تخطَّ إلى المحتوى
QuenchWorks

ghost

صورة · Apps & productivity · standard · v6.57.1

D 30موقّعة بـ cosignSPDX SBOMمنشأ SLSAamd64 · arm64أُعيد بناؤها 2026-08-26

Open-source Node.js publishing platform for blogs, newsletters, and membership sites. Packaged from Ghost's official npm distribution on a hardened Wolfi Node 22; configured entirely via environment and backed by an external MySQL/MariaDB with a content PVC for themes, images, and data.

الإصدار

يعيش الخط الأحدث في الصفحة الأساسية؛ وللخطوط الأقدم صفحاتها الخاصة لتتمكّن من تثبيت ذلك الإصدار بالضبط والتحقق منه.

البصمة الحالية (التي ينشرها المخطط)

sha256:e2f5df3f4bc83722eb8e82b4e07eb697ed1d08d024c94d910aa30681e5eb506a

تُرفَق التواقيع وقائمة المكوّنات والمنشأ جميعها بهذه البصمة. ثبّت عليها لعمليات سحب قابلة للتكرار ومقاومة للعبث.

موقّعة
cosign بدون مفتاح
SBOM
SPDX، على البصمة
المنشأ
بناء SLSA
المعماريات
amd64، arm64
تعمل كـ
nonroot (uid 1001)
نظام الملفات الجذر
للقراءة فقط
حجم الصورة
175.2 MB

الإصدارات المنشورة

6 وسوم

كل وسم هو فهرس متعدد المعماريات (amd64 + arm64) مثبّت بالبصمة. موسوم بالإصدار، وليس أبدًا :latest.

الإصدارالحجمالنشرالبصمة
6.57.1الأحدث175.2 MB2026-08-26sha256:e2f5df3f4bc8…
6.55.0182.8 MB2026-08-02sha256:39498f8e00d8…
6.54.1182.8 MB2026-07-28sha256:7f589269c385…
6.54.0182.7 MB2026-07-28sha256:f96aead1ba13…
6.52.1397.7 MB2026-07-14sha256:a6d36a40663d…
6.49.0372.1 MB2026-06-28sha256:d6b815df0eee…

تقرير الأمان (Trivy)

D· 0/10023 fixable · rebuild clears them

تفاصيل الثغرات

ghost 6.57.1 · 30 CVE
الثغرة (CVE)الخطورةالحزمةالإصدار المثبَّتمُصلَحة فيالوصف
CVE-2026-75899HIGHfast-uri3.1.52.4.5, 3.1.6, 4.1.3fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding
CVE-2026-75931HIGHfast-uri3.1.52.4.5, 3.1.6, 4.1.3fast-uri: fast-uri: Host confusion via skipped IDN canonicalization
CVE-2026-75975HIGHfast-uri3.1.52.4.5, 3.1.6, 4.1.3fast-uri: fast-uri: Server-side request forgery via malformed IPv6 normalization
CVE-2026-76172HIGHfast-uri3.1.52.4.5, 3.1.6, 4.1.3fast-uri: fast-uri: URI parsing flaw enables server-side request forgery and redirects
CVE-2026-77037HIGHmulter2.2.02.3.0multer vulnerable to Denial of Service via file descriptor leak on aborted uploads
CVE-2026-77078HIGHmulter2.2.02.3.0multer vulnerable to Denial of Service via crafted multipart field names
CVE-2026-82333HIGHmulter2.2.02.3.0multer vulnerable to Denial of Service via oversized array index in field names
CVE-2026-84375HIGHjs-yaml4.3.14.3.2, 3.15.2js-yaml: js-yaml: Denial of Service vulnerability in YAML parsing
GHSA-2x7j-588g-ccc2HIGHnodemailer9.0.19.1.0Nodemailer: Quadratic (O(n²)) time complexity in addressparser allows remote denial of service via a crafted address list
GHSA-rgj7-g3m4-5g8cHIGHsharp0.35.30.35.4sharp: Vulnerabilities in libheif: GHSA-g89c-p67h-r497 and GHSA-2jg2-4ch7-h545
CVE-2020-8203HIGHlodash.pick4.4.0غير قابلة للإصلاحnodejs-lodash: prototype pollution in zipObjectDeep function
CVE-2022-37620HIGHhtml-minifier4.0.0غير قابلة للإصلاحkangax html-minifier REDoS vulnerability
CVE-2025-71329HIGHimage-size1.2.1غير قابلة للإصلاحimage-size: image-size: Denial of Service via crafted image buffer with zero-valued size field
CVE-2025-71330HIGHimage-size1.2.1غير قابلة للإصلاحimage-size: image-size: Denial of Service via crafted ICNS image buffer
CVE-2026-19693HIGHextract-zip2.0.1غير قابلة للإصلاحextract-zip: extract-zip: Arbitrary file write via symlink in archive
CVE-2026-56876HIGHextract-zip2.0.1غير قابلة للإصلاحextract-zip: github.com/maxogden/extract-zip: extract-zip: Arbitrary file write and information disclosure via symlink validation bypass
CVE-2026-18374MEDIUMglibc-2.442.44-r12.44-r6glibc: glibc: Heap buffer overflow via attacker-controlled fopen mode string
CVE-2026-18374MEDIUMglibc-2.44-locale-posix2.44-r12.44-r6glibc: glibc: Heap buffer overflow via attacker-controlled fopen mode string
CVE-2026-18374MEDIUMld-linux-2.442.44-r12.44-r6glibc: glibc: Heap buffer overflow via attacker-controlled fopen mode string
CVE-2026-63670MEDIUMsanitize-html2.17.52.17.6ApostropheCMS: Mutation-XSS / allowedTags bypass via literal `</textarea/>` solidus close
CVE-2026-82417MEDIUMqs6.15.36.16.0qs: qs: Denial of Service via improper validation in stringify function
CVE-2026-82562MEDIUMqs6.15.36.16.0qs: qs: Denial of Service via array limit bypass in query string parsing
CVE-2026-84371MEDIUMsanitize-html2.17.52.17.7sanitize-html: stored XSS via SVG SMIL URI-list scheme-policy bypass
CVE-2026-85091MEDIUMzlib1.3.2-r41.3.3-r0zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vul ...
GHSA-8m3c-c648-2xjjMEDIUMnodemailer9.0.19.1.1Nodemailer: resolveContent() on a MailMessage bypasses disableFileAccess/disableUrlAccess when called with the legacy signature
GHSA-cc9r-2j5m-2m83MEDIUMnodemailer9.0.19.1.0Nodemailer: Recipient-domain validation bypass via RFC 5322 comment mis-parsing leads to email delivery to an attacker-controlled domain
GHSA-rgwj-5xj2-c3m3MEDIUMmysql23.22.53.23.1MySQL2: Unbounded zlib inflate in compressed MySQL protocol handler allows decompression-bomb DoS
GHSA-wmmp-3585-3rmpMEDIUMnodemailer9.0.19.1.0Nodemailer: IDN/Punycode domain allow-list bypass leads to email delivery to an attacker-controlled domain
GHSA-984p-xq9m-4rjwMEDIUMexpress-brute1.0.1غير قابلة للإصلاحRate Limiting Bypass in express-brute
CVE-2026-77063LOWmulter2.2.02.3.0multer vulnerable to file size limit bypass via async fileFilter race condition
0
حرجة
16
عالية
13
متوسطة
1
منخفضة
0
غير معروفة

