Compare commits

..

10 Commits

Author SHA1 Message Date
kawaiipunk ef27645a30 chore: publish 3.0.0+7.0.0 release
continuous-integration/drone/push Build is failing
continuous-integration/drone/tag Build is passing
2026-06-02 17:42:25 +01:00
kawaiipunk 5d3c019b83 Add release notes 2026-06-02 17:41:56 +01:00
kawaiipunk f450f2e6ba bump ENTRYPOINT_CONF_VERSION to v9 2026-06-02 17:37:29 +01:00
kawaiipunk c75c18f185 chore: update image tags 2026-06-02 17:31:29 +01:00
moritz 7e170adbb4 Merge pull request 'Added xtra chown to ensure correct perms on every container start' (#57) from kawaiipunk/wordpress:main into main
continuous-integration/drone/push Build is failing
Reviewed-on: #57
2026-05-26 17:10:01 +00:00
kawaiipunk 66e0687456 Removed redundant chown
continuous-integration/drone/pr Build is failing
2026-05-26 17:05:24 +01:00
kawaiipunk 9209f007cb revert 69cf451b98
continuous-integration/drone/push Build is failing
revert Merge pull request 'chore(deps): update wordpress docker tag to v7' (#55) from renovate/wordpress-7.x into main

Reviewed-on: #55

Sorry this was done by mistake!
2026-05-26 14:08:49 +00:00
kawaiipunk 69cf451b98 Merge pull request 'chore(deps): update wordpress docker tag to v7' (#55) from renovate/wordpress-7.x into main
continuous-integration/drone/push Build is failing
Reviewed-on: #55
2026-05-26 13:59:35 +00:00
kawaiipunk 73a2e98d2e Added xtra chown to ensure correct perms on every container start
continuous-integration/drone/pr Build is failing
2026-05-26 14:10:22 +01:00
renovate-bot 0e229168fc chore(deps): update wordpress docker tag to v7
continuous-integration/drone/pr Build is failing
2026-05-22 00:34:30 +00:00
8 changed files with 15 additions and 22 deletions
+2 -9
View File
@@ -1,8 +1,8 @@
export PHP_UPLOADS_CONF_VERSION=v4
export ENTRYPOINT_CONF_VERSION=v8
export ENTRYPOINT_CONF_VERSION=v9
export ENTRYPOINT_MAILRELAY_CONF_VERSION=v2
export MSMTP_CONF_VERSION=v4
export HTACCESS_CONF_VERSION=v5
export HTACCESS_CONF_VERSION=v3
export USERS_CONF_VERSION=v1
wp() {
@@ -107,10 +107,3 @@ fix_mysql() {
show_plugins() {
wp "plugin list --fields=name,status,wporg_status,version,update_version,auto_update,tested_up_to,wporg_last_updated"
}
rotate_db_pass() {
DB_PASS=$(cat /run/secrets/db_password)
DB_ROOT_PASS=$(cat /run/secrets/db_root_password)
echo "ALTER USER 'root'@'localhost' IDENTIFIED BY '${DB_ROOT_PASS}'; ALTER USER 'root'@'%' IDENTIFIED BY '${DB_ROOT_PASS}'; ALTER USER 'wordpress'@'%' IDENTIFIED BY '${DB_PASS}'; FLUSH PRIVILEGES;" | mariadb -u root --skip-password 2>/dev/null \
|| echo "ALTER USER 'root'@'localhost' IDENTIFIED BY '${DB_ROOT_PASS}'; ALTER USER 'root'@'%' IDENTIFIED BY '${DB_ROOT_PASS}'; ALTER USER 'wordpress'@'%' IDENTIFIED BY '${DB_PASS}'; FLUSH PRIVILEGES;" | mariadb -u root -p"${DB_ROOT_PASS}"
}
+1 -1
View File
@@ -3,7 +3,7 @@ version: "3.8"
services:
app:
image: "wordpress:latest"
image: "wordpress:7.0.0"
volumes:
- "wordpress:/var/www/html/"
environment:
+3 -3
View File
@@ -3,7 +3,7 @@ version: "3.8"
services:
app:
image: "wordpress:6.9.5"
image: "wordpress:7.0.0"
volumes:
- "wordpress_content:/var/www/html/wp-content/"
networks:
@@ -62,10 +62,10 @@ services:
- "traefik.http.middlewares.${STACK_NAME}-redirect.redirectregex.replacement=https://${DOMAIN}/$${2}"
- "traefik.http.middlewares.${STACK_NAME}-redirect.redirectregex.permanent=true"
- "coop-cloud.${STACK_NAME}.timeout=${TIMEOUT}"
- "coop-cloud.${STACK_NAME}.version=2.19.5+6.9.5"
- "coop-cloud.${STACK_NAME}.version=3.0.0+7.0.0"
db:
image: "mariadb:12.2"
image: "mariadb:12.3"
volumes:
- "mariadb:/var/lib/mysql"
networks:
+2 -1
View File
@@ -52,9 +52,10 @@ if [ ! -f "$UPLOADS_HTACCESS" ]; then
Require all denied
</FilesMatch>
EOF
chown www-data:www-data "$UPLOADS_HTACCESS"
fi
chown -R www-data:www-data /var/www/html/wp-content/uploads/
if [ -n "$@" ]; then
"$@"
fi
+1 -6
View File
@@ -3,11 +3,6 @@
Require all denied
</FilesMatch>
# Block XML-RPC
<Files xmlrpc.php>
Require all denied
</Files>
{{ if eq (env "MULTISITE") "" -}}
# BEGIN WordPress
@@ -64,4 +59,4 @@ RewriteRule ^(.*\.php)$ $1 [L]
RewriteRule . index.php [L]
# END WordPress Multisite
{{- end }}
{{- end }}
-1
View File
@@ -1 +0,0 @@
patch to block XML-RPC via htaccess
-1
View File
@@ -1 +0,0 @@
temporarily block rest api against wp2shell CVE
+6
View File
@@ -0,0 +1,6 @@
- WordPress upgraded from 6.9.4 to 7.0 (major! test before deploying)
- MariaDB upgraded from 10.x to 11.4 (major! SSL now enabled by default)
- ENTRYPOINT_CONF_VERSION bumped to v9
- Breaking: MariaDB 11.4 enables SSL by default — if clients don't support SSL, add --disable-ssl to db command
- Breaking: WordPress 7.0 introduces new AI features and admin theme changes
- Backup database and files before upgrading