Join GitHub today
GitHub is home to over 31 million developers working together to host and review code, manage projects, and build software together.
Sign upFix dist automation security #20629
Comments
brson
added
the
A-infrastructure
label
Jan 6, 2015
This comment has been minimized.
This comment has been minimized.
|
CC @bheesham |
brson
added
the
I-nominated
label
Jan 14, 2015
This comment has been minimized.
This comment has been minimized.
|
Nominating because this could cause very bad problems if a stable release gets overwritten. |
This comment has been minimized.
This comment has been minimized.
|
It looks like creating a |
brson
added this to the 1.0 milestone
Jan 15, 2015
brson
added
P-medium
and removed
I-nominated
labels
Jan 15, 2015
brson
referenced this issue
Jan 16, 2015
Closed
Invalidate artifacts on CloudFront more reliably #21239
alexcrichton
closed this
Apr 2, 2015
This comment has been minimized.
This comment has been minimized.
|
I believe this has been fixed, but feel free to correct me @brson |
This comment has been minimized.
This comment has been minimized.
|
I don't consider this fixed yet because buildbot is still not behind HTTPS. |
alexcrichton
reopened this
May 26, 2015
This comment has been minimized.
This comment has been minimized.
|
Proxying requests to Buildbot through a server that supports TLS is the only way to get HTTPS working with Buildbot. The buildbot web interface is already being proxied through nginx, so the configuration just needs to be tweaked to get it to be served over HTTPS. |
This comment has been minimized.
This comment has been minimized.
|
Shouldn't this be P-High? It is a security vulnerability. |
steveklabnik
added
P-high
and removed
P-medium
labels
Jun 29, 2016
This comment has been minimized.
This comment has been minimized.
|
@DemiMarie thanks for the ping here. I believe that at one point, we re-named |
This comment has been minimized.
This comment has been minimized.
|
I've now configured letsencrypt and buildbot is behind HTTPS now, so I'm gonna close this. @brson though if I'm forgetting something feel free to reopen! |
alexcrichton
closed this
Jun 29, 2016
This comment has been minimized.
This comment has been minimized.
|
@alexcrichton Not @brson, just thinking in general about security, but just wondering if the buildbot credentials should be changed, since the current ones might have been leaked (and possibly changed to use TLS client certificates). HPKP might also be useful (the buildbot certificate should never change without everyone knowing). |
This comment has been minimized.
This comment has been minimized.
|
@DemiMarie yes that's a good idea to change the passwords. |
brson commentedJan 6, 2015
Our buildbot instance is set up so that anybody with the not-so-secret credentials can trigger a build. At present this means that anybody can publish any commit in the repo to a release channel at will.