Can we submit unpacked plugin files with the difypkg file? #6

Closed
opened 2026-02-22 17:15:29 -05:00 by yindo · 7 comments
Owner

Originally created by @fdb02983rhy on GitHub (Mar 7, 2025).

It's difficult to check what changes were made in the PR if only difypkg was submitted.

Originally created by @fdb02983rhy on GitHub (Mar 7, 2025). It's difficult to check what changes were made in the PR if only difypkg was submitted.
yindo closed this issue 2026-02-22 17:15:29 -05:00
Author
Owner

@hjlarry commented on GitHub (Mar 10, 2025):

+1

@hjlarry commented on GitHub (Mar 10, 2025): +1
Author
Owner

@bowenliang123 commented on GitHub (Mar 13, 2025):

+1

@bowenliang123 commented on GitHub (Mar 13, 2025): +1
Author
Owner

@fdb02983rhy commented on GitHub (Mar 13, 2025):

@LogicOber Hi, please take it into consideration if possible.

@fdb02983rhy commented on GitHub (Mar 13, 2025): @LogicOber Hi, please take it into consideration if possible.
Author
Owner

@kurokobo commented on GitHub (Mar 14, 2025):

I agree with this proposal.

From a slightly different perspective, the current PR could be abused as a means of getting a maliciously crafted ZIP file to unzip on the reviewer's end.

For example, a ZIP file attached to an email from an unknown source is usually recommended to be discarded without unzipping, but in order to review the PRs in this repository, one has no choice but to unzip them at their own peril. This is not a very desirable situation.

@kurokobo commented on GitHub (Mar 14, 2025): I agree with this proposal. From a slightly different perspective, the current PR could be abused as a means of getting a maliciously crafted ZIP file to unzip on the reviewer's end. For example, a ZIP file attached to an email from an unknown source is usually recommended to be discarded without unzipping, but in order to review the PRs in this repository, one has no choice but to unzip them at their own peril. This is not a very desirable situation.
Author
Owner

@kevintsai1202 commented on GitHub (Mar 17, 2025):

+1 Auto check also decompresses the file before checking. Why not upload the source code first, let the system complete the check, and then have it package the files?

@kevintsai1202 commented on GitHub (Mar 17, 2025): +1 Auto check also decompresses the file before checking. Why not upload the source code first, let the system complete the check, and then have it package the files?
Author
Owner

@LogicOber commented on GitHub (Apr 13, 2025):

Thank you everyone for your feedback and support. We have already discussed the relevant issues internally and will follow up on subsequent strategies as soon as possible. 💙

@LogicOber commented on GitHub (Apr 13, 2025): Thank you everyone for your feedback and support. We have already discussed the relevant issues internally and will follow up on subsequent strategies as soon as possible. 💙
Author
Owner

@crazywoola commented on GitHub (Feb 3, 2026):

Hi @fdb02983rhy, thanks for opening this issue.

Why this is being closed

This issue tracker is reserved for actionable bugs/tasks. This report looks like a usage question.

Next steps

Please use the community channels instead:

If this is actually a bug/task, please open a new issue with clear reproducible details.

Thanks for understanding and for supporting Dify.

@crazywoola commented on GitHub (Feb 3, 2026): Hi @fdb02983rhy, thanks for opening this issue. ### Why this is being closed This issue tracker is reserved for actionable bugs/tasks. This report looks like a usage question. ### Next steps Please use the community channels instead: - https://forum.dify.ai/ - https://discord.com/invite/FngNHpbcY7 If this is actually a bug/task, please open a new issue with clear reproducible details. Thanks for understanding and for supporting Dify.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: langgenius/dify-plugins#6