Skip to content

security: enforce HTTPS for Javadoc external links#11

Open
kcvabeysinghe wants to merge 1 commit intogoogle:masterfrom
kcvabeysinghe:patch-1
Open

security: enforce HTTPS for Javadoc external links#11
kcvabeysinghe wants to merge 1 commit intogoogle:masterfrom
kcvabeysinghe:patch-1

Conversation

@kcvabeysinghe
Copy link

Fix: Upgrade junit.org Javadoc URLs to HTTPS in build.gradle.kts.

Security Rationale:
Currently, the build script fetches Javadoc resources over plain HTTP (http://junit.org).
Although the server redirects to HTTPS, the initial cleartext request is vulnerable to Man-in-the-Middle (MitM) stripping attacks. An attacker on the network could intercept this request and inject malicious artifacts (like a spoofed package-list) before the secure redirect occurs.

Hardcoding HTTPS guarantees a secure connection from the start and ensures the integrity of the generated documentation.

@google-cla
Copy link

google-cla bot commented Jan 3, 2026

Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA).

View this failed invocation of the CLA check for more information.

For the most up to date status, view the checks section at the bottom of the pull request.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant