Skip to content

๐Ÿ›ก๏ธ Sentinel: [HIGH] ๋นˆ ํ˜ธ์ŠคํŠธ๋ช…์„ ์•…์šฉํ•œ SSRF ์šฐํšŒ ์ทจ์•ฝ์  ํŒจ์น˜ - #1095

Draft
seonghobae wants to merge 4 commits into
developfrom
sentinel/fix-ssrf-empty-hostname-11491511834681904698
Draft

๐Ÿ›ก๏ธ Sentinel: [HIGH] ๋นˆ ํ˜ธ์ŠคํŠธ๋ช…์„ ์•…์šฉํ•œ SSRF ์šฐํšŒ ์ทจ์•ฝ์  ํŒจ์น˜#1095
seonghobae wants to merge 4 commits into
developfrom
sentinel/fix-ssrf-empty-hostname-11491511834681904698

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 2, 2026

Copy link
Copy Markdown
Contributor

Current scope

Fix malformed empty-host URLs that could cross the SSRF URL-safety boundary in both the control-plane and CLI validators.

Current exact head: 30fbcdcd345a0de9a597ab1ce03e199068770838 against develop@e71d37e7c58118e6764c96ab7c4492fe33eed6f8.

The production fix rejects an empty parsed hostname before IP/DNS classification. Fleet TDD added executable coverage in descendant 6109aa9c3dd44355db3b2af2668cd57437731a36 for both validators and for http://, https://, http://user@, and https://user@. The current head 30fbcdcdโ€ฆ is a non-semantic descendant of that repair (6109aaโ€ฆ โ†’ 30fbcdโ€ฆ compares with files=[]), so the test/fix delta is retained without force or destructive restack.

Verification state

Keep this PR Draft. Do not transfer predecessor checks.

At current exact head 30fbcdcdโ€ฆ, Tests 33737129256, Security Process 33737129265, Security Scan 33737129440, SAST 33737129460, OSV 33737130262, Scorecard 33737129402, Pinned HTTPS Coverage 33737129308, OpenSSF Evidence Coverage 33737129410, Scan path coverage 33737129355, and Retention Audit Coverage 33737129234 are queued. No exact-head terminal GREEN has been established yet.

The pre-checkout runner-admission evidence has been routed to the canonical .github#712 owner path. Do not merge, mark Ready, or claim release readiness until unchanged-head repository/security evidence is terminal and review state remains clean.

@google-labs-jules

Copy link
Copy Markdown

๐Ÿ‘‹ Jules, reporting for duty! I'm here to lend a hand with this pull request.

When you start a review, I'll add a ๐Ÿ‘€ emoji to each comment to let you know I've read it. I'll focus on feedback directed at me and will do my best to stay out of conversations between you and other bots or reviewers to keep the noise down.

I'll push a commit with your requested changes shortly after. Please note there might be a delay between these steps, but rest assured I'm on the job!

For more direct control, you can switch me to Reactive Mode. When this mode is on, I will only act on comments where you specifically mention me with @jules. You can find this option in the Pull Request section of your global Jules UI settings. You can always switch back!

New to Jules? Learn more at jules.google/docs.


For security, I will only act on instructions from the user who triggered this task.

@coderabbitai

coderabbitai Bot commented Sep 2, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

โค๏ธ Share

Comment @coderabbitai help to get the list of available commands.

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Review found 1 potential issue.

Devin Review

Comment thread appguardrail_core/controlplane.py
@seonghobae
seonghobae marked this pull request as draft September 3, 2026 09:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Backlog

Development

Successfully merging this pull request may close these issues.

1 participant