ruby-rdf / rdf-vocab

Common RDF Vocabularies
The Unlicense
50 stars 29 forks source link

Gemfile: use secure protocol for GitHub sources #52

Closed dunn closed 7 years ago

dunn commented 7 years ago

The 'github' shortcut uses the insecure git:// protocol.

dunn commented 7 years ago

Package/dependency managers are an attack vector; npm is the most notable but it's possible to exploit gem as well: http://incolumitas.com/2016/06/08/typosquatting-package-managers/

So this makes us a bit less vulnerable.

gkellogg commented 7 years ago

Doesn’t require a new release at this point.