From 7829404728f3d30eb7a7a81904881bafb9be1dc5 Mon Sep 17 00:00:00 2001 From: pedrooot Date: Wed, 7 Oct 2026 16:20:05 +0200 Subject: [PATCH] fix(image): name the allowlist in the rejection message --- prowler/providers/image/lib/registry/base.py | 11 ++++++++--- 1 file changed, 8 insertions(+), 3 deletions(-) diff --git a/prowler/providers/image/lib/registry/base.py b/prowler/providers/image/lib/registry/base.py index 6f823db745..571b0b7b1e 100644 --- a/prowler/providers/image/lib/registry/base.py +++ b/prowler/providers/image/lib/registry/base.py @@ -25,6 +25,11 @@ _MAX_RETRIES = 3 _BACKOFF_BASE = 1 _USER_AGENT = f"Prowler/{prowler_version} (registry-adapter)" +_ALLOWLIST_HINT = ( + "To scan a registry on a private network, list the trusted ranges in " + "PROWLER_IMAGE_PROVIDER_ALLOWED_PRIVATE_NETWORKS." +) + _NON_PUBLIC_IP_PROPERTIES = ( "is_private", "is_loopback", @@ -245,8 +250,8 @@ class RegistryAdapter(ABC): raise ImageRegistryAuthError( file=__file__, message=( - f"Host {host!r} resolves to non-public address {resolved_ip}. " - "This may indicate an SSRF attempt." + f"Host {host!r} resolves to non-public address " + f"{resolved_ip}. {_ALLOWLIST_HINT}" ), ) else: @@ -255,7 +260,7 @@ class RegistryAdapter(ABC): file=__file__, message=( f"URL targets a non-public address: {host}. " - "This may indicate an SSRF attempt." + f"{_ALLOWLIST_HINT}" ), )