# Collecting your thoughts about Manivest V3 and the Recommended Extensions program

**URL:** <https://discourse.mozilla.org/t/collecting-your-thoughts-about-manivest-v3-and-the-recommended-extensions-program/45846>\
**Category:** Development\
**Created:** [September 26, 2019, 10:21am UTC](https://discourse.mozilla.org/t/collecting-your-thoughts-about-manivest-v3-and-the-recommended-extensions-program/45846 "2019-09-26T10:21:10Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![Lusito](https://sea1.discourse-cdn.com/flex001/user_avatar/discourse.mozilla.org/lusito/32/4767_2.png) [@Lusito](https://discourse.mozilla.org/u/Lusito)\
**Post date:** [September 26, 2019, 10:21am UTC](https://discourse.mozilla.org/t/collecting-your-thoughts-about-manivest-v3-and-the-recommended-extensions-program/45846/1 "2019-09-26T10:21:10Z")

</div>

As the developer of a recommended extension ([forget me not](https://addons.mozilla.org/firefox/addon/forget_me_not/)), I have been invited by Mozilla to join a full day workshop at [MozFest](https://www.mozillafestival.org). The workshop has been described as:

> The focus of our day together will be exploring ways to optimize the Recommended Extensions program, improve the overall quality of its content, and gather your thoughts on Firefox’s approach to Google’s Manifest v3 changes.

I have my own opinion on these topics, but I thought it would be a good idea to collect some more thoughts on this. So in order to gather the most important concerns and thoughts about this, I would ask you to create one comment per concern/thought and let people upvote them. If one comment would contain multiple concerns, it would be hard to find out what people voted for.

Please keep the comments short and to the point and also write down if you are an extension developer or just a user.

I will then try to address these issues at the workshop and write up a summary of the day for you.

Thanks in advance!

---

<div class="post-metadata">

**Author:** ![juraj.masiar](https://sea1.discourse-cdn.com/flex001/user_avatar/discourse.mozilla.org/juraj.masiar/32/30587_2.png) [@juraj.masiar](https://discourse.mozilla.org/u/juraj.masiar)\
**Post date:** [September 26, 2019, 11:16am UTC](https://discourse.mozilla.org/t/collecting-your-thoughts-about-manivest-v3-and-the-recommended-extensions-program/45846/2 "2019-09-26T11:16:40Z")

</div>

Manifest v3:  
I know this is hard to hear, but we need to stay as compatible as **possible** (_where it makes sense, no way I’m using browser without working AdBlock!_) - to make it easy for developers to support “less popular” browsers (sadly, it’s Firefox now).

Extending limited API is of course welcomed 🙂

---

<div class="post-metadata">

**Author:** ![RobH](https://avatars.discourse-cdn.com/v4/letter/r/94ad74/32.png) [@RobH](https://discourse.mozilla.org/u/RobH)\
**Post date:** [September 26, 2019, 1:52pm UTC](https://discourse.mozilla.org/t/collecting-your-thoughts-about-manivest-v3-and-the-recommended-extensions-program/45846/3 "2019-09-26T13:52:20Z")

</div>

Please preserve the editing and blocking features of the webRequest API. I am a developer and have some basic extensions that rely on this, for example [here](https://github.com/revddit/revddit-quarantined) and [here](https://github.com/revddit/revddit-language-fix).

---

<div class="post-metadata">

**Author:** ![juraj.masiar](https://sea1.discourse-cdn.com/flex001/user_avatar/discourse.mozilla.org/juraj.masiar/32/30587_2.png) [@juraj.masiar](https://discourse.mozilla.org/u/juraj.masiar)\
**Post date:** [September 26, 2019, 2:41pm UTC](https://discourse.mozilla.org/t/collecting-your-thoughts-about-manivest-v3-and-the-recommended-extensions-program/45846/4 "2019-09-26T14:41:04Z")

</div>

“Recommended **Developers** program”

_(yes, new program for recommending addon developers, not just selected addons)_

---

<div class="post-metadata">

**Author:** ![Lusito](https://sea1.discourse-cdn.com/flex001/user_avatar/discourse.mozilla.org/lusito/32/4767_2.png) [@Lusito](https://discourse.mozilla.org/u/Lusito)\
**Post date:** [September 26, 2019, 3:12pm UTC](https://discourse.mozilla.org/t/collecting-your-thoughts-about-manivest-v3-and-the-recommended-extensions-program/45846/5 "2019-09-26T15:12:41Z")

</div>

Not sure what you want to tell me with that quote… Are you suggesting a new program, which recommends developers rather than extensions?

---

<div class="post-metadata">

**Author:** ![caitlin](https://sea1.discourse-cdn.com/flex001/user_avatar/discourse.mozilla.org/caitlin/32/6091_2.png) [@caitlin](https://discourse.mozilla.org/u/caitlin)\
**Post date:** [September 26, 2019, 5:41pm UTC](https://discourse.mozilla.org/t/collecting-your-thoughts-about-manivest-v3-and-the-recommended-extensions-program/45846/6 "2019-09-26T17:41:04Z")

</div>

@juraj.masiar I’m interested in learning more about this. 🙂

---

<div class="post-metadata">

**Author:** ![juraj.masiar](https://sea1.discourse-cdn.com/flex001/user_avatar/discourse.mozilla.org/juraj.masiar/32/30587_2.png) [@juraj.masiar](https://discourse.mozilla.org/u/juraj.masiar)\
**Post date:** [September 26, 2019, 7:14pm UTC](https://discourse.mozilla.org/t/collecting-your-thoughts-about-manivest-v3-and-the-recommended-extensions-program/45846/7 "2019-09-26T19:14:28Z")

</div>

The idea behind is simple - **good developers produces good (safe) addons**.  
But who is good and who’s not?  
Right now you cant tell, because it’s all anonymous. You have “AdBlock XY” made by user “AdBlock XY”.

Imagine going for a job interview with a anonymous mask and saying to your new boss: “_Hi, I will, work for your anonymously and remotely. You will see only my login name. Now give me access to your Git so that I can start coding and publishing_”. 😃  
**No one would hire you, yet this is what we have here right now.**

I think having a real person (with a real consequences) behind each addon is the best protection against malicious addons.  
**And recommending these developers and their addons would yield much more “safe” extensions.**

---

<div class="post-metadata">

**Author:** ![rugkx](https://sea1.discourse-cdn.com/flex001/user_avatar/discourse.mozilla.org/rugkx/32/19322_2.png) [@rugkx](https://discourse.mozilla.org/u/rugkx)\
**Post date:** [September 26, 2019, 9:00pm UTC](https://discourse.mozilla.org/t/collecting-your-thoughts-about-manivest-v3-and-the-recommended-extensions-program/45846/8 "2019-09-26T21:00:40Z")

</div>

@juraj.masiar I like the general idea. Though it should obviously not require personal data, i.e. stay anonymous. But there are other criteria you can use to judge the quality of add-ons and thus developers making them.  
So good add-ons may just lead to the dev account being “validated” or so.  
Also if people want to do nefarious things, it does not matter whether they are anonymous.

* * *

My comment though. I’m [a dev](https://addons.mozilla.org/firefox/user/rugkme/).

- Manifest V3: I’ve [already written up my thoughts here](https://discourse.mozilla.org/t/declarativenetrequest-in-firefox/35347).
- Recommend extensions: Still don’t really know which criteria actually counts (maybe it would be useful to show an explanation near the existing add-ons). Also, the submission process via mail is archaic. A web form would be better.

---

<div class="post-metadata">

**Author:** ![Lusito](https://sea1.discourse-cdn.com/flex001/user_avatar/discourse.mozilla.org/lusito/32/4767_2.png) [@Lusito](https://discourse.mozilla.org/u/Lusito)\
**Post date:** [September 26, 2019, 9:39pm UTC](https://discourse.mozilla.org/t/collecting-your-thoughts-about-manivest-v3-and-the-recommended-extensions-program/45846/9 "2019-09-26T21:39:52Z")

</div>

@juraj.masiar This seems more like a “validated developer” like @rugkx suggests . There is no way to tell if a developer is good simply by seeing that he/she did the full registration. I see good in having a “identity verified” badge of sorts for such developers, but calling it “recommended developers” is not a good idea, since people will confuse it with good code.

@rugkx I’m not sure either. My extension was a “featured” extension before, I guess that is why it was considered in the first place. A few snippets from the emails I received back then might explain their process it a bit:

> Recommended extensions will be an actively managed list of extensions that meet our highest standards of security, utility, and user experience.

> In preparation for the program launch in June, the add-ons editorial team has spent the past several months identifying extensions we believe are strong candidates for the Recommended list.

So my best guess is, that they take a look at how good and how up to date the listing is, try to use the extension to see how the UX is and do a deep manual inspection of the code.

The amount of users and reviews are probably also relevant, but some recommended extensions have started with very few users (lower thousands), so you don’t have to be extremely popular, just well received it seems.

But I will try and gather some facts about this.

---

<div class="post-metadata">

**Author:** ![grahamperrin](https://sea1.discourse-cdn.com/flex001/user_avatar/discourse.mozilla.org/grahamperrin/32/17266_2.png) [@grahamperrin](https://discourse.mozilla.org/u/grahamperrin)\
**Post date:** [September 28, 2019, 4:38pm UTC](https://discourse.mozilla.org/t/collecting-your-thoughts-about-manivest-v3-and-the-recommended-extensions-program/45846/10 "2019-09-28T16:38:30Z")

</div>

### Recommended Extensions

I’d like Mozilla to offer recommendations only where there’s a **demonstrably good track record for basics** such as release notes.

Amber alerts for these developers of recommended extensions:

- [LastPass](https://addons.mozilla.org/user/2338345/) – [https://forums.lastpass.com/viewtopic.php?f=6&t=288305&p=1156665#p1156665](https://forums.lastpass.com/viewtopic.php?f=6&t=288305&p=1156665#p1156665)
- [Maxime RF](https://addons.mozilla.org/user/6294433/) – [https://web.archive.org/web/20191004005005/https://addons.mozilla.org/en-GB/firefox/addon/enhancer-for-youtube/reviews/1413370/](https://web.archive.org/web/20191004005005/https://addons.mozilla.org/en-GB/firefox/addon/enhancer-for-youtube/reviews/1413370/)

… singling out those two developers only because their extensions are amongst the ones that I used recently (or in the past). I imagine a long list of other developers under the same umbrella.

Perspective: end user; interests in QA, best practice and so on.

---

<div class="post-metadata">

**Author:** ![Lusito](https://sea1.discourse-cdn.com/flex001/user_avatar/discourse.mozilla.org/lusito/32/4767_2.png) [@Lusito](https://discourse.mozilla.org/u/Lusito)\
**Post date:** [September 28, 2019, 8:51pm UTC](https://discourse.mozilla.org/t/collecting-your-thoughts-about-manivest-v3-and-the-recommended-extensions-program/45846/11 "2019-09-28T20:51:53Z")

</div>

Is it just release notes or are there any other “basics” that are missing on recommended extensions?

Btw, found this description on the blog on the criteria recommended extensions must meet:  
[https://blog.mozilla.org/addons/2019/04/08/recommended-extensions-program-coming-soon/](https://blog.mozilla.org/addons/2019/04/08/recommended-extensions-program-coming-soon/)

I don’t see release notes in there, but I agree, that it should be part of it. I always thought it was mandatory to enter the “version notes” during upload process.

---

<div class="post-metadata">

**Author:** ![grahamperrin](https://sea1.discourse-cdn.com/flex001/user_avatar/discourse.mozilla.org/grahamperrin/32/17266_2.png) [@grahamperrin](https://discourse.mozilla.org/u/grahamperrin)\
**Post date:** [October 2, 2019, 4:01am UTC](https://discourse.mozilla.org/t/collecting-your-thoughts-about-manivest-v3-and-the-recommended-extensions-program/45846/12 "2019-10-02T04:01:10Z")

</div>

> [@Lusito](#):
>
> … any other “basics” that are missing on recommended extensions? …

Recommended extensions aside, for a moment … in the past it seemed too easy for a developer to publish e.g.:

- a _summary_ that was almost useless
- a _description_ that was (i) empty; (ii) blindly copied from a useless summary; or (iii) simply nondescript.

Now, speeding through the first two pages of [Search results – Add-ons for Firefox (en-US)](https://addons.mozilla.org/search/?type=extension&page_size=100&sort=created) I reckon that the pre-publication checks have become more stringent 👍

Refocusing on **recommended extensions** … from [https://developer.mozilla.org/docs/Mozilla/Add-ons/AMO/Policy/Reviews#Content](https://developer.mozilla.org/docs/Mozilla/Add-ons/AMO/Policy/Reviews#Content):

> > … should have an easy-to-read description about everything it does, and any information it collects. …

– for recommended extensions, I’d make such things a _must have_ (not a _should have_).

> [@Lusito](#):
>
> … I always thought it was mandatory to enter the “version notes” …

Maybe not mandatory, given the frequency with which I find no notes.

Notes should be required, for updates, and there should be a check to ensure that human-readable text is entered (i.e. not U+00A0 (nbsp) or whatever for white space alone to work around the requirement).

Is e.g empty [https://addons.mozilla.org/addon/enhancer-for-youtube/versions/2.0.95/updateinfo/](https://addons.mozilla.org/addon/enhancer-for-youtube/versions/2.0.95/updateinfo/) a result of allowing white space alone?

---

<div class="post-metadata">

**Author:** ![Lusito](https://sea1.discourse-cdn.com/flex001/user_avatar/discourse.mozilla.org/lusito/32/4767_2.png) [@Lusito](https://discourse.mozilla.org/u/Lusito)\
**Post date:** [November 9, 2019, 2:16pm UTC](https://discourse.mozilla.org/t/collecting-your-thoughts-about-manivest-v3-and-the-recommended-extensions-program/45846/13 "2019-11-09T14:16:36Z")

</div>

Check out the review here: [Mozilla workshop about Manifest V3 and the Recommended Extensions Program](https://discourse.mozilla.org/t/mozilla-workshop-about-manifest-v3-and-the-recommended-extensions-program/48336)
