Restrict IPs for packages dependency proxy
Merge branch 'security-1106-ssrf-via-dependency-proxy-17-2' into '17-2-stable-ee' See merge request gitlab-org/security/gitlab!4390 Changelog: security
Showing
- ee/lib/api/concerns/dependency_proxy/packages_helpers.rb 16 additions, 2 deletionsee/lib/api/concerns/dependency_proxy/packages_helpers.rb
- ee/spec/features/dependency_proxy/packages/maven_spec.rb 32 additions, 0 deletionsee/spec/features/dependency_proxy/packages/maven_spec.rb
- ee/spec/features/dependency_proxy/packages/npm_spec.rb 32 additions, 0 deletionsee/spec/features/dependency_proxy/packages/npm_spec.rb
- ee/spec/requests/api/dependency_proxy/packages/maven_spec.rb 31 additions, 0 deletionsee/spec/requests/api/dependency_proxy/packages/maven_spec.rb
- ee/spec/support/shared_examples/features/dependency_proxy/packages_shared_examples.rb 15 additions, 0 deletions...les/features/dependency_proxy/packages_shared_examples.rb
- lib/gitlab/workhorse.rb 20 additions, 2 deletionslib/gitlab/workhorse.rb
- spec/lib/gitlab/workhorse_spec.rb 71 additions, 1 deletionspec/lib/gitlab/workhorse_spec.rb
- workhorse/_support/lint_last_known_acceptable_go1.21.txt 9 additions, 8 deletionsworkhorse/_support/lint_last_known_acceptable_go1.21.txt
- workhorse/_support/lint_last_known_acceptable_go1.22.txt 9 additions, 8 deletionsworkhorse/_support/lint_last_known_acceptable_go1.22.txt
- workhorse/internal/dependencyproxy/dependencyproxy.go 40 additions, 4 deletionsworkhorse/internal/dependencyproxy/dependencyproxy.go
- workhorse/internal/dependencyproxy/dependencyproxy_test.go 82 additions, 5 deletionsworkhorse/internal/dependencyproxy/dependencyproxy_test.go
- workhorse/internal/sendurl/sendurl.go 12 additions, 0 deletionsworkhorse/internal/sendurl/sendurl.go
- workhorse/internal/sendurl/sendurl_test.go 13 additions, 0 deletionsworkhorse/internal/sendurl/sendurl_test.go
- workhorse/internal/transport/transport.go 113 additions, 0 deletionsworkhorse/internal/transport/transport.go
- workhorse/internal/transport/transport_test.go 110 additions, 0 deletionsworkhorse/internal/transport/transport_test.go
Please register or sign in to comment