public inbox for gentoo-dev@lists.gentoo.org
 help / color / mirror / Atom feed
* [gentoo-dev] [PATCH 1/2] git-r3.eclass: Update docs to discourage unsafe protocols
@ 2017-08-19  8:25 Michał Górny
  2017-08-19  8:25 ` [gentoo-dev] [PATCH 2/2] git-r3.eclass: Explicitly warn about unsecure protocols Michał Górny
                   ` (2 more replies)
  0 siblings, 3 replies; 12+ messages in thread
From: Michał Górny @ 2017-08-19  8:25 UTC (permalink / raw
  To: gentoo-dev; +Cc: Michał Górny

---
 eclass/git-r3.eclass | 14 +++++++++-----
 1 file changed, 9 insertions(+), 5 deletions(-)

diff --git a/eclass/git-r3.eclass b/eclass/git-r3.eclass
index bc7d4d920299..42b586811368 100644
--- a/eclass/git-r3.eclass
+++ b/eclass/git-r3.eclass
@@ -105,10 +105,14 @@ fi
 # @ECLASS-VARIABLE: EGIT_REPO_URI
 # @REQUIRED
 # @DESCRIPTION:
-# URIs to the repository, e.g. git://foo, https://foo. If multiple URIs
-# are provided, the eclass will consider them as fallback URIs to try
-# if the first URI does not work. For supported URI syntaxes, read up
-# the manpage for git-clone(1).
+# URIs to the repository, e.g. https://foo. If multiple URIs are
+# provided, the eclass will consider the remaining URIs as fallbacks
+# to try if the first URI does not work. For supported URI syntaxes,
+# read up the manpage for git-clone(1).
+#
+# URIs should be using https:// whenever possible. http:// and git://
+# URIs are unsafe and their use (even if only as a fallback) makes
+# MITM attacks possible.
 #
 # It can be overriden via env using ${PN}_LIVE_REPO variable.
 #
@@ -116,7 +120,7 @@ fi
 #
 # Example:
 # @CODE
-# EGIT_REPO_URI="git://a/b.git https://c/d.git"
+# EGIT_REPO_URI="https://a/b.git https://c/d.git"
 # @CODE
 
 # @ECLASS-VARIABLE: EVCS_OFFLINE
-- 
2.14.1



^ permalink raw reply related	[flat|nested] 12+ messages in thread

end of thread, other threads:[~2017-09-03 18:08 UTC | newest]

Thread overview: 12+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2017-08-19  8:25 [gentoo-dev] [PATCH 1/2] git-r3.eclass: Update docs to discourage unsafe protocols Michał Górny
2017-08-19  8:25 ` [gentoo-dev] [PATCH 2/2] git-r3.eclass: Explicitly warn about unsecure protocols Michał Górny
2017-08-19 22:01   ` [gentoo-dev] " Duncan
2017-08-19 22:39     ` Michał Górny
2017-08-23  8:46   ` [gentoo-dev] " Andrew Savchenko
2017-08-25 13:51     ` Michał Górny
2017-09-03 18:00       ` Andrew Savchenko
2017-08-25 15:46     ` Hanno Böck
2017-09-03 18:08       ` Andrew Savchenko
2017-08-20 18:05 ` [gentoo-dev] [PATCH 1/2] git-r3.eclass: Update docs to discourage unsafe protocols William Hubbs
2017-08-20 19:25   ` Michał Górny
2017-08-25 13:52 ` Michał Górny

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox