Closed Bug 444136 Opened 16 years ago Closed 15 years ago

Create framework to automatically scan add-ons for bad patterns

Categories

(addons.mozilla.org Graveyard :: Administration, defect)

defect
Not set
normal

Tracking

(Not tracked)

VERIFIED FIXED

People

(Reporter: fligtar, Assigned: rjwalsh)

References

Details

Attachments

(1 file)

Did this last summer and we should do it again. Grep all xpis for updateURL and extensions.update.url and contact any authors for hits. updateURLs may have been introduced from bug 443791 and we don't check for extensions.update.url on upload.
We should automate this.  Justin, could you spend some time later this quarter planning a security and code scanning framework?  I've seen quite a few of these bugs.
This is now a tracking bug for the scanning tool/framework.  We should work on requirements so we can start work on this in Q1 2009.
Assignee: nobody → fligtar
Summary: grep add-ons for updateURLs → Create framework to automatically scan add-ons for bad patterns
Throwing this into a milestone
Target Milestone: --- → 5.0.2
Target Milestone: 5.0.2 → Future
Blocks: 476057
Assignee: fligtar → nobody
This is practically a dupe of bug 371210 but I'll leave it open for now.  They both depend on each other though and the other bug has more discussion, specs, and a mockup.
Assignee: nobody → rjbuild1088
Depends on: 371210
Target Milestone: Future → 5.0.9
Framework is in, initial tests are in.  We can improve as we go along in other bugs.
Status: NEW → RESOLVED
Closed: 15 years ago
Resolution: --- → FIXED
Attached image Screenshot
Only one example of a potentially bad pattern, but there are others I've found, just haven't attached here.
Verified FIXED.
Status: RESOLVED → VERIFIED
Product: addons.mozilla.org → addons.mozilla.org Graveyard
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: