Skip to content

Commit ace249d

Browse files
committed
ci: remove dangerous registry wildcards to prevent data exfiltration via tenant subdomains
1 parent 2e2a753 commit ace249d

1 file changed

Lines changed: 0 additions & 5 deletions

File tree

.github/workflows/docker.yml

Lines changed: 0 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -204,12 +204,7 @@ jobs:
204204
registry-1.docker.io:443
205205
auth.docker.io:443
206206
docker.io:443
207-
*.gcr.io:443
208-
*.pkg.dev:443
209-
*.quay.io:443
210207
quay.io:443
211-
*.dkr.ecr.*.amazonaws.com:443
212-
*.azurecr.io:443
213208
docker-images-prod.s3.us-west-2.amazonaws.com:443
214209
docker-images-prod.s3.us-east-1.amazonaws.com:443
215210
osv-vulnerabilities.storage.googleapis.com:443

0 commit comments

Comments
 (0)