Skip to content

Update GlobaLeaks APT source URL to HTTPS#4775

Open
orazioedoardo wants to merge 1 commit intoglobaleaks:stablefrom
orazioedoardo:patch-1
Open

Update GlobaLeaks APT source URL to HTTPS#4775
orazioedoardo wants to merge 1 commit intoglobaleaks:stablefrom
orazioedoardo:patch-1

Conversation

@orazioedoardo
Copy link

Packages are obviously signed but HTTPS protects users from potential MITM attacks exploiting bugs like this https://justi.cz/security/2019/01/22/apt-rce.html

Before submitting a pull request, please ensure the following:

  • The pull request includes a description of the problem you're trying to solve.
  • The pull request provides an overview of the suggested solution.
  • The proposed code is fully functional.
  • The proposed code includes relevant tests to verify its functionality.
  • All new and existing tests pass successfully.
  • Overall code quality and test coverage metrics are not reduced by more than 0.5%

Packages are obviously signed but HTTPS protects users from potential MITM attacks exploiting bugs like this https://justi.cz/security/2019/01/22/apt-rce.html
@orazioedoardo orazioedoardo requested a review from a team as a code owner March 6, 2026 13:40
@github-project-automation github-project-automation bot moved this to Needs triaging in GLOBALEAKS Mar 6, 2026
@evilaliv3
Copy link
Member

Very proper and correct feedback @orazioedoardo

We very look forward to good contributions like your.

I confirm that regardless the fact the attack would cause a downgrade mostly its impact could be significant.

I will definitely ensure to retest your patch and take it to production.

Thank you!

we welcome you on our community.globaleaks.org (out of slack in matter of days!)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Needs triaging

Development

Successfully merging this pull request may close these issues.

2 participants