Repository navigation
chore: enter security-only maintenance and point to Video.js 10 - #1867
Merged
Merged
Conversation
Add SECURITY.md (private vulnerability reporting) and AGENTS.md, add maintenance notices to the READMEs and CONTRIBUTING.md, and route feature requests, docs requests, and questions to Video.js 10. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Lead the package descriptions with the deprecation, tag the player entry points @deprecated with the migration guide, and log a one-time console notice when a player connects. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
New issues and PRs from outside the team are classified by Claude Sonnet 5.5. Anything that might be a security report is labelled and left open; everything else gets the maintenance message and is closed. close-backlog.sh closes the existing backlog with the same messages. Remove the weekly lockfile refresh, which upgraded dependencies on every run. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This was referenced Oct 6, 2026
Merged
Point agents at the Video.js skill, the migration guides' AI Quickstart prompts, and the llms.txt indexes instead of restating the migration. Add an AGENTS.md to vidstack and @vidstack/react and copy it into the published package. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This was referenced Oct 6, 2026
This was referenced Oct 7, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Vidstack enters security-only maintenance now that Video.js 10 is GA: priority security fixes for 1.x until January 2028, nothing else. This PR points people and coding agents at Video.js 10 from every surface they read, and automates issue and PR triage. It mirrors Plyr's sampotts/plyr#2921.
Docs and repository
SECURITY.md: supported versions, and private vulnerability reporting (already enabled in settings) as the only channel.AGENTS.mdat the root and in each package. They point agents at the Video.js skill, the migration guides'.mdversions (whose AI Quickstart section holds the prompt, maintained in videojs/v10), and thellms.txtindexes. The root file also limits work in this repository to security fixes.copy-pkg-files.jsnow copies each package'sAGENTS.mdinto the published package.CONTRIBUTING.md.Package deprecation
vidstackand@vidstack/reactdescriptions lead with the deprecation, andvideo.jsis added to the keywords. Both reach npm throughcopy-pkg-files.js.@deprecatedJSDoc, with the migration guide link, on the coreMediaPlayer,MediaPlayerElement,VidstackPlayer, and the ReactMediaPlayer.console.infowhen the first player connects, whatever the log level, since production builds default to silent. It runs inonConnect, so it's browser-only and covers web components, React, and the CDNVidstackPlayer.create()from one place. It names both guides because the core can't tell which framework is in use.Triage
.github/workflows/maintenance-triage.ymlruns when someone outside the team opens an issue or PR (owners, members, collaborators, and bots are skipped)..github/maintenance/triage.mjsasks Claude Sonnet 5.5 (claude-sonnet-5-5, effortlow, structured output) only whether the item is security-related. The model never writes the reply; the workflow posts one of three fixed messages from.github/maintenance/:securitylabel and a message pointing atSECURITY.md; the item stays open.pull_request_targetnever checks out PR code. It sparse-checks-out.github/maintenance/from the base branch and reads the title and body from the payload.workflow_dispatchtakes an issue or PR number, anddry_run(the default) only logs the decision. Use it to spot-check the classifier on closed issues after merge..github/maintenance/close-backlog.shcloses the existing backlog with the same messages. It's a dry run by default,KEEPleaves numbers open, and it skips anything labelledsecurity.weekly.yml. It rebuilt the lockfile from scratch and auto-merged dependency upgrades every week, which security-only maintenance rules out, and it has failed every run since at least September.Each run costs about a cent, from the
ANTHROPIC_API_KEYsecret (already added).Checks
actionlintpasses on the new workflow, andclose-backlog.shpassesbash -n.triage.mjsran against a mock Messages API, which confirmed:claude-sonnet-5-5,fallbacks: "default", effortlow, JSON schema output;mainin a fresh install, all in the hls, dash, and google-cast providers.After merge
close-backlog.sh, dry run first.🤖 Generated with Claude Code