Skip to content

[codex] fix: pin safe fetch to vetted public IPs#358

Open
aa-matsunari wants to merge 1 commit intosafishamsi:v4from
aa-matsunari:codex/harden-safe-fetch
Open

[codex] fix: pin safe fetch to vetted public IPs#358
aa-matsunari wants to merge 1 commit intosafishamsi:v4from
aa-matsunari:codex/harden-safe-fetch

Conversation

@aa-matsunari
Copy link
Copy Markdown

Summary

  • pin outbound fetches to vetted public IPs instead of re-resolving during connect
  • revalidate redirect targets and cover the hardened path with tests

Changed files

  • graphify/security.py
  • tests/test_security.py

Impact

  • reduces DNS rebinding / SSRF exposure in URL ingestion flows

Tests

  • /tmp/graphify-review/.venv/bin/python -m pytest /tmp/graphify-review-pr3/tests/test_security.py

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant