Skip to content

Resolve horrific installation-based security issue#19

Merged
scribu merged 1 commit intowp-cli:masterfrom
grahamc:patch-1
Jul 26, 2013
Merged

Resolve horrific installation-based security issue#19
scribu merged 1 commit intowp-cli:masterfrom
grahamc:patch-1

Conversation

@grahamc
Copy link
Copy Markdown
Contributor

@grahamc grahamc commented Jul 26, 2013

Expecting HTTP traffic to not be mangled, especially when a potential attacker
knows users are planning on piping it directly to bash, is a horrifying idea.

Instead, link to the HTTPS version hosted on github.com. Same outcome, less
horribleness.

Expecting HTTP traffic to not be mangled, especially when a potential attacker
knows users are planning on piping it directly to bash, is a horrifying idea.

Instead, link to the HTTPS version hosted on github.com. Same outcome, less
horribleness.
@scribu
Copy link
Copy Markdown
Member

scribu commented Jul 26, 2013

It didn't occur to me to use raw.github.com. Thanks!

Wondering if we should go one step further and disable access to http://wp-cli.org/installer.sh (Jekyll supports that).

scribu pushed a commit that referenced this pull request Jul 26, 2013
Resolve horrific installation-based security issue
@scribu scribu merged commit 1a98b5b into wp-cli:master Jul 26, 2013
@grahamc
Copy link
Copy Markdown
Contributor Author

grahamc commented Jul 26, 2013

I'd recommend it :)

schlessera pushed a commit that referenced this pull request Jan 25, 2022
Resolve horrific installation-based security issue
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants