adoptium / jenkins-helper

Jenkins Node helper API and helper jobs
Apache License 2.0
8 stars 26 forks source link

Security: Enable SSL Signature Checks #58

Closed steelhead31 closed 9 months ago

steelhead31 commented 9 months ago

Remove disabled signature checks for download of Jenkins slave.jar from HTTPs served jenkins server.

Fixes https://github.com/adoptium/infrastructure/issues/3342

Identified in Trail Of Bits Security Audit: TOB-9

steelhead31 commented 9 months ago

/thaw

github-actions[bot] commented 9 months ago

Sorry @steelhead31, the code freeze is still in place.

steelhead31 commented 9 months ago

/thaw