Re: [Development] Proposing QUIP-23: Qt-Security header in source code files

2024-07-11 Thread Volker Hilsheimer via Development
> On 11 Jul 2024, at 15:51, Giuseppe D'Angelo wrote: > > On 11/07/2024 15:21, Volker Hilsheimer wrote: >> For many APIs, application code provides the data (perhaps indirectly), >> e.g. to QDateTime::fromString. In that case we can assume that the >> application had at least some chance to scru

Re: [Development] Nominating Anu Aliyas for approver rights

2024-07-11 Thread Michal Klocek via Development
+1 great work ! On 6/27/24 13:01, Allan Sandfeld Jensen wrote: Hello Qt development I would like to nominate Anu Aliyas as an approver for the Qt project. Anu has been working as a Senior Engineer on QtWebEngine for over a year, mainly working as our resident macOS expert. Authored chang

Re: [Development] Proposing QUIP-23: Qt-Security header in source code files

2024-07-11 Thread Giuseppe D'Angelo via Development
On 11/07/2024 15:21, Volker Hilsheimer wrote: For many APIs, application code provides the data (perhaps indirectly), e.g. to QDateTime::fromString. In that case we can assume that the application had at least some chance to scrub the input, or at the very least control where that string comes fr

Re: [Development] Proposing QUIP-23: Qt-Security header in source code files

2024-07-11 Thread Volker Hilsheimer via Development
> On 11 Jul 2024, at 13:26, Giuseppe D'Angelo via Development > wrote: > > On 10/07/2024 19:08, Kai Köhne via Development wrote: >> That's a lot of questions. But a lot comes down to: Can we agree on parts of >> Qt that are more critical and, therefore, should be subject to additional >> secur

Re: [Development] Proposing QUIP-23: Qt-Security header in source code files

2024-07-11 Thread Tuukka Turunen via Development
Hi, Yes, exactly that (untrusted input) and especially the parts where this is done by Qt (so that it is not even possible for the app to check etc). There might be some other ones as well, but main idea is to separate those few places where extra good care must be taken from the baseline (whic

Re: [Development] Proposing QUIP-23: Qt-Security header in source code files

2024-07-11 Thread Giuseppe D'Angelo via Development
On 10/07/2024 19:08, Kai Köhne via Development wrote: That's a lot of questions. But a lot comes down to: Can we agree on parts of Qt that are more critical and, therefore, should be subject to additional security (in terms of approvers, coding standards, fuzzing ...)? And can we then document

[Development] [Announce] Qt Creator 14 RC released

2024-07-11 Thread List for announcements regarding Qt releases and development via Announce via Development
We are happy to announce the release of Qt Creator 14 RC! https://www.qt.io/blog/qt-creator-14-rc-released -- Eike Ziller Principal Software Engineer The Qt Company GmbH Erich-Thilo-Str. 10 12489 Berlin, Germany eike.zil...@qt.io https://qt.io Geschäftsführer: Mika Pälsi, Juha Varelius, Jouni