EFForg / https-everywhere

A browser extension that encrypts your communications with many websites that offer HTTPS but still allow unencrypted connections.
https://eff.org/https-everywhere
Other
3.37k stars 1.1k forks source link

objects.githubusercontent.com is not forced HTTPS #20227

Closed wesinator closed 1 year ago

wesinator commented 1 year ago

Type: ruleset/website issue

//: # Domain: http://objects.githubusercontent.com

this domain is not forced https for any urls, either by the server or by https-everywhere extension. Many Github projects use this domain for file release downloads.

e.g. download links for Assets on https://github.com/EFForg/https-everywhere/releases/tag/2022.5.24 objects.githubusercontent.com insecure request