depends on unmaintained go-accept-headers
mev-boost depends on go-accept-headers, a project that has one commit and hasn't been touched in 12 years.
Adopting the source and moving it inside the mev-boost repository would feel safer.
Hey @come-maiz it's not unmaintained, it's just that it doesn't require any maintenance.
Personally, I don't feel that there's anything wrong/unsafe about that.
You are looking at it optimistically, and you might be right :)
This smells weird. I feel that this developer could be missing, or uninterested in this project, and in that case we cannot rely on them when the project starts to require maintenance. Or, if it's so straight-forward that it doesn't require maintenance, then maybe it shouldn't be a dependency.
At least, contact them to see if they are still aware and vigilant of the project?
Exact reference: https://github.com/flashbots/mev-boost/blob/develop/go.mod#L15
github.com/timewasted/go-accept-headers v0.0.0-20130320203746-c78f304b1b09