Enforce secure POST redirects
- Share the `HOMEBREW_NO_INSECURE_REDIRECT` predicate with `CurlPostDownloadStrategy` and URL audits. - Apply `--proto-redir =https` in the shared curl execution path so redirect-following calls use curl-level enforcement. - Strip caller-provided `--proto-redir` values while the policy is enabled so they cannot weaken the redirect restriction. - Route GitHub artifact downloads through `curl_download` for the same policy.
M
Mike McQuaid committed
232f8703610326d0062a3dc6dde8dcc65a864733
Parent: fe40380