fix(ci): remove insecure git clone flag, add ca-certificates

Remove -c http.sslverify=false from all git clones
(enables proper TLS verification, closes MITM risk).
Explicitly install ca-certificates in every CI Docker image.
This commit is contained in:
2026-01-21 17:10:37 +01:00
parent 85c817ee8c
commit 8353a29b4f
5 changed files with 13 additions and 8 deletions

View File

@@ -11,6 +11,7 @@ RUN dnf install -y \
autoconf-archive \
automake \
awk \
ca-certificates \
ccache \
gcc \
git \
@@ -50,7 +51,7 @@ ENV TERM=xterm
RUN mkdir -p /usr/src
WORKDIR /usr/src
RUN git clone --depth 1 -c http.sslverify=false https://git.jabber.space/devs/stabber
RUN git clone --depth 1 https://git.jabber.space/devs/stabber
WORKDIR /usr/src/stabber
RUN ./bootstrap.sh
RUN ./configure --prefix=/usr --disable-dependency-tracking
@@ -59,7 +60,7 @@ RUN make install
WORKDIR /usr/src
RUN mkdir -p /usr/src/libstrophe
RUN git clone --depth 1 -c http.sslverify=false https://github.com/strophe/libstrophe
RUN git clone --depth 1 https://github.com/strophe/libstrophe
WORKDIR /usr/src/libstrophe
RUN ./bootstrap.sh
RUN ./configure --prefix=/usr