State what the default blocklist covers (closes #244)
check / check (push) Successful in 4m23s
check / check (push) Successful in 4m23s
The default blocklist covers private and reserved space, plus public addresses that serve cloud credentials. A provider's other services on public addresses, such as IBM Cloud's 161.26.0.0/16 and 166.8.0.0/14, are deliberately not on it: they serve no credentials, reaching them can be legitimate, and every cloud has some, so a partial list would promise coverage it does not give. The README's egress section and the comment above blockedNetworks now state this rule, so nobody infers wider coverage and a future candidate can be accepted or refused against it. No list change. Model: opus-5-5
This commit is contained in:
@@ -43,6 +43,12 @@ var (
|
||||
// permit specific blocks out of this set with
|
||||
// ALLOWED_EGRESS_CIDRS; see Guard.
|
||||
//
|
||||
// A public address belongs here only if it serves cloud
|
||||
// credentials; a provider's other services on public addresses,
|
||||
// such as its DNS resolvers or package mirrors, stay out, since
|
||||
// reaching them can be legitimate and no list of them could be
|
||||
// complete.
|
||||
//
|
||||
//nolint:gochecknoglobals // package-level network list is appropriate here
|
||||
var blockedNetworks []*net.IPNet
|
||||
|
||||
|
||||
Reference in New Issue
Block a user