[Hackage] #239: security hole: anyone can replace a package

Hackage trac at galois.com
Thu Feb 14 07:04:44 EST 2008


#239: security hole: anyone can replace a package
--------------------------------+-------------------------------------------
  Reporter:  guest              |        Owner:        
      Type:  defect             |       Status:  new   
  Priority:  normal             |    Milestone:        
 Component:  HackageDB website  |      Version:        
  Severity:  normal             |   Resolution:        
  Keywords:                     |   Difficulty:  normal
Ghcversion:  6.8.2              |     Platform:        
--------------------------------+-------------------------------------------
Comment (by ross at soi.city.ac.uk):

 It used to reject repeat uploads, but people complained.  It can easily be
 turned on again.

 Putting the uploader and upload date on the package page is also in the
 works.

-- 
Ticket URL: <http://hackage.haskell.org/trac/hackage/ticket/239#comment:1>
Hackage <http://haskell.org/cabal/>
Hackage: Cabal and related projects


More information about the cabal-devel mailing list