Skip to content

fix: make the minimum TLS version explicit - #123

Open
sachaservan wants to merge 2 commits into
mainfrom
fix/codeql-alerts
Open

sachaservan wants to merge 2 commits into
mainfrom
fix/codeql-alerts

Conversation

@sachaservan

@sachaservan sachaservan commented Sep 19, 2026 •

Copy link
Copy Markdown
Member

Explicitly require TLS 1.2 or newer in the synchronous socket wrapper and both pinned TLS contexts, addressing CodeQL #2 without changing certificate verification. Replace the substring-based rejection assertion with the exact expected error for #3.

Add regression coverage for TLS policy and secret-free fallback logging. Alert #1 remains unchanged: it flags the constant environment-variable name, not a secret value.


Summary by cubic

Makes the minimum TLS version explicit: the sync socket wrapper and both pinned SSL contexts now require TLSv1_2 or newer instead of relying on ssl.create_default_context() defaults, addressing CodeQL alert #2 without changing certificate verification. The transport origin-rejection test now asserts the exact error message instead of a substring, covering alert #3.

  • Adds tests that enforce the TLS minimum and peer verification even when the default context is lax.
  • Adds a test that the in-memory cache-secret fallback warning does not log the secret.
  • Alert dep: update verifier version #1 remains unchanged: it flags the constant environment-variable name, not a secret value.

Written for commit b91f254. Summary will update on new commits.

Review in cubic

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 4 files

Reply with feedback, questions, or to request a fix.

Fix all with cubic | Re-trigger cubic

Comment thread tests/test_certificate_reverification.py
Comment thread tests/test_certificate_reverification.py Outdated

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant