Renovate's 'abandonment' functionality is reasonable, but has some improvements to make to make sure that we're giving our users the clearest view of whether they should be "worried" about an abandonment.
As discussed in #42727, and noted in https://social.treehouse.systems/@dalias@hachyderm.io/116932451629129149, there are a few issues with our current view:
- we only look at recent releases
- a project may be active (and the maintainer responding to issues) but no releases have been needed
- a project may be inactive because it's feature complete
To improve this, we should perform some tweaks to "Abandonment" as a concept:
(This is something I've been thinking about for a while, and after a listen to https://opensourcesecurity.io/2026/2026-07-VCRI-josh-marpet/ today alongside https://social.treehouse.systems/@dalias@hachyderm.io/116932451629129149, now's the time to raise this)
The CHAOSS Community does not currently have a metric for this, so looking at Value Chain Risk's suggested metrics may be a good step here.
See also:
Renovate's 'abandonment' functionality is reasonable, but has some improvements to make to make sure that we're giving our users the clearest view of whether they should be "worried" about an abandonment.
As discussed in #42727, and noted in https://social.treehouse.systems/@dalias@hachyderm.io/116932451629129149, there are a few issues with our current view:
To improve this, we should perform some tweaks to "Abandonment" as a concept:
MaintainedscorepackageRules-based ovrrides(This is something I've been thinking about for a while, and after a listen to https://opensourcesecurity.io/2026/2026-07-VCRI-josh-marpet/ today alongside https://social.treehouse.systems/@dalias@hachyderm.io/116932451629129149, now's the time to raise this)
The CHAOSS Community does not currently have a metric for this, so looking at Value Chain Risk's suggested metrics may be a good step here.
See also: