[Zope-Coders] Re: Zope tests:

Tres Seaver tseaver at zope.com
Sun May 23 17:18:55 EDT 2004


Chris McDonough wrote:
> FWIW, the reason the tests aren't being run properly is because
> cvs.zope.org's :pserver mode isn't functional yet.

We are waiting on a "blessed" upstream (fedora-legacy for RH9) fix for 
the remote root vulnerability in CAN-2004-0396.  As another thought, we 
have noted at ZC that :pserver: is a frequent source of "Oh, shit" 
vulnerabilities, and are pondering leaving it disabled *forever*.  Who 
gets hurt here?  Are there really folks tracking with 'cvs up' in 
pserver-based checkouts?

Chris' testrunner, for instance, could be modified to do a 'wget' 
against the ViewCVS tarball maker.

Tres.
-- 
===============================================================
Tres Seaver                                tseaver at zope.com
Zope Corporation      "Zope Dealers"       http://www.zope.com




More information about the Zope-Coders mailing list