gulpjs / liftoff

Launch your command line tool with ease.
MIT License
840 stars 52 forks source link

Additional maintainers?.. #115

Closed kibertoad closed 2 years ago

kibertoad commented 3 years ago

Hi! I'm a maintainer of knex and we use your package. There were complaints of security vulnerabilities that transitively come from liftoff. Would you be open to accepting additional maintainers into your project in order to address the vulnerabilities?

kibertoad commented 3 years ago

@phated

phated commented 3 years ago

This project is going through a complete rewrite and then will be properly migrated to the @gulpjs organization.

kibertoad commented 3 years ago

Thank you for the heads-up!

kibertoad commented 3 years ago

@phated Would you be open to releasing a hotfix version if we provide a PR that would resolve current security warnings about liftoff? Our users keep complaining about security warnings they are getting, and we can't remove liftoff dependency without a semver major.