conda-forge / conda-forge/libxml2-feedstock

Upstream unmaintained and vulnerable?

Open
#169 1 comment 0 reactions 0 assignees View on GitHub
Dominant language
Shell
Stars
3
Forks
42
Avg merge
29m
Merged PRs (30d)
1

Description

Currently the upstream readme [contains](https://gitlab.gnome.org/GNOME/libxml2/-/blob/9c80a89af2fdf4f853892f84e46580f4902658ba/README.md#security) the statement
> This project is unmaintained and has [known security issues](https://gitlab.gnome.org/GNOME/libxml2/-/issues/346). It is foolish to use this software to process untrusted data.

Additionally, the maintainer [removed](https://gitlab.gnome.org/GNOME/libxml2/-/commit/9c80a89af2fdf4f853892f84e46580f4902658ba) themselves and while some people have shown interest in stepping up, it's unclear how that will turn out.

This is obviously not great™️ for such a low-level package with [130+ direct dependencies](https://conda-forge.org/status/migration/?name=libxml2214), and many more transitive ones.

FYI @conda-forge/libxml2 @conda-forge/core

Contributor guide

Open the contributing guide

Research direction

Review the upstream README security statement, the linked libxml2 issue 346, and the referenced upstream commit first. The issue does not identify a repository file or a concrete change, so a contributor would need a maintainer decision on the desired outcome before implementation or verification is possible.

Written by the indexing model from the issue text.

Assessment

Domain
security
Issue type
Bug
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
15/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.