rustsec/advisory-db

`prettytables-rs` is abandoned

Nukesor opened this issue · 4 comments

The prettytables-rs library has been abandoned.
There's been no active development since roughly three years and the author hasn't been reachable as well.

There exists an open PR and an open ticket to mark the crate as deprecated/abandoned, but the author has not answered on either yet.

There hasn't been any comments of the crate's maintainer on any other issue since several years either.

Ping @phsym

Thanks for caring and following up.

I have additionally sent an e-mail to the maintainer - the maintainer seems to have had some activity a week ago

As per recent policy change if the maintainer does not answer in 90 days we might merge informational / unmaintained if we don't get any clarification re: maintenance policy for security fixes or maintenance handover potential.

Generally however in the past we have required that maintainer is completely unreachable so we'll see.

The maintainer has responded to myself and is keen to either merge security fixes or hand over the crate.

Sadly I didn't get answer around feasibility for us to flag informational so by precedent I am veering towards caution on this.

In that case, I'm just going to close this issue :)

I see that this isn't a security issue per-se (yet). I'm still a bit curious why the author doesn't take care of this project since this many years without properly abandoning it or at least flagging it as unmaintained, but I guess that's not for me to decide.