-
Notifications
You must be signed in to change notification settings - Fork 209
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Project Dead? Does it need more maintainers? #128
Comments
I'd be happy to give contributor bits and npm ownership to a person who has a track of maintaining some packages with reasonable download count. Thanks so much for raising this topic! |
Hey! |
This is now more important than ever. Someone needs to get in and fix this SSRF attack vulnerability |
To be fair, if your only means of protecting unsecured or vulnerable local resources from being access is a thin veil of Does no one use AWS Security Groups? If you know you have potentially vulnerable or intentionally unauthenticated local services why would you use policies like GCP's Concerning that anyone is panicked about this one. |
I'm not panicked, but I can tell you that many IT projects do dependency checks as a first line of defense (e.g. npm audit). Being a base package to over 3k packages, this issue is blocking a lot of people. That's why the pressure is so high. I don't want to know how many are silently subscribed to #136, just to see when its fixed. :) |
Is this project dead?
Are there not enough project maintainers? @indutny Do you see a need for them within this project?
There are a number of PRs and Issues that have had no activity or have stalled progress. (Some even from a couple years ago)
Additionally, there are also some deviations RFCs that need to be/have addressed in PRs (Ex: RFC 5753, RFC 6598...)
No one can expect
indutny
to spend hours on an open source project because it is a dependency for theirs.They have a life.
That being said there needs to be steps taken to ensure the future of this project:
CONTRIBUTING.md, CODE_OF_CONDUCT.md, SECURITY.md
I am by no means the correct person for that.
There more qualified people with more time than I do currently.
But who ever has the time and wants to help with maintaining this package, please speak up.
The text was updated successfully, but these errors were encountered: