Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Remove "UltraDistSensor" #278

Merged
merged 1 commit into from
Jul 26, 2021
Merged

Conversation

per1234
Copy link
Contributor

@per1234 per1234 commented Jul 26, 2021

This library is being removed from Library Manager by Arduino due to security concerns.

Although there are no concerns about the library code itself, the library.properties metadata file contains an unfortunate typo in the url field. This causes the "More Info" link provided by the Library Manager to take the user to a misspelling of github.com owned by a typo squatter. The library author has already corrected this error (shubhamtrivedi95/UltraDistSensor@fea546b), but there has not been a release of the library in the ~4 years since that time, and no response to an inquiry about the situation made ~3.5 years ago (shubhamtrivedi95/UltraDistSensor#1).

This was surely an honest mistake, without any malicious intent on the library author's part, but we need to resolve the situation. @shubhamtrivedi95 we will be happy to add the library back once you have done the following:

  • Create a new release or tag in the library's repository with the corrected url value.
  • Delete the 1.0 tag that has the bad URL from the library's repository.

You can open a pull request to this repository to add the library back, following the standard process described here:
https://github.com/arduino/library-registry#adding-a-library-to-library-manager

This library is being removed from Library Manager by Arduino due to security concerns.

Although there are no concerns about the library code itself, the library.properties metadata file contains an unfortunate typo in the `url` field. This causes the "More Info" link provided by the Library Manager to take the user to a misspelling of github.com owned by a typo squatter. The library author has already corrected this error, but there has not been a release of the library in the ~4 years since that time, and no response to an inquiry about the situation made ~3.5 years ago.

This was surely an honest mistake, without any malicious intent on the library author's part, but we need to resolve the situation. We will be happy to add the library back once the library maintainer has done the following:

- Create a new release or tag in the library's repository with the corrected `url` value.
- Delete the `1.0` tag that has the bad URL from the library's repository.
@github-actions
Copy link
Contributor

Hi @per1234.
Your pull request has been detected as something other than a Library Manager submission.
A maintainer will need to review it before it can be merged.

If you intended to submit a library, please check the instructions and update your pull request if necessary:
https://github.com/arduino/library-registry/blob/main/README.md#instructions

@per1234 per1234 requested review from rsora and ubidefeo July 26, 2021 08:47
per1234 added a commit to per1234/library-registry that referenced this pull request Jul 26, 2021
@per1234 per1234 mentioned this pull request Jul 26, 2021
@per1234 per1234 merged commit d6867eb into arduino:main Jul 26, 2021
@per1234 per1234 deleted the remove-UltraDistSensor branch July 26, 2021 13:21
@rsora rsora added the topic: removal Remove library from the list label Sep 22, 2021
@per1234 per1234 self-assigned this Nov 20, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
topic: removal Remove library from the list
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants