Tracking package unavailability

21 views
Skip to first unread message

Aditya Sirish A Yelgundhalli

unread,
Oct 14, 2021, 2:11:42 PM10/14/21
to wg-securing-cr...@googlegroups.com
Hello everyone,

I was curious to know if anyone has examples of packages becoming
unavailable, perhaps due to developers yanking them off a central
repository (eg: left-pad, mimemagic) or infrastructure for a niche
package going offline (eg: libisl a few days ago). I'm trying to collect
some examples of these instances and I'd appreciate any pointers to
specific examples, perhaps those that were less high profile, as well as
any lists of such incidents people have handy. I'm not focusing as much
on instances of service outages, say if NPM goes down for a few hours etc.

Thank you!

- Aditya

OpenPGP_signature

Aditya Sirish A Yelgundhalli

unread,
Oct 18, 2021, 10:39:20 AM10/18/21
to wg-securing-cr...@googlegroups.com
Hello everyone,

I put together a list of such incidents here:
https://github.com/adityasaky/availability-woes. The idea is to also
track repository policies that enable or mitigate availability concerns.

Please feel free to add to it by opening an issue or a pull request!

Thanks,
Aditya
OpenPGP_signature
Reply all
Reply to author
Forward
0 new messages