Skip to content

Drop support for fetching public keys by URL in the search index#2731

Merged
Hayden-IO merged 1 commit intomainfrom
url-fix
Jan 22, 2026
Merged

Drop support for fetching public keys by URL in the search index#2731
Hayden-IO merged 1 commit intomainfrom
url-fix

Conversation

@Hayden-IO
Copy link
Contributor

This mitigates blind SSRF. Note that this API was marked as experimental so while this is a breaking change to the API, we offered no guarantee of stability.

Fixes GHSA-4c4x-jm2x-pf9j

Summary

Release Note

Documentation

This mitigates blind SSRF. Note that this API was marked as experimental
so while this is a breaking change to the API, we offered no guarantee
of stability.

Fixes GHSA-4c4x-jm2x-pf9j

Signed-off-by: Hayden <8418760+Hayden-IO@users.noreply.github.com>
@Hayden-IO Hayden-IO merged commit 60ef2bc into main Jan 22, 2026
16 checks passed
@Hayden-IO Hayden-IO deleted the url-fix branch January 22, 2026 00:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants