Skip to content

Please Archive Repo #1022

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
JamesClarke7283 opened this issue Apr 1, 2025 · 3 comments
Open

Please Archive Repo #1022

JamesClarke7283 opened this issue Apr 1, 2025 · 3 comments

Comments

@JamesClarke7283
Copy link

JamesClarke7283 commented Apr 1, 2025

Hello, ive know this project for a while and used it before back when it worked.

It was a really good project, and i am greatful for all the people who worked on it.

I just revisited this project as i wanted to try it out again. The repo says it has recent commits and the wiki page said its being maintained, so i attempted to build the apk.

Some issues show some people using it successfully last year so i thought it would be possible to do that myself.

5 hours later of trial and error to get this thing to build(android studio doesn't even let me use the required versions for deps for security and other reasons, some of which return 404 anyway), i used a manual (CLI) method to do it, and the app didn't even work when it was installed. While i will never get those 5 hours back, i would like to mitigate others from making the same mistake:

Since this project has now been unmaintained for ~8 years, i would request this project to be archived immediately.

Ive read the "revival" issue and readme update.

If anyone wants to continue development. Please do it on a fork.

The organization this repo is under are not maintaining it. Many of the wiki pages like development status. Say its being maintained.

And the readme points to a fork "revival", when i visit the repo. Its empty.

So can we please officially sunset this repo as " archived", i don't want more confusion to other users, who may spend lots of time trying to get it to work, where it wont.

I am sure some users have, with great difficulty. But if they know its not maintained, they will know it might be very hard to get working.

Also note that this application at time of writing depends on java 7 and outdated deps, etc. Users should assume the application is not secure & is vulnerable, i would not be surprised if a 9.x CVE impacts it RN

Many thanks,
James Clarke

@andr3jx
Copy link
Contributor

andr3jx commented Apr 6, 2025

Hi, thanks for initiating this. Unfortunately I don't think there is anybody who has the rights to do that. SecUpwN vanished a long time ago. As someone who was part of the original core team, I will request GitHub support to archive the repo and hope that they can act on this.

@andr3jx
Copy link
Contributor

andr3jx commented Apr 6, 2025

The best I could do is submit a request by reporting it for malware. Here my message:

Hello GitHub Support,

I'm writing to request that the following repository be archived due to long-term abandonment and potential harm caused by outdated information as well as non-functional or vulnerable components.

Repository: https://github.com/CellularPrivacy/Android-IMSI-Catcher-Detector

This project has not been updated in over 8 years and has no active maintainers. Despite its age, it still appears active to users and developers, which is misleading — especially since the app deals with sensitive topics like mobile network security.

Outdated software in this domain can give users a false sense of protection, which may lead to privacy or security risks. Archiving it would help signal clearly that the project is no longer maintained and prevent further confusion.

I understand that it is a very unusual request but I couldn't find a better channel where this can be initiated.

I see myself as qualified to submit this request because I am part of the original core team and have close familiarity with the project.

Thank you for your time and consideration.

Best regards,
andr3jx

@JamesClarke7283
Copy link
Author

JamesClarke7283 commented Apr 7, 2025

The best I could do is submit a request by reporting it for malware. Here my message:

Hello GitHub Support,
I'm writing to request that the following repository be archived due to long-term abandonment and potential harm caused by outdated information as well as non-functional or vulnerable components.
Repository: https://github.com/CellularPrivacy/Android-IMSI-Catcher-Detector
This project has not been updated in over 8 years and has no active maintainers. Despite its age, it still appears active to users and developers, which is misleading — especially since the app deals with sensitive topics like mobile network security.
Outdated software in this domain can give users a false sense of protection, which may lead to privacy or security risks. Archiving it would help signal clearly that the project is no longer maintained and prevent further confusion.
I understand that it is a very unusual request but I couldn't find a better channel where this can be initiated.
I see myself as qualified to submit this request because I am part of the original core team and have close familiarity with the project.
Thank you for your time and consideration.
Best regards,
andr3jx

Thanks for doing this.
The weblate commits should also stop coming in in the meantime, some people who only have a cursory read of history might think the project is active because of the recent commits, also if people are spending time doing translations for this project in its broken state, it might not have much benefit, and misdirect their time from other projects which are active.

I think on the weblate end it should also be clear this project is dead.

If people want to contribute translations, maybe a PR is better(maybe weblate supports this). that way we dont have that false sense of activity creating confusion.

We also run the risk of an ubuntu like incident where you get malicous translations come in, promoting malware or containing harmful content.

To my knowledge the weblate commits seem to be automatically commited to the repo, as no recent 'merged' PR's are for translations.

All an all this repo is a ticking time bomb all while its not archived, only a matter of when this gets exploited.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants