Re: [Wikitech-l] Announcing a new security testing tool for MediaWiki extensions "phan-taint-check-plugin"

2017-12-11 Thread zppix e
Brian, When you were talking about it in IRC it sounded cool, looking at the current project is even better! However can I suggest maybe making this into a wmflabs tool so we can choose to run certain repos without using our own personal ram/resources? Thank you for all you do. Merry Christmas a

Re: [Wikitech-l] Announcing a new security testing tool for MediaWiki extensions "phan-taint-check-plugin"

2017-12-11 Thread Greg Rundlett (freephile)
Thanks Brian! As an integrator, I'm often concerned about the quality of 3rd party extensions. This should be super useful. I hope to give feedback once I get this setup and run various checks with it. Greg Rundlett https://qualitybox.us ___ Wikitech-l

[Wikitech-l] [MediaWiki-announce] MediaWiki 1.30 Available!

2017-12-11 Thread Cindy Cicalese
Hello everyone, I am happy to announce the availability of the general release of MediaWiki 1.30! MediaWiki 1.30 includes all changes released in the smaller 1.30.0-wmf.* software deployments to Wikimedia sites over six months, totaling almost 1500 commits by around 116 unique authors. This i

[Wikitech-l] Announcing a new security testing tool for MediaWiki extensions "phan-taint-check-plugin"

2017-12-11 Thread Brian Wolff
Hello everyone, For the last little while I have been working on a new tool to automatically detect common security issues in MediaWiki extensions. The tool can detect a number of issues, including: * XSS ** We include here using wfMessage( 'foo' )->text() when you should have used ->escaped()

Re: [Wikitech-l] FLIF for Wikimedia

2017-12-11 Thread bawolff
To be clear, there are generally no objections to "1) accept FLIF (and possibly serve PNG thumbs for browsers without js" other than convince commons it would be a good idea to accept the format. All the controversial bit is converting files to FLIF. Accepting FLIF files for upload is non-controver

[Wikitech-l] Discovery Weekly Update for the week starting 2017-12-04

2017-12-11 Thread Chris Koerner
Hello, This is the weekly update from the search team at the foundation for the week starting 2017-12-04. == Discussions== === Search === * Upgrading to ElasticSearch 5.5.x took a lot of smaller sections of work to be completed [0] ** Complete a Kibana security release [1] ** Upgrading Logstash c

Re: [Wikitech-l] FLIF for Wikimedia

2017-12-11 Thread Chico Venancio
I concur with the extension idea. I'd add that have options for degrees of using FLIF would be a good idea as well. I.E. the decision could be to simply 1) accept FLIF (and possibly serve PNG thumbs for browsers without js), to 2) encourage FLIF use, or to 3)"force" FLIF by converting everything to

Re: [Wikitech-l] FLIF for Wikimedia

2017-12-11 Thread Bartosz Dziewoński
If you want to work on implementing support for FLIF, I would recommend doing it as an extension (similar to e.g. https://www.mediawiki.org/wiki/Extension:PdfHandler) rather than in MediaWiki core. -- Bartosz Dziewoński ___ Wikitech-l mailing list W

Re: [Wikitech-l] FLIF for Wikimedia

2017-12-11 Thread Max Semenik
10 дек. 2017 г. 23:42 пользователь "Ruben Kelevra" написал: So... to break the current discussion down, there is no hard "we don't want this format" yet shown up. Nope, you've been provided ample reasons why a phab ticket requesting this will probably be declined on the spot. __

Re: [Wikitech-l] FLIF for Wikimedia

2017-12-11 Thread Ruben Kelevra
Hey Brian, On 11.12.2017 00:10, Brian Wolff wrote: > Maybe not a hard no, but I would rate the probability as somewhere around > 1%. > > If you really wanted to push this (with the understanding that its probably > not going anywhere) I would say make a report, comingup with a solid case > with a