verify upstream certs & reject unverified#158
Merged
Conversation
SafeDep Report SummaryNo dependency changes detected. Nothing to scan. This report is generated by SafeDep Github App |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #158 +/- ##
==========================================
+ Coverage 39.03% 39.37% +0.34%
==========================================
Files 86 86
Lines 5336 5348 +12
==========================================
+ Hits 2083 2106 +23
+ Misses 3065 3046 -19
- Partials 188 196 +8 ☔ View full report in Codecov by Sentry. 🚀 New features to boost your workflow:
|
Contributor
There was a problem hiding this comment.
Pull request overview
This PR hardens the proxy’s upstream TLS behavior by explicitly configuring the upstream http.Transport to enforce certificate verification and a minimum TLS version, and adds tests to prevent regressions.
Changes:
- Set
goproxy.ProxyHttpServer.Trto a custom upstream transport that enforcesInsecureSkipVerify=falseandMinVersion >= TLS1.2. - Add unit tests asserting the upstream transport is secured and that untrusted upstream certs are rejected by default.
Reviewed changes
Copilot reviewed 2 out of 2 changed files in this pull request and generated 3 comments.
| File | Description |
|---|---|
proxy/proxy.go |
Introduces newUpstreamTransport and wires it into NewProxyServer to enforce secure upstream TLS settings. |
proxy/proxy_test.go |
Adds tests validating upstream TLS config and failure behavior against an untrusted TLS server. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
abhisek
reviewed
Feb 12, 2026
abhisek
approved these changes
Feb 12, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Uh oh!
There was an error while loading. Please reload this page.