Add missing public registries and changelog hosts to egress allowlist - #281
Merged
v-abhishekbhaskar merged 1 commit intoSep 30, 2026
Merged
Conversation
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The additions are narrowly scoped, correctly grouped, and covered by positive and exact-host boundary tests.
Review effort: Balanced
Findings: None
What changed in this PR
Adds 18 exact-match public registry, metadata, and release-note hosts to the global egress allowlist.
Changes:
- Adds nine public registry/metadata hosts.
- Adds nine changelog/documentation hosts.
- Tests allowed hosts, redirects, excluded services, and namespace boundaries.
| File | Description |
|---|---|
internal/handlers/egress_allowlist_defaults.yaml |
Adds exact hosts under their relevant ecosystems. |
internal/handlers/egress_allowlist_test.go |
Verifies access and prevents unsafe host widening. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
v-sachin-sandhu
approved these changes
Sep 30, 2026
v-abhishekbhaskar
deleted the
abhishekbhaskar/add-missing-domains-tier1-tier2
branch
September 30, 2026 21:15
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What are you trying to accomplish?
Adds 18 public hosts that are currently blocked by the egress allowlist but are needed for updates to work correctly. No entries are removed or widened.
Every host was verified on the wire — anonymous fetch of a real artifact, with the full redirect chain traced — before being added.
Tier 1: public registries (9). Placed by ecosystem, so
ecosystem_default_domainsstays accurate as provenance.nexus.payara.fishapi.opentofu.orgrepository.mulesoft.orgwp-languages.github.iopkg.go.devreleases.aspose.comartifacts.alfresco.commaven.repository.redhat.comrepo.grails.orgapi.opentofu.orgis worth calling out: the proxy already ships an OpenTofu credential handler, so we were authenticating that ecosystem while blocking its public registry API.Tier 2: changelog and release-note hosts (9). These extend the category established in #280 — Dependabot follows
project_urlsfrom PyPI metadata and<url>from POMs to render release notes, so blocking them degrades pull request bodies without affecting resolution.cryptography.io,numpy.org,docs.sentry.io,coverage.readthedocs.io,reference.langchain.com,developer.nvidia.com(pip/uv),rubydoc.info(bundler), and thecloud.google.com/docs.cloud.google.compair.Anything you want to highlight for special attention from reviewers?
Five hosts were verified and deliberately excluded, each with a test asserting it stays blocked:
repo.magento.comreturns 401 — it needs aregistries:credential, and allowlisting it would mask a configuration error as a working setup.console.cloud.google.comredirects to a Google sign-in page. It is the web console, not a registry, and allowingcloud.google.commust not reach it.www.reddit.comis aproject_urlscommunity link.packagecloud.ioandapi.cloudsmith.ioare multi-tenant with path-based tenancy, per the documenteddl.cloudsmith.ioprecedent.cloud.google.com301-redirects todocs.cloud.google.com, so both ends of the chain are required. This is the third cross-origin redirect pair in this allowlist, afterpackages.atlassian.comand thedocs.pydantic.dev/psycopg.orgpairs in #280.coverage.readthedocs.ioextends a known long tail. Read the Docs subdomains are project-creatable, so.readthedocs.iowould be an exfiltration channel and must stay exact. Probes forevil.readthedocs.ioandevil.coverage.readthedocs.ioguard this. Expect further one-off Python docs hosts over time; the alternative to adding them individually is deciding the changelog category is not worth maintaining.wp-languages.github.iois on a user-creatable namespace. It is exact-only, withgithub.io,evil.github.ioandevil.wp-languages.github.ioall asserted blocked.How will you know you've accomplished your goal?
Each added host returned a real artifact anonymously, with no cross-origin redirect except the pair noted above. Representative checks:
nexus.payara.fish— 200, realpayara-bommaven-metadata.xmlapi.opentofu.org— 200, 27 KB provider index JSONartifacts.alfresco.com— 200, 88 KBmaven-metadata.xmlmaven.repository.redhat.com— 200, realjboss-parentmetadatawp-languages.github.io— 200,packages.jsonTest coverage:
TestEgressAllowlist_PublicVendorRegistriesAllowed— new; 9 allowed, 20 blockedTestEgressAllowlist_ChangelogHostsSecondWaveAllowed— new; 9 allowed, 13 blockedTestEgressDefaults_NoRedundantEntries— confirms none of the 18 duplicates or is shadowed by an existing entryChecklist