Closed Bug 1172148 Opened 9 years ago Closed 9 years ago

Signing severity is stripped from validator messages in internal JARs.

Categories

(addons.mozilla.org Graveyard :: Add-on Validation, defect)

defect
Not set
critical

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: kmag, Assigned: kmag)

Details

Due to the way messages are propagated from internal JAR files to the top-level XPI, the `signing_severity` field is stripped out, and the warnings do not prevent the add-on from being signed.
Correction: The messages are still counted in the `signing_summary`, so they should still prevent validation. But the signing severity is not shown in the validator output, which is still likely to cause problems.
Fixed in https://github.com/mozilla/amo-validator/commit/00d920eb046792b4403b001e77b129ca58b51ef8

Thanks Kris!
Status: NEW → RESOLVED
Closed: 9 years ago
Resolution: --- → FIXED
Group: addons-security
Product: addons.mozilla.org → addons.mozilla.org Graveyard
You need to log in before you can comment on or make changes to this bug.