Files
devops-lib-gcp/ai-blitz/task-01-securityScan-hardcoded-ip.md
T
2026-08-26 02:02:24 +05:30

23 lines
1.6 KiB
Markdown

# Task 01: Replace hard-coded IP in `securityScan.groovy` with DNS hostname
- **Type:** Bug fix (security, P0)
- **Source:** `BUGS_AND_IMPROVEMENTS_REPORT.md` §2.1 + `review-learnings.md` rule `P0_HARDCODED_IP_IN_PIPELINE`
## Goal
`src/com/meesho/stages/securityScan.groovy` no longer references a bare IP for the scanner endpoint; the `P0_HARDCODED_IP_IN_PIPELINE` rule in `review-learnings.md` no longer needs the "known exception" carve-out for this file.
## Acceptance Criteria
- [ ] `securityScan.groovy:11` uses a DNS hostname (e.g. `security-scan.meeshogcp.in` or whatever DevOps allocates) instead of `172.31.5.29:63232`
- [ ] If no DNS exists yet, the task surfaces a DevOps ask before merging — does **not** ship with a placeholder IP
- [ ] `grep -rE '\b(172|10|192)\.[0-9]+\.[0-9]+\.[0-9]+:[0-9]+' src/com/meesho/ vars/` returns zero hits for HTTP/curl targets
- [ ] `review-learnings.md` rule `P0_HARDCODED_IP_IN_PIPELINE` has its "known exception: securityScan.groovy:11 uses 172.31.5.29:63232 pending remediation" carve-out **removed** in the same PR
- [ ] No retry / behavioural change — same POST shape, single call, only the hostname changes
- [ ] Smoke-test via a Jenkins job pointed at `@Library('devops-lib@<branch>')` confirming the scan POST succeeds against the new DNS
## Notes / known gotchas
- The receiver is a Meesho-internal scanner — coordinate with the security team to confirm the DNS name and that it's reachable from the Jenkins agent pod's network policy.
- Don't add a fallback to the IP "just in case" — the whole point of the rule is to fail loud on DNS issues, not to silently drop back to a hardcoded address.