As per [this report](https://snyk.io/vuln/npm%3Aibm_db%3A20161219), the installer should be downloading files over https, not bare http. It looks like a one-line change, so it is probably easier for one of the committers to fix rather than mucking with contribution policies. /cc @qpresley