[wp-trac] [WordPress Trac] #25926: No source code is not included for the zxcvbn library

WordPress Trac noreply at wordpress.org
Tue Nov 12 14:34:16 UTC 2013


#25926: No source code is not included for the zxcvbn library
--------------------------------+-----------------------------
 Reporter:  Denis-de-Bernardy   |      Owner:
     Type:  defect (bug)        |     Status:  new
 Priority:  normal              |  Milestone:  Awaiting Review
Component:  External Libraries  |    Version:  3.7.1
 Severity:  blocker             |   Keywords:
--------------------------------+-----------------------------
 While scanning the code base wondering if a js-based sha1 implementation
 was already included, I ran into the zxcvbn library — minified,
 unreadable, and undocumented.

 Admittedly, searching trac quickly led me to r25156 and a link to the
 original files. But for a moment, I genuinely wondered if it was something
 malicious that crept into my wp-includes folder.

 We should add some kind of comment in there to say what it is and where it
 comes from. Or maybe a zxcvbn.txt file with a note so we don't need to
 keep the lines around when it gets updated. *Something* — if only to
 comply with the GPL.

--
Ticket URL: <http://core.trac.wordpress.org/ticket/25926>
WordPress Trac <http://core.trac.wordpress.org/>
WordPress blogging software


More information about the wp-trac mailing list