Skip to content

CG Manifest links to dead/insecure component downloadUrls #4170

Open
@247arjun

Description

@247arjun

500+ components (almost 20% of all components) in the Component Governance manifest have insecure HTTP links to their downloadUrl.

Additionally, many of the links are dead (HTTP 404, 501 etc.)

Example package that returns HTTP 404:
CG Manifest link: http://ftp.debian.org/debian/pool/main/t/ttf-arphic-uming/ttf-arphic-uming_0.2.20080216.1.orig.tar.gz

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions