--- eclass/git-r3.eclass | 14 +++++++++----- 1 file changed, 9 insertions(+), 5 deletions(-)
diff --git a/eclass/git-r3.eclass b/eclass/git-r3.eclass index bc7d4d920299..42b586811368 100644 --- a/eclass/git-r3.eclass +++ b/eclass/git-r3.eclass @@ -105,10 +105,14 @@ fi # @ECLASS-VARIABLE: EGIT_REPO_URI # @REQUIRED # @DESCRIPTION: -# URIs to the repository, e.g. git://foo, https://foo. If multiple URIs -# are provided, the eclass will consider them as fallback URIs to try -# if the first URI does not work. For supported URI syntaxes, read up -# the manpage for git-clone(1). +# URIs to the repository, e.g. https://foo. If multiple URIs are +# provided, the eclass will consider the remaining URIs as fallbacks +# to try if the first URI does not work. For supported URI syntaxes, +# read up the manpage for git-clone(1). +# +# URIs should be using https:// whenever possible. http:// and git:// +# URIs are unsafe and their use (even if only as a fallback) makes +# MITM attacks possible. # # It can be overriden via env using ${PN}_LIVE_REPO variable. # @@ -116,7 +120,7 @@ fi # # Example: # @CODE -# EGIT_REPO_URI="git://a/b.git https://c/d.git" +# EGIT_REPO_URI="https://a/b.git https://c/d.git" # @CODE # @ECLASS-VARIABLE: EVCS_OFFLINE -- 2.14.1