composer / composer/packagist

Malware-frozen packages should maybe remain accessible

Open
#1,843 1 comment 0 reactions 1 assignee Claimed by @Seldaek View on GitHub
Dominant language
PHP
Stars
1.8k
Forks
488
Avg merge
2d 21h
Merged PRs (30d)
32

Description

Right now packages marked as malware by admins become uninstallable, metadata is gone and the package page is hidden from the public.

Same is true for packages marked as spam.

It'd be good to leave malware ones at least publicly accessible in the UI for the public record. Maybe minus the readme as that could contain bad links.. To be determined whether the metadata should remain accessible or not, maybe we should still dump the package with the malware/filterlist data but no versions?

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.