mev-boost icon indicating copy to clipboard operation
mev-boost copied to clipboard

depends on unmaintained go-accept-headers

Open come-maiz opened this issue 5 months ago • 3 comments

mev-boost depends on go-accept-headers, a project that has one commit and hasn't been touched in 12 years.

Adopting the source and moving it inside the mev-boost repository would feel safer.

come-maiz avatar Jul 04 '25 15:07 come-maiz

Hey @come-maiz it's not unmaintained, it's just that it doesn't require any maintenance.

Personally, I don't feel that there's anything wrong/unsafe about that.

jtraglia avatar Jul 04 '25 20:07 jtraglia

You are looking at it optimistically, and you might be right :)

This smells weird. I feel that this developer could be missing, or uninterested in this project, and in that case we cannot rely on them when the project starts to require maintenance. Or, if it's so straight-forward that it doesn't require maintenance, then maybe it shouldn't be a dependency.

At least, contact them to see if they are still aware and vigilant of the project?

come-maiz avatar Jul 05 '25 02:07 come-maiz

Exact reference: https://github.com/flashbots/mev-boost/blob/develop/go.mod#L15

github.com/timewasted/go-accept-headers v0.0.0-20130320203746-c78f304b1b09

ottok avatar Aug 04 '25 02:08 ottok