Description
configuration.insecure_ssl = true on github_organization_webhook disables certificate verification for the HTTPS receiver. The connection may remain encrypted, but the receiver’s identity is not verified.
Potential impact
An attacker on the traffic path may impersonate the receiver and intercept or alter event data.
Remediation
Set configuration.insecure_ssl = false and install a valid certificate on the receiver. Also verify webhook signatures at the receiving end.
Examples
The examples enable certificate verification for the same HTTPS receiver. Manage the shared secret used for signatures securely and separately.
Before
hcl
resource "github_organization_webhook" "webhook" {
name = "web"
configuration {
url = "https://example.com/webhook"
content_type = "form"
insecure_ssl = true
}
events = ["issues"]
}
After
hcl
resource "github_organization_webhook" "webhook" {
name = "web"
configuration {
url = "https://example.com/webhook"
content_type = "form"
insecure_ssl = false
}
events = ["issues"]
}