Skip to content

fix(security): re-enable TLS verification in blockscout frontend and pin CI action SHAs - #462

Closed
mertcano wants to merge 1 commit into
circlefin:mainfrom
mertcano:mertcano-patch-1
Closed

mertcano wants to merge 1 commit into
circlefin:mainfrom
mertcano:mertcano-patch-1

Conversation

@mertcano

Copy link
Copy Markdown

Summary of Changes

Addresses security and supply-chain vulnerabilities identified during the workspace audit across arc-node (Findings F-02 and F-06).


Key Remediations

  1. Re-Enable TLS Certificate Verification (F-02 / CWE-295):

    • Commented out NODE_TLS_REJECT_UNAUTHORIZED=0 in deployments/monitoring/config-blockscout/frontend/frontend.env.
    • Prevents disabling certificate verification across the Node.js process, protecting outbound Blockscout traffic against man-in-the-middle (MITM) attacks.
    • Documented NODE_EXTRA_CA_CERTS inline as the safe alternative for corporate proxy (e.g., ZScaler) environments requiring custom root certificates.
  2. Supply-Chain Integrity via Action Pinning (F-06 / CWE-829):

    • Pinned all third-party GitHub Actions in .github/workflows/ci.yml to immutable 40-character commit SHAs: - actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 - actions-rust-lang/setup-rust-toolchain@166cdcfd11aee3cb47222f9ddb555ce30ddb9659 # v1 - taiki-e/install-action@7623a79cdfecb99d681017af368ca353d9f49bb5 # v2 - actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0 - foundry-rs/foundry-toolchain@908c540300062bd5a7e473851cdb4282204cee09 # v1 - bufbuild/buf-action@fd21066df7214747548607aaa45548ba2b9bc1ff # v1.4.0 - docker/setup-buildx-action@d7f5e7f509e45cec5c76c4d5afdd7de93d0b3df5 # v4.1.0 - docker/build-push-action@f9f3042f7e2789586610d6e8b85c8f03e5195baf # v7.2.0
    • Retained semantic version comments for traceability while protecting CI runners from tag mutation attacks.

Verification

  • YAML Validation: Verified .github/workflows/ci.yml with PyYAML (syntax and schema clean).
  • TLS Configuration: Re-scanned active environment variables; zero active NODE_TLS_REJECT_UNAUTHORIZED=0 instances remain.
  • Formatting: Preserved POSIX Unix LF line endings across all modified files.

…pin CI action SHAs

### Summary of Changes
Addresses security and supply-chain vulnerabilities identified during the workspace audit across `arc-node` (Findings F-02 and F-06).

---

### Key Remediations

1. **Re-Enable TLS Certificate Verification (F-02 / CWE-295):**
   - Commented out `NODE_TLS_REJECT_UNAUTHORIZED=0` in `deployments/monitoring/config-blockscout/frontend/frontend.env`.
   - Prevents disabling certificate verification across the Node.js process, protecting outbound Blockscout traffic against man-in-the-middle (MITM) attacks.
   - Documented `NODE_EXTRA_CA_CERTS` inline as the safe alternative for corporate proxy (e.g., ZScaler) environments requiring custom root certificates.

2. **Supply-Chain Integrity via Action Pinning (F-06 / CWE-829):**
   - Pinned all third-party GitHub Actions in `.github/workflows/ci.yml` to immutable 40-character commit SHAs:
     - `actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3`
     - `actions-rust-lang/setup-rust-toolchain@166cdcfd11aee3cb47222f9ddb555ce30ddb9659 # v1`
     - `taiki-e/install-action@7623a79cdfecb99d681017af368ca353d9f49bb5 # v2`
     - `actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0`
     - `foundry-rs/foundry-toolchain@908c540300062bd5a7e473851cdb4282204cee09 # v1`
     - `bufbuild/buf-action@fd21066df7214747548607aaa45548ba2b9bc1ff # v1.4.0`
     - `docker/setup-buildx-action@d7f5e7f509e45cec5c76c4d5afdd7de93d0b3df5 # v4.1.0`
     - `docker/build-push-action@f9f3042f7e2789586610d6e8b85c8f03e5195baf # v7.2.0`
   - Retained semantic version comments for traceability while protecting CI runners from tag mutation attacks.

---

### Verification
- **YAML Validation:** Verified `.github/workflows/ci.yml` with `PyYAML` (syntax and schema clean).
- **TLS Configuration:** Re-scanned active environment variables; zero active `NODE_TLS_REJECT_UNAUTHORIZED=0` instances remain.
- **Formatting:** Preserved POSIX Unix LF line endings across all modified files.
@github-actions

Copy link
Copy Markdown
Contributor

Hi @mertcano,

Thank you for your interest in contributing to Arc Node.

This PR has been automatically closed because it does not reference a GitHub issue. All PRs must reference an existing issue using the format Closes: #XXX.

To contribute properly:

  1. Find an existing issue you'd like to work on, or open a new issue describing your proposed change
  2. Comment on the issue requesting assignment and wait for maintainer approval
  3. Only submit a PR after you have been assigned to the issue

Please see our CONTRIBUTING.md for more details.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant