Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Download archives by tree hash instead of tag (#281)
* Download archives by tree hash instead of tag Since we don't do any validation of the archives, downloading based on tag presents a potential security hole whereby a compromised repository retags a version. This should fix that by downloading the archive for the tree directly. Note that the documentation (https://developer.github.com/v3/repos/contents/#get-archive-link) says that it should be a valid git reference, but using hashes seems to work as well. * add note to method
- Loading branch information