Skip to content

Add Tilt HUD auth fix reference#8278

Open
cookesan wants to merge 1 commit into
github:cookesan/advisory-improvement-8278from
cookesan:tilt-c73q-fix-reference
Open

Add Tilt HUD auth fix reference#8278
cookesan wants to merge 1 commit into
github:cookesan/advisory-improvement-8278from
cookesan:tilt-c73q-fix-reference

Conversation

@cookesan

Copy link
Copy Markdown

Adds the upstream merge commit that fixed missing authentication on Tilt HUD server endpoints for GHSA-c73q-8xxr-rgqm.

Evidence checked:

  • fix: secure mutating and sensitive requests to HUD server tilt-dev/tilt#6776 merged as 47393fba7f6ef5e305d5e814551feef8e4acbc0a.
  • v0.37.4 includes that merge commit and lists the HUD server fix in the release notes.
  • go list -m -json github.com/tilt-dev/tilt@v0.37.4 resolves to tag v0.37.4; the module archive includes token checks for sensitive and mutating HUD endpoints, origin validation, and loopback guards for debug endpoints.

@github-actions github-actions Bot changed the base branch from main to cookesan/advisory-improvement-8278 June 29, 2026 11:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant