Wednesday, November 23, 2011

Re: Dubious scripts at vim.org

Well - yes, we should encourage English language on the web site. No
choice.

Imagine you're Japanese and you're not fluent in English.
Doing what has been done seems to be the straight forward way to share
your script.
They usually meet on lingr.com. I'll sent a message.
Hopefully they reply. I've also CCd the author of the script in this
mail. [1]

Distributing .exe files is of course a security risk - but runnig VimL
is as well (it can use system()).. - I agree that reviewing VimL can be
done - reviewing .exe files is very hard.

We can't review - but PHP has a Zip implementation - thus checking for
.exe files would be trivial.

We can't do security review of all those plugins - and many
users don't have the skills to do so themselves. Using plugins always
means running risk :( How can we improve this in general? Its not
related to .exe files or using a foreign language..

VAM contais a hint that I considered doing exactly that: distributing
curl.exe as vim plugin for bootstrapping which would be useful for
Windows users ..

Marc Weber

[1]: this thread http://groups.google.com/group/vim_use/browse_thread/thread/a43196f035faa840

--
You received this message from the "vim_use" maillist.
Do not top-post! Type your reply below the text you are replying to.
For more information, visit http://www.vim.org/maillist.php

No comments: