-
Notifications
You must be signed in to change notification settings - Fork 610
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
rust-bus
crates are possibly unmaintained
#7013
Comments
FWIW, the original maintainer who closed down the rust-bus org has allowed crates that they were maintainers to new maintainers, so maybe they'd be open to new maintainers taking over rust-bus, as well? |
before we opened rust-lang/rfcs#3463, we discussed to also include the "Abandoned projects" concept from https://peps.python.org/pep-0541/, which would solve some parts of this problem. due to the pushback we already got on the RFC it seems unlikely for this to be implemented in the Rust ecosystem in the near future though.
we discussed this in the crates.io team meeting last week, but we do not see any necessity for immediate action from our side. as far as we can tell all of the crates should still have a regular (non-team/org) owner that can transfer permissions, if needed. |
Thank you for taking the time to discuss it! 👍🏽 |
Rust-bus was used a backup. The org didn't actively intervene, so the de-facto maintenance status of these crates hasn't changed. |
Recreated orgs get a new GitHub ID, which makes it appear as an entirely different org in crates.io. |
54
crates they maintained on crates.io are updated within the last year.The other
64
crates have been updated the last time over more than a year ago. Which makes me think, that rust-bus maintainers could be one of the main maintainers of these crates, and it might be warranted to assume they are now unmaintained?I see no policy in removing maintainers from a crate on crates.io.
Does this problem warrant exceptional measures, as the impact on the ecosystem might be a bit more widespread?
The Github org seems to be not available anymore, but what happens, if the org gets deleted and some other people claim that name?
Related: #6949
CC rustsec/advisory-db#1756
The text was updated successfully, but these errors were encountered: