Conversation
Add the exact host dotnetcli.blob.core.windows.net to the dotnet_sdk egress allowlist. It serves releases-index.json, Microsoft's production Azure Blob storage for .NET release metadata (documented in dotnet/core). Pinned as an exact host because the dotnetcli storage account is globally unique and Microsoft-owned; a leading-dot or glob form over the shared blob.core.windows.net domain would be attacker-satisfiable. Adds positive and negative (child widening) regression probes.
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The narrowly scoped allowlist entry has authoritative ownership evidence and appropriate regression coverage.
Review effort: Balanced
Findings: None
What changed in this PR
Adds Microsoft’s exact .NET release-metadata host to the global egress defaults.
Changes:
- Allowlisted
dotnetcli.blob.core.windows.netfordotnet_sdk. - Added positive and exact-host boundary tests.
| File | Description |
|---|---|
internal/handlers/egress_allowlist_defaults.yaml |
Adds the exact Microsoft-owned metadata host. |
internal/handlers/egress_allowlist_test.go |
Verifies access while blocking child subdomains. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|
Looks like Dependabot should be using |
jurre
left a comment
There was a problem hiding this comment.
It looks like this is actually an deprecated endpoint as per dotnet/core#10262 and we should be using this instead: https://builds.dotnet.microsoft.com/dotnet/release-metadata/releases-index.json, that's also already in the allow list. cc @JamieMagee you might have more context.
I'm fine merging this as a stop-gap until we have that fixed
What are you trying to accomplish?
Dependabot
nuget/ .NET SDK update jobs need to readreleases-index.jsonfromhttps://dotnetcli.blob.core.windows.net/dotnet/release-metadata/releases-index.json, but that host is not in the static egress allowlist, so the request is blocked under enforce.This adds
dotnetcli.blob.core.windows.netas an exact host to thedotnet_sdkecosystem defaults ininternal/handlers/egress_allowlist_defaults.yaml.Why it belongs in the static defaults (public, provider-controlled infrastructure):
azuredns(azuredns-hostmaster.microsoft.comSOA).200anonymously (no auth challenge).CN=*.blob.core.windows.net, O=Microsoft Corporation.dotnet/corerepo README documents this exact URL as Microsoft's production Azure Blob storage for .NET release metadata ("We use ... Azure Blob Storage as our production platform").Anything you want to highlight for special attention from reviewers?
Matching form — exact host, deliberately not leading-dot/glob.
blob.core.windows.netis a shared multi-tenant storage domain where the storage-account label is customer-choosable, so a.blob.core.windows.netor*…blob.core.windows.netform would be attacker-satisfiable. The exact host pins the globally-unique, Microsoft-owneddotnetcliaccount, which cannot be spoofed — the same reasoning used for the existingnugetregistryv2prod.blob.core.windows.netentry.A negative child probe (
https://evil.dotnetcli.blob.core.windows.net/payload) was added toTestEgressAllowlist_NewEntriesDoNotWidenBeyondExactHostsso that any future widening of this entry to a leading-dot suffix fails CI.How will you know you've accomplished your goal?
go build ./...— passes.go test ./internal/handlers/ -run TestEgress -count=1— all egress tests pass, includingTestEgressDefaults_NoRedundantEntries(not already covered) andTestEgressDefaults_AliasedEcosystemsStayInSync.https://dotnetcli.blob.core.windows.net/dotnet/release-metadata/releases-index.jsonis allowed..dotnetcli.blob.core.windows.netmakes the child probe fail (confirmed), then reverted.Checklist