Closed Bug 1190335 Opened 10 years ago Closed 8 years ago

Automation for reviewing add-ons based on the open extension API

Categories

(addons.mozilla.org Graveyard :: Add-on Validation, defect, P3)

defect

Tracking

(Not tracked)

RESOLVED INVALID

People

(Reporter: gkrizsanits, Unassigned)

References

(Blocks 1 open bug)

Details

This is quite a challenging task probably. This bug probably should be a meta. But because of the urgency I would prefer to have something landed relatively early, and then do the rest of the work in follow-ups. We need a script that analyzes Add-ons and in some cases r+ them in other cases requires manual review for them while giving useful hints for the reviewer why it needs special attention. Or in some case just r- them while giving some useful reason. There should be probably both static and dynamic checks. Even after r+, continuous negative feedback from users should raise a red flag and attract manual review even after the Add-on got an r+ already and are in use. Probably same for performance issues, but not sure how to get there. - it should check if permissions are really needed - it should check for possible add injection - it should check for possible data fishing - it should do some performance tests - it should check for dangerous evals
This bug is about forming a plan for what to do. Implementation will happen separately and maybe a little later.
Priority: -- → P1
Component: Extension Compatibility → WebExtensions
Product: Firefox → Toolkit
Version: unspecified → 34 Branch
We probably need to expand this bug in relation to the validator.
Blocks: 1210037
Component: WebExtensions → Add-on Validation
Priority: P1 → P3
Product: Toolkit → addons.mozilla.org
Version: 34 Branch → unspecified
Product: addons.mozilla.org → addons.mozilla.org Graveyard
Jorgev, I think we should probably close this bug and start a PRD for this for 2017. Chances are that all this work will be done in the linter or new reviewer tools and not in Bugzilla anyway. I've added this to the Trello board: https://trello.com/c/oylgAz2L/66-review-queue-evolution so it can go into the PMs queue. All status in this case suck, so picking invalid.
Status: NEW → RESOLVED
Closed: 8 years ago
Flags: needinfo?(jorge)
Resolution: --- → INVALID
Flags: needinfo?(jorge)
Blocks: 1343132
You need to log in before you can comment on or make changes to this bug.