[Top][All Lists]

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

.gitmodules security

From: Vincent Lefevre
Subject: .gitmodules security
Date: Sun, 6 Feb 2022 21:22:11 +0100
User-agent: Mutt/2.1.5+134 (92686e5d) vl-138565 (2022-02-02)

The .gitmodules file contains:

[submodule "gnulib"]
        path = gnulib
        url = git://
[submodule "bootstrap"]
        path = gl-mod/bootstrap
        url =

but AFAIK, there is no host authentication done with the "git:"
protocol, so that this is vulnerable to MitM attacks.

How about changing this to https?

Vincent Lefèvre <> - Web: <>
100% accessible validated (X)HTML - Blog: <>
Work: CR INRIA - computer arithmetic / AriC project (LIP, ENS-Lyon)

reply via email to

[Prev in Thread] Current Thread [Next in Thread]