اسحب الصورة

شغّلها مباشرة باستخدام Docker أو Podman أو أي عبء عمل في Kubernetes. تعمل بدون صلاحيات الجذر، بنظام ملفات جذر للقراءة فقط، ومبنية لـ amd64 و arm64.

اسحب (وسم)

docker pull ghcr.io/quenchworks/images/ghost:6.57.1

مثبّتة بالبصمة (موصى به)

docker pull ghcr.io/quenchworks/images/ghost@sha256:e2f5df3f4bc83722eb8e82b4e07eb697ed1d08d024c94d910aa30681e5eb506a

الوسوم

6.57.16.57.1-amd646.57.1-arm64

الصور موسومة بإصدار التطبيق (وليس أبدًا :latest): فهرس متعدد المعماريات إضافة إلى وسوم لكل معمارية.

إصدار التطبيق
6.57.1
المعماريات
amd64, arm64
تعمل كـ
nonroot (uid 1001)
نظام الملفات الجذر
للقراءة فقط
الرخصة
MIT

تحقّق من سلسلة التوريد

هذه الصورة موقّعة بـ cosign وتحمل قائمة مكوّنات SPDX SBOM وشهادة منشأ بناء SLSA على البصمة نفسها. تحقّق من الثلاثة جميعها بنفسك:

# 1. signature — built and signed by QuenchWorks CI
cosign verify ghcr.io/quenchworks/images/ghost:6.57.1 \
  --certificate-identity-regexp 'https://github.com/quenchworks/.+' \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com

# 2. SLSA build provenance — which workflow built it, from what
cosign verify-attestation --type https://slsa.dev/provenance/v1 ghcr.io/quenchworks/images/ghost:6.57.1 \
  --certificate-identity-regexp 'https://github.com/quenchworks/.+' \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com

# 3. SPDX SBOM — the package inventory
cosign verify-attestation --type https://spdx.dev/Document/v2.3 ghcr.io/quenchworks/images/ghost:6.57.1 \
  --certificate-identity-regexp 'https://github.com/quenchworks/.+' \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com

راجع دليل SBOM والمنشأ لقراءة قائمة المكوّنات واستخدام هذه الفحوص في التكامل المستمر.

الشفافية

تحمل كل صورة قائمة مكوّناتها ومنشأها كشهادات على البصمة نفسها، قابلة للتحقق علنًا بالأوامر أعلاه (تفحص الحزمة وسجلّ شفافية Sigstore، وهو Rekor).

المشروع المنبع: https://ghost.org