Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Hide NGINX version #2305

Merged
merged 2 commits into from
Jul 29, 2024
Merged

Hide NGINX version #2305

merged 2 commits into from
Jul 29, 2024

Conversation

sjberman
Copy link
Contributor

@sjberman sjberman commented Jul 29, 2024

Problem: As a user of NGF, I want the NGINX version of my installation of NGF hidden by default, so that I do not inadvertently expose which vulnerabilities my version of NGINX is vulnerable to.

Solution: Hide the nginx version that's included in responses.

Testing: Verified in the browser and using curl that the nginx version is not included.

Please focus on (optional): If you any specific areas where you would like reviewers to focus their attention or provide
specific feedback, add them here.

Closes #1507

Checklist

Before creating a PR, run through this checklist and mark each as complete.

  • I have read the CONTRIBUTING doc
  • I have added tests that prove my fix is effective or that my feature works
  • I have checked that all unit tests pass after adding my changes
  • I have updated necessary documentation
  • I have rebased my branch onto main
  • I will ensure my PR is targeting the main branch and pulling from my branch from my own fork

Release notes

If this PR introduces a change that affects users and needs to be mentioned in the release notes,
please add a brief note that summarizes the change.

Hide NGINX version that is included in responses.

Problem: As a user of NGF, I want the NGINX version of my installation of NGF hidden by default, so that I do not inadvertently expose which vulnerabilities my version of NGINX is vulnerable to.

Solution: Hide the nginx version that's included in responses.
@sjberman sjberman requested a review from a team as a code owner July 29, 2024 18:56
@github-actions github-actions bot added the chore Pull requests for routine tasks label Jul 29, 2024
Copy link

codecov bot commented Jul 29, 2024

Codecov Report

All modified and coverable lines are covered by tests ✅

Project coverage is 87.76%. Comparing base (06a0090) to head (580b502).

Additional details and impacted files
@@           Coverage Diff           @@
##             main    #2305   +/-   ##
=======================================
  Coverage   87.76%   87.76%           
=======================================
  Files          96       96           
  Lines        6793     6793           
  Branches       50       50           
=======================================
  Hits         5962     5962           
  Misses        774      774           
  Partials       57       57           

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@sjberman sjberman enabled auto-merge (squash) July 29, 2024 21:00
@sjberman sjberman merged commit bfd25a5 into nginxinc:main Jul 29, 2024
37 checks passed
@sjberman sjberman deleted the chore/hide-version branch July 29, 2024 21:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
chore Pull requests for routine tasks
Projects
Archived in project
Development

Successfully merging this pull request may close these issues.

Hide NGINX Version by Default
3 participants