Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add directory HEADER in https://updates.jenkins.io/download/plugins/ #4012

Open
jtnord opened this issue Mar 26, 2024 · 1 comment
Open

Add directory HEADER in https://updates.jenkins.io/download/plugins/ #4012

jtnord opened this issue Mar 26, 2024 · 1 comment

Comments

@jtnord
Copy link

jtnord commented Mar 26, 2024

Service(s)

Archives

Summary

NB: sercice may be wrong - not sure what maps to updates.jenkins.io

The Jenkins security team is constantly getting reports from "security researchers" that downloads are offering insecure directory listings.

Even though we document this at https://www.jenkins.io/security/reporting/#infrastructure people are not RTFMing...

It may reduce the spam we get if we added either a file for either ReadmeName of HeaderName that gave a simple overview of what the site is and that the directory listings are expected.
https://cwiki.apache.org/confluence/display/httpd/DirectoryListings#DirectoryListings-HeadersandFooters

Reproduction steps

navigate to https://updates.jenkins.io/download/plugins/

notice you have a directory listing with no other information

expected behaviour -
you have a directory listing saying this is the public contents of all jenkins plugins and versions for download (and is expected to be public)

NOTES

same possibly applies to get.jenkins.io, and mirrors.jenkins.io in addition to updates.jenkins.io

@jtnord jtnord added the triage Incoming issues that need review label Mar 26, 2024
@dduportal dduportal added this to the infra-team-sync-2024-03-26 milestone Mar 26, 2024
@lemeurherve
Copy link
Member

@dduportal dduportal removed this from the infra-team-sync-2024-04-02 milestone Apr 3, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants