Add remaining public registries to egress allowlist after full rollout - #282
Merged
v-abhishekbhaskar merged 2 commits intoOct 1, 2026
Merged
v-abhishekbhaskar merged 2 commits into
v-abhishekbhaskar merged 2 commits into
Conversation
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Two exact S3 entries lack child-host regression probes required to prevent unsafe widening.
Review effort: Balanced
Findings: 1
Open (1)
What changed in this PR
Adds public registry, artifact, and changelog hosts to the embedded egress allowlist.
Changes:
- Adds 22 exact-host allowlist entries across several ecosystems.
- Adds positive and negative regression coverage.
| File | Description |
|---|---|
internal/handlers/egress_allowlist_defaults.yaml |
Adds public infrastructure and changelog hosts. |
internal/handlers/egress_allowlist_test.go |
Tests allowed hosts and security boundaries. |
💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
honeyankit
approved these changes
Oct 1, 2026
v-abhishekbhaskar
deleted the
abhishekbhaskar/add-remaining-public-registries-allowlist
branch
October 1, 2026 06:45
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

What are you trying to accomplish?
Production telemetry showed a set of genuinely public package registries and changelog hosts being denied by the egress allowlist. None of them require credentials, so there is no
registries:configuration a user could add to fix them — they can only be resolved in the embedded defaults. This PR adds them.Two categories are included. The first is public registry and artifact infrastructure, where a denial actually breaks dependency resolution. The second is changelog and release-note hosts, which Dependabot follows from package metadata to render pull request bodies; a denial there degrades PR descriptions but never breaks an update.
Public registries and artifact infrastructure
Added to
maven: &jvm_registries(inherited bygradle):repo.opencollab.dev,maven.restlet.talend.com,maven.fpregistry.io,repo.essentialsx.net,repo.dmulloy2.net,api.xposed.info,packages.nuxeo.com,maven.fullstory.com,maven.lokalise.com,repository.medallia.com,jogamp.org,jcenter.bintray.com,salesforce-marketingcloud.github.io,a8c-libs.s3.amazonaws.com.Added to
nuget:pkg.kzu.app. Added toterraform:archivist.terraform.io. Added tojulia:storage.julialang.netandjulialang-storage-us-east-1.s3.us-east-1.amazonaws.com.Changelog and release-note hosts
Added to
pip: &python_registries(inherited byuv):click.palletsprojects.com,pytest-mock.readthedocs.io,redis.readthedocs.io. Added to the JVM list:logging.apache.org.Every host was verified on the wire before being added. Each returns
404rather than401for an absent artifact, which confirms the server answers without demanding credentials — the distinction that separates a genuinely public registry from a private one that merely has a reachable root URL.Anything you want to highlight for special attention from reviewers?
Two cross-origin redirect chains required listing both ends.
jcenter.bintray.comis retired but still301-redirects torepo1.maven.org, which is already allowlisted, so only the entry point of the chain needed adding.storage.julialang.net302-redirects package tarballs to a virtual-hosted S3 bucket. Allowlisting only the host recorded in telemetry would have left both chains failing mid-flight.The Julia S3 bucket is pinned exactly rather than globbed, and this is deliberate. The obvious shape would be
julialang-storage-*.s3.*.amazonaws.com, but I probed the namespace first: onlyjulialang-storage-us-east-1exists, and the sibling region names (julialang-storage-eu-west-1,us-west-2and others) returnNoSuchBucket— they are unclaimed and registrable by anyone today. A glob would therefore hand every job an attacker-registrable destination, the same reasoning already recorded forprod-<region>-starport-layer-bucket. The YAML carries a note to add a region explicitly if Julia ever adds one, and a test asserts the unclaimed siblings stay blocked.Hosts deliberately left blocked, with tests asserting they stay that way.
mobile-sdks.forter.comandnuget.devexpress.comreturn401, so they need aregistries:credential — allowlisting them would mask a user configuration error rather than fix one.nuget.hangfire.io,nuget.abp.io,registry.nes.herodevs.comandconnect.advancedcustomfields.comare commercial feeds tenanted by a license key in the path.dc.services.visualstudio.comis Application Insights telemetry ingestion from the NuGet tooling, not a registry, and is better left denied.dl.bintray.comis retired and serves nothing.How will you know you've accomplished your goal?
Two new tests cover the additions.
TestEgressAllowlist_PublicRegistriesThirdWaveAllowedasserts 18 representative registry URLs are permitted and 40 related URLs stay blocked.TestEgressAllowlist_ChangelogHostsThirdWaveAllowedasserts 4 changelog URLs are permitted and 13 stay blocked.The blocked probes are the substance of the tests rather than an afterthought. Every exact entry has an
evil.<host>child probe, so a later widening to a leading-dot suffix cannot pass silently — a gap this check caught in an earlier wave. Lookalike parents and suffix-appending attacker domains (archivist.terraform.io.attacker.com) are covered, as are the path-style S3 apexes and the unclaimed Julia sibling buckets.Checklist