Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Abandonware #1397

Open
Kojoley opened this issue Apr 15, 2024 · 0 comments
Open

Abandonware #1397

Kojoley opened this issue Apr 15, 2024 · 0 comments

Comments

@Kojoley
Copy link

Kojoley commented Apr 15, 2024

Thanks for the awesome project, I really love the idea!

I think we have little understanding the scope of abandoned software and how much of it is still present in repositories. Repology shows such packages as newest, which is technically not wrong but lacks clarity about the health of the actual software and how new it actually is. I would understand if you consider this as out of the scope of Repology project.

For example:

  • mcrypt project is dead since 2008 but still presented in a lot of current repositories. The worst thing - it's a cryptography library that has multiple know security vulnerabilities, downstream package maintainers do patch them but you never know.
  • SDL Image is not dead project, Repology refers to SDL v1 compatible version 1.2.12 which was released in 2012, git repository branch SDL-1.2 contains version 1.2.13 with about 100 commits since 1.2.12 tag and includes fixes for known security vulnerabilities, but we don't know what repositories actually ships.
  • Nose is dead since 2015 and gave a major headache when Python 3.11 broke it.

IIUC Repology already collects information about project home page where a release date could be found or in case of a repository where the last commit was made. Showing that information would be already a great improvement, which can later be used to automatically flag packages as possibly obsolete/abandoned.

EOL distros like CentOS 6 (released in 2011, updates stopped in 2017, EOL since 2020) which is reported at 14% of newest packages or Ubuntu 14.04 (released in 2014, updates stopped in 2019, EOL 2024) which is reported at 22% of newest are probably good proxies to determine abandonware. It's actually scary how many unmaintained software could be still in use.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant