Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

This package needs a new maintainer - or an archive-flag #79

Open
infabo opened this issue Oct 30, 2020 · 11 comments
Open

This package needs a new maintainer - or an archive-flag #79

infabo opened this issue Oct 30, 2020 · 11 comments

Comments

@infabo
Copy link

infabo commented Oct 30, 2020

This project is stale. No PRs merged since 2018, no commits since 2018. No communication on any issues by the repository-owner. I guess this project should be handed over to a new maintainer or at least should be marked "archived".

@rogeriorc
Copy link

@kevva ?

@XhmikosR
Copy link
Contributor

@sindresorhus @1000ch: is there any chance we could update this package?

Most imagemin bin packages are using it and there are plenty of improvements we could make. I can make a few PRs later to help out.

@1000ch
Copy link

1000ch commented Jan 12, 2022

I would like to take over the maintainer of this package if I have a chance/permission.

@XhmikosR
Copy link
Contributor

I made master...XhmikosR:dev and seems to work good. I could use more eyes, but happy to open a PR.

@XhmikosR
Copy link
Contributor

@1000ch I think the only solution would be if someone forked and published new scoped packages. I don't have the time to maintain these packages, but I've made PRs updating a lot of things:

Feel free to cherry pick the patches and publish new packages if you are up to it :)

Just drop a message here and the other repos so that people see it and switch.

@kingthorin
Copy link

@kevva can we get some of this moved along somehow? These pending updates are keeping downstream packages vulnerable which is quite disappointing.

@genediazjr
Copy link

genediazjr commented Jun 5, 2022

How do we move forward from this in case @kevva is no longer available?
Hi @sindresorhus, any chance we can have this updated to the latest dependencies? Thank you!

@apepper
Copy link

apepper commented Nov 14, 2022

There is the fork https://www.npmjs.com/package/@mole-inc/bin-wrapper , but I don't know how well it is maintained.

@brodo
Copy link

brodo commented Jan 31, 2023

Same here. This fork seems to be actively maintained.

@kingthorin
Copy link

The problem is dependency chains and getting other package maintainers to adapt.

@XhmikosR
Copy link
Contributor

I just published @xhmikosr/bin-wrapper.

It doesn't help with other packages using the package out there, but at least if everything works well, the security vulnerabilities should be gone.

Note that I don't have the bandwidth to make any improvements, but if someone spots any new bugs in my packages, feel free to make a PR.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

8 participants