✓ No known CVEs patched
This release patches 1 known CVE
Topics
automation
cloud-management
devops
iac
infrastructure-automation
infrastructure-orchestration
+6 more
ocaml
opentofu
pulumi
tacos
terraform
terraform-github-actions
Affected surfaces
auth
Summary
AI summaryAdded missing security response headers, set session cookie SameSite attribute, and aligned Sln code with stategraph.
Full changelog
What's Changed
- #1406 FIX Add missing security response headers and session cookie SameSite by @joshpollara in https://github.com/terrateamio/terrateam/pull/1407
- #1415 ADD Bring sln from stategraph + bust warnings like in stategraph + misc alignments by @tamiyasigmar in https://github.com/terrateamio/terrateam/pull/1423
Full Changelog: https://github.com/terrateamio/terrateam/compare/20260724-0700-f26f18d...20260724-1002-315ce05
Security Fixes
- Added security response headers (e.g., X-Content-Type-Options, X-Frame-Options) and configured session cookies with SameSite attribute to mitigate CSRF risks.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Terrateam
Terrateam is open-source GitOps infrastructure orchestration. It integrates with GitHub to automate Terraform, OpenTofu, CDKTF, Terragrunt, and Pulumi workflows through pull requests.
Related context
Beta — feedback welcome: [email protected]