nccgroup / sobelow

Security-focused static analysis for the Phoenix Framework
Apache License 2.0
1.66k stars 92 forks source link

Plans for ongoing maintenance? #113

Closed prehnRA closed 1 year ago

prehnRA commented 2 years ago

First of all, thanks for the great tool. The hard work is really appreciated.

I've noticed that there hasn't been a lot of activity here lately-- PRs not getting merged (or reviewed), issues with minimal discussion, and a stale hex release.

Would you be open to assistance in maintaining Sobelow? I understand that priorities shift for people and companies over time, and it would be a shame for this work to get left behind.

Thanks.

houllette commented 1 year ago

I wanted to chime in here as well - the company I work at has a vested interest in the success / upkeep in Sobelow, so I would happily volunteer myself to assist in maintenance

willricketts commented 1 year ago

I also am very interested in the maintenance plan going forward.

andrewek commented 1 year ago

Is it worth considering a public fork?

My employer makes pretty heavy use of Sobelow, and I'm sure we're not the only ones.

houllette commented 1 year ago

@GriffinMB has added me as a maintainer (thanks, Griffin!) so I will start to work my way through issues and PRs to get low hanging fruit patched in!

Like I mentioned earlier in this thread, the company I work at (Podium) has a vested interest in the success of Sobelow - as I know many of you in the community do as well. So I am taking it upon myself to ensure that continual upkeep of the project continues and the Application Security team at Podium will continue to monitor / maintain the repo (potentially add some new features/vulns too 👀)