Repository navigation
fix(release): disable http.followRedirects on authenticated git commands - #91
Conversation
Closes the deferred GH006 hardening item from node-atera#81's CodeRabbit review (task_1788483503324_98138700, item 1): git's http.followRedirects defaults to 'initial', so the inline Basic-auth header (-c http.extraheader) could be sent to a redirected host on the first request of a compromised/malicious redirect. Adds -c http.followRedirects=false alongside the existing -c http.extraheader on all 3 authenticated git commands (fetch --tags, tag push, release/next push) in release.yml. Same pattern already present on node-halopsa, node-syncro, node-ninjaone (applied separately, verified live before this change). This closes the remaining 7 of 10 GH006 repos to match.
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (1)
Included review availability: This review used your included allowance. 0 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 2 reviews per hour. 📝 WalkthroughWalkthroughThe release workflow disables HTTP redirects for the tag fetch, version-tag push, and ChangesRelease workflow
Priority: ➖ Normal Estimated code review effort: 2 (Simple) | ~5 minutes Change: Bug fix Suggested reviewers: Merge Risk: ⚪ Minimal · up to The release commands now fail rather than follow HTTP redirects. The visible workflow uses direct HTTPS URLs, and no actionable merge-blocking risk is established. Architecture SummaryArchitecture risk: 🔵 Low · up to The changed surface does not map to a changed system, dependency edge, entrypoint, or external dependency. Changed systems: None identified. Architecture concerns Review detailsBefore / after behavior
🚥 Pre-merge checks | ✅ 6✅ Passed checks (6 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
✨ Simplify code
Comment |
|
@coderabbitai review |
✅ Action performedReview finished.
|
Summary
-c http.followRedirects=falsealongside the existing-c http.extraheader=...on all 3 authenticated git commands inrelease.yml(fetch --tags, tag push, release/next push).http.followRedirectsdefaults toinitial, so the inline Basic-auth header could be sent to a redirected host on the first request of a compromised/malicious redirect — cheap, mechanical fix, no behavior change to normal operation.Test plan
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.Summary by CodeRabbit