Conversation
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: vinokurig The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
| throw new IOException( | ||
| "Only http and https URLs are allowed, got: " + scheme + " in URL " + url); | ||
| } | ||
| URLConnection connection = parsedUrl.openConnection(); |
… providers Restrict URL fetching to http/https schemes only, rejecting file://, ftp://, jar:, and other schemes that could be exploited to read local files or access cloud metadata endpoints. Also fix incorrect null-check in ScmService that validated `repository` twice instead of `filePath`. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
|
Docker image build succeeded: quay.io/eclipse/che-server:pr-1048 kubectl patch commandkubectl patch -n eclipse-che "checluster/eclipse-che" --type=json -p="[{"op": "replace", "path": "/spec/components/cheServer/deployment", "value": {containers: [{image: "quay.io/eclipse/che-server:pr-1048", name: che}]}}]" |
|
/retest |
|
@vinokurig: The following tests failed, say
Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
… providers
What does this PR do?
Restrict URL fetching to
http/httpsschemes only, rejectingfile://,ftp://,jar:, and other schemes that could be exploited to read local files or access cloud metadata endpoints. Also fix incorrect null-check in ScmService that validatedrepositorytwice instead offilePath.Screenshot/screencast of this PR
What issues does this PR fix or reference?
https://redhat.atlassian.net/browse/CRW-11956
How to test this PR?
N/A
PR Checklist
As the author of this Pull Request I made sure that:
What issues does this PR fix or referenceandHow to test this PRcompletedRelease Notes
Reviewers
Reviewers, please comment how you tested the PR when approving it.