I just realized that with distributed WordPress packages and signing, all vendor code must be isolated to avoid one trusted vendor from publishing an update with another vendor's package content which would overwrite it.
5. While this proposal addresses signing and trust, it does not solve directory name isolation for plugins and themes — that would require a separate solution entirely.
What do you think? Is this simple enough to encourage adoption? What could be improved?
3. For the first install of any plugin or theme, users would need to explicitly specify the trusted key for the vendor. Each download page would prominently display the public key for users to specify.
4. Key rotation could be automated via custom HTTP headers with signed payloads. A single valid public key would ensure that revoked or invalid keys stop working immediately.
Here is a proposal for distributed WordPress package signing:
1. The system relies on users adding the public keys of trusted vendors to their site settings. The update API then includes Ed25519 signatures of SHA256 ZIP hashes in the HTTP headers of the updates.
2. This approach could work seamlessly with a Composer for automated CI/CD installs through a custom plugin.
Did you know that the WordPress PHPUnit testing library supports a magic global $wp_tests_options variable to pre-configure any option values such as the enabled plugins or custom plugin options?
Version 0.11.0 of the Two-Factor plugin for WordPress has been released with a fix to an issue introduced in the previous version related to filtering the available methods, along with some other usability improvements.
Here’s a one-click deploy workflow I use with a #WordPress#monorepo to quickly iterate and release plugin updates. Since there’s not much out there on doing this right, I’m sharing to hear your thoughts and ideas. How do you handle this? https://www.youtube.com/watch?v=MYZRSpEDUB0
@normis Es joprojām meklēju kādu torni vai jumtu Cēsīs, kur uzlikt repeater vai router nodi. Atrodu vietas, kur varētu dabūt 140m virs jūras līmeņa. Tehniski vajadzētu aizniegt Rīgu.
Is there a self-hosted option for watching YouTube videos without the ads? Ideally, something distributed where peers can seed the videos and potentially auto-download everything from my subscriptions?