Some of the finding from this article are interesting even though I do not share the same conclusions as the article. Spoiler alert I have 2 packages in the 136 packages
#php #ecosystem
> 23% appear abandoned, making dependency audits essential.
How do you know that the package is abandoned versus it is just stable and needs little to no maintenance
@nyamsprod The concept of feature-complete is elusive to many people.
@afilina @nyamsprod "it hasn't been updated for two years so is probably unmaintained and full of vulnerabilities" - in reality it is a validation library and there are only so many times you can rewrite a check for string length before it gets ridiculous. I suppose updating a change log each week with, "still no need for a change" is a solution to satisfy the need some have for something new every week.