build: bump forgejo/postgres/ntfy images, pin caddy alpine variant #62

Sammanfogat
supernaut sammanfogade 1 incheckning från build/forgejo-v15.0.4 in i main 2026-07-10 12:39:22 +00:00
Ägare

Bumps the four core container images and aligns one runbook command.

Changes

Image From → To Notes
forgejo 15.0.3 → 15.0.4 Security release — write-perm cache fix, migration allow/deny-list enforcement (onedev/pagure/codebase), Go 1.26.5 + x/image bumps. No breaking changes.
postgres 17-trixie → 17.10-trixie Pins the floating minor tag (the repo's PIN versions; never use 'latest' convention).
caddy 2.11.4 → 2.11.4-alpine Base-image variant switch (Debian → Alpine/musl). Low risk — Caddy is a static Go binary — and smaller. Note: superseded once the custom xcaddy build in #48 lands.
ntfy v2.25.0 → v2.26.0 Security release — template CPU-DoS timeout, Markdown javascript:/data: URL stripping.

Docs:

  • README-runner-image.md — server-version reference updated to 15.0.4.
  • docs/runbook.md — the caddy hash-password command now uses the pinned 2.11.4-alpine tag so it reuses the image already on the host.

Why manual

These *_image_tag YAML variables aren't tracked by Renovate (bare config:recommended has no manager for them), so they were found and bumped by hand. Tracked in #61.

Apply

Two of these are security releases — apply reasonably promptly. ansible-playbook site.yml re-pulls the pinned tags and restarts the affected containers (Forgejo, Postgres, Caddy on all hosts, ntfy on monitoring).

Refs #61

Bumps the four core container images and aligns one runbook command. ## Changes | Image | From → To | Notes | | --- | --- | --- | | `forgejo` | `15.0.3` → `15.0.4` | **Security release** — write-perm cache fix, migration allow/deny-list enforcement (onedev/pagure/codebase), Go 1.26.5 + `x/image` bumps. No breaking changes. | | `postgres` | `17-trixie` → `17.10-trixie` | Pins the floating minor tag (the repo's *PIN versions; never use 'latest'* convention). | | `caddy` | `2.11.4` → `2.11.4-alpine` | **Base-image variant switch** (Debian → Alpine/musl). Low risk — Caddy is a static Go binary — and smaller. Note: superseded once the custom `xcaddy` build in #48 lands. | | `ntfy` | `v2.25.0` → `v2.26.0` | **Security release** — template CPU-DoS timeout, Markdown `javascript:`/`data:` URL stripping. | Docs: - `README-runner-image.md` — server-version reference updated to `15.0.4`. - `docs/runbook.md` — the `caddy hash-password` command now uses the pinned `2.11.4-alpine` tag so it reuses the image already on the host. ## Why manual These `*_image_tag` YAML variables aren't tracked by Renovate (bare `config:recommended` has no manager for them), so they were found and bumped by hand. Tracked in #61. ## Apply Two of these are security releases — apply reasonably promptly. `ansible-playbook site.yml` re-pulls the pinned tags and restarts the affected containers (Forgejo, Postgres, Caddy on all hosts, ntfy on monitoring). Refs #61
supernaut lade till 1 incheckning 2026-07-10 12:29:00 +00:00
- forgejo 15.0.3 → 15.0.4 (security: write-perm cache, migration allow/deny-list
  enforcement across onedev/pagure/codebase, go 1.26.5 + x/image bumps)
- postgres 17-trixie → 17.10-trixie (pin the floating minor tag)
- caddy 2.11.4 → 2.11.4-alpine (switch to the alpine base variant)
- ntfy v2.25.0 → v2.26.0 (security: template CPU-DoS timeout, markdown
  javascript:/data: URL stripping)
- docs(runbook): hash-password command uses the pinned alpine caddy tag

Container image tags aren't Renovate-tracked, so these were found manually; see #61.
supernaut sammanfogade incheckning 3fcb9b17a7 till main 2026-07-10 12:39:22 +00:00
supernaut tog bort grenen build/forgejo-v15.0.4 2026-07-10 12:39:23 +00:00
supernaut refererade denna ändringsförfrågan från en incheckning 2026-07-29 21:08:22 +00:00
supernaut refererade denna ändringsförfrågan från en incheckning 2026-07-29 21:23:51 +00:00
supernaut refererade denna ändringsförfrågan från en incheckning 2026-08-03 09:41:34 +00:00
supernaut refererade denna ändringsförfrågan från en incheckning 2026-08-03 09:41:34 +00:00
Logga in för att delta i denna konversation.
Inga granskare
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra!62
Ingen beskrivning angiven.