Skip to content

fix(supply-chain): honour HTTPS_PROXY on license registry routes - #117

Merged
balcsida merged 1 commit into
mainfrom
fix/supply-chain-enrichment-proxy
Sep 23, 2026
Merged

balcsida merged 1 commit into
mainfrom
fix/supply-chain-enrichment-proxy

Conversation

@balcsida

Copy link
Copy Markdown
Owner

What

License enrichment built its own http.Transport without a Proxy func. On a cluster whose only egress is an HTTP proxy, every registry lookup recorded unavailable while the GitHub client (which honours the standard variables) kept working, so the Dependencies & Licenses page never showed a license.

  • internal/supplychain/license/route.go: use the process proxy configuration (HTTPS_PROXY/NO_PROXY) like every other outbound client. The private-address policy now resolves the route host explicitly, so a route to an internal address is still refused even though the socket only ever reaches the (private) proxy; a direct connection still dials only the addresses that passed the check.
  • resolvers_test.go: TestFetcherUsesEgressProxy runs a real CONNECT proxy, asserts exactly one CONNECT example.com:443, and that a route resolving to 10.0.0.5 is rejected before any connection. Fails without the fix, passes with it.
  • docs/operations.md, CHANGELOG.md: one entry each.

User-visible behaviour

Registry routes work behind an egress proxy. No configuration change is required; deployments without a proxy are unaffected. A TLS-intercepting proxy needs its CA in GRAPHNEST_SUPPLY_CHAIN_REGISTRY_<ECO>_CA_FILE (documented).

Security

The private-address policy is unchanged in effect: it is now evaluated against the route host name in both the direct and proxied cases. Direct connections dial only policy-approved answers, so no rebinding window is introduced.

Verification

make fmt lint staticcheck
GOWORK=off go test -race -count=1 ./internal/supplychain/...
GOWORK=off go build ./cmd/graphnest-server

The registry fetcher built its own http.Transport without a Proxy func,
so on a cluster whose only egress is an HTTP proxy every enrichment job
recorded `unavailable` while the GitHub client (which honours the
standard variables) kept working, and the inventory never showed a
license.

Use the process proxy configuration like every other outbound client.
The private-address policy now resolves the route host explicitly, so a
route to an internal address is still refused even though the socket
only ever reaches the (private) proxy, and a direct connection still
dials only the addresses that passed the check.

Co-Authored-By: Claude <noreply@anthropic.com>
@balcsida
balcsida merged commit 481ecc0 into main Sep 23, 2026
11 of 12 checks passed
@balcsida
balcsida deleted the fix/supply-chain-enrichment-proxy branch September 23, 2026 19:53
Repository owner deleted a comment from chatgpt-codex-connector Bot Sep 24, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant