-
Notifications
You must be signed in to change notification settings - Fork 425
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Eventlistener expose information about cluster #1070
Comments
Nice catch. The |
Agreed. Is there a particular issue that exposing the namespace/el name exposes us to? |
Issues go stale after 90d of inactivity. /lifecycle stale Send feedback to tektoncd/plumbing. |
Stale issues rot after 30d of inactivity. /lifecycle rotten Send feedback to tektoncd/plumbing. |
Rotten issues close after 30d of inactivity. /close Send feedback to tektoncd/plumbing. |
@tekton-robot: Closing this issue. In response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
Expected Behavior
Not showing the namespace where the eventlistenner is running
Actual Behavior
Additional Info
It's usually bad security practice to expose cluster internal information to the public, since the eventlistenner are usually exposed to the internet for GitHUB or other VCS webhooks it may be better to hide this information.
The text was updated successfully, but these errors were encountered: