In an excellent example of one of the most overused XKCD images, the libxml2 library has for a little while lost its only maintainer, with [Nick Wellnhofer] making good on his plan to step down by the end of the year.
While this might not sound like a big deal, the real scope of this problem is rather profound. Not only is libxml2 part of GNOME, it’s also used as dependency by a huge number of projects, including web browsers and just about anything that processes XML or XSLT. Not having a maintainer in the event that a fresh, high-risk CVE pops up would obviously be less than desirable.




Also he was getting every week cve issues, which are often not urgent issues. Yet it costs him a lot of time. He also considers security issues now just the same as a normal issue. Not giving it priority anymore, since that doesn’t make sense anymore for him.