[Koha-bugs] [Bug 23975] Add ability to search and install plugins from GitHub

bugzilla-daemon at bugs.koha-community.org bugzilla-daemon at bugs.koha-community.org
Fri May 1 01:09:47 CEST 2020


https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=23975

David Cook <dcook at prosentient.com.au> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
                 CC|                            |dcook at prosentient.com.au

--- Comment #35 from David Cook <dcook at prosentient.com.au> ---
(In reply to Jonathan Druart from comment #31)
> I am sorry but I have concerns about this patch. Feel free to ignore them.
> 
> To me this feature is not ready as it.
> With those patches, the default will be to search on theke and bws github
> repo. Nothing says that the plugins are fetched from "outside".
> Did anyone review those plugins?
> Why only those 2 companies? What about others (ptfs-e, biblibre, inlibro,
> etc)?
> What if a plugin that have security issues is pushed to those repos?
> 

I have those same concerns. At the very least, there should be transparency
about where the plugins are being fetched from.

> When are you going to work on follow-up bugs? Is the plan to have them ready
> for 20.05?

I've done the plugin signing work on
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=24632, but I only did
it for manually uploaded plugins. I only noticed this bug's functionality as I
was wrapping up my initial work. I'll have to revisit it...

-- 
You are receiving this mail because:
You are watching all bug changes.


More information about the Koha-bugs mailing list