Open
Description
500+ components (almost 20% of all components) in the Component Governance manifest have insecure HTTP links to their downloadUrl
.
Additionally, many of the links are dead (HTTP 404, 501 etc.)
Example package that returns HTTP 404:
CG Manifest link: http://ftp.debian.org/debian/pool/main/t/ttf-arphic-uming/ttf-arphic-uming_0.2.20080216.1.orig.tar.gz
Metadata
Metadata
Assignees
Labels
No labels