New Webhook IP Address

Hi,

It looks like 18.184.195.184 has been added to sonarcloud webhook processing servers.

Can https://sonarcloud.io/documentation/security/ be updated to reflect this IP address needs to be white-listed pls? Would have saved us some head-scratching! :slight_smile:

Any others we should be aware of?

Thanks.

Hi Peter,

You’re right, we forgot to update https://sonarcloud.io/documentation/security/ with this 6 new IPs you can add to your white-list:

  • 18.194.206.183
  • 3.121.87.141
  • 18.184.195.184
  • 18.185.94.218
  • 3.120.158.225
  • 18.184.94.13

Hi there , can’t find full list of webhook ip address , can you provide full list here ?

Hi,

The list of ip adresses is no longer available. Instead, you can ensure that webhooks comes from SonarCloud by using a secret.
See the “Securing you webhooks” section from the webhooks documentation page for more info.

1 Like

And how whitelist via firewall by secret?
Almost impossible, can you provide hook range ?

Hi @SimonyanG,

By design, the IP addresses SonarCloud is invoking webhooks from will change with time (e.g. with the service auto-scaling). We can’t commit to a specific IP range, so therefore indeed, it is not realistic to use firewalls to protect webhooks targets.

Instead, to protect your endpoint, the correct solution is to use a secret, as explained in the webhooks documentation page.