Llucs commented on PR #42361: URL: https://github.com/apache/superset/pull/42361#issuecomment-5071721570
> I just realize that the PR's author is also `backon` author, which should be disclaimed beforehand. The commit history and all issues are all handed singlehandedly by the author as well; giving me a bit of suspicion honestly. Idk, I sorta need a token of trust in this world full of threat actors these days. Thanks for pointing that out. You're absolutely right—I should have disclosed from the beginning that I'm the author and maintainer of backon. That was an oversight on my part, and I apologize for not making that explicit in the discussion and this PR. I completely understand your concern, especially given the current supply-chain security landscape. My intention was simply to propose a maintained, drop-in replacement for an archived dependency—not to hide my relationship with the project. I don't expect anyone to take my word for it. Please evaluate backon as you would any other dependency: review the source code, test suite, release history, API compatibility, and maintenance practices. If there are any questions about the implementation, compatibility, release process, or security considerations, I'm more than happy to answer them openly. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
