Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

subtle or subtle-ng? #176

Open
brycx opened this issue Feb 10, 2021 · 4 comments
Open

subtle or subtle-ng? #176

brycx opened this issue Feb 10, 2021 · 4 comments
Labels
dependencies Issues or improvements related to used dependencies

Comments

@brycx
Copy link
Member

brycx commented Feb 10, 2021

See issues regarding the dalek-cryptography organization:

I'm not sure I'm comfortable continuing to rely on the subtle crate. The above seem to be somewhat opposing statements of what has happened, though I still feel weird about the removal of crate owners, even if "warranted" by the maintainer of the org. IMHO, the thing should have happened with more transparency to begin with (like they should've made an announcement).

Currently, I'm leaning towards switching to subtle-ng.

@brycx brycx added the dependencies Issues or improvements related to used dependencies label Feb 10, 2021
@vlmutolo
Copy link
Contributor

At the end of the day, all we know about the situation is that founder A claims the he removed maintainer B from his project due to Code of Conduct violations, maintainer B claims that he and other maintainers were removed for reasons that remain undisclosed, and we as outsiders don’t really have a way of verifying any of that.

The lack of transparency from the dalek founder is a little concerning. I would have preferred to know exactly which part of the Code of Conduct was violated.

It would also be helpful to hear from the other maintainers on the issue. They may be able to clear some things up.

But what it really comes down to is whether subtle-ng will be maintained as actively as subtle going forward. If so, they I personally would switch due to the lack of transparency from the owner of subtle. That would be enough for me to make the change.

But if subtle-ng won’t have the same resources behind it, then it may be hard to justify switching over. But maybe subtle doesn’t need that much maintenance.

@cathieyun
Copy link

I added some clarification here. Hope that helps.

@brycx
Copy link
Member Author

brycx commented Feb 23, 2021

It definitely helps @cathieyun! Thanks again for clarifying/confirming.

@brycx
Copy link
Member Author

brycx commented Mar 14, 2021

I wrote @hdevalence a bit back, about expected support for subtle-ng, but haven't gotten any answer yet. I agree with you @vlmutolo. Currently, subtle probably does not need that much maintenance. Seeing as the subtle is currently used more than subtle-ng, I think we can stick with it for now.

I'll keep the issue open in case there are other developments, like subtle not getting attention, etc. Let's keep a close eye on the dependency for a bit. Unless any sudden developments occur, we're keeping subtle for 0.16.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Issues or improvements related to used dependencies
Projects
None yet
Development

No branches or pull requests

3 participants