Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Is it abandoned project? #73

Open
stalkerg opened this issue Feb 20, 2024 · 3 comments
Open

Is it abandoned project? #73

stalkerg opened this issue Feb 20, 2024 · 3 comments

Comments

@stalkerg
Copy link

@dwolfhub sorry for tagging you but seems like we should know your plans.
Because a such project tied with security I think it dangerous use it without releases in last 4 years.

As I understand should be next changes:

  1. Support new pythons up to 3.13 (ci, builds)
  2. Drop python up to 3.8 (especial 2.7)
  3. Probably move CI to GitHub.
  4. Add type hints.
  5. Fix security flaws - DOS exploit #70
  6. Fix performance and etc like in Memory usage awareness: recommend late import #72
  7. Word's list should be extended by local countries words (it's still alphabet but not English)

Because a such lib used in many other projects, I suppose it's important. Originally it was made (ported) by @gvanrossum when he worked in DropBox, maybe we can ask him what to do next.

@gvanrossum
Copy link

I was never involved in this project and have no plans for it.

@stalkerg
Copy link
Author

stalkerg commented Feb 20, 2024

My apologize, I made this assumption base on https://github.com/dropbox/python-zxcvbn
(it's still not archive however)

@petterreinholdtsen
Copy link

Would be nice to know what the plan is to know what to do with the Debian package, https://tracker.debian.org/pkg/python-zxcvbn.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants