Skip to content

Require HTTPS for CFITSIO downloads and redirects - #95

Open
tpn wants to merge 1 commit into
mainfrom
codex/cfitsio-https-download-20261002
Open

tpn wants to merge 1 commit into
mainfrom
codex/cfitsio-https-download-20261002

Conversation

@tpn

@tpn tpn commented Oct 2, 2026

Copy link
Copy Markdown
Collaborator

Summary

The CFITSIO wheel-build download follows redirects without restricting their protocol. Require HTTPS for both the initial request and redirects, while retaining the pinned SHA-256 check before extraction.

Validation

  • Bash syntax and repository commit hooks passed, including ShellCheck, mypy, and the lockfile check.
  • A fresh CFITSIO 4.7.0 download using the updated command matched the pinned SHA-256.

Repository hygiene

The change is limited to the download command and adds no dependencies or generated artifacts.

Signed-off-by: Trent Nelson <trentn@nvidia.com>
@tpn
tpn requested a review from melo-gonzo as a code owner October 2, 2026 23:33
@coderabbitai

coderabbitai Bot commented Oct 2, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are limited based on label configuration.

🏷️ Required labels (at least one) (1)
  • ai-review

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Repository: NVIDIA/cuPhoton/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Enterprise
  • Run ID: 4815143e-23be-40e4-aa65-4a3ca3d017ca

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Comment @coderabbitai help to get the list of available commands.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant