Runtime-only Dockerfile.runtime copies a pre-built dist/ into the nginx image; sidesteps the Node-on-emulation libuv crash when building on Apple Silicon for linux/amd64. nginx.conf hardened: - HSTS, X-Content-Type-Options, X-Frame-Options DENY, Referrer-Policy - Permissions-Policy locking down camera/microphone/geolocation/payment - Content-Security-Policy with strict default-src self + connect-src scoped to our backend - COOP / CORP same-origin - X-Robots-Tag noindex (not a public marketing site) - server_tokens off Confidence: high Scope-risk: narrow
9 lines
70 B
Plaintext
9 lines
70 B
Plaintext
node_modules
|
|
qa/screenshots
|
|
.git
|
|
*.log
|
|
.DS_Store
|
|
.vscode
|
|
.idea
|
|
*.bak*
|