Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Flip --incompatible_disallow_unverified_http_downloads to default to …
…true As discussed in #8607, downloading files over plain http without reasonable verification afterwards (e.g., checking the sha256 sum) is a security risk and therefore should be discouraged. Flip the the corresponding flag disallowing such downloads to true. The flag was available with default false already in 0.29, and migration was possible even before that, simply by adding known-good checksums. Change-Id: Ia3d46115996bf7b7c4aed56dcd15fa7317b5d4fa PiperOrigin-RevId: 261662705
- Loading branch information