Skip to content

Conversation

@trottomv
Copy link
Owner

@trottomv trottomv commented Sep 4, 2025

  • Upgrade to jinja2~=3.1.0
  • Remove hardcoded secrets using os.getenv
  • Add timeout handler to requests
  • Security hardening of Dockerfile
  • Fix SSTI vulnerability on jinja2 template rendering
  • Turn on coraza waf

@trottomv trottomv self-assigned this Sep 4, 2025
@trottomv trottomv force-pushed the security-remediations branch 2 times, most recently from 9967050 to 76fb0a0 Compare September 4, 2025 15:19
@trottomv trottomv force-pushed the security-remediations branch 2 times, most recently from 12b8790 to 2748d5c Compare November 2, 2025 07:38
- Upgrade to jinja2~=3.1.0
- Remove hardcoded secrets using os.getenv
- Add timeout handler to requests
- Security hardening of Dockerfile
- Fix SSTI vulnerability on jinja2 template rendering
- Turn on coraza waf
@trottomv trottomv force-pushed the security-remediations branch from 2748d5c to 9188789 Compare November 2, 2025 11:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants