Re: Re: [PEPr] Comment on RFC::EvalForbiddance

From: Date: Tue, 16 Aug 2005 20:17:53 +0000
Subject: Re: Re: [PEPr] Comment on RFC::EvalForbiddance
References: 1 2 3 4  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-39438@lists.php.net to get a copy of this message
On Tue Aug 16, 2005 at 11:3224PM +0400, Alexey Borzov wrote: > So the only thing you gain from these proposal is a lot of noise from > package developers who are using eval() and would like to continue doing so. You (and a few others) have raised reasonable points today. I'm not yet sure if I like them, but I'll think about them and adjust the proposal accordingly. If nothing else, we all spent a few minutes today digesting the problems with eval(). ;-) > >>While I do understand that in morons' packages eval() may create a huge > >>security threat, > > > >I wouldn't call Stig and Daniel morons, but you are of course free to call > >people whatever you want. :-) > > OK, using the word "moron" wasn't the brightest idea on my part, sorry. > > Indeed, these guys didn't have resources to even review the package they > inherited for possible security issues. And now you think that people of > their qualification will review package belonging to someone else?.. The RfC does not mention code review in the way you are imagining it anywhere. Instead it demands that in cases where people want to add new code that uses eval(), this *small portion* of code gets reviewed. - Martin

« previous php.pear.dev (#39438) next »