A community based topic aggregation platform built on atproto

fix(security): build Caddy from pinned official image, pin PDS/postgres digests master

The edge proxy ran ghcr.io/slothcroissant/caddy-cloudflaredns:latest — a mutable tag from a third-party registry — while holding both Cloudflare DNS tokens and terminating all TLS. Anyone who could push that tag could ship a Caddy that intercepts every request. `docker compose pull` (setup-production) would have taken it silently. - docker/caddy/Dockerfile: build Caddy ourselves from the official caddy:2.11.4 / 2.11.4-builder images (both digest-pinned) with caddy-dns/cloudflare@v0.2.4 via xcaddy. Trust narrows to Docker Official Images + a Go module verified by sumdb. Same Caddy version prod runs today. - docker-compose.prod.yml: caddy → build + coves/caddy:${CADDY_VERSION}; pds pinned to 0.4.193@sha256 (the digest currently pulled); postgres:15 pinned by digest. Upgrades are now reviewed commits that bump the pin. - scripts/deploy.sh: VERSION defaults to the git short SHA so the appview image tag says which commit is running instead of :latest. - scripts/setup-production.sh: pull only postgres/pds, build appview + caddy. Verified locally: image builds, `caddy list-modules` includes dns.providers.cloudflare, and `caddy validate` against the prod Caddyfile parses through to Cloudflare provider provisioning. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>