-
Notifications
You must be signed in to change notification settings - Fork 568
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
CG Manifest links to dead/insecure component downloadUrls #4170
Comments
List of dead linksHTTP 403
HTTP 404
HTTP 410
HTTP 500
|
List of valid insecure (HTTP) links
|
Wow, thank you for the detailed analysis, @247arjun! We are cleaning-up the manifest entries as we go and have plans to give it a more thorough sweep, so this will help immensely! |
@247arjun, thank you for reporting the issue. We maintain individual copies of each source archive in our blob storage and the necessity to update the secure link was not a prior concern and rest assured, we are committed to resolving it promptly. |
500+ components (almost 20% of all components) in the Component Governance manifest have insecure HTTP links to their
downloadUrl
.Additionally, many of the links are dead (HTTP 404, 501 etc.)
Example package that returns HTTP 404:
CG Manifest link:
http://ftp.debian.org/debian/pool/main/t/ttf-arphic-uming/ttf-arphic-uming_0.2.20080216.1.orig.tar.gz
The text was updated successfully, but these errors were encountered: