Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Status of the project & maintainer? #424

Closed
tmikaeld opened this issue Mar 5, 2020 · 5 comments
Closed

Status of the project & maintainer? #424

tmikaeld opened this issue Mar 5, 2020 · 5 comments

Comments

@tmikaeld
Copy link

tmikaeld commented Mar 5, 2020

I'm worried that something might have happened to the Maintainer, I see no activity since April 2018 except for some bot that's committing to a repo every month.

More than 350 projects on NPM depend entirely on this library, a lof of high-profile companies too, like Fabric, Microsoft, Bitcore, Wire, Mozilla etc.

And there's even a Vulnerability that's not addressed + pull requests that haven't been checked.

@davedoesdev
Copy link
Contributor

@tmikaeld
Copy link
Author

@davedoesdev Seems to be only a bot that's active on the account.

@davedoesdev
Copy link
Contributor

I'm going to deprecate https://github.com/davedoesdev/node-jsjws and move my projects to libsodium.
There are decent libsodium JS modules.

@davedoesdev
Copy link
Contributor

davedoesdev commented Mar 30, 2020

I've deprecated node-jsjws now and moved to libsodium (sodium-native or sodium-plus) and jose.

@kjur
Copy link
Owner

kjur commented Mar 31, 2020

Minerva vulnerability was mitigated in the 8.0.13 release today. Thanks.

@kjur kjur closed this as completed Mar 31, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants