Version.fetch_{binary,source}: Check that the repository is trusted
Only fetch binaries and sources from trusted repositories, as otherwise the hashes are fairly meaningless. (cherry picked from commit feaf536a2fc4b76e74073f27e868f60fcb3cb8a8) CVE-2019-15796 LP: #1858973
Loading
Please register or sign in to comment