[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Security concerns with minified javascript code



 ❦ 26 août 2015 15:44 +1000, Riley Baird <BM-2cVqnDuYbAU5do2DfJTrN7ZbAJ246S4XiX@bitmessage.ch> :

>> For years, we have been able to ship generated files without checking if
>> they can really be built from sources (for example, autoconf stuff). And
>> JS stuff should comply to stricter standards from day one? 
>
> JS stuff has been in Debian for a long time; it isn't fair to say that
> this is day one.

It's still young compared to autoconf stuff. And JS stuff is mostly
outdated in Debian due to the absence of the most common build
tool. Come on, we don't even have a modern jQuery. It's hard. Having
fellow developers nitpicking on stuff is not helping.

> And autoconf isn't really a fair comparison, because you can generally
> read the output files of autoconf, whereas minified JS is just
> impossible.

Sure, you can proofread a 30k-line configure script without a
problem. So, the condition is now "must be generated from source only if
the generated from is hard-but-not-impossible to read". Most people
(including me) just didn't want to deal with the bugs in those autoconf
scripts that may require specific versions of autoconf/automake and some
additional build dependencies. This is now mostly done but autoconf is
as old as Debian and the generalized use of dh-autoreconf is 2-year
old. Grunt is from 2012.
-- 
She is not refined.  She is not unrefined.  She keeps a parrot.
		-- Mark Twain

Attachment: signature.asc
Description: PGP signature


Reply to: