Reproducible builds pinned to a chromium release, a real minimum version, store paperwork, and small hardening for both extensions #1
Labels
No labels
bug
documentation
enhancement
security
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
Postulo/postulo-firefox#1
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Found in the 2026-09-15 audit of the plugin repositories. This issue covers both browser extensions: the Firefox build wraps
postulo-chromium, so the fixes land in both repositories. The extension itself is well built: MV3,activeTab, host permission only as an optional per-instance request, no content scripts, no inline script, nothing passed toinnerHTML, a log that never records the token, and 115 keys complete in 39 locales.postulo-firefox
source.json:3has"ref": "main", andscripts/build.mjs:20-21clones over the network at build time. AMO source submissions are therefore not reproducible, and the two extensions drift: the local.sourcecheckout is at14653e5, older than chromium's08774a2.→ Pin a tag or commit SHA, and check in CI that the pin equals chromium's latest tag.
manifest.json:46-51setsstrict_min_version 128.0alongsidedata_collection_permissions, which Firefox supports only from about 140 (Android 142).→ Raise the minimum, and let
web-ext lintconfirm it.upload-artifact@v3withcontinue-on-error.→ Update it, and add a tag workflow that produces the signed, zipped artifact.
postulo-chromium (and both stores)
README.md:19), but the Chrome Web Store requires a standalone policy URL for extensions that handle authentication and page content, and AMO asks too.→
PRIVACY.mdpublished at a stable URL, stating what is stored (the instance address and token, instorage.local, unencrypted, as browsers offer), what is sent and where, and that nothing else is collected. Add store listing assets.unlimitedStorageis broader than needed. It exists to keep captured page HTML.→ Cap stored HTML per capture and drop the permission.
→
content_security_policy.extension_pages: "script-src 'self'; object-src 'none'", so the default can't loosen silently.