[TYPO3-dev] Removing "enable extension without reviews" checkbox

Benjamin Mack benni at typo3.org
Fri Jun 19 10:51:01 CEST 2009


Hey,

I personally think that it worries people (that they need to disable the 
checkbox -- how do they know why they should disable it? we know because 
we did it for 100+ installations, but let's don't forget the newbies).

Here are my suggestions:

1. In the Extension Manager, add a link:
  * List or look up reviewed extensions [search in all extensions]

To make it easier for people to switch but still have the user know 
about the difference.


2. Update the documentation in the EM about revieweing (what it actually 
means and that there are only a few reviewed). Maybe even a link on a 
TYPO3.org page to keep the info up to date.


3. Make the reviews based on date.
Basically a link that says: Was last reviewed on 2009-05-04 with version 
1.4.5 and proven secure.
And then it's reviewed for 6 months or if the version has not changed.

4. It's hard to keep up reviewing an extension that is releasing a minor 
fix every 1-2 months.
Maybe if we'd have a nice diff-system for every extension update (and 
the security team actually only sees the modified lines and can update 
the review with a few clicks), that would help too.


All the best,
Benni.




More information about the TYPO3-dev mailing list