Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Link to more active fork #21

Open
mnoack opened this issue Nov 15, 2013 · 6 comments
Open

Link to more active fork #21

mnoack opened this issue Nov 15, 2013 · 6 comments

Comments

@mnoack
Copy link

mnoack commented Nov 15, 2013

Hi guys, the guy who manages the rails_xss gem (https://github.com/joloudov/rails_xss) has a much more active repo, and we're about to open a Pull Request for more fixes (Array.join).

Rather than have this looking like the official repo which is outdated perhaps it could have a readme pointing to this guy or have him/myself added to this repo? or even rebase off this guy and if possible monitor PR's? something along the lines?

Note: Yes unfortunately we still need rails_xss this as we use Radiant which is on rails2 so we can't just upgrade to rails3 yet.

@rafaelfranca
Copy link
Member

cc @NZKoz

@mnoack
Copy link
Author

mnoack commented Jan 8, 2014

@rafaelfranca @NZKoz I guess the absence of comments kind of re-enforces my point :)

@grosser
Copy link

grosser commented Jan 8, 2014

👍 1 less project to baby-sit @rafaelfranca ;)

@rafaelfranca
Copy link
Member

As this project is security related I'm not sure we will recommend our users to use a fork. This is why I cc'ed @NZKoz

@NZKoz
Copy link
Member

NZKoz commented Jan 8, 2014

Yeah, we've closed off this repository because we no longer offer any guarantees for 2.3 based apps, it's unsupported.

I think that linking to another repository might imply some level of security review which we simply haven't done.

@grosser
Copy link

grosser commented Jan 8, 2014

"A maintained but not reviewed repo can be found here"

On Wed, Jan 8, 2014 at 11:53 AM, Michael Koziarski <[email protected]

wrote:

Yeah, we've closed off this repository because we no longer offer any
guarantees for 2.3 based apps, it's unsupported.

I think that linking to another repository might imply some level of
security review which we simply haven't done.


Reply to this email directly or view it on GitHubhttps://github.com//issues/21#issuecomment-31871358
.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants