Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Track unmaintained crates. #233

Closed
dpc opened this issue Aug 29, 2019 · 4 comments
Closed

Track unmaintained crates. #233

dpc opened this issue Aug 29, 2019 · 4 comments

Comments

@dpc
Copy link
Collaborator

dpc commented Aug 29, 2019

Shamelessly copying what RustSec is doing, can't hurt. rustsec/advisory-db#134

The question is - can we reuse existing issues system for that, with some convention, or do we need any additional primitives?

@dpc
Copy link
Collaborator Author

dpc commented Aug 29, 2019

Maybe we can just make the version field optional. Without version the review would be for the whole package. There the reviewer can just put any cries or praises for the package as a whole, not just particular version. Some additional keys might be useful to mark common problems: lack of maintainers, obsoleted, etc.

@BurntSushi
Copy link

I like the idea of reviews for whole packages. My only concern there is that praises (or criticisms) may become stale. I guess the timestamp would help alleviate that.

@dpc
Copy link
Collaborator Author

dpc commented Aug 30, 2019

Timestamp is in all proofs by default, so we can tweak how it works once it become a problem, yes.

@dpc
Copy link
Collaborator Author

dpc commented Jan 15, 2022

This has been implemented and cargo crev verify --show-all will display UM flag for crates that were reported as unmaintained.

@dpc dpc closed this as completed Jan 15, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants