conda-forge / conda-forge/libxml2-feedstock
Upstream unmaintained and vulnerable?
- Dominant language
- Shell
- Stars
- 3
- Forks
- 42
- Avg merge
- 29m
- Merged PRs (30d)
- 1
Description
Currently the upstream readme [contains](https://gitlab.gnome.org/GNOME/libxml2/-/blob/9c80a89af2fdf4f853892f84e46580f4902658ba/README.md#security) the statement
> This project is unmaintained and has [known security issues](https://gitlab.gnome.org/GNOME/libxml2/-/issues/346). It is foolish to use this software to process untrusted data.
Additionally, the maintainer [removed](https://gitlab.gnome.org/GNOME/libxml2/-/commit/9c80a89af2fdf4f853892f84e46580f4902658ba) themselves and while some people have shown interest in stepping up, it's unclear how that will turn out.
This is obviously not great™️ for such a low-level package with [130+ direct dependencies](https://conda-forge.org/status/migration/?name=libxml2214), and many more transitive ones.
FYI @conda-forge/libxml2 @conda-forge/core
Contributor guide
Research direction
Review the upstream README security statement, the linked libxml2 issue 346, and the referenced upstream commit first. The issue does not identify a repository file or a concrete change, so a contributor would need a maintainer decision on the desired outcome before implementation or verification is possible.
Written by the indexing model from the issue text.
Assessment
- Domain
- security
- Issue type
- Bug
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 15/100