Closed
Bug 1190335
Opened 10 years ago
Closed 8 years ago
Automation for reviewing add-ons based on the open extension API
Categories
(addons.mozilla.org Graveyard :: Add-on Validation, defect, P3)
addons.mozilla.org Graveyard
Add-on Validation
Tracking
(Not tracked)
RESOLVED
INVALID
People
(Reporter: gkrizsanits, Unassigned)
References
(Blocks 1 open bug)
Details
This is quite a challenging task probably. This bug probably should be a meta. But because of the urgency I would prefer to have something landed relatively early, and then do the rest of the work in follow-ups.
We need a script that analyzes Add-ons and in some cases r+ them in other cases requires manual review for them while giving useful hints for the reviewer why it needs special attention. Or in some case just r- them while giving some useful reason.
There should be probably both static and dynamic checks.
Even after r+, continuous negative feedback from users should raise a red flag and attract manual review even after the Add-on got an r+ already and are in use. Probably same for performance issues, but not sure how to get there.
- it should check if permissions are really needed
- it should check for possible add injection
- it should check for possible data fishing
- it should do some performance tests
- it should check for dangerous evals
| Reporter | ||
Updated•10 years ago
|
Blocks: webextensions-chrome-gaps
This bug is about forming a plan for what to do. Implementation will happen separately and maybe a little later.
Priority: -- → P1
Component: Extension Compatibility → WebExtensions
Product: Firefox → Toolkit
Version: unspecified → 34 Branch
Comment 2•10 years ago
|
||
We probably need to expand this bug in relation to the validator.
Blocks: 1210037
Component: WebExtensions → Add-on Validation
Priority: P1 → P3
Product: Toolkit → addons.mozilla.org
Version: 34 Branch → unspecified
| Assignee | ||
Updated•9 years ago
|
Product: addons.mozilla.org → addons.mozilla.org Graveyard
Comment 3•8 years ago
|
||
Jorgev, I think we should probably close this bug and start a PRD for this for 2017. Chances are that all this work will be done in the linter or new reviewer tools and not in Bugzilla anyway.
I've added this to the Trello board: https://trello.com/c/oylgAz2L/66-review-queue-evolution so it can go into the PMs queue. All status in this case suck, so picking invalid.
Status: NEW → RESOLVED
Closed: 8 years ago
Flags: needinfo?(jorge)
Resolution: --- → INVALID
Updated•8 years ago
|
Flags: needinfo?(jorge)
You need to log in
before you can comment on or make changes to this bug.
Description
•