Non-Git build might download submodules over unencrypted HTTP

Caolán McNamara caolanm at redhat.com
Tue Nov 1 13:14:34 UTC 2022


On Mon, 2022-10-24 at 00:35 +0200,
some-java-user-99206970363698485155 at vodafonemail.de wrote:
> Hello,
> it looks like building LibreOffice without Git might download
> submodules over unencrypted HTTP without checking authenticity or
> integrity. The relevant code is here:
> https://github.com/LibreOffice/core/blob/648c70ac2caf2646ee8ff49bd8d846016d289b38/Makefile.in#L263

https://gerrit.libreoffice.org/c/core/+/142025 to use https instead of
http at least



More information about the LibreOffice mailing list