[TYPO3-extrev] ext_rev and security team
Patrick Rodacker
patrick.rodacker at the-reflection.de
Fri Feb 17 19:29:45 CET 2006
Hi Michael,
Michael Hirdes wrote on 15.02.2006 07:52:
> at the moment, we have to separate things a little bit:
> 1. to have the new TER2 started, all extensions wich are in the TER2
> have to be reviewed to security issues. as we have the security team, we
> thought, it would be best, to do that there.
Totally agreed, so how can one support the sec team in this matter? Just
to help speeding up ;)
> 2. these are "just" security and code reviews. in the sec team, we _not_
> review the functionallity or the usability of the extension in detail.
>
> 3. we still need some extrevteam. In my opinion we should think over the
> way, how to review extensions robert brought on the idea of doing it
> like a book review for example, or like a test in a computer magazine.
> my idea was, to start that whole discussion again after launching TER2,
> typo3 4.0.0 and the new typo3.org, as we had to see, what TER2 brings.
Ok, are there some figures available about how many extensions have been
reviewed? I only had the chance to read through some of the
documentations from the first approach (checklist, reporp) but never got
any numbers about how many reviews have been done actually.
I would like to support the coordination of the extrevteam and would be
glad if some information about the "old" review process could be stated.
Regards
Patrick
More information about the TYPO3-team-extrev
mailing list