Bug 424456 - Tag filtering / Heuristic: Prevent GHNS packages to offer arbitrary files (like an mp4 for symbol packages)
Summary: Tag filtering / Heuristic: Prevent GHNS packages to offer arbitrary files (li...
Status: REPORTED
Alias: None
Product: frameworks-knewstuff
Classification: Frameworks and Libraries
Component: general (show other bugs)
Version: 5.72.0
Platform: Other Other
: NOR normal
Target Milestone: ---
Assignee: Jeremy Whiting
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2020-07-20 10:40 UTC by postix
Modified: 2020-07-20 11:54 UTC (History)
3 users (show)

See Also:
Latest Commit:
Version Fixed In:
Sentry Crash Report:


Attachments
Screenshot. (344.28 KB, image/png)
2020-07-20 10:40 UTC, postix
Details

Note You need to log in before you can comment on or make changes to this bug.
Description postix 2020-07-20 10:40:18 UTC
Created attachment 130275 [details]
Screenshot.

SystemSettings -> Symbols -> Get New Symbols and search for "OS Catalina" By "zayronXIO". If you click on "install" you are also offered to download a screen recording. I am not sure if this is in the sense of the GHNS feature?
Comment 1 Dan Leinir Turthra Jensen 2020-07-20 10:47:45 UTC
You're correct it's not, but it's more a problem that KNewStuff doesn't really have much in the way of a concept of content types. We could arguably begin filtering out download entries from the list which aren't supported, but we would need a heuristic that makes sense for literally any type of content you can conceive of. The tag filtering may well work for this purpose, but in the meantime, please report this to the author of that entry (who I guess hasn't quite understood what the uploaded data gets used for).
Comment 2 postix 2020-07-20 11:52:18 UTC
(In reply to Dan Leinir Turthra Jensen from comment #1)

> but we would need a heuristic that makes sense for literally any type of
> content you can conceive of. The tag filtering may well work for this
> purpose

This sounds reasonable.


> but in the meantime, please report this to the author of that entry
> (who I guess hasn't quite understood what the uploaded data gets used for).

I will do so that later.