From 52ea902ef99a387e27e3d0559f1c8f8f36e32cb3 Mon Sep 17 00:00:00 2001 From: Jonathan Nieder Date: Wed, 25 Oct 2017 14:19:06 -0700 Subject: [PATCH] Update git submodules * Update plugins/download-commands from branch 'stable-2.14' - CloneWithCommitMsgHook: Stop passing --insecure to curl Validating certs is an important feature of HTTPS that we should not disable, especially when downloading code that is going to be trusted. This "curl" invocation does not take place until after a successful "git clone", so the -k option would not be useful for dealing with misconfigured https servers. Any configuration that needs -k would already be broken because of the "git clone" that comes before it. Reported-by: Gert van Dijk Bug: Issue 7562 Change-Id: Ibe14bba5c1ce30a771515ff7985796aa1b8cdadf --- plugins/download-commands | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/plugins/download-commands b/plugins/download-commands index 8357e942dd..b88b58b670 160000 --- a/plugins/download-commands +++ b/plugins/download-commands @@ -1 +1 @@ -Subproject commit 8357e942dd9da82884a4e1b6e4697479153d0496 +Subproject commit b88b58b670be36f332285e1818695ac45b5be5b3