New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Update GHES host check #1648
Update GHES host check #1648
Conversation
|
||
const hostname = ghUrl.hostname.trimEnd().toUpperCase() | ||
const isGitHubHost = (hostname == 'GITHUB.COM') | ||
const isProximaHost = (hostname.endsWith('GHE.COM') || hostname.endsWith('GHE.LOCALHOST')) |
Check failure
Code scanning / CodeQL
Incomplete URL substring sanitization High
GHE.COM
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
???
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
???
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Incomplete URL substring sanitization
'GHE.COM' may be preceded by an arbitrary host name.
updating alowed hosts in artifact ghes check using dot prepend ghe host
1e316cc
to
3b02a6f
Compare
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
R
What are we doing?
Currently, we are only checking equality against
github.com
to ensure artifact and cache actions are being run in a non-enterprise host. We need to update this check to allow requests fromghe.com
andghe.localhost
, additional allowed hostnames for production and local development.Fixes https://github.com/github/actions-results-team/issues/2208
How are we doing it?
isGhes
How do I test?