Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

build: bump nginx 1.27.0 to 1.27.1 #2506

Merged
merged 2 commits into from
Aug 27, 2024
Merged

Conversation

SchoNie
Copy link
Contributor

@SchoNie SchoNie commented Aug 27, 2024

Normally Dependabot will trigger this but there is an issue: dependabot/dependabot-core#10452 the nginx 1.27.1 image is being detected as pre-release.

I waited 2 weeks but there seems no progress in that issue so I decided to create this PR.

Changes with nginx 1.27.1                                        14 Aug 2024

*) Security: processing of a specially crafted mp4 file by the
   ngx_http_mp4_module might cause a worker process crash
   (CVE-2024-7347).
   Thanks to Nils Bars.

*) Change: now the stream module handler is not mandatory.

*) Bugfix: new HTTP/2 connections might ignore graceful shutdown of old
   worker processes.
   Thanks to Kasei Wang.

*) Bugfixes in HTTP/3.

@buchdag buchdag added the type/build PR that affect the build system or external dependencies label Aug 27, 2024
Link to nginx changelog

Co-authored-by: Nicolas Duchon <[email protected]>
@buchdag buchdag merged commit 1baf048 into nginx-proxy:main Aug 27, 2024
2 checks passed
@SchoNie SchoNie deleted the nginx-1.27.1 branch August 27, 2024 20:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
type/build PR that affect the build system or external dependencies
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants