# Taking control of contrib nodes when not being maintained

**URL:** <https://discourse.nodered.org/t/taking-control-of-contrib-nodes-when-not-being-maintained/20344>\
**Category:** General\
**Created:** [14 January 2020 22:24 UTC](https://discourse.nodered.org/t/taking-control-of-contrib-nodes-when-not-being-maintained/20344 "2020-01-14T22:24:41Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![cymplecy](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/cymplecy/32/2773_2.png) [@cymplecy](https://discourse.nodered.org/u/cymplecy)\
**Post date:** [14 January 2020 22:24 UTC](https://discourse.nodered.org/t/taking-control-of-contrib-nodes-when-not-being-maintained/20344/1 "2020-01-14T22:24:41Z")

</div>

Just starting a discussion

There are a number of useful contrib nodes that end up not being maintained

How about copying them into the official Node-RED sphere?

But obviously too much work for core devs so I thought, why not have another level in between a  
node-red-node and a node-red-contrib node

For these type of nodes, @knolleary and @dceejay create a repository but let other approved devs maintain it and do all the actual work.

Then if this person/persons drops away - other devs could take over.

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [14 January 2020 22:33 UTC](https://discourse.nodered.org/t/taking-control-of-contrib-nodes-when-not-being-maintained/20344/2 "2020-01-14T22:33:16Z")

</div>

Once they are in the 'official Node-RED sphere' then the Node-RED project has to maintain them.

Given we don't get much help maintaining the existing node-red-nodes repository, I'm not immediately inclined for the project to take on more responsibility. If more people were actively contributing, then it would be a different matter.

That said, there clearly is an issue with contrib nodes becoming unmaintained. I would hope that if there were particular nodes of interest, then individuals could work with the previous maintainer to take on the ownership. Putting the nodes into the Node-RED organisation in github (and all that implies, whether intended or not), isn't necessarily the right first step.

---

<div class="post-metadata">

**Author:** ![molesworth](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/molesworth/32/11748_2.png) [@molesworth](https://discourse.nodered.org/u/molesworth)\
**Post date:** [14 January 2020 22:35 UTC](https://discourse.nodered.org/t/taking-control-of-contrib-nodes-when-not-being-maintained/20344/3 "2020-01-14T22:35:49Z")

</div>

> [@knolleary](#):
>
> Once they are in the 'official Node-RED sphere' then the Node-RED project has to maintain them.
> 
> Putting the nodes into the Node-RED organisation in github (and all that implies, whether intended or not), isn't necessarily the right first step.

Good point. Maybe some sort of "in transit" repository, with selected / approved maintainers would be a good half-way house?

---

<div class="post-metadata">

**Author:** ![afelix](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/afelix/32/9743_2.png) [@afelix](https://discourse.nodered.org/u/afelix)\
**Post date:** [14 January 2020 22:42 UTC](https://discourse.nodered.org/t/taking-control-of-contrib-nodes-when-not-being-maintained/20344/4 "2020-01-14T22:42:41Z")

</div>

Something else to think about @cymplecy is when the author of the contrib node simply stops responding regardless of personal situation. I can see that happening towards myself if my health further worsens. It wouldn’t just be ownership of a repository, but once packages are registered to npm that name is registered too, and only the original owner can transfer the ownership for that.

A result of that would be (numerous) forked nodes that get published on their own package. It already happens like that, try searching the flows library for “elasticsearch”, they all have the same original contrib node. It makes searching for nodes from the palette even harder as you can’t see the real difference between all of them without checking out the source code.

The idea definitely has merit, but don’t forget about the difficulties it might/can get also deal with ownership towards the OpenJS Foundation, as that what’s moving to the node-red organisation would likely mean as well. Even just forking would make it difficult I believe. But food for thought for sure

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [14 January 2020 22:48 UTC](https://discourse.nodered.org/t/taking-control-of-contrib-nodes-when-not-being-maintained/20344/5 "2020-01-14T22:48:36Z")

</div>

> [@afelix](#):
>
> A result of that would be (numerous) forked nodes that get published on their own package. It already happens like that, try searching the flows library for “elasticsearch”, they all have the same original contrib node.

Indeed. **Any** activity like this must start with a conversation with the original maintainer. Get their approval to take it on and not just fork and cause confusion.

A good example is the Cloudant node we have in the IBM Cloud. The original maintainer left IBM a while ago and isn't able to maintain it any more. Having discussed it with him, he has recently added me as an owner to the npm module so I can publish updates. I'm now going to work with the authors of all the forks to try to bring them back together to one node.

I suspect there are other nodes with multiple forks that would also benefit from some rationalisation - particularly those for popular technologies (such as elasticsearch as @afelix mentions). There's a lot of nodes in the flow library that have no real need to be there and just cause confusion. But it's too big a task for one person to do.

---

<div class="post-metadata">

**Author:** ![drmibell](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/drmibell/32/8424_2.png) [@drmibell](https://discourse.nodered.org/u/drmibell)\
**Post date:** [14 January 2020 23:42 UTC](https://discourse.nodered.org/t/taking-control-of-contrib-nodes-when-not-being-maintained/20344/6 "2020-01-14T23:42:04Z")

</div>

> [@knolleary](#):
>
> But it's too big a task for one person to do.

Especially if that person is looking after the NR core.

Perhaps a place to start would be to develop a couple of bits of code or even NR flows that could scan the [flow library](https://flows.nodered.org) and

1. Identify nodes that had not been updated for more than (for example) a year and send an email to the maintainer(s) asking whether they are still active and willing to keep the node current or, if not, whether he/she would be willing to transfer ownership.
2. Compile and publish a list of nodes that are available for "adoption" so that volunteers could ask to take over maintenance.

I'm not convinced this would accomplish much, but it might be worth a try. The problems of multiple forks or abandoned nodes might call for more drastic action, such as purging them from the library and listening for the screams.

---

<div class="post-metadata">

**Author:** ![dceejay](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/dceejay/32/38_2.png) [@dceejay](https://discourse.nodered.org/u/dceejay)\
**Post date:** [14 January 2020 23:46 UTC](https://discourse.nodered.org/t/taking-control-of-contrib-nodes-when-not-being-maintained/20344/7 "2020-01-14T23:46:23Z")

</div>

> [@drmibell](#):
>
> develop a couple of bits of code

and who would do that ?

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [14 January 2020 23:53 UTC](https://discourse.nodered.org/t/taking-control-of-contrib-nodes-when-not-being-maintained/20344/8 "2020-01-14T23:53:42Z")

</div>

> [@drmibell](#):
>
> Identify nodes that had not been updated for more than (for example) a year and send an email to the maintainer(s) asking whether they are still active and willing to keep the node current or, if not, whether he/she would be willing to transfer ownership.

I think there is merit to this. Not necessarily the second part (asking about transferring ownership) initially. With some data mining we could identify nodes that look abandoned and approach the maintainer to see if it's active. Part of that will also be the npm download stats as there are plenty of useful nodes that are stable and not needed an update. If the recent npm stats are negligible, the owner confirms it's a dead node and it's clearly not a high value node, would could remove it from the flow library.

Its worth some thought. Yes there's work involved, but the flow library is over due a tidy up and this would one way of tackling it.

---

<div class="post-metadata">

**Author:** ![dceejay](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/dceejay/32/38_2.png) [@dceejay](https://discourse.nodered.org/u/dceejay)\
**Post date:** [14 January 2020 23:54 UTC](https://discourse.nodered.org/t/taking-control-of-contrib-nodes-when-not-being-maintained/20344/9 "2020-01-14T23:54:02Z")

</div>

> [@drmibell](#):
>
> publish a list of nodes that are available for "adoption"

though that could lead to this sort of situation - [https://github.com/dominictarr/event-stream/issues/116](https://github.com/dominictarr/event-stream/issues/116)

---

<div class="post-metadata">

**Author:** ![afelix](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/afelix/32/9743_2.png) [@afelix](https://discourse.nodered.org/u/afelix)\
**Post date:** [15 January 2020 00:56 UTC](https://discourse.nodered.org/t/taking-control-of-contrib-nodes-when-not-being-maintained/20344/10 "2020-01-15T00:56:08Z")

</div>

> [@knolleary](#):
>
> With some data mining we could identify nodes that look abandoned and approach the maintainer to see if it's active.

I might be speaking before my turn but to future readers: please don’t see this as an open invitation to start scraping the flows library page as it’s already under load (as was mentioned in other topics once or twice in the last view months)  
If you’d like to check out the library like that, just clone the catalogue repository and work your way through that JSON file, no need to put stress on more Node-RED resources than strictly needed.

---

<div class="post-metadata">

**Author:** ![drmibell](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/drmibell/32/8424_2.png) [@drmibell](https://discourse.nodered.org/u/drmibell)\
**Post date:** [15 January 2020 01:34 UTC](https://discourse.nodered.org/t/taking-control-of-contrib-nodes-when-not-being-maintained/20344/11 "2020-01-15T01:34:51Z")

</div>

> [@dceejay](#):
>
> could lead to this sort of situation - [https://github.com/dominictarr/event-stream/issues/116](https://github.com/dominictarr/event-stream/issues/116)

Ouch! That's ugly. I guess it was naive of me to assume only good intentions in the NR community. I recall some earlier discussion of detecting malicious code in contributed nodes, but I don't remember where it went.

---

<div class="post-metadata">

**Author:** ![vlturner](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/vlturner/32/15211_2.png) [@vlturner](https://discourse.nodered.org/u/vlturner)\
**Post date:** [15 January 2020 03:00 UTC](https://discourse.nodered.org/t/taking-control-of-contrib-nodes-when-not-being-maintained/20344/12 "2020-01-15T03:00:12Z")

</div>

How can one get to help as a maintainer?

---

<div class="post-metadata">

**Author:** ![cymplecy](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/cymplecy/32/2773_2.png) [@cymplecy](https://discourse.nodered.org/u/cymplecy)\
**Post date:** [15 January 2020 09:11 UTC](https://discourse.nodered.org/t/taking-control-of-contrib-nodes-when-not-being-maintained/20344/13 "2020-01-15T09:11:13Z")

</div>

> [@knolleary](#):
>
> Once they are in the 'official Node-RED sphere' then the Node-RED project has to maintain them.

Just to clarify what I was thinking

This new class of nodes wouldn't be in the main repository - It would be a separate one.  
_(Lets call it the community nodes repository)_

The additional work load for you and Dave should only be to approve devs to work on particular nodes.

Once that's done - the node dev(s) do all the maintenance on their assigned nodes

---

<div class="post-metadata">

**Author:** ![dceejay](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/dceejay/32/38_2.png) [@dceejay](https://discourse.nodered.org/u/dceejay)\
**Post date:** [15 January 2020 09:55 UTC](https://discourse.nodered.org/t/taking-control-of-contrib-nodes-when-not-being-maintained/20344/14 "2020-01-15T09:55:02Z")

</div>

The overall contribution guidelines are here - [https://nodered.org/about/contribute/](https://nodered.org/about/contribute/)  
but the net is - find a bug / pick an existing issue - offer to help / propose a solution - discuss here - if it's good then create an issue (or add to existing) - write code - test it - raise a Pull request. You are now a contributor.

---

<div class="post-metadata">

**Author:** ![Paul-Reed](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/paul-reed/32/66906_2.png) [@Paul-Reed](https://discourse.nodered.org/u/Paul-Reed)\
**Post date:** [15 January 2020 10:02 UTC](https://discourse.nodered.org/t/taking-control-of-contrib-nodes-when-not-being-maintained/20344/15 "2020-01-15T10:02:10Z")

</div>

> [@drmibell](#):
>
> ...Identify nodes that had not been updated for more than (for example) a year

Is that a good measure of an abandoned node?  
Maybe it was just well written in the first place, and therefore there was no need to carry out tweaks & fixes 😉

---

<div class="post-metadata">

**Author:** ![drmibell](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/drmibell/32/8424_2.png) [@drmibell](https://discourse.nodered.org/u/drmibell)\
**Post date:** [15 January 2020 15:27 UTC](https://discourse.nodered.org/t/taking-control-of-contrib-nodes-when-not-being-maintained/20344/16 "2020-01-15T15:27:22Z")

</div>

> [@Paul-Reed](#):
>
> Is that a good measure of an abandoned node?

I didn't suggest it as a measure, just an indicator that it might be worth a ping from the dev team to see if the author is still active.

> [@Paul-Reed](#):
>
> Maybe it was just well written in the first place

Do you mean like [node-red-contrib-random-event-generator](https://flows.nodered.org/node/node-red-contrib-random-event-generator)? 🙂 I wouldn't mind an annual e-mail asking if I am willing to respond to issues.

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [15 January 2020 16:22 UTC](https://discourse.nodered.org/t/taking-control-of-contrib-nodes-when-not-being-maintained/20344/17 "2020-01-15T16:22:51Z")

</div>

There are some really valuable thoughts in this thread.

1. Helping maintain core nodes

2. Identifying unmaintained nodes

---

<div class="post-metadata">

**Author:** ![Paul-Reed](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/paul-reed/32/66906_2.png) [@Paul-Reed](https://discourse.nodered.org/u/Paul-Reed)\
**Post date:** [15 January 2020 22:06 UTC](https://discourse.nodered.org/t/taking-control-of-contrib-nodes-when-not-being-maintained/20344/18 "2020-01-15T22:06:11Z")

</div>

> [@TotallyInformation](#):
>
> There are some really valuable thoughts in this thread

Yes agree, and having experienced this issue a number of times it's very frustrating, and by example, and most recently with `node-red-contrib-ringdoorbell` where I've raised an issue, but suspect that the author may not respond.  
So my next step maybe to try & fix the problem and publish `node-red-contrib-ringdoorbell-2` which isn't really a good solution, as well you know.  
But as there is only one 'Ring doorbell' node, it maybe the only way forward.

---

<div class="post-metadata">

**Author:** ![dceejay](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/dceejay/32/38_2.png) [@dceejay](https://discourse.nodered.org/u/dceejay)\
**Post date:** [15 January 2020 23:14 UTC](https://discourse.nodered.org/t/taking-control-of-contrib-nodes-when-not-being-maintained/20344/19 "2020-01-15T23:14:01Z")

</div>

Yes you've raised an issue, you could also offer a Pull Request to fix it. The author may be more responsive to actual offers of help. You can also try a direct email, to check if they are still interested, and then finally yes go ahead and create a new version.

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [15 January 2020 23:29 UTC](https://discourse.nodered.org/t/taking-control-of-contrib-nodes-when-not-being-maintained/20344/20 "2020-01-15T23:29:49Z")

</div>

> [@dceejay](#):
>
> You can also try a direct email

If you get no luck on their issue list, then this can be a useful next step. One tip - `npm owner ls <module-name>` will list the owners of the module and their email addresses. Useful if a node doesn't list a git repo or other obvious way to contact the author.

If you do go that route, just keep in mind you have no idea why the user hasn't responded. It could be they have turned off github notifications for some personal reason. They may have had to move onto other things. So tread gently and be a positive representative of the NR community.

On the topic of identifying unmaintained nodes... this is certainly something I'm going to look at. If anyone is interested in collaborating, please do message me directly or on slack. I've got access to all the raw data, so as @afelix said, please don't go scraping the flow library site directly.

[Next page](https://discourse.nodered.org/t/taking-control-of-contrib-nodes-when-not-being-maintained/20344.md?page=2)
