr.io/ammnt/freenginx:${{ needs.build-and-publish.outputs.app_version }} format: sarif - exit-code: "1" - exit-level: "warn" ignore: "CIS-DI-0005,CIS-DI-0010" output: "dockle.sarif" @@ -218,8 +216,7 @@ jobs: image: ghcr.io/ammnt/freenginx:${{ needs.build-and-publish.outputs.app_version }} sarif-file: scout.sarif write-comment: true - summary: false - exit-code: true + summary: true github-token: ${{ secrets.GH_TOKEN }} - name: Trivy scan๐Ÿ›ก๏ธ @@ -230,9 +227,6 @@ jobs: scan-type: image format: sarif output: trivy.sarif - severity: "MEDIUM,HIGH,CRITICAL" - scanners: "vuln,secret" - exit-code: "1" github-pat: ${{ secrets.GH_TOKEN }} trivy-config: trivy.yaml @@ -242,7 +236,6 @@ jobs: with: image: ghcr.io/ammnt/freenginx:${{ needs.build-and-publish.outputs.app_version }} fail-build: false - severity-cutoff: critical output-format: sarif output-file: grype.sarif @@ -254,7 +247,7 @@ jobs: with: image: ghcr.io/ammnt/freenginx:${{ needs.build-and-publish.outputs.app_version }} sarif: true - args: --file=Dockerfile.template --sarif-file-output=snyk.sarif + args: --file=Dockerfile.template --severity-threshold=critical --sarif-file-output=snyk.sarif - name: Generate SBOM with Syft๐Ÿ“‹ if: matrix.scanner == 'syft' @@ -286,7 +279,7 @@ jobs: release: needs: [build-and-publish, security-scans] - runs-on: ubuntu-24.04 + runs-on: ubuntu-26.04 permissions: contents: write steps: diff --git a/hadolint.yaml b/hadolint.yaml index 34e91da..c90f807 100644 --- a/hadolint.yaml +++ b/hadolint.yaml @@ -1,4 +1,4 @@ -failure-threshold: warning +failure-threshold: error no-color: false no-fail: true trustedRegistries: From 916ef02ac47617bc44d5f2266fdb8b642293fd64 Mon Sep 17 00:00:00 2001 From: ammnt Date: Sun, 4 Oct 2026 13:30:41 +0300 Subject: [PATCH 12/14] Enhance .env variable loading to ensure only valid key-value pairs are processed --- .github/workflows/build.yml | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index 62f0833..f8d1ab9 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -40,8 +40,9 @@ jobs: - name: Load .env variablesโ˜๏ธ id: load_env run: | + set -euo pipefail while IFS= read -r line; do - if [[ ! "$line" =~ ^# ]] && [[ -n "$line" ]]; then + if [[ ! "$line" =~ ^# ]] && [[ -n "$line" ]] && [[ "$line" == *=* ]]; then key="${line%%=*}" value="${line#*=}" echo "$key=$value" >> $GITHUB_OUTPUT From 91586c8ab0d4bfb16ef359dc7ce02c5c6dcbf3d9 Mon Sep 17 00:00:00 2001 From: ammnt Date: Sun, 4 Oct 2026 18:19:20 +0300 Subject: [PATCH 13/14] Enhance .env variable loading to ensure only valid key-value pairs are processed --- .github/workflows/build.yml | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index f8d1ab9..73ee023 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -92,6 +92,7 @@ jobs: - name: Slim and push image with Mint๐Ÿ”ง run: | + set -euo pipefail curl -sSfL "https://github.com/mintoolkit/mint/releases/latest/download/dist_linux.tar.gz" | tar -zxf - ./dist_linux/mint --quiet build \ --target ghcr.io/ammnt/freenginx:${{ steps.load_env.outputs.APP_VERSION }} \ @@ -111,6 +112,7 @@ jobs: - name: Get image digest๐Ÿ”ข id: digest run: | + set -euo pipefail DIGEST=$(docker inspect -f='{{index .RepoDigests 0}}' ghcr.io/ammnt/freenginx:${{ steps.load_env.outputs.APP_VERSION }} | cut -d'@' -f2) echo "digest=$DIGEST" >> $GITHUB_OUTPUT @@ -118,6 +120,7 @@ jobs: env: CI: true run: | + set -euo pipefail export DIVE_VERSION=$(curl -sSfL "https://api.github.com/repos/wagoodman/dive/releases/latest" | jq -r '.tag_name // empty' | sed -E 's/^v?([0-9][^"]+).*/\1/') curl -sSfL "https://github.com/wagoodman/dive/releases/download/v${DIVE_VERSION}/dive_${DIVE_VERSION}_linux_amd64.tar.gz" | tar -zxf - ./dive --config ./dive-ci.yml -j dive.report.json ghcr.io/ammnt/freenginx:${{ steps.load_env.outputs.APP_VERSION }} @@ -152,6 +155,7 @@ jobs: COSIGN_KEY: ${{ secrets.COSIGN_KEY }} COSIGN_PASSWORD: ${{ secrets.COSIGN_PASSWORD }} run: | + set -euo pipefail cosign sign -y --key env://COSIGN_KEY ghcr.io/ammnt/freenginx@${{ steps.digest.outputs.digest }} cosign sign -y --key env://COSIGN_KEY ammnt/freenginx@${{ steps.digest.outputs.digest }} @@ -183,6 +187,7 @@ jobs: - name: Checkov scan๐Ÿ” if: matrix.scanner == 'checkov' run: | + set -euo pipefail curl -sSfLO "https://github.com/bridgecrewio/checkov/releases/latest/download/checkov_linux_X86_64.zip" unzip -q ./checkov_linux_X86_64.zip ./dist/checkov \ From 8ee6e35779068d61ead78a324eb2d152a069fa6b Mon Sep 17 00:00:00 2001 From: ammnt Date: Sun, 4 Oct 2026 19:33:53 +0300 Subject: [PATCH 14/14] Remove BASE_VERSION and BASE_HASH from CI/CD workflow outputs and build arguments --- .env | 2 -- .github/workflows/build.yml | 2 -- 2 files changed, 4 deletions(-) diff --git a/.env b/.env index 4e5e116..71e3f2e 100644 --- a/.env +++ b/.env @@ -1,4 +1,2 @@ -BASE_VERSION=3.24.2 -BASE_HASH=31b6477333eb8257db9e5d7c3a7264fd0467928756f0bbcc27d35bea5d28cdbd OPENSSL_VERSION=4.0.3 APP_VERSION=1.31.4 diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index 73ee023..087dd2e 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -83,8 +83,6 @@ jobs: cache-from: type=gha cache-to: type=gha,mode=max build-args: | - BASE_VERSION=${{ steps.load_env.outputs.BASE_VERSION }} - BASE_HASH=${{ steps.load_env.outputs.BASE_HASH }} OPENSSL_VERSION=${{ steps.load_env.outputs.OPENSSL_VERSION }} APP_VERSION=${{ steps.load_env.outputs.APP_VERSION }} VCS_REF=${{ steps.load_env.outputs.VCS_REF }}