← Back to context

Comment by evanelias

4 months ago

No, absolutely not. That's precisely how you end up with bad actors inserting malware into FOSS projects they've taken over.

If a maintainer doesn't want to continue a project, and there's no existing contributor who has demonstrated both the qualifications and interest in taking over a project, the responsible thing to do is archive it – not give committer rights to some rando.

In the future, if someone else wants to take a stab at continuing the project, they can fork it. Crucially that moves the project to a different namespace – as it absolutely should, for security reasons.

Fair point. However, officially announcing the end of the project is not too much to ask.