jenkinsci / hipchat-plugin

HipChat notification plugin for Jenkins
https://plugins.jenkins.io/hipchat/
54 stars 85 forks source link

Security warnings about the Jenkins headshot image #94

Closed reist closed 7 years ago

reist commented 7 years ago

Hipchat uses https, yet the image for Jenkins is given as "http://bit.ly/2ctIstd". This causes warnings in Firefox and Chromium, and https://bit.ly/2ctIstd works just as well. This is the only insecure element for me in Hipchat, and it would be nice to get a green lock instead of a yellow one.

aldaris commented 7 years ago

Nice find. I blame it on bit.ly that generates http URL by default :(

aldaris commented 7 years ago

Should be fixed in the upcoming 2.1.1 version.