Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Prune the list of trusted fetch origins #791

Closed
wants to merge 1 commit into from

Conversation

GarboMuffin
Copy link
Member

GitHub, GitLab, and Bitbucket pages allow redirects to untrusted sources. Itch and GameJolt really shouldn't have been on this list in the first place.

GitHub, GitLab, and Bitbucket pages allow redirects to untrusted sources
Itch and GameJolt really shouldn't have been on this list in the first place. We don't actually trust them.
@LilyMakesThings
Copy link

LilyMakesThings commented Aug 16, 2023

This is a really frustrating pull request

@NexusKitten

This comment was marked as spam.

@GarboMuffin
Copy link
Member Author

raw.githubusercontent.com remains trusted

GitHub Pages and friends unfortunately allow redirects to other (untrusted) sites

@LilyMakesThings
Copy link

raw.githubusercontent.com remains trusted

GitHub Pages and friends unfortunately allow redirects to other (untrusted) sites

That does not resolve the fact that some extensions will look dangerous to unknowing users when they really aren't. The problem comes from blocks that let you redirect.

The solution is to put a blanket warning on all redirects, no? Unless I'm not seeing the bigger picture

@GarboMuffin GarboMuffin marked this pull request as draft August 16, 2023 02:08
@GarboMuffin
Copy link
Member Author

Itch, GameJolt, and ScratchDB will be re-added to the list

@GarboMuffin GarboMuffin deleted the rethink-fetch-security branch August 25, 2023 21:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants