From c1075aeaaae3850bce929bcf37d83e59f7247a51 Mon Sep 17 00:00:00 2001 From: Nirbheek Chauhan Date: Tue, 7 Aug 2018 20:02:01 +0530 Subject: bzip2.recipe: Only use our mirror for fetching the tarball Upstream didn't support HTTPS, and is dead now. https://lwn.net/Articles/762264/ Updating all older branches to reduce the efficacy of a possible malicious tarball upload to the bzip.org website since it is now in unknown hands. --- recipes/bzip2.recipe | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/recipes/bzip2.recipe b/recipes/bzip2.recipe index 02d47eea..1501b1d3 100644 --- a/recipes/bzip2.recipe +++ b/recipes/bzip2.recipe @@ -7,7 +7,9 @@ class Recipe(recipe.Recipe): version = '1.0.6' licenses = [License.BSD_like] stype = SourceType.TARBALL - url = 'http://bzip.org/1.0.6/bzip2-1.0.6.tar.gz' + # This URL doesn't support https, so we don't use it + #url = 'https://bzip.org/%(version)s/bzip2-%(version)s.tar.gz' + url = 'https://gstreamer.freedesktop.org/src/mirror/bzip2-%(version)s.tar.gz' patches = ['bzip2/0001-Fix-Makefiles-and-add-support-for-Windows-and-OS-X.patch'] files_libs = ['libbz2'] -- cgit v1.2.3