Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Mitigate jenkins faults reported by Upguard #3400

Open
Tracked by #3380
sxa opened this issue Feb 16, 2024 · 4 comments
Open
Tracked by #3380

Mitigate jenkins faults reported by Upguard #3400

sxa opened this issue Feb 16, 2024 · 4 comments
Assignees

Comments

@sxa
Copy link
Member

sxa commented Feb 16, 2024

Details private but can be shared with anyone in the team able to work on it.

@TiagoLucas22478
Copy link

Hey @sxa and other Adoptium committers,
What can we at the Foundation do for this issue to go easier?
There are some findings on UpGuard and we see this issue is not getting a lot of traction.

@mbarbero

@sxa
Copy link
Member Author

sxa commented Jul 9, 2024

Replying via email - many of them appear to be because we're using an Ubuntu-supported nginx and upguard may be objecting because it's not a later version.

@sxa sxa added the Jenkins label Jul 9, 2024
@sxa sxa self-assigned this Jul 9, 2024
@sxa sxa modified the milestones: 2024-06 (June), 2024-07 (July) Jul 9, 2024
@sxa
Copy link
Member Author

sxa commented Jul 9, 2024

server_tokens off; added to nginx configuration on jenkins and TRSS in order to remove the version number from HTTP responses.

EDIT 25/July: Same change applied to AWX server.

@sxa
Copy link
Member Author

sxa commented Sep 4, 2024

Struggling to find a suitable option in the CloudFlare UI that will allow the port 80 remediation (Upguard seems unwilling to accept anything that isn't a straight HTTP redirect)

@sxa sxa removed this from the 2024-08 (August) milestone Nov 1, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
Status: Todo
Development

No branches or pull requests

2 participants