Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Remove repo pass netrc option from repos #2214

Closed
wants to merge 1 commit into from

Conversation

anbraten
Copy link
Member

Not trusted clone plugins should never get our credentials as an attacker could simply replace the clone step by a malicious one and therefore gather netrc credentials.

@woodpecker-bot
Copy link
Collaborator

woodpecker-bot commented Aug 15, 2023

Deployment of preview was successful: https://woodpecker-ci-woodpecker-pr-2214.surge.sh

@6543
Copy link
Member

6543 commented Aug 15, 2023

before we remove that option, we nee to make sure why it was added in the first place and if this can be solved in an other way now :)

@6543 6543 added the breaking will break existing installations if no manual action happens label Aug 15, 2023
@anbraten
Copy link
Member Author

@6543 It was added as fallback to allow custom clone images which are not listed as trusted images.

@anbraten
Copy link
Member Author

closing as of #2601

@anbraten anbraten closed this Oct 17, 2023
@anbraten anbraten deleted the security branch October 17, 2023 08:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
breaking will break existing installations if no manual action happens security
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants