gchart 使用安全吗?
gchart 的主页,这是 Google Web Toolkit (GWT) 的客户端图表插件),有一篇长篇大论,讲述了该项目的唯一维护者如何认为他的 Google 帐户已被黑客入侵,因此他将“否认/放弃我自己的项目和 Google 帐户”。这是否意味着该项目是一个孤儿项目?有人接手吗?
将您的项目基于其他人的代码总是存在风险,因为他们可能会在您的项目生命周期内停止支持或放弃它,但在我看来,随着 Java 和 GWT 的快速发展,在新项目中使用 gchart 可能会是一个很大的错误。我说得对吗?
The home page for gchart, a client side charting add-in for Google Web Toolkit (GWT), has a long screed about how the project's only maintainer thinks his Google account has been hacked and because of that he will be "disavowing/abandoning my own project and Google account". Does that mean the project is an orphan? Is somebody taking it over?
There is always a risk on basing your project on somebody else's code because they may stop supporting it or abandon it during your project's life time, but it seems to me that with the fast evolution of Java and GWT, using gchart in a new project may be a big mistake. Am I right?
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。
绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论
评论(2)
我在一个全新的 Google Code 项目中发布了客户端 GChart 2.7(未受到我的笔记本电脑之前的 Rootkit 污染),您可以在此处找到该项目:
http://clientsidegchart.googlecode.com
有关我为防止未来违规而采取的新的安全相关改进的详细信息,请点击主页上的“发行说明”链接参见 GChart 2.7 发行说明。
我希望我没有花这么长时间才重新发布。我试图纠正我直接控制的问题部分:我对与计算机安全和系统管理相关的所有事情的深深无知。
我鼓励您再次关注重新发布的、安全性和管理性更好的客户端 GChart 2.7。
John C. Gunther,客户端 GChart 作者
I've released Client-side GChart 2.7 in a brand-new Google Code project (untainted by the previous rootkitting of my laptop) that you can find here:
http://clientsidegchart.googlecode.com
For details on the new security-related improvements I've instituted in an effort to prevent a future breach, follow the "release notes" link on the home page to the GChart 2.7 release notes.
I wish it had not taken me so long to re-release. I was attempting to correct the part of the problem that was under my direct control: my deep ignorance of all things related to computer security and systems administration.
I encourage you to give the re-released, better-secured and administered, Client-side GChart 2.7 a second look.
John C. Gunther, Client-side GChart author
我不得不这么说。如果该项目的唯一维护者失去了对其帐户的控制,则使用 gchart 的任何后续版本可能意味着您在不知不觉中实施了恶意代码。
除非他启动另一个项目来推动代码库向前发展,否则我会避免这样做。
I would have to say so. If the only maintainer of the project has lost control of his account, using any subsequent versions of gchart could mean you're implementing malicious code un-knowingly.
Unless he spins up another project to move the code-base forward, I'd avoid it.