[MEDIUM] Protect build dependency downloads with HTTPS - #745
Open
OskarEichler wants to merge 1 commit into
Open
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Use HTTPS for every direct OpenSSL, Kerberos, PostgreSQL, and EnterpriseDB PostgreSQL archive download used by cross-build and CI packaging paths.
Urgency: MEDIUM. The PostgreSQL and EnterpriseDB HTTP endpoints currently return build inputs directly over plaintext rather than redirecting to TLS. An on-path attacker could replace a native dependency or CI test archive. The resulting files are compiled, linked into binary gems, or executed during CI.
Evidence
Focused header checks showed:
http://ftp.postgresql.org/...returns the archive directly with HTTP 200.http://get.enterprisedb.com/...returns the archive directly with HTTP 200.Verification
rbenv exec ruby -c ext/extconf.rbgit diff --checkScope and compatibility
This changes transport only. Versions, archive names, build flags, and workflow behavior remain unchanged.
Breaking-change note: none expected. Environments unable to establish TLS to these upstream hosts will need working CA trust rather than falling back to plaintext downloads.