0.46.5 — h2 DoS fix + nginx security headers
Security + hardening
- server —
h20.4.14 → 0.4.18, patching RUSTSEC-2026-0258 (HTTP/2 unbounded empty DATA frames — DoS). Surgical bump:sqlx/pgvectorunchanged, verified with the--release --lockedbuild. - client + docs (nginx) — security headers (CSP et al.) are now re-applied on asset / service-worker / manifest responses. nginx replaces inherited
add_headerin any block that adds its own, so those responses had been served without the security headers.
Other RustSec transitive advisories remain accepted (no safe upstream fix; vulnerable paths unreachable here — a blanket cargo update breaks pgvector/sqlx, so they need a coordinated bump). See SECURITY-SCAN-REPORT.md.
🐳 ghcr.io/dim145/figurecollector-{server,client,docs}:0.46.5
📝 Full changelog: 0.46.4...0.46.5