تخطَّ إلى المحتوى
QuenchWorks

ghost 0.0.4

مخطط · Apps & productivity · standard · v0.0.4

مثبّتة بالبصمةموقّعة بـ cosignSPDX SBOMمنشأ SLSAamd64 · arm64

Open-source Node.js publishing platform for blogs, newsletters, and membership sites. Packaged from Ghost's official npm distribution on a hardened Wolfi Node 22; configured entirely via environment and backed by an external MySQL/MariaDB with a content PVC for themes, images, and data.

الإصدار

يعيش الخط الأحدث في الصفحة الأساسية؛ وللخطوط الأقدم صفحاتها الخاصة لتتمكّن من تثبيت ذلك الإصدار بالضبط والتحقق منه.

إصدار صادر

هذا هو إصدار 0.0.4 من مخطط ghost ، نُشر بتاريخ 2026-07-10.للاطّلاع على تقرير الأمان الحي وبصمة الصورة المنشورة حاليًا، راجع أحدث إصدار.

موقّعة
cosign بدون مفتاح
SBOM
SPDX، على الصورة
المنشأ
بناء SLSA
المعماريات
amd64، arm64
تعمل كـ
nonroot (uid 1001)
نظام الملفات الجذر
للقراءة فقط

تقرير الأمان (Trivy)

D· 0/10020 fixable · rebuild clears them

تفاصيل الثغرات

ghost 6.55.0 · 25 CVE
الثغرة (CVE)الخطورةالحزمةالإصدار المثبَّتمُصلَحة فيالوصف
CVE-2026-13697HIGHundici7.28.07.29.0, 8.9.0undici: undici: Information disclosure and Denial of Service via malformed Cache-Control directives
CVE-2026-18446HIGHfast-uri3.1.42.4.4, 3.1.5, 4.1.2fast-uri: fast-uri: Host confusion vulnerability via backslash in URI authority
CVE-2026-58043HIGHnodejs-2222.23.1-r122.23.2-r0nodejs: Node.js: Unauthorized filesystem access due to Permission Model enforcement flaw
CVE-2026-67213HIGHnanoid3.3.163.3.17, 5.1.6nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customA ...
CVE-2026-69152HIGHbrace-expansion5.0.81.1.18, 2.1.4, 3.0.6, 5.0.9brace-expansion: brace-expansion: Denial of Service via unbounded intermediate arrays
CVE-2026-69192HIGHip-address10.2.010.3.1ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass
GHSA-5p4m-2wfm-xmqjHIGHjs-yaml4.3.04.3.1, 3.15.1JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported
CVE-2020-8203HIGHlodash.pick4.4.0غير قابلة للإصلاحnodejs-lodash: prototype pollution in zipObjectDeep function
CVE-2022-37620HIGHhtml-minifier4.0.0غير قابلة للإصلاحkangax html-minifier REDoS vulnerability
CVE-2025-71329HIGHimage-size1.2.1غير قابلة للإصلاحimage-size: image-size: Denial of Service via crafted image buffer with zero-valued size field
CVE-2025-71330HIGHimage-size1.2.1غير قابلة للإصلاحimage-size: image-size: Denial of Service via crafted ICNS image buffer
CVE-2026-14643MEDIUMundici7.28.07.29.0, 8.9.0undici: undici: Cross-user information disclosure due to improper Cache-Control directive parsing
CVE-2026-15157MEDIUMundici6.27.06.28.0, 7.29.0, 8.9.0undici: undici: HTTP header injection via unvalidated blob-like body type property
CVE-2026-15157MEDIUMundici7.28.06.28.0, 7.29.0, 8.9.0undici: undici: HTTP header injection via unvalidated blob-like body type property
CVE-2026-16728MEDIUMundici6.27.06.28.0, 7.29.0, 8.9.0undici: undici: Response desynchronization via retry interceptor with mismatched Content-Length
CVE-2026-16728MEDIUMundici7.28.06.28.0, 7.29.0, 8.9.0undici: undici: Response desynchronization via retry interceptor with mismatched Content-Length
CVE-2026-16729MEDIUMundici6.27.06.28.0, 7.29.0, 8.9.0undici: Undici: Cookie attribute injection allows bypassing security protections
CVE-2026-16729MEDIUMundici7.28.06.28.0, 7.29.0, 8.9.0undici: Undici: Cookie attribute injection allows bypassing security protections
CVE-2026-54272MEDIUMip-address10.2.010.2.1ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification
CVE-2026-56850MEDIUMnodejs-2222.23.1-r122.23.2-r0nodejs: Node.js: mTLS client identities can be reused due to HTTPS Agent connection flaw
CVE-2026-69198MEDIUMip-address10.2.010.2.2ip-address: ip-address: Server-Side Request Forgery (SSRF) and trust-boundary bypass
CVE-2026-71498MEDIUMre21.25.21.26.1node-re2 provides RE2 regular expression bindings for Node.js. Prior t ...
GHSA-55q2-fjhq-7xh7MEDIUMdompurify3.4.123.4.13DOMPurify: IN_PLACE hook removal leaves a detached subtree executable, causing XSS
GHSA-984p-xq9m-4rjwMEDIUMexpress-brute1.0.1غير قابلة للإصلاحRate Limiting Bypass in express-brute
CVE-2026-56847LOWnodejs-2222.23.1-r122.23.2-r0A flaw in Node.js Permission Model enforcement allows `trace_events.cr ...
0
حرجة
11
عالية
13
متوسطة
1
منخفضة
0
غير معروفة

تقرير الأمان (Trivy) · image ghost 6.55.0

ثبّت المخطط

انشر إلى Kubernetes بإعدادات افتراضية مُحصّنة. يثبّت المخطط صورته ببصمة موقّعة، فلا تتعقّبها بنفسك أبدًا.

تثبيت (مثبّت على 0.0.4)

helm install my-ghost oci://ghcr.io/quenchworks/charts/ghost --version 0.0.4
إصدار المخطط
0.0.4
رخصة المخطط
MIT
رخصة التطبيق
MIT
منفذ الخدمة
2368
موقّع
cosign (بدون مفتاح)
صدر
2026-07-10

تحقّق من المخطط

cosign verify ghcr.io/quenchworks/charts/ghost:0.0.4 \
  --certificate-identity-regexp 'https://github.com/quenchworks/.+' \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com

الشفافية

يَنشُر المخطط شهاداته على GitHub ، والصورة التي ينشرها تحمل شهاداتها على البصمة نفسها، قابلة للتحقق علنًا بالأوامر أعلاه. كلاهما يُسجَّل في سجلّ شفافية Sigstore (Rekor)، الذي يفحصه cosign verify نيابةً عنك.

المشروع المنبع: https://ghost.org