Skip to content

chore: enter security-only maintenance and point to Video.js 10 - #1867

Merged
mihar-22 merged 4 commits into
mainfrom
chore/security-only-maintenance
Oct 6, 2026
Merged

mihar-22 merged 4 commits into
mainfrom
chore/security-only-maintenance

Conversation

@mihar-22

@mihar-22 mihar-22 commented Oct 6, 2026 •

Copy link
Copy Markdown
Member

Vidstack enters security-only maintenance now that Video.js 10 is GA: priority security fixes for 1.x until January 2028, nothing else. This PR points people and coding agents at Video.js 10 from every surface they read, and automates issue and PR triage. It mirrors Plyr's sampotts/plyr#2921.

Docs and repository

  • SECURITY.md: supported versions, and private vulnerability reporting (already enabled in settings) as the only channel.
  • AGENTS.md at the root and in each package. They point agents at the Video.js skill, the migration guides' .md versions (whose AI Quickstart section holds the prompt, maintained in videojs/v10), and the llms.txt indexes. The root file also limits work in this repository to security fixes. copy-pkg-files.js now copies each package's AGENTS.md into the published package.
  • Maintenance notices at the top of the root README, both package READMEs (the npm READMEs), and CONTRIBUTING.md.
  • Issue templates: the feature request and docs templates are removed. Contact links now point to private vulnerability reporting, the migration guide, and the videojs/v10 discussions; these replace the old Q&A and Discord links. The bug report template explains that non-security bugs are closed.

Package deprecation

  • The vidstack and @vidstack/react descriptions lead with the deprecation, and video.js is added to the keywords. Both reach npm through copy-pkg-files.js.
  • @deprecated JSDoc, with the migration guide link, on the core MediaPlayer, MediaPlayerElement, VidstackPlayer, and the React MediaPlayer.
  • A one-time console.info when the first player connects, whatever the log level, since production builds default to silent. It runs in onConnect, so it's browser-only and covers web components, React, and the CDN VidstackPlayer.create() from one place. It names both guides because the core can't tell which framework is in use.

Triage

  • .github/workflows/maintenance-triage.yml runs when someone outside the team opens an issue or PR (owners, members, collaborators, and bots are skipped).
  • .github/maintenance/triage.mjs asks Claude Sonnet 5.5 (claude-sonnet-5-5, effort low, structured output) only whether the item is security-related. The model never writes the reply; the workflow posts one of three fixed messages from .github/maintenance/:
    • Not security: the maintenance message, then the item is closed (issues as not planned).
    • Possibly security: the security label and a message pointing at SECURITY.md; the item stays open.
  • Decline handling:
    • A policy decline is retried server-side on Anthropic's default fallback model.
    • If the item is still declined, it's treated as possibly security, since exploit details are the likely trigger.
    • Any other failure fails the job and leaves the item untouched.
  • pull_request_target never checks out PR code. It sparse-checks-out .github/maintenance/ from the base branch and reads the title and body from the payload.
  • workflow_dispatch takes an issue or PR number, and dry_run (the default) only logs the decision. Use it to spot-check the classifier on closed issues after merge.
  • .github/maintenance/close-backlog.sh closes the existing backlog with the same messages. It's a dry run by default, KEEP leaves numbers open, and it skips anything labelled security.
  • Removes weekly.yml. It rebuilt the lockfile from scratch and auto-merged dependency upgrades every week, which security-only maintenance rules out, and it has failed every run since at least September.

Each run costs about a cent, from the ANTHROPIC_API_KEY secret (already added).

Checks

  • actionlint passes on the new workflow, and close-backlog.sh passes bash -n.
  • triage.mjs ran against a mock Messages API, which confirmed:
    • the request: claude-sonnet-5-5, fallbacks: "default", effort low, JSON schema output;
    • the classify, decline, and truncated-response paths, and the step outputs.
  • oxfmt 0.51.0 passes on the changed sources.
  • Typecheck shows the same 10 TS2883 errors as main in a fresh install, all in the hls, dash, and google-cast providers.
  • I couldn't run the build locally: the lockfile has no macOS arm64 rolldown binding. CI covers the build.

After merge

  1. Dispatch the triage workflow as a dry run on a few closed issues, including Unable set request headers #1545 ("Unable set request headers"), which is a likely false positive. Check the logged reasons.
  2. Merge the fix PRs for the final release, cut it, then retag and deprecate on npm.
  3. Run close-backlog.sh, dry run first.

🤖 Generated with Claude Code

mihar-22 and others added 3 commits October 5, 2026 19:17
Add SECURITY.md (private vulnerability reporting) and AGENTS.md, add maintenance notices to the READMEs and CONTRIBUTING.md, and route feature requests, docs requests, and questions to Video.js 10.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Lead the package descriptions with the deprecation, tag the player entry points @deprecated with the migration guide, and log a one-time console notice when a player connects.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
New issues and PRs from outside the team are classified by Claude Sonnet 5.5. Anything that might be a security report is labelled and left open; everything else gets the maintenance message and is closed. close-backlog.sh closes the existing backlog with the same messages. Remove the weekly lockfile refresh, which upgraded dependencies on every run.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Point agents at the Video.js skill, the migration guides' AI Quickstart prompts, and the llms.txt indexes instead of restating the migration. Add an AGENTS.md to vidstack and @vidstack/react and copy it into the published package.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant