GitHub organization webhook TLS certificate verification is disabled

Verify the TLS certificate of the webhook receiver.

Description

configuration.insecure_ssl = true on github_organization_webhook disables certificate verification for the HTTPS receiver. The connection may remain encrypted, but the receiver’s identity is not verified.

Potential impact

An attacker on the traffic path may impersonate the receiver and intercept or alter event data.

Remediation

Set configuration.insecure_ssl = false and install a valid certificate on the receiver. Also verify webhook signatures at the receiving end.

Examples

The examples enable certificate verification for the same HTTPS receiver. Manage the shared secret used for signatures securely and separately.

Before

hcl
resource "github_organization_webhook" "webhook" {
  name = "web"

  configuration {
    url          = "https://example.com/webhook"
    content_type = "form"
    insecure_ssl = true
  }

  events = ["issues"]
}

After

hcl
resource "github_organization_webhook" "webhook" {
  name = "web"

  configuration {
    url          = "https://example.com/webhook"
    content_type = "form"
    insecure_ssl = false
  }

  events = ["issues"]
}

References