Re: security advisories alerts

Davide Moro <davide.moro-LsPWZfGv9U5Wk0Htik3J/[email protected]>
Newsgroups gmane.comp.web.zope.plone.devel
Message-ID <[email protected]>
Il 13/11/2013 18:43, Alexander Loechel ha scritto:
> Hi,
>
> as Guido told, I have been working on some products that care about 
> security and hotfixes.
>
> Therefore a addition in plone.app.vulnerabilities 
> (https://github.com/plone/plone.app.vulnerabilities) was implemented 
> to check if a specific version is vulnerable, and in my git location 
> https://github.com/loechel?tab=repositories are some products on which 
> I still work: plone.break_* and buildout.autoapplayplonehotfixes
>
> I also work on additional pages for plone.app.hud on version 
> information and update possibilities.
>
> As soon as the branch of plone.app.vulnerabilities is merged and 
> installed on plone.org I would finalize my products and cut a release.

Cool, thank you guys!

Are your sanity checks able to reveal third party products with known 
vulnerabilities or just plone core vulnerabilities? For example:
https://plone.org/news/ploneformgen-vulnerability-requires-immediate-upgrade

Regards,

davide

-- 
Davide Moro
Technical Development Manager
http://linkedin.com/in/davidemoro82

Redomino Srl
http://redomino.com
HQ Largo Valgioie 14, Turin IT
Phone +39 0117499875


------------------------------------------------------------------------------
DreamFactory - Open Source REST & JSON Services for HTML5 & Native Apps
OAuth, Users, Roles, SQL, NoSQL, BLOB Storage and External API Access
Free app hosting. Or install the open source package on any LAMP server.
Sign up and see examples for AngularJS, jQuery, Sencha Touch and Native!
http://pubads.g.doubleclick.net/gampad/clk?id=63469471&iu=/4140/ostg.clktrk
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.