Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add exclusion patterns for curl-unecrypted-url #71

Merged
merged 2 commits into from
Jan 6, 2025

Conversation

fruechel-canva
Copy link
Contributor

curl-unecrypted-url produces a lot of false positives on repositories with lots of cloud infrastructure code for AWS or GCP. These providers use link local URLs via HTTP without TLS. This is equivalent to localhost patterns.

@CLAassistant
Copy link

CLAassistant commented Dec 13, 2024

CLA assistant check
All committers have signed the CLA.

GrosQuildu
GrosQuildu previously approved these changes Dec 13, 2024
Copy link
Collaborator

@GrosQuildu GrosQuildu left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, thanks for the PR!

@mschwager
Copy link
Member

LGTM - the one suggestion I have is that we add the AWS IPv6 metadata address too: https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/instancedata-data-retrieval.html#instancedata-inside-access

@mschwager
Copy link
Member

Hey @fruechel-canva, are you still interested in this PR?

@fruechel-canva
Copy link
Contributor Author

Hi @mschwager, sorry for the delay. I had to get approval from legal for the CLA and then went on a holiday break. I've signed the CLA and added the IPv6 address like you proposed. Let me know if you need anything else!

Copy link
Member

@mschwager mschwager left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No worries @fruechel-canva! Thanks for the improvements here, we appreciate it!

curl-unecrypted-url produces a lot of false positives on repositories
with lots of cloud infrastructure code for AWS or GCP. These providers
use link local URLs via HTTP without TLS. This is equivalent to
localhost patterns.
@mschwager mschwager merged commit 1e3cf08 into trailofbits:main Jan 6, 2025
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants