3 ms·
Explain how you would be able to evaluate the trustworthiness of a person asking to transfer ownership to.
by jsd1982 8y ago
Explain how you would be able to evaluate the trustworthiness of a person asking to transfer ownership to.
- xvector 8y agoIf you can't evaluate the trustworthiness who you're handing the package over to, just don't hand it over. Mark it as deprecated and call it a day. This is Open Source 101.
- Ayesh 8y agoGitHub has a Read Only option, and package managers of most languages have a way to convey that the project is abandoned or provided security fixes only. You don't have to feel guilty to abandon the projects. Most us do it, every day.
- meowface 8y agoAt the very least, a few years of regularly contributing to Node projects on GitHub. The account he handed it over to has essentially zero history: https://github.com/right9ctrl https://github.com/right9ctrl. The one repo they have is just a copy of https://github.com/barrysteyn/node-scrypt https://github.com/barrysteyn/node-scrypt. I'm not against handing over projects, but some vetting has to be done.
- trickstra 8y agoActually, it's not as hard as you make it sound: 1. - don't transfer - mark your repo Abandoned, tell people to use that other person's fork if you have to 2. - does that person have any other online presence? Long running? 3. - does he also put his face in front of the crowd? Talk at conferences? This creates accountability - someone like that wouldn't pull out the same kind of injection, because he could be caught for that and his "brand" would be destroyed.
- jsd1982 8y agoThis is a reasonable response. I'm not sure why you're down voted but I gave you a up vote.