-
Notifications
You must be signed in to change notification settings - Fork 1.2k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
security issue with a dead simple fix: download debootstrap using HTTPS #2067
Labels
Comments
Oops. Sign the CLA and open a PR? |
I'm not going to sign a CLA for trivial changes that are not even
copyrightable. Security fixes should definitely take priority over a CLA
anyhow, especially with a fix this trivial.
Additionally, asking contributors to sign a CLA means asking them to spend
time reviewing legal documents instead of code. Really, contributors should
also consult a lawyer, since you/your org certainly did when putting up your CLA.
I think it is reasonable to require the Apache CLA, since that is a standard
legal document written by an organization that is working in the public
interest. If your org wants to sponsor a lawyer to consult with me, like the
Free Software Foundation does with their licenses, then I would consider your CLA.
I was hoping to get elementaryOS in crouton, but the CLA requirement is
unfortunately a make or break deal for me.
|
DennisLfromGA
added a commit
to DennisLfromGA/crouton
that referenced
this issue
Sep 17, 2015
RE: security issue with a dead simple fix: download debootstrap using HTTPS - originally by @eighthav - [issue 2067](dnschneid#2067) Right now, crouton downloads debootstrap from anonscm.debian.org using an HTTP link. That URL is also accessible using an HTTPS link, e.g.
DennisLfromGA
added a commit
to DennisLfromGA/crouton
that referenced
this issue
Sep 17, 2015
RE: security issue with a dead simple fix: download debootstrap using HTTPS dnschneid#2067 - originally by eighthave Right now, crouton downloads debootstrap from anonscm.debian.org using an HTTP link. That URL is also accessible using an HTTPS link, e.g.
Jeez Louise - I'll do it - #2121 |
Sorry, didn't intend to start here with a rant, but asking to sign a CLA to
add a single letter is pretty extreme.
|
No problem as far as I'm concerned; I've already signed the CLA and I think it's a simple but warranted mod. Thanx for the suggestion and fix. |
Sorry for the hassle...e-mail me if you want to talk to our legal department :) |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Right now,
crouton
downloadsdebootstrap
from anonscm.debian.org using an HTTP link. That URL is also accessible using an HTTPS link, e.g.The text was updated successfully, but these errors were encountered: