Relax rate limiting for downloads.wordpress.org/plugin-checksums/

It appears that the pluginPlugin A plugin is a piece of software containing a group of functions that can be added to a WordPress website. They can extend functionality or add new features to your WordPress websites. WordPress plugins are written in the PHP programming language and integrate seamlessly with WordPress. These can be free in the WordPress.org Plugin Directory https://wordpress.org/plugins/ or can be cost-based plugin from a third-party checksum download endpoint has had some rate limiting added, which is affecting clients of that endpoint.

See https://github.com/wp-cli/checksum-command/issues/91
See https://wordpress.slack.com/archives/C02QB8GMM/p1659451832035669

The legitimate uses of the endpoint do result in the checksums of all plugins on a site being requested in a short period of time. I’m unsure if clients avoid requesting 404 urls or only 200’s.

#downloads #ratelimit #prio2

Helpscout cannot email to @wordpress.org…

Helpscout cannot email to wordpress.orgWordPress.org The community site where WordPress code is created and shared by the users. This is where you can download the source code for WordPress core, plugins and themes as well as the central location for community conversations and organization. https://wordpress.org/ from wordpress.org

Occasionally there’s the need for Helpscout inboxes, which are @wordpress.org inboxes to send emails to other @wordpress.org email addresses, these might be just CC’ing a given WordPress.org user, or forwarding an email to a different Helpscout instance.

Unfortunately, it appears that this is currently blocked by the WordPress.org SMTP servers. Can we allow HelpScout to send-as wordpress.org to WordPress.org?

The relevant part from the bounce is: (noting, I’ve replaced the inboxes for spam purposes, dpo is the sender, and recipient was security in this case)

Final-Recipient: rfc822;mailbox-here@wordpresss.org
Action: failed
Status: 5.7.1 (delivery not authorized)
Remote-MTA: dns;mail.wordpress.org (198.143.164.147)
Diagnostic-Code: smtp;554 5.7.1 <helpscout-inbox@wordpress.org>: Sender address rejected: Access denied
X-PowerMTA-BounceCategory: invalid-sender

The bounce email is available here: https://secure.helpscout.net/conversation/1966354976/301771 and stored in the private PasteBin as #184485 with ID of 2d0a5. (Alternatively, ask a Neso team member for a copy of the email if you’re unable to locate that and unable to locate the HS credentials)

#mail #helpscout #prio3