Bug#1077869: [Pkg-zsh-devel] Bug#1077869: zsh: please use secure URLs in debian/upstream/metadata

2024-08-05 Thread Simon McVittie
On Mon, 05 Aug 2024 at 17:15:00 +0200, Axel Beckert wrote: > Simon McVittie wrote: > > +Repository: https://git.code.sf.net/p/zsh/code > > Odd. Works with "git clone", but not in a browser. Oh well. The more helpful git "forges" will generally allow the same URL for interactive browsing and `git

Bug#1077869: [Pkg-zsh-devel] Bug#1077869: zsh: please use secure URLs in debian/upstream/metadata

2024-08-05 Thread Axel Beckert
Control: tag -1 + confirmed Hi Simon, Simon McVittie wrote: > While looking for upstream fixes for zsh compatibility with gcc 14, > I noticed that the source package uses git:// and http:// URLs in > debian/upstream/metadata, which do not authenticate the identity of the > remote server and so ar

Bug#1077869: zsh: please use secure URLs in debian/upstream/metadata

2024-08-03 Thread Simon McVittie
Source: zsh Version: 5.9-6 Severity: wishlist Tags: patch While looking for upstream fixes for zsh compatibility with gcc 14, I noticed that the source package uses git:// and http:// URLs in debian/upstream/metadata, which do not authenticate the identity of the remote server and so are vulnerabl