-
Notifications
You must be signed in to change notification settings - Fork 31
Open
Labels
enhancementNew feature or requestNew feature or request
Description
PR #35 demonstrates a potential issue with automatic approval of PRs. Data in a prior submission can be changed, pass verification, and potentially auto-merged. In this case the author and license are changed. It would also be possible to change the download URL and SHA.
Some ways to address this:
- An add-on release is expected to be immutable, once submitted, users may have it installed. To fix an issue, a new version should be released.
- Don't allow file deletion without manual approval (requiring explanation).
- Introduce a way for authors to digitally sign add-on releases, so their origin can be confirmed.
Metadata
Metadata
Assignees
Labels
enhancementNew feature or requestNew feature or request