Description
During a security and tooling review of arc-node, two supply-chain and transport security areas were identified:
-
Blockscout Frontend TLS Verification:
- In
deployments/monitoring/config-blockscout/frontend/frontend.env, NODE_TLS_REJECT_UNAUTHORIZED=0 disables certificate verification process-wide for Node.js, exposing outbound traffic to MITM risks.
- It should be commented out, documenting
NODE_EXTRA_CA_CERTS as the recommended path for corporate proxy environments.
-
CI Action SHA Pinning:
- Third-party GitHub Actions in
.github/workflows/ci.yml (actions/checkout, setup-rust-toolchain, install-action, setup-node, foundry-toolchain, buf-action, etc.) currently reference mutable tags/branches instead of immutable 40-character commit SHAs.
Proposed Solution
- Comment out
NODE_TLS_REJECT_UNAUTHORIZED=0 and add guidance comments.
- Pin third-party CI actions to full commit SHAs with version comments.
I already have the tested patch ready and verified. Could you please assign this issue to me so I can submit the PR?
Description
During a security and tooling review of
arc-node, two supply-chain and transport security areas were identified:Blockscout Frontend TLS Verification:
deployments/monitoring/config-blockscout/frontend/frontend.env,NODE_TLS_REJECT_UNAUTHORIZED=0disables certificate verification process-wide for Node.js, exposing outbound traffic to MITM risks.NODE_EXTRA_CA_CERTSas the recommended path for corporate proxy environments.CI Action SHA Pinning:
.github/workflows/ci.yml(actions/checkout,setup-rust-toolchain,install-action,setup-node,foundry-toolchain,buf-action, etc.) currently reference mutable tags/branches instead of immutable 40-character commit SHAs.Proposed Solution
NODE_TLS_REJECT_UNAUTHORIZED=0and add guidance comments.I already have the tested patch ready and verified. Could you please assign this issue to me so I can submit the PR?