Blame yourselves devs, not the author who donated hours and hours of free work for your benefit.
Blame yourselves devs, not the author who donated hours and hours of free work for your benefit.
Just mark it as deprecated and call it a day, like a normal and responsible person.
Somebody really needs to explain to me how this works. The dude's bio on github is "antipodean wandering albatross". Nothing against it btw.
Says you! I don't agree with that. Author clearly doesn't either. You're painting it as though the author knowingly handed it over to some hacker when in reality he had 0 cares about this package and just handed it over to the first guy who asked. I would have done the same probably.
If you don't have the care to maintain it or do any sort of vetting, you shouldn't have the care to do anything at all. Literally, leaving this unmaintained would have been a better solution.