4fa4e5fe4ad356e1531bd60715b7e01f510ab083

Author
Donncha Ó Cearbhaill <donncha@donncha.is>
Committer
Marc Cornellà <marc.cornella@live.com>
Date

Message

Use HTTPS for manual git clone to avoid  MITM (#6043)

The git:// transport is completely unauthenticated. An attacker on the local or upstream network can easily man-in-the-middle an oh-my-zsh update and get remote code execution on your system. Only the https:// git transport should be used.

Diff

 1diff --git a/README.md b/README.md
 2index a6d74cbd2bfe8c2874bdd20a2ee65c013d8a8ebd..128a07fb5ab0ee6dfd9d2218088de07fa1a7c3a2 100644
 3--- a/README.md
 4+++ b/README.md
 5@@ -141,7 +141,7 @@ export ZSH="$HOME/.dotfiles/oh-my-zsh"; sh -c "$(curl -fsSL https://raw.githubus
 6 ##### 1. Clone the repository:
 7 
 8 ```shell
 9-git clone git://github.com/robbyrussell/oh-my-zsh.git ~/.oh-my-zsh
10+git clone https://github.com/robbyrussell/oh-my-zsh.git ~/.oh-my-zsh
11 ```
12 
13 ##### 2. *Optionally*, backup your existing `~/.zshrc` file: