Skip to content

6d7a/setup truststore for forked children - #1545

Open
6d7a wants to merge 2 commits into
mainfrom
6d7a/setup-truststore-for-forked-children
Open

6d7a wants to merge 2 commits into
mainfrom
6d7a/setup-truststore-for-forked-children

Conversation

@6d7a

@6d7a 6d7a commented Sep 25, 2026

Copy link
Copy Markdown
Contributor

Context

Closes #1508
1.54.0 introduced two TLS issues that caused backwards incompatibility:

  • Python 3.14's multiprocessing behavior left processes with inconsistent TLS bundles
  • Our Rust ureq client differed in its configuration from our python client, which caused issues for some users in self-hosted environments

What has been done

  • we now make sure to use the system trust store in child processes
  • our HTTP clients in Rust and Python now use similar configurations set by the same environment variables

PR check list

  • As much as possible, the changes include tests (unit and/or functional)
  • If the changes affect the end user (new feature, behavior change, bug fix) then the PR has a changelog entry (see doc/dev/getting-started.md). If the changes do not affect the end user, then the skip-changelog label has been added to the PR.

@6d7a
6d7a requested a review from a team as a code owner September 25, 2026 15:36
@codecov

codecov Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 95.23810% with 1 line in your changes missing coverage. Please review.
✅ Project coverage is 94.49%. Comparing base (d9a60b9) to head (4e92269).
⚠️ Report is 2 commits behind head on main.

Files with missing lines Patch % Lines
ggshield/cmd/utils/debug.py 75.00% 1 Missing ⚠️
Additional details and impacted files
@@            Coverage Diff             @@
##             main    #1545      +/-   ##
==========================================
- Coverage   94.50%   94.49%   -0.01%     
==========================================
  Files         200      201       +1     
  Lines       12767    12780      +13     
==========================================
+ Hits        12065    12077      +12     
- Misses        702      703       +1     
Flag Coverage Δ
unittests 94.49% <95.23%> (-0.01%) ⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

The rust-based http-client introduced breaking changes to users that were relying on custom CAs. This commit introduces a custom agent that provides better support in these cases and maintains backwards compatibility with the client used in ggshield's python logic.
@6d7a
6d7a force-pushed the 6d7a/setup-truststore-for-forked-children branch from 48ef81a to 4e92269 Compare September 28, 2026 06:59

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

ggshield 1.54.0 fails TLS verification with internal CA in GitLab pre-receive hook

1 participant