Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Confirm AAW Jfrog - Authentication\Data Exfiltration #1958

Closed
esneek opened this issue Jun 7, 2024 · 1 comment
Closed

Confirm AAW Jfrog - Authentication\Data Exfiltration #1958

esneek opened this issue Jun 7, 2024 · 1 comment
Labels
kind/bug Something isn't working triage/support

Comments

@esneek
Copy link

esneek commented Jun 7, 2024

The VRS project would like to open the flow to AAW Jfrog for package management. Before that, we would like to confirm the following:

  • users cannot upload packages
  • anyone can access it (not authenticated)
  • the process to upload packages - who does it?
  • If we open the flow to AAW Jfrog, there is not risk that users can upload files then access from the Internet.
@esneek esneek added kind/bug Something isn't working triage/support labels Jun 7, 2024
@Souheil-Yazji
Copy link
Contributor

  • users cannot upload packages
  • anyone can access it (not authenticated)
  • the process to upload packages - who does it? Answer: we have a group with push permissions, and we also have an admin group for Jose & Myself. Both have the ability to push packages to a private test repo, no other repos allow push.
  • If we open the flow to AAW Jfrog, there is not risk that users can upload files then access from the Internet. Answer users won't be able to push packages without 1. Authenticating 2. Having a repo created for them 3. being granted the permissions to push to that repo.

Let me know if you have any other questions.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
kind/bug Something isn't working triage/support
Projects
None yet
Development

No branches or pull requests

2 participants