fix: do not download and execute binaries via HTTP (#14914)

This fixes a couple of trivial remote code execution opportunities.
This commit is contained in:
Leopold Schabel
2021-01-29 02:59:40 +01:00
committed by GitHub
parent d6873b82ab
commit 31019e9828
3 changed files with 3 additions and 3 deletions

View File

@ -507,7 +507,7 @@ prepareDeploy() {
if [[ -n $releaseChannel ]]; then
echo "Downloading release from channel: $releaseChannel"
rm -f "$SOLANA_ROOT"/solana-release.tar.bz2
declare updateDownloadUrl=http://release.solana.com/"$releaseChannel"/solana-release-x86_64-unknown-linux-gnu.tar.bz2
declare updateDownloadUrl=https://release.solana.com/"$releaseChannel"/solana-release-x86_64-unknown-linux-gnu.tar.bz2
(
set -x
curl -L -I "$updateDownloadUrl"