<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>CVE on Text Matrix</title><link>https://txtmix.com/tags/cve/</link><description>Recent content in CVE on Text Matrix</description><generator>Hugo</generator><language>zh-cn</language><lastBuildDate>Tue, 21 Jul 2026 20:06:14 +0800</lastBuildDate><atom:link href="https://txtmix.com/tags/cve/index.xml" rel="self" type="application/rss+xml"/><item><title>Nginx 1.31 安全修复与现代部署：30 岁反向代理的常青之道</title><link>https://txtmix.com/posts/tech/nginx-1-31-security-and-modern-deployment/</link><pubDate>Sun, 07 Jun 2026 12:56:00 +0800</pubDate><guid>https://txtmix.com/posts/tech/nginx-1-31-security-and-modern-deployment/</guid><description>&lt;h1 id="nginx-131-安全修复与现代部署30-岁反向代理的常青之道">Nginx 1.31 安全修复与现代部署：30 岁反向代理的常青之道&lt;/h1>
&lt;blockquote>
&lt;p>&lt;strong>目标读者&lt;/strong>：运维 / SRE；架构师；评估 API gateway / 反向代理方案的人
&lt;strong>核心问题&lt;/strong>：Nginx 1.31.1 修复了哪些安全问题？在容器化、Kubernetes、Service Mesh 时代，Nginx 还有什么不可替代的位置？
&lt;strong>难度&lt;/strong>：⭐⭐（中级）
&lt;strong>来源&lt;/strong>：&lt;a href="https://nginx.org/" target="_blank" rel="noopener noreffer ">Nginx 官方公告&lt;/a> + &lt;a href="https://github.com/nginx/nginx" target="_blank" rel="noopener noreffer ">nginx/nginx&lt;/a>，30k+ ★ / BSD-2-Clause / 2026-06-07&lt;/p></description></item><item><title>Trivy 实战指南：Aqua Security 开源的「全能」安全扫描器</title><link>https://txtmix.com/posts/tech/trivy-aquasecurity-security-scanner-guide/</link><pubDate>Thu, 04 Jun 2026 15:00:00 +0800</pubDate><guid>https://txtmix.com/posts/tech/trivy-aquasecurity-security-scanner-guide/</guid><description>&lt;h1 id="trivy-实战指南aqua-security-开源的全能安全扫描器">Trivy 实战指南：Aqua Security 开源的「全能」安全扫描器&lt;/h1>
&lt;h2 id="核心判断">核心判断&lt;/h2>
&lt;p>&lt;code>Trivy&lt;/code>（仓库 &lt;a href="https://github.com/aquasecurity/trivy" target="_blank" rel="noopener noreffer ">aquasecurity/trivy&lt;/a>）不是&amp;quot;又一款&amp;quot;漏洞扫描器，而是把 &lt;strong>CVE 漏洞、SBOM 软件物料清单、IaC 错误配置、敏感密钥、License 风险&lt;/strong> 五类扫描压进同一把 CLI 刀的工具。它能在容器镜像、文件系统、Git 远程仓库、虚拟机镜像、Kubernetes 集群这 5 种目标上做同一种事——告诉你哪儿不安全、为什么、怎么修。&lt;/p></description></item></channel></rss>