From d4f0dd1d37e7a997c2feb83771c9206c3b632b09 Mon Sep 17 00:00:00 2001 From: murph Date: Tue, 22 Sep 2026 16:35:28 +0000 Subject: [PATCH] fix(release): disable http.followRedirects on authenticated git commands Closes the deferred GH006 hardening item from node-atera#81's CodeRabbit review (task_1788483503324_98138700, item 1): git's http.followRedirects defaults to 'initial', so the inline Basic-auth header (-c http.extraheader) could be sent to a redirected host on the first request of a compromised/malicious redirect. Adds -c http.followRedirects=false alongside the existing -c http.extraheader on all 3 authenticated git commands (fetch --tags, tag push, release/next push) in release.yml. Same pattern already present on node-halopsa, node-syncro, node-ninjaone (applied separately, verified live before this change). This closes the remaining 7 of 10 GH006 repos to match. --- .github/workflows/release.yml | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index f839365..47b47e8 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -124,7 +124,7 @@ jobs: set -euo pipefail AUTH_HEADER="AUTHORIZATION: basic $(printf 'x-access-token:%s' "$GITHUB_TOKEN" | base64 | tr -d '\n')" echo "::add-mask::$AUTH_HEADER" - git -c http.extraheader="$AUTH_HEADER" fetch "https://github.com/${{ github.repository }}.git" --tags + git -c http.extraheader="$AUTH_HEADER" -c http.followRedirects=false fetch "https://github.com/${{ github.repository }}.git" --tags VERSION=$(jq -r '.version' package.json) PKG_NAME=$(jq -r '.name' package.json) @@ -161,7 +161,7 @@ jobs: AUTH_HEADER="AUTHORIZATION: basic $(printf 'x-access-token:%s' "$GITHUB_TOKEN" | base64 | tr -d '\n')" echo "::add-mask::$AUTH_HEADER" git tag "v${VERSION}" - git -c http.extraheader="$AUTH_HEADER" push "https://github.com/${{ github.repository }}.git" "v${VERSION}" + git -c http.extraheader="$AUTH_HEADER" -c http.followRedirects=false push "https://github.com/${{ github.repository }}.git" "v${VERSION}" - name: "Publish: npm publish" if: steps.mode.outputs.mode == 'publish' && steps.mode.outputs.npm_published == 'false' @@ -270,7 +270,7 @@ jobs: publishes until this merges." AUTH_HEADER="AUTHORIZATION: basic $(printf 'x-access-token:%s' "$PUSH_TOKEN" | base64 | tr -d '\n')" echo "::add-mask::$AUTH_HEADER" - git -c http.extraheader="$AUTH_HEADER" push --force "https://github.com/${{ github.repository }}.git" release/next + git -c http.extraheader="$AUTH_HEADER" -c http.followRedirects=false push --force "https://github.com/${{ github.repository }}.git" release/next if gh pr view release/next --json state --jq .state 2>/dev/null | grep -q OPEN; then gh pr edit release/next --title "chore(release): ${VERSION}"