Skip to content

[Security] Re-enable TLS verification in Blockscout frontend and pin CI action SHAs #464

Description

@mertcano

Description

During a security and tooling review of arc-node, two supply-chain and transport security areas were identified:

  1. Blockscout Frontend TLS Verification:

    • In deployments/monitoring/config-blockscout/frontend/frontend.env, NODE_TLS_REJECT_UNAUTHORIZED=0 disables certificate verification process-wide for Node.js, exposing outbound traffic to MITM risks.
    • It should be commented out, documenting NODE_EXTRA_CA_CERTS as the recommended path for corporate proxy environments.
  2. CI Action SHA Pinning:

    • Third-party GitHub Actions in .github/workflows/ci.yml (actions/checkout, setup-rust-toolchain, install-action, setup-node, foundry-toolchain, buf-action, etc.) currently reference mutable tags/branches instead of immutable 40-character commit SHAs.

Proposed Solution

  • Comment out NODE_TLS_REJECT_UNAUTHORIZED=0 and add guidance comments.
  • Pin third-party CI actions to full commit SHAs with version comments.

I already have the tested patch ready and verified. Could you please assign this issue to me so I can submit the PR?

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions