From 90b2b811787b588731f14dc0da8f4577966bb6c0 Mon Sep 17 00:00:00 2001 From: Claude Date: Mon, 20 Jul 2026 09:14:39 +0000 Subject: [PATCH] chore(deps): bump traefik from v3.3 to v3.7 in traefik feature The pinned traefik image (v3.3, released Dec 2024) is on an unmaintained minor branch. Current upstream security fixes only land on v3.7.x/v3.6.x/v2.11.x. Notably CVE-2026-33186 (gRPC-Go HTTP/2 :path pseudo-header authorization bypass, CVSS 7.8) was fixed in v3.6.12/v3.7.0-ea.3 and is not backported to v3.3. Bumping to the v3.7 floating tag keeps the container on a supported, patched branch. Also bumps the traefik feature's own devcontainer-feature.json version (1.3.1 -> 1.3.2) per this repo's semver convention for tool version bumps. --- src/traefik/devcontainer-feature.json | 2 +- src/traefik/install.sh | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/src/traefik/devcontainer-feature.json b/src/traefik/devcontainer-feature.json index 2eb98ba..67fde9f 100644 --- a/src/traefik/devcontainer-feature.json +++ b/src/traefik/devcontainer-feature.json @@ -1,6 +1,6 @@ { "id": "traefik", - "version": "1.3.1", + "version": "1.3.2", "name": "Traefik Reverse Proxy", "description": "Traefik reverse proxy with subdomain routing to local services", "documentationURL": "https://doc.traefik.io/traefik/", diff --git a/src/traefik/install.sh b/src/traefik/install.sh index 717846f..5423603 100644 --- a/src/traefik/install.sh +++ b/src/traefik/install.sh @@ -49,7 +49,7 @@ chmod 666 "$CONFIG_DIR/traefik.yml" cat > "$CONFIG_DIR/docker-compose.yml" <