Skip to content

Add missing public registries and changelog hosts to egress allowlist - #281

Merged
v-abhishekbhaskar merged 1 commit into
mainfrom
abhishekbhaskar/add-missing-domains-tier1-tier2
Sep 30, 2026
Merged

v-abhishekbhaskar merged 1 commit into
mainfrom
abhishekbhaskar/add-missing-domains-tier1-tier2

Conversation

@v-abhishekbhaskar

Copy link
Copy Markdown
Contributor

What are you trying to accomplish?

Adds 18 public hosts that are currently blocked by the egress allowlist but are needed for updates to work correctly. No entries are removed or widened.

Every host was verified on the wire — anonymous fetch of a real artifact, with the full redirect chain traced — before being added.

Tier 1: public registries (9). Placed by ecosystem, so ecosystem_default_domains stays accurate as provenance.

Host Ecosystem
nexus.payara.fish maven/gradle
api.opentofu.org opentofu
repository.mulesoft.org maven/gradle
wp-languages.github.io composer
pkg.go.dev go_modules
releases.aspose.com maven/gradle
artifacts.alfresco.com maven/gradle
maven.repository.redhat.com maven/gradle
repo.grails.org gradle

api.opentofu.org is worth calling out: the proxy already ships an OpenTofu credential handler, so we were authenticating that ecosystem while blocking its public registry API.

Tier 2: changelog and release-note hosts (9). These extend the category established in #280 — Dependabot follows project_urls from PyPI metadata and <url> from POMs to render release notes, so blocking them degrades pull request bodies without affecting resolution. cryptography.io, numpy.org, docs.sentry.io, coverage.readthedocs.io, reference.langchain.com, developer.nvidia.com (pip/uv), rubydoc.info (bundler), and the cloud.google.com / docs.cloud.google.com pair.

Anything you want to highlight for special attention from reviewers?

Five hosts were verified and deliberately excluded, each with a test asserting it stays blocked:

  • repo.magento.com returns 401 — it needs a registries: credential, and allowlisting it would mask a configuration error as a working setup.
  • console.cloud.google.com redirects to a Google sign-in page. It is the web console, not a registry, and allowing cloud.google.com must not reach it.
  • www.reddit.com is a project_urls community link.
  • packagecloud.io and api.cloudsmith.io are multi-tenant with path-based tenancy, per the documented dl.cloudsmith.io precedent.

cloud.google.com 301-redirects to docs.cloud.google.com, so both ends of the chain are required. This is the third cross-origin redirect pair in this allowlist, after packages.atlassian.com and the docs.pydantic.dev / psycopg.org pairs in #280.

coverage.readthedocs.io extends a known long tail. Read the Docs subdomains are project-creatable, so .readthedocs.io would be an exfiltration channel and must stay exact. Probes for evil.readthedocs.io and evil.coverage.readthedocs.io guard this. Expect further one-off Python docs hosts over time; the alternative to adding them individually is deciding the changelog category is not worth maintaining.

wp-languages.github.io is on a user-creatable namespace. It is exact-only, with github.io, evil.github.io and evil.wp-languages.github.io all asserted blocked.

How will you know you've accomplished your goal?

Each added host returned a real artifact anonymously, with no cross-origin redirect except the pair noted above. Representative checks:

  • nexus.payara.fish — 200, real payara-bom maven-metadata.xml
  • api.opentofu.org — 200, 27 KB provider index JSON
  • artifacts.alfresco.com — 200, 88 KB maven-metadata.xml
  • maven.repository.redhat.com — 200, real jboss-parent metadata
  • wp-languages.github.io — 200, packages.json
  • All nine changelog pages — 200

Test coverage:

  • TestEgressAllowlist_PublicVendorRegistriesAllowed — new; 9 allowed, 20 blocked
  • TestEgressAllowlist_ChangelogHostsSecondWaveAllowed — new; 9 allowed, 13 blocked
  • TestEgressDefaults_NoRedundantEntries — confirms none of the 18 duplicates or is shadowed by an existing entry

Checklist

  • I have run the complete test suite to ensure all tests and linters pass.
  • I have thoroughly tested my code changes to ensure they work as expected, including adding additional tests for new functionality.
  • I have written clear and descriptive commit messages.
  • I have provided a detailed description of the changes in the pull request, including the problem it addresses, how it fixes the problem, and any relevant details about the implementation.
  • I have ensured that the code is well-documented and easy to understand.

@v-abhishekbhaskar v-abhishekbhaskar self-assigned this Sep 30, 2026
@v-abhishekbhaskar
v-abhishekbhaskar requested a review from a team as a code owner September 30, 2026 19:05
Copilot AI balanced review requested due to automatic review settings September 30, 2026 19:05

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The additions are narrowly scoped, correctly grouped, and covered by positive and exact-host boundary tests.

Review effort: Balanced
Findings: None

What changed in this PR

Adds 18 exact-match public registry, metadata, and release-note hosts to the global egress allowlist.

Changes:

  • Adds nine public registry/metadata hosts.
  • Adds nine changelog/documentation hosts.
  • Tests allowed hosts, redirects, excluded services, and namespace boundaries.
File Description
internal/​handlers/​egress_allowlist_defaults.yaml Adds exact hosts under their relevant ecosystems.
internal/​handlers/​egress_allowlist_test.go Verifies access and prevents unsafe host widening.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@v-abhishekbhaskar
v-abhishekbhaskar merged commit 0d4fe7f into main Sep 30, 2026
113 checks passed
@v-abhishekbhaskar
v-abhishekbhaskar deleted the abhishekbhaskar/add-missing-domains-tier1-tier2 branch September 30, 2026 21:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants