Skip to content
This repository has been archived by the owner on Oct 11, 2021. It is now read-only.

Add detection of URL shortening links #180

Open
pauby opened this issue Jun 27, 2018 · 0 comments
Open

Add detection of URL shortening links #180

pauby opened this issue Jun 27, 2018 · 0 comments

Comments

@pauby
Copy link
Member

pauby commented Jun 27, 2018

Add the ability for the validator to detect URL shortening service URL's and reject a package that uses them.

URL shortened links are a potential security vulnerability as they can be changed outside of the package. While changing the installer download file would be detected by the checksum changing, links inside the .nuspec file do not have that protection.

URL shortening services would be (not exhaustive):

  • goo.gl
  • bit.ly
  • t.co
  • ow.ly
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant