<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Goshs on Project Wintermute</title><link>https://wintermutecore.com/tags/goshs/</link><description>Recent content in Goshs on Project Wintermute</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 28 Sep 2026 07:17:05 +0000</lastBuildDate><atom:link href="https://wintermutecore.com/tags/goshs/index.xml" rel="self" type="application/rss+xml"/><item><title>goshs v2.1.7 - Protocol ACL on Every File Transfer</title><link>https://wintermutecore.com/posts/goshs-v2-1-7-release-protocol-acl/</link><pubDate>Mon, 28 Sep 2026 07:17:05 +0000</pubDate><guid>https://wintermutecore.com/posts/goshs-v2-1-7-release-protocol-acl/</guid><description>&lt;p&gt;goshs &lt;code&gt;v2.1.7&lt;/code&gt; was published on 28 September 2026. The notes call it a security release that resolves six advisories, with five GHSA ids written out, centered on &lt;code&gt;httpserver.ProtocolACL&lt;/code&gt;. SFTP, FTP, TFTP, and SMB now apply the per folder &lt;code&gt;.goshs&lt;/code&gt; rules that HTTP and WebDAV already enforced, and a folder with an &lt;code&gt;auth&lt;/code&gt; entry is denied on those protocols because they cannot present the basic auth credential.&lt;/p&gt;</description></item></channel></rss>