Skip to content

Conversation

@benwebber
Copy link

Thanks for maintaining this fork.

This package makes insecure requests to the Embedly API. This is fixed upstream but of course not released (embedly#28). This changeset back-ports the upstream patch.

I believe that this patch is within the spirit of the fork because it plugs a security a hole. Please feel free to close this if you disagree.

I noticed that everything is "http://".

Shouldn't we use "https://"?

To hide our keys from public view?
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants