Repository navigation
DROP 1.2.1
[1.2.1] - 2026-08-11
One security fix, and a correction to the note published with 1.2.0.
Upgrading is not enough on its own — restart your static apps. The nginx
config is regenerated from buildStartSpec, which runs on start and on
restart, so drop restart <app> (or the dashboard's Restart button, or the
MCP restart_app tool) applies the fix. A full redeploy is not required.
Before restarting, this tells you whether an app is exposed:
curl -o /dev/null -w '%{http_code}\n' https://<app>/.git/config # 200 = exposedAfter restarting it reads 404 either way, so it can no longer answer "was
I exposed, do I need to rotate a token?". That question is settled on the box,
and upgrading does not erase the evidence:
sudo grep -hE '^\s*url\s*=' /var/drop/data/webapps/*/.git/config | grep '@'Any app listed there was cloned with a personal access token in its remote
URL. If it is also a plain-root static app (outputDirectory is the app
root, not dist/build), that token was publicly fetchable — rotate it.
The 404 stops the bleeding but does not un-publish what was already fetched.
Security
-
A static app no longer serves its own dotfiles. The generated nginx
config now returns 404 for any path with a.-prefixed segment, at any
depth, with.well-known/carved out. For a plain-root static app the
document root is the app directory, sotry_files $urihappily served
/.git/config— the full repository history, and for an app cloned before
1.2.0 the personal access token baked into it — and/.env. Measured
againstnginx:alpinebefore and after:GET /.git/configreturned 200
with the token in the body, and now returns 404.This corrects the note published with 1.2.0, which named Caddy's
file_serveras the culprit. It is not:staticPathis never set, so that
branch is dead code. Static apps are served by nginx in their own container
and Caddy only reverse-proxies to it. The exposure was real, the component
named was wrong.An SPA is unaffected — its root is
/app/<outputDirectory>, so.git
sits outside the document root. That asymmetry is why this went unnoticed:
the SPA case, which is most apps, was always safe.Takes effect when the app's nginx config is next regenerated — a restart is
enough, see the upgrade note above.