Skip to content

Add remaining public registries to egress allowlist after full rollout - #282

Merged
v-abhishekbhaskar merged 2 commits into
mainfrom
abhishekbhaskar/add-remaining-public-registries-allowlist
Oct 1, 2026
Merged

v-abhishekbhaskar merged 2 commits into
mainfrom
abhishekbhaskar/add-remaining-public-registries-allowlist

Conversation

@v-abhishekbhaskar

Copy link
Copy Markdown
Contributor

What are you trying to accomplish?

Production telemetry showed a set of genuinely public package registries and changelog hosts being denied by the egress allowlist. None of them require credentials, so there is no registries: configuration a user could add to fix them — they can only be resolved in the embedded defaults. This PR adds them.

Two categories are included. The first is public registry and artifact infrastructure, where a denial actually breaks dependency resolution. The second is changelog and release-note hosts, which Dependabot follows from package metadata to render pull request bodies; a denial there degrades PR descriptions but never breaks an update.

Public registries and artifact infrastructure

Added to maven: &jvm_registries (inherited by gradle): repo.opencollab.dev, maven.restlet.talend.com, maven.fpregistry.io, repo.essentialsx.net, repo.dmulloy2.net, api.xposed.info, packages.nuxeo.com, maven.fullstory.com, maven.lokalise.com, repository.medallia.com, jogamp.org, jcenter.bintray.com, salesforce-marketingcloud.github.io, a8c-libs.s3.amazonaws.com.

Added to nuget: pkg.kzu.app. Added to terraform: archivist.terraform.io. Added to julia: storage.julialang.net and julialang-storage-us-east-1.s3.us-east-1.amazonaws.com.

Changelog and release-note hosts

Added to pip: &python_registries (inherited by uv): click.palletsprojects.com, pytest-mock.readthedocs.io, redis.readthedocs.io. Added to the JVM list: logging.apache.org.

Every host was verified on the wire before being added. Each returns 404 rather than 401 for an absent artifact, which confirms the server answers without demanding credentials — the distinction that separates a genuinely public registry from a private one that merely has a reachable root URL.

Anything you want to highlight for special attention from reviewers?

Two cross-origin redirect chains required listing both ends. jcenter.bintray.com is retired but still 301-redirects to repo1.maven.org, which is already allowlisted, so only the entry point of the chain needed adding. storage.julialang.net 302-redirects package tarballs to a virtual-hosted S3 bucket. Allowlisting only the host recorded in telemetry would have left both chains failing mid-flight.

The Julia S3 bucket is pinned exactly rather than globbed, and this is deliberate. The obvious shape would be julialang-storage-*.s3.*.amazonaws.com, but I probed the namespace first: only julialang-storage-us-east-1 exists, and the sibling region names (julialang-storage-eu-west-1, us-west-2 and others) return NoSuchBucket — they are unclaimed and registrable by anyone today. A glob would therefore hand every job an attacker-registrable destination, the same reasoning already recorded for prod-<region>-starport-layer-bucket. The YAML carries a note to add a region explicitly if Julia ever adds one, and a test asserts the unclaimed siblings stay blocked.

Hosts deliberately left blocked, with tests asserting they stay that way. mobile-sdks.forter.com and nuget.devexpress.com return 401, so they need a registries: credential — allowlisting them would mask a user configuration error rather than fix one. nuget.hangfire.io, nuget.abp.io, registry.nes.herodevs.com and connect.advancedcustomfields.com are commercial feeds tenanted by a license key in the path. dc.services.visualstudio.com is Application Insights telemetry ingestion from the NuGet tooling, not a registry, and is better left denied. dl.bintray.com is retired and serves nothing.

How will you know you've accomplished your goal?

Two new tests cover the additions. TestEgressAllowlist_PublicRegistriesThirdWaveAllowed asserts 18 representative registry URLs are permitted and 40 related URLs stay blocked. TestEgressAllowlist_ChangelogHostsThirdWaveAllowed asserts 4 changelog URLs are permitted and 13 stay blocked.

The blocked probes are the substance of the tests rather than an afterthought. Every exact entry has an evil.<host> child probe, so a later widening to a leading-dot suffix cannot pass silently — a gap this check caught in an earlier wave. Lookalike parents and suffix-appending attacker domains (archivist.terraform.io.attacker.com) are covered, as are the path-style S3 apexes and the unclaimed Julia sibling buckets.

Checklist

  • I have run the complete test suite to ensure all tests and linters pass.
  • I have thoroughly tested my code changes to ensure they work as expected, including adding additional tests for new functionality.
  • I have written clear and descriptive commit messages.
  • I have provided a detailed description of the changes in the pull request, including the problem it addresses, how it fixes the problem, and any relevant details about the implementation.
  • I have ensured that the code is well-documented and easy to understand.

@v-abhishekbhaskar v-abhishekbhaskar self-assigned this Oct 1, 2026
@v-abhishekbhaskar
v-abhishekbhaskar requested a review from a team as a code owner October 1, 2026 06:18
Copilot AI balanced review requested due to automatic review settings October 1, 2026 06:18

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Two exact S3 entries lack child-host regression probes required to prevent unsafe widening.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
What changed in this PR

Adds public registry, artifact, and changelog hosts to the embedded egress allowlist.

Changes:

  • Adds 22 exact-host allowlist entries across several ecosystems.
  • Adds positive and negative regression coverage.
File Description
internal/​handlers/​egress_allowlist_defaults.yaml Adds public infrastructure and changelog hosts.
internal/​handlers/​egress_allowlist_test.go Tests allowed hosts and security boundaries.

💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread internal/handlers/egress_allowlist_test.go
@v-abhishekbhaskar
v-abhishekbhaskar merged commit a0b7d59 into main Oct 1, 2026
112 checks passed
@v-abhishekbhaskar
v-abhishekbhaskar deleted the abhishekbhaskar/add-remaining-public-registries-allowlist branch October 1, 2026 06:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants