Scaleway service discovery: honor follow_redirects in the configured HTTP client
Fixed in: Verified in Prometheus 3.12.0; first fixed release across all branches not established
details
- Finding IDs
- F-PROMETHEUS-SCALEWAY-SD-001
- Status
- fixed publicly
- Fixed in
- Verified in Prometheus 3.12.0; first fixed release across all branches not established
- Recorded credit
- Public fix author: roidelapluie. Public 1seal credit and a causal link to our report are not established.
- Note
- Merged 2026-04-21. NewClientFromConfig replaces the direct RoundTripper so the configured redirect policy is used. This matches the earlier report about follow_redirects being ignored. The retained maintainer response treated it as a configuration correction, not a security vulnerability. It is not a claim that every redirect-related credential exposure is fixed.
F-PROMETHEUS-SCALEWAY-SD-001: Outbound request trust. The HTTP client must preserve the explicitly configured redirect behavior. Reviewed 7 Oct 2026. Mechanism assessed by 1seal.
Mechanism source for F-PROMETHEUS-SCALEWAY-SD-001
Security area (1seal assessment): Semantics. The HTTP client must preserve the explicitly configured redirect behavior. Reviewed 7 Oct 2026.