# What to do about archived go dependencies?

**URL:** <https://anchorecommunity.discourse.group/t/what-to-do-about-archived-go-dependencies/279>\
**Category:** General\
**Created:** [December 12, 2024, 5:18pm UTC](https://anchorecommunity.discourse.group/t/what-to-do-about-archived-go-dependencies/279 "2024-12-12T17:18:16Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![popey](https://yyz2.discourse-cdn.com/free1/user_avatar/anchorecommunity.discourse.group/popey/32/429_2.png) [@popey](https://anchorecommunity.discourse.group/u/popey)\
**Post date:** [December 12, 2024, 5:18pm UTC](https://anchorecommunity.discourse.group/t/what-to-do-about-archived-go-dependencies/279/1 "2024-12-12T17:18:16Z")

</div>

Hey gang!

There was mention somewhere last week that [mitchellh (Mitchell Hashimoto) · GitHub](http://github.com/mitchellh) archived a bunch of their repos as they’ve moved on from Go development to something else, zig?

Anyway, I wondered, other than Mitchell’s Go projects that we depend on, how many others have been archived. So I wrote a script, and here’s the result after pointing it at Syft, Grype, Grant and Stereoscope as a test. I can scan all the other open source repos, but figured I’d start the conversation with what we have here:

**Do we have a plan for “dealing” with these?**

## All

- [GitHub - facebookincubator/nvdtools: A set of tools to work with the feeds (vulnerabilities, CPE dictionary etc.) distributed by National Vulnerability Database (NVD)](https://github.com/facebookincubator/nvdtools)
- [GitHub - mitchellh/copystructure: Go (golang) library for deep copying values in Go.](https://github.com/mitchellh/copystructure)
- [GitHub - mitchellh/go-homedir: Go library for detecting and expanding the user's home directory without cgo.](https://github.com/mitchellh/go-homedir)
- [https://github.com/mitchellh/hashstructure/v2](https://github.com/mitchellh/hashstructure/v2)
- [GitHub - mitchellh/mapstructure: Go library for decoding generic map values into native Go structures and vice versa.](https://github.com/mitchellh/mapstructure)
- [GitHub - mitchellh/reflectwalk: reflectwalk is a Go library for "walking" complex structures, similar to walking a filesystem.](https://github.com/mitchellh/reflectwalk)
- [GitHub - pkg/errors: Simple error handling primitives](https://github.com/pkg/errors)
- [GitHub - sagikazarmark/slog-shim: Backward-compatible shim for log/slog](https://github.com/sagikazarmark/slog-shim)

## Grype & Syft

- [https://github.com/facebookincubator/nvdtools/wfn](https://github.com/facebookincubator/nvdtools/wfn)

## Grype

- [GitHub - mitchellh/go-testing-interface: Go (golang) library to expose \*testing.T as an interface.](https://github.com/mitchellh/go-testing-interface)

## Grant

- [https://github.com/mholt/archiver/v3](https://github.com/mholt/archiver/v3)

---

<div class="post-metadata">

**Author:** ![kzantow](https://yyz2.discourse-cdn.com/free1/user_avatar/anchorecommunity.discourse.group/kzantow/32/17_2.png) [@kzantow](https://anchorecommunity.discourse.group/u/kzantow)\
**Post date:** [December 16, 2024, 4:29pm UTC](https://anchorecommunity.discourse.group/t/what-to-do-about-archived-go-dependencies/279/2 "2024-12-16T16:29:28Z")

</div>

It looks like we should probably update to use the Viper fork of mapstructure anywhere we’re directly depending on it: [GitHub - go-viper/mapstructure: Go library for decoding generic map values into native Go structures and vice versa.](https://github.com/go-viper/mapstructure), especially since we’re already pulling this in with Viper updates.
