Open Bug 1753276 Opened 3 years ago Updated 2 months ago

Sign Dictionary Add-On types and require new addon types to be signed

Categories

(Toolkit :: Add-ons Manager, enhancement, P2)

enhancement

Tracking

()

People

(Reporter: tjr, Unassigned)

References

Details

(Keywords: sec-want, Whiteboard: [addons-jira])

Dictionary add-on types are missing from SIGNED_TYPES - it would be good to revisit this decision, consider signing them, and in general require all new add-on types to be signed via an explicit opt-out list instead of opt-in.

To determine the feasibility of enforcing this, we need to know whether there are unsigned dictionaries in use. This information is available in telemetry with bug 1751516.

Before that fix I only saw "extension" and "service" types, now there are more: https://sql.telemetry.mozilla.org/queries/83975/source

See Also: → 1751516
Severity: -- → N/A
Priority: -- → P2
Whiteboard: addons-jira
Whiteboard: addons-jira → [addons-jira]

(In reply to Tom Ritter [:tjr] from comment #0)

[...] consider signing them, and in general require all new add-on types to be signed via an explicit opt-out list instead of opt-in.

Note that AMO signs all add-ons nowadays.

See Also: → 1593316
You need to log in before you can comment on or make changes to this bug.