Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

jenkins: whitelist IPs allowed to push status changes #142

Merged
merged 2 commits into from
Jul 14, 2017

Conversation

phillipj
Copy link
Member

@phillipj phillipj commented May 6, 2017

This is needed to ensure not everyone on the internet can push an inline status to any PR if they know the bot URL.

@jbergstroem does this seem sufficient?

Closes #61

addaleax

This comment was marked as off-topic.

@phillipj
Copy link
Member Author

phillipj commented May 6, 2017

Fixed commented issues and force pushed.

addaleax

This comment was marked as off-topic.

This is needed to ensure not everyone on the internet can push an inline
status to any PR if they know the bot URL.
@phillipj
Copy link
Member Author

Rebased and force pushed to fix merge conflict with recent updates to master.

@phillipj phillipj merged commit e2d989e into nodejs:master Jul 14, 2017
@phillipj phillipj deleted the whitelist-jenkins-ips branch July 14, 2017 20:29
phillipj added a commit to phillipj/build that referenced this pull request Nov 7, 2017
Providing `$JENKINS_WORKER_IPS` environment variable at startup will
activate the whitelist implemented in the bot, validating who's allowed
pushed Jenkins job updates to inline PRs on github.com.

Refs nodejs/github-bot#142
phillipj added a commit to phillipj/build that referenced this pull request Nov 7, 2017
Providing `$JENKINS_WORKER_IPS` environment variable at startup will
activate the whitelist implemented in the bot, validating who's allowed
to pushed Jenkins job updates as inline PR statuses on github.com.

Refs nodejs/github-bot#142
phillipj added a commit to phillipj/build that referenced this pull request Nov 27, 2017
Providing `$JENKINS_WORKER_IPS` environment variable at startup will
activate the whitelist implemented in the bot, validating who's allowed
to pushed Jenkins job updates as inline PR statuses on github.com.

Refs: nodejs/github-bot#142
PR-URL: nodejs#985
Reviewed-By: Jon Moss <me@jonathanmoss.me>
Reviewed-By: Joyee Cheung <joyeec9h3@gmail.com>
Reviewed-By: Rod Vagg <rod@vagg.org>
phillipj added a commit to nodejs/build that referenced this pull request Nov 27, 2017
Providing `$JENKINS_WORKER_IPS` environment variable at startup will
activate the whitelist implemented in the bot, validating who's allowed
to pushed Jenkins job updates as inline PR statuses on github.com.

Refs: nodejs/github-bot#142
PR-URL: #985
Reviewed-By: Jon Moss <me@jonathanmoss.me>
Reviewed-By: Joyee Cheung <joyeec9h3@gmail.com>
Reviewed-By: Rod Vagg <rod@vagg.org>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants