Skip to content

fix(release): disable http.followRedirects on authenticated git commands - #91

Merged
wyre-agent-fleet[bot] merged 1 commit into
mainfrom
murph/gh006-followredirects-hardening
Oct 5, 2026
Merged

wyre-agent-fleet[bot] merged 1 commit into
mainfrom
murph/gh006-followredirects-hardening

Conversation

@wyre-agent-fleet

@wyre-agent-fleet wyre-agent-fleet Bot commented Sep 22, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Closes the deferred GH006 hardening item from node-atera#81's CodeRabbit review (task_1788483503324_98138700, item 1): adds -c http.followRedirects=false alongside the existing -c http.extraheader=... on all 3 authenticated git commands in release.yml (fetch --tags, tag push, release/next push).
  • git's http.followRedirects defaults to initial, so the inline Basic-auth header could be sent to a redirected host on the first request of a compromised/malicious redirect — cheap, mechanical fix, no behavior change to normal operation.
  • Same pattern already live on node-halopsa/node-syncro/node-ninjaone (verified before this change) — this brings the remaining 7 of 10 GH006 repos in line.

Test plan

  • Diff is exactly 3 lines changed, one flag added per authenticated git command, no other changes.
  • Verified the pre-change state (flag absent) and the already-fixed repos' exact pattern live via the GitHub API before writing this diff, to match byte-for-byte.
  • Not merging — Aaron-walled per this task family's established convention (see task_1788457898992's original GH006 rollout).

View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

Summary by CodeRabbit

  • Chores
    • Release publishing now avoids following HTTP redirects when fetching tags and pushing version tags or the next-release branch. The specified HTTPS destinations and existing authorization headers remain unchanged. This update affects the release process only; there are no changes to app features or user-facing behavior.

Closes the deferred GH006 hardening item from node-atera#81's CodeRabbit
review (task_1788483503324_98138700, item 1): git's http.followRedirects
defaults to 'initial', so the inline Basic-auth header (-c
http.extraheader) could be sent to a redirected host on the first
request of a compromised/malicious redirect. Adds -c
http.followRedirects=false alongside the existing -c http.extraheader on
all 3 authenticated git commands (fetch --tags, tag push, release/next
push) in release.yml.

Same pattern already present on node-halopsa, node-syncro, node-ninjaone
(applied separately, verified live before this change). This closes the
remaining 7 of 10 GH006 repos to match.
@coderabbitai

coderabbitai Bot commented Sep 22, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: a6f98492-809a-4878-90dc-de6fe75290c9
📥 Commits

Reviewing files that changed from the base of the PR and between e664885 and d4f0dd1.

📒 Files selected for processing (1)
  • .github/workflows/release.yml

Included review availability: This review used your included allowance. 0 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 2 reviews per hour.


📝 Walkthrough

Walkthrough

The release workflow disables HTTP redirects for the tag fetch, version-tag push, and release/next push. The commands retain their existing inline authorization headers and explicit HTTPS URLs.

Changes

Release workflow

Layer / File(s) Summary
Disable redirects for release Git commands
.github/workflows/release.yml
The tag fetch and two pushes set http.followRedirects=false. Their existing authorization headers and HTTPS URLs remain unchanged.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~5 minutes

Change: Bug fix

Suggested reviewers: asachs01

Merge Risk: ⚪ Minimal · up to d4f0d

The release commands now fail rather than follow HTTP redirects. The visible workflow uses direct HTTPS URLs, and no actionable merge-blocking risk is established.

Architecture Summary

Architecture risk: 🔵 Low · up to d4f0d

The changed surface does not map to a changed system, dependency edge, entrypoint, or external dependency.

Changed systems: None identified.

Architecture concerns
No architecture-level concerns identified.

Review details

Before / after behavior

  • observed — Modified behavior in .github/workflows/release.yml: The tag fetch now disables HTTP redirects while retaining its inline authorization header and explicit HTTPS URL.
  • observed — Modified behavior in .github/workflows/release.yml: The version-tag push now disables HTTP redirects while retaining its inline authorization header and explicit HTTPS URL.
  • observed — Modified behavior in .github/workflows/release.yml: The force-push of release/next now disables HTTP redirects while retaining its inline authorization header and explicit HTTPS URL.
🚥 Pre-merge checks | ✅ 6
✅ Passed checks (6 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: disabling HTTP redirects for authenticated Git commands in the release workflow.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Changelog Entry ✅ Passed The PR changes only .github/workflows/release.yml. It adds http.followRedirects=false to three authenticated Git commands. The custom check explicitly treats changes limited to CI workflows as hav…
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
✨ Simplify code
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@asachs01

asachs01 commented Oct 5, 2026

Copy link
Copy Markdown
Collaborator

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@wyre-agent-fleet
wyre-agent-fleet Bot merged commit 8f18c00 into main Oct 5, 2026
5 checks passed
@wyre-agent-fleet
wyre-agent-fleet Bot deleted the murph/gh006-followredirects-hardening branch October 5, 2026 19:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant