Skip to content

chore: Add comments rationalising authless world-accessible socket#3943

Merged
DrJosh9000 merged 1 commit into
mainfrom
comment-authless-world-accessible-socket
May 25, 2026
Merged

chore: Add comments rationalising authless world-accessible socket#3943
DrJosh9000 merged 1 commit into
mainfrom
comment-authless-world-accessible-socket

Conversation

@DrJosh9000
Copy link
Copy Markdown
Contributor

@DrJosh9000 DrJosh9000 commented May 25, 2026

Description

Make the Kubernetes socket less of a HackerOne / deepsec magnet.

Context

https://slopcannon.tail952194.ts.net/lachlan/deepsec-buildkite-agent/HIGH/agent-missing-auth-efa096ce58.md

Changes

Add some comments.

Testing

  • Tests have run locally (with go test ./...). Buildkite employees may check this if the pipeline has run automatically.
  • Code is formatted (with go tool gofumpt -extra -w .)

Disclosures / Credits

It keeps being reported on H1, and was also found by deepsec.
I authored the words.

@DrJosh9000 DrJosh9000 requested review from a team as code owners May 25, 2026 02:09
@DrJosh9000 DrJosh9000 added the internal Non-user facing, internal change. label May 25, 2026
@DrJosh9000 DrJosh9000 enabled auto-merge May 25, 2026 02:10
@DrJosh9000 DrJosh9000 merged commit e174d2c into main May 25, 2026
4 of 5 checks passed
@DrJosh9000 DrJosh9000 deleted the comment-authless-world-accessible-socket branch May 25, 2026 03:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

internal Non-user facing, internal change.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants