HomePhabricator

Remove clang-tidy-vs from clang-tools-extra (PR41791)

Authored by arphaman on Aug 27 2019, 11:36 AM.

Description

Remove clang-tidy-vs from clang-tools-extra (PR41791)

The clang-tidy-vs visual studio plugin in clang-tools-extra contains a
security vulnerability in the YamlDotNet package [1]. I posted to cfe-dev [2],
asking if there was anyone who was interested in updating the the plugin
to address the vulnerability. Reid mentioned that Zach (the original committer),
said that there's another plugin (Clang Power Tools) that provides clang-tidy support,
with additional extra features, so it would be ok to remove clang-tidy-vs.

This commit removes the plugin to address the security vulnerability, and adds
a section to the release notes that mentions that the plugin was removed, and
suggests to use Clang Power Tools.

Fixes PR 41791.

[1]: https://nvd.nist.gov/vuln/detail/CVE-2018-1000210
[2]: http://lists.llvm.org/pipermail/cfe-dev/2019-August/063196.html

Differential Revision: https://reviews.llvm.org/D66813

llvm-svn: 370096

Details

Committed
arphamanAug 27 2019, 11:36 AM
Differential Revision
D66813: Remove clang-tidy-vs plugin from clang-tools-extra
Parents
rG2f2feebf4d30: Revert Autogenerate the shebang lines for tools/opt-viewer
Branches
Unknown
Tags
Unknown