[wp-trac] [WordPress Trac] #35318: Automate anti-virus scanning of WordPress zips

WordPress Trac noreply at wordpress.org
Wed Jan 6 10:51:13 UTC 2016


#35318: Automate anti-virus scanning of WordPress zips
------------------------------+------------------------------
 Reporter:  jorbin            |       Owner:
     Type:  enhancement       |      Status:  new
 Priority:  normal            |   Milestone:  Awaiting Review
Component:  Build/Test Tools  |     Version:
 Severity:  normal            |  Resolution:
 Keywords:                    |     Focuses:
------------------------------+------------------------------

Comment (by netweb):

 Related: #25117 <- We can build the zips via the Grunt task/s in that
 ticket

 There's a couple of NPM modules that use the VirusTotal API, though no
 Grunt wrappers for these modules.

 Thinking about and addressing how the WordPress project would be treated
 as the canonical/authoritative source for these packages to ensure someone
 else could not impersonate the WordPress project to override/replace the
 hash/signatures with malware/compromised packages will make for an
 interesting ticket here :)

--
Ticket URL: <https://core.trac.wordpress.org/ticket/35318#comment:1>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list