check / check (push) Waiting to run
On Linux a connection to the unspecified address [::] or 0.0.0.0 reaches the host's own loopback, and the SSRF guard let [::] through. Both unspecified addresses now sit in alwaysBlockedNetworks, so an allowlist reaches loopback only through an entry that covers a loopback address, never through one that covers only 0.0.0.0 or ::; ::/128 joins the default blocklist beside 0.0.0.0/8. IPv6 multicast (ff00::/8) and documentation space (2001:db8::/32) are refused by default. Every default blocklist entry gets a one-line comment, and the README, the rules above each list, the two pinning tests and the allowlist refusal test follow. Model: opus-5-5