diff --git a/internal/handlers/egress_allowlist_defaults.yaml b/internal/handlers/egress_allowlist_defaults.yaml index e80fddf..918176c 100644 --- a/internal/handlers/egress_allowlist_defaults.yaml +++ b/internal/handlers/egress_allowlist_defaults.yaml @@ -466,6 +466,11 @@ ecosystem_default_domains: # Official Microsoft .NET SDK/runtime build hosts. - builds.dotnet.microsoft.com - ci.dot.net + # .NET release metadata index (releases-index.json), served from Microsoft's + # production Azure Blob storage (documented in dotnet/core). Exact host: the + # "dotnetcli" account is globally unique and Microsoft-owned, so it cannot be + # spoofed. + - dotnetcli.blob.core.windows.net hex: - repo.hex.pm - hex.pm diff --git a/internal/handlers/egress_allowlist_test.go b/internal/handlers/egress_allowlist_test.go index 7af8f6f..0dba991 100644 --- a/internal/handlers/egress_allowlist_test.go +++ b/internal/handlers/egress_allowlist_test.go @@ -718,6 +718,7 @@ func TestEgressAllowlist_NewEntriesDoNotWidenBeyondExactHosts(t *testing.T) { "https://evil.julialang-s3.julialang.org/bin", "https://evil.maven.artifacts.atlassian.com/maven", "https://evil.mirrors.huaweicloud.com/repository/npm", + "https://evil.dotnetcli.blob.core.windows.net/payload", } // Sibling hosts: names sharing a parent with an added entry. These pin the @@ -901,6 +902,7 @@ func TestEgressAllowlist_AddedMissingDomainsAllowed(t *testing.T) { "https://repo.broadcom.com/artifactory/repo", "https://builds.dotnet.microsoft.com/dotnet/Sdk/x.zip", "https://ci.dot.net/public/dotnet/x.nupkg", + "https://dotnetcli.blob.core.windows.net/dotnet/release-metadata/releases-index.json", "https://charts.bitnami.com/bitnami/index.yaml", "https://charts.jetstack.io/charts/cert-manager.tgz", "https://prometheus-community.github.io/helm-charts/index.yaml",