ros-infrastructure / cookbook-ros-buildfarm

Apache License 2.0
2 stars 2 forks source link

Bundle publish-over-ssh plugin. #106

Closed nuclearsandwich closed 2 years ago

nuclearsandwich commented 2 years ago

This PR is stacked on top of #105 and should be rebased once that PR merges.

This plugin has been delisted citing unresolved security issues1.

Many of these problems require administrator permissions to leverage but some of them are exploitable without. To mitigate this issue 330d9c666a7a53fca50f88acd4df8e33e7269a29 blocks these requests at the nginx reverse proxy layer.

v-lopez commented 2 years ago

Tested this on our private farm and worked great, although our plugin was already manually installed.

nuclearsandwich commented 2 years ago

Merging in order to deploy to test farm.