Repository navigation
git/github: default GitHub webhooks to TLS verification - #3714
knative-prow[bot] merged 1 commit into
Conversation
|
|
|
Welcome @Vi-shub! It looks like this is your first PR to knative/func π |
|
Hi @Vi-shub. Thanks for your PR. I'm waiting for a knative member to verify that this patch is reasonable to test. If it is, they should reply with Regular contributors should join the org to skip this step. Once the patch is verified, the new status will be reflected by the I understand the commands that are listed here. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
Codecov Reportβ Patch coverage is
Additional details and impacted files@@ Coverage Diff @@
## main #3714 +/- ##
==========================================
+ Coverage 56.18% 56.98% +0.79%
==========================================
Files 181 181
Lines 20928 21116 +188
==========================================
+ Hits 11758 12032 +274
+ Misses 8007 7861 -146
- Partials 1163 1223 +60
Flags with carried forward coverage won't be shown. Click here to find out more. β View full report in Codecov by Harness. π New features to boost your workflow:
|
|
@lkingland @gauron99 do you recall why we would disable tls here? Tests maybe? |
|
@Vi-shub welcome, Please recommit with one line changed. As for the actual change - I see it was written like this 3 years ago (#1594) when first added and there is no comments about it in the PR besides the code comment. I suggest the func team review this and take a decision. |
I dont remember this ever changing, might be older than my work here π |
Set repository webhook HookConfig insecure_ssl to 0 so GitHub verifies TLS when delivering to HTTPS payload URLs Signed-off-by: Vi-shub <smsharma3121@gmail.com>
1e5ad39 to
d032347
Compare
Thanks for catching that youβre right. The large diff was almost certainly from CRLF vs LF on my side (whole file re-normalized), not an intentional reformat. I have reset Codecov should look sane once the diff is actually one line (or a single small hunk) instead of line-ending churn. |
|
@matejvasek @gauron99 can you review this please. Thankyou for your time :) |
|
/ok-to-test |
There was a problem hiding this comment.
Pull request overview
Updates the GitHub webhook creation logic in pkg/git/github to default to secure TLS certificate verification when delivering webhooks to HTTPS payload URLs, aligning behavior with GitHubβs recommended insecure_ssl setting and addressing #3713.
Changes:
- Change repository webhook
insecure_ssldefault from"1"(skip TLS verification) to"0"(verify TLS) inClient.CreateWebHook. - Remove the prior insecure default and associated inline TODO by making the secure behavior explicit.
π‘ Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
|
/approve |
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: matejvasek, Vi-shub The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
pkg/git/githubtoinsecure_ssl: "0"so GitHub verifies TLS when delivering to HTTPS payload URLs."1") and the associated TODO inCreateWebHook./kind bug
Fixes #3713
GitHubβs webhook
insecure_sslsetting was hard-coded to"1", which disables TLS certificate verification for HTTPS webhook targets. The secure default is"0"for normal HTTPS endpoints. Users whose controller URL uses a certificate that GitHub does not trust (for example self-signed TLS in lab environments) may need a follow-up opt-in if hook creation or deliveries fail.@davidhadas @lkingland can you please review this. Thanks for your time.