X Tutup
The Wayback Machine - https://web.archive.org/web/20210301083513/https://github.com/github/codeql/issues/5163
Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Use HTTPS links in documentation and comments #5163

Open
Marcono1234 opened this issue Feb 15, 2021 · 1 comment
Open

Use HTTPS links in documentation and comments #5163

Marcono1234 opened this issue Feb 15, 2021 · 1 comment

Comments

@Marcono1234
Copy link
Contributor

@Marcono1234 Marcono1234 commented Feb 15, 2021

It appears there are quite a few http:// links in the documentation and code comments of this project despite the target websites supporting HTTPS (sometimes HTTPS has to be explicitly requested because the website does not upgrade connections on its own).

A quick search for http: yielded about 4000 findings, however I assume a lot are false positives (e.g. because they are part of an XML namespace declaration) and some target sites might not support HTTPS, or are not properly configured (outdated certificate, wrong domain name).

However, for the websites which do support HTTPS it would be good to update the links. Otherwise for http:// links the browser will first send an unencrypted HTTP request which an attacker in the same network is able to see and for which they can spoof a response.

Slightly related: #4379

@hmakholm
Copy link
Contributor

@hmakholm hmakholm commented Feb 16, 2021

Thanks for pointing out this issue. We will include it in our planning for improvements to the documentation. If you would like to help more directly, we would be happy to review pull requests that update links.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Linked pull requests

Successfully merging a pull request may close this issue.

None yet
2 participants
X Tutup