Skip to content

DROP 1.2.1

Choose a tag to compare

@github-actions github-actions released this 11 Aug 16:50
· 288 commits to develop since this release
468d9ef

[1.2.1] - 2026-08-11

One security fix, and a correction to the note published with 1.2.0.

Upgrading is not enough on its own — restart your static apps. The nginx
config is regenerated from buildStartSpec, which runs on start and on
restart, so drop restart <app> (or the dashboard's Restart button, or the
MCP restart_app tool) applies the fix. A full redeploy is not required.

Before restarting, this tells you whether an app is exposed:

curl -o /dev/null -w '%{http_code}\n' https://<app>/.git/config   # 200 = exposed

After restarting it reads 404 either way, so it can no longer answer "was
I exposed, do I need to rotate a token?". That question is settled on the box,
and upgrading does not erase the evidence:

sudo grep -hE '^\s*url\s*=' /var/drop/data/webapps/*/.git/config | grep '@'

Any app listed there was cloned with a personal access token in its remote
URL. If it is also a plain-root static app (outputDirectory is the app
root, not dist/build), that token was publicly fetchable — rotate it.
The 404 stops the bleeding but does not un-publish what was already fetched.

Security

  • A static app no longer serves its own dotfiles. The generated nginx
    config now returns 404 for any path with a .-prefixed segment, at any
    depth, with .well-known/ carved out. For a plain-root static app the
    document root is the app directory, so try_files $uri happily served
    /.git/config — the full repository history, and for an app cloned before
    1.2.0 the personal access token baked into it — and /.env. Measured
    against nginx:alpine before and after: GET /.git/config returned 200
    with the token in the body
    , and now returns 404.

    This corrects the note published with 1.2.0, which named Caddy's
    file_server as the culprit. It is not: staticPath is never set, so that
    branch is dead code. Static apps are served by nginx in their own container
    and Caddy only reverse-proxies to it. The exposure was real, the component
    named was wrong.

    An SPA is unaffected — its root is /app/<outputDirectory>, so .git
    sits outside the document root. That asymmetry is why this went unnoticed:
    the SPA case, which is most apps, was always safe.

    Takes effect when the app's nginx config is next regenerated — a restart is
    enough, see the upgrade note above.