Repository navigation
Conversation
The v26 rebase re-applied our allowlist patch by hand and lost 198.18.0.0/15. Oathkeeper then failed every Keto check on clusters whose Service CIDR is 198.18.0.0/15 (nearbyone-tracker#2591). AllowInternalDialFunc now takes its prefixes from ssrf_nby.go: - NBY_SSRF_ALLOWED_PREFIXES is the complete allowlist, comma separated, IPv4 and IPv6. Unset or empty keeps the default. - The default holds the private and reserved ranges a cluster may use. It never allows 169.254.0.0/16, 0.0.0.0/8, fe80::/10 or IPv6 ranges that embed an IPv4 address. - An invalid or IPv4-mapped prefix panics at startup. The patch lives in its own file so a rebase cannot drop it silently. The test pins the default list and checks the override and the wiring in ssrf.go. The nby-ssrf-allowlist workflow runs it on every push to the fork branches. Signed-off-by: OscarMoya <oscar.moya@nearbycomputing.com>
Upstream Format runs prettier, which rejects single-quoted strings. Signed-off-by: OscarMoya <oscar.moya@nearbycomputing.com>
OscarMoya
added this pull request to stack #3
October 7, 2026 16:06
govulncheck found these reachable in all four binaries, inherited from the upstream base: - golang.org/x/text v0.38.0 -> v0.41.0 (GO-2026-5970) - google.golang.org/grpc v1.81.1 -> v1.83.2 (GO-2026-6348, 6061, 6441, 6443; 6443 regressed in 1.83.0 and is fixed in 1.83.2) - go.opentelemetry.io/otel/exporters v1.44.0 -> v1.45.0 (GO-2026-6505) Also raised, flagged at module level only: x/crypto v0.56.0, x/mod v0.40.0, x/net v0.58.0, mongo-driver v1.17.7. Only the minimum fixed versions were requested; the other modules moved as required, and the go directive becomes 1.26.0 because the new x/ modules need it. No fix exists yet for GO-2026-5932 (x/crypto/openpgp) and the aws-sdk-go S3 crypto advisories (GO-2022-0635, GO-2022-0646). Signed-off-by: OscarMoya <oscar.moya@nearbycomputing.com>
The raised golang.org/x/tools and x/term versions need checksums for the tools declared in go.mod (goimports, buf, goveralls), which the format, lint and test jobs run. Added with go list -deps tool; go.mod is unchanged. Signed-off-by: OscarMoya <oscar.moya@nearbycomputing.com>
Grype matches GHSA-r9w3-57w2-gch2 against the fork's pseudo-version v2.0.0-..., which sorts below the fix. The fix commit 0b84568 (v26.2.0) is in this branch, so .grype.yml ignores it for the hydra/v2 package only. Signed-off-by: OscarMoya <oscar.moya@nearbycomputing.com>
kubescape/github-action@main now runs Kubescape in its own container without the Docker socket, so it cannot see the image the job just built and falls back to Docker Hub (manifest unknown). v3.0.21 is a Docker container action, which gets the socket, and it takes the same inputs. Pinned by commit SHA. Signed-off-by: OscarMoya <oscar.moya@nearbycomputing.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Oathkeeper
v26.2.1-ips-alpinerefuses the Keto IP on clusters whose Service CIDR is 198.18.0.0/15 (+Orange PRE), so everyremote_jsonrule (group management, branding) returns 500 "no such host". The v25 patch (Nov 2025) allowed 100.64.0.0/10 and 198.18.0.0/15. Upstream v26 moved the list fromoryx/httpx/ssrf.gotooryx/ipx/ssrf.go, and 198.18.0.0/15 was lost on the way:v26.2.1-ipswas built from a commit that is on no GitHub branch. Its compiled binary also lacks 198.18.0.0/15.Change (identical in all four forks)
oryx/ipx/ssrf_nby.goholds the lists.AllowInternalDialFuncinoryx/ipx/ssrf.gouses them: a 2-line change in the upstream file.ProhibitInternalDialFunc(strict client) is unchanged.NBY_SSRF_ALLOWED_PREFIXESis the complete allowlist, comma-separated, IPv4 and IPv6. Non-empty replaces the default. Unset or empty keeps it. An invalid or IPv4-mapped prefix panics at startup, naming the env var.Guard against the next rebase
oryx/ipx/ssrf_nby_test.gopins the default list. It checks allowed and denied addresses, the override, invalid values and the wiring: 169.254.169.254 is refused before connecting, 198.18.0.1 is not. Each of these mutations fails it:ssrf.goreverted to the upstream list, the upstream list minus 169.254, 198.18/15 dropped, 224/4 dropped..github/workflows/nby-ssrf-allowlist.ymlrunsgo test ./ipx/inoryx/on push toallow-ip-ranges*andnby-*, and on PRs intoallow-ip-ranges*. Nothing ran the vendored oryx tests before.go vet,go test -race ./ipx/and the full binary build pass in all four forks.Dependency fixes
govulncheck found these reachable in all four binaries, inherited from the upstream base:
CI
Upstream Ory's CI fails on the same jobs: the image scanners fail on master of all four ory/* repos, and ory/kratos no longer has the CLI docs job.
kubescape/github-actionto v3.0.21 by commit SHA.@mainnow runs Kubescape in its own container without the Docker socket, so it cannot see the image the job built..docker/Dockerfile-buildcopies thegithub.com/ory/rpctestreplace module beforego mod download, and copiesoryx/go.sumto the right path. Upstream master has the same bug: the image never built. New.grype.yamlignores 4 Oathkeeper self-advisories, scoped to the oathkeeper package, each with its fix commit..grype.ymlignores GHSA-r9w3-57w2-gch2, scoped togithub.com/ory/hydra/v2. Its fix commit0b84568fffcc(v26.2.0) is in the branch. One "Run OIDC conformity tests" run ended INTERRUPTED in the conformance suite's browser automation. The same job passed on the earlier head that already had the dependency bump. It was re-run.github.repository_owner == 'ory', the guard upstream uses for its upstream-only jobs. It publishes to ory/docs with the Ory bot token, and the floatingory/ci/docs/cli-next@masteraction no longer fits this clidoc version.Verified
Images built from these PR heads and pushed to the registry: oathkeeper
v26.2.1-ips3-alpine, hydrav26.2.1-ips3, ketov26.2.1-ips3, kratosv26.2.1-oidc-ips3.NBY_SSRF_ALLOWED_PREFIXESpresent, no panic or "no such host" in the logs. Oathkeeper to Ketoremote_json:GET /perms/manage/group/<id>200,POST /perms/manage/group/<id>/user/<id>201, and Oathkeeper loggedgranted=truefor both rules.v26.2.1-ips-alpinereproduces "lookup ...: no such host" (500), ips3 returns 200, an override without 198.18 returns 500 again, and a bad value stops the container at startup.Refs nbycomp/nearbyone-tracker#2591.