Skip to content

Concerns about yard-activesupport-concern #1092

@tagliala

Description

@tagliala

Hello,

I noticed that this project recently introduced dependency on yard-activesupport-concern that has not been updated in over a decade and is still at version 0.0.1. Given that its functionality appears to be minimal, would it not make sense to integrate its features directly into this library?

Bundling this code could help reduce external dependencies, simplify maintenance, and improve long-term project stability. Is there a specific reason for having introduced this outdated gem?

Recent incidents, such as the widespread npm supply chain attack (where malicious packages were published and billions of weekly downloads were put at risk), have made me increasingly wary of relying on third-party dependencies.
Even trusted sources can be compromised, and attacks like these are difficult to detect and mitigate.

Removing unnecessary dependencies helps reduce our attack surface and makes this project safer.

Thank you for considering this suggestion

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions