Re: Policy for Abandoned Extensions

From: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
To: Joe Conway <mail(at)joeconway(dot)com>
Cc: "David E(dot) Wheeler" <david(at)justatheory(dot)com>, PostgreSQL Hackers <pgsql-hackers(at)lists(dot)postgresql(dot)org>
Subject: Re: Policy for Abandoned Extensions
Date: 2026-10-10 18:02:04
Message-ID: 127034.1791655324@sss.pgh.pa.us
Views: Whole Thread | Raw Message | Download mbox | Resend email
Thread:
Lists: pgsql-hackers

Joe Conway <mail(at)joeconway(dot)com> writes:
> It may be impractical, but given cases like the XZ Utils backdoor
> situation (i.e where a malicious person showed up offering to "help"
> maintain an open source project where the original maintainer was
> stepping away), it seems like any transfer process needs a vetting step.

Yeah, if the replacement maintainer is malicious or even merely
incompetent, things could be worse than leaving the extension alone.
But that wasn't on David's list of worries, so I imagine he thinks
that's a soluble problem.

regards, tom lane

In response to

Responses

Browse pgsql-hackers by date

  From Date Subject
Next Message Hannu Krosing 2026-10-10 19:45:19 Re: Idea to enhance pgbench by more modes to generate data (multi-TXNs, UNNEST, COPY BINARY)
Previous Message Joe Conway 2026-10-10 17:57:47 Re: Policy for Abandoned Extensions