Only the latest release available on the Releases page is supported with security updates.
Please report security issues privately:
- Go to the Security tab of this repository.
- Click Report a vulnerability (private vulnerability reporting).
- Describe the issue, impact, and steps to reproduce.
For issues that cannot use GitHub Security Advisories, email security@neohiro.io (PGP key on request). All reports get an acknowledgement within 72 hours.
Do not open a public issue for anything you believe is exploitable.
You can expect an initial response within 7 days. Please allow a reasonable time for a fix before any public disclosure.
This tool intentionally modifies system or network configuration across multiple distribution families (Debian, RHEL/Fedora, SUSE, Arch). Always review what will be applied, keep backups/restoration points, and test on non-critical systems first.
Every package download, update, and upgrade is preceded by
apt_https_guard (see lib/apt-https.sh). The audit spans every app
store on the host, not just the distro package manager:
apt, dnf, yum, zypper, pacman, apk, flatpak, snap,
docker, brew, pip, npm, cargo, gem, nix, fwupd.
Detection is format-agnostic: any non-comment line carrying an http://
URL in a store's configuration, or a plaintext transport URL exported in
the environment, is reported. Signature verification catches forged
packages; only TLS prevents a downgrade to an older, genuinely-signed,
vulnerable build.
On apt the guard:
- installs
/etc/apt/apt.conf.d/99neohiro-force-https, whoseAcquire::http::AllowRedirect "false"prevents anhttps://mirror from silently downgrading a fetch to plaintext HTTP; - rewrites
http://repo URLs tohttps://insources.list,sources.list.d/*.list, and DEB822*.sources; - backs every file up to
/var/backups/neohiro-apt-https/first and logs it to/var/log/linux-install-rollback.log; - applies each change by staging in the target's own directory and
rename(2), so an interrupted run cannot leave a truncated repo file; - runs a verification
apt-get updateand rolls the rewrite back automatically if a mirror does not serve the same paths over HTTPS.
Other stores are reported rather than rewritten, because whether
https://<same host><same path> exists is not knowable offline and
silently breaking a working mirror is worse than the threat. Opt in with
NEOHIRO_APT_HTTPS_REWRITE=1.
Escape hatches and audit tooling:
sudo bash linuxinstall.sh --apt-https-audit # read-only, exit 1 if plaintext remains
sudo bash linuxinstall.sh --apt-https-off # restore backups, remove the drop-in
NEOHIRO_APT_HTTPS=0 # disable the guard for one runThe optional NEOHIRO_APT_BLOCK_PORT80=1 adds ufw deny out 80/tcp.
It is off by default because a blanket outbound block also affects
unrelated plaintext protocols, and the guard declines to add it while
any plaintext endpoint is still configured.
Under curl | sudo bash the guard is loaded from lib/apt-https.sh
(fetched from the same base the script already trusts) rather than
duplicated inline, so there is one implementation to audit. If it cannot
be loaded the script says so and runs with the guard inactive — it never
reports success for a precaution that is not running.
Maintained by neohiro.