Why should this tool be removed?
Fluent Reader’s last commit was on October 15th, 2023, more than a year ago. That in itself is not the reason I am proposing for its removal.
According to Fluent Reader’s GitHub README, one of the app’s dependencies is Electron. One of Fluent Reader’s last commits involved updating the app’s Electron version to v27.0.0 to fix a critical vulnerability with WebP (see link to GitHub issue in the following paragraph). For reference, the current stable Electron version at the time I’m writing this is v33.0.2.
There is already precedent for removing tools which, because of their unmaintained status, have dependencies which lag behind upstream (see hat.sh). In Fluent Reader’s case, lagging behind in Electron updates is particularly problematic due to
- the fact that Fluent Reader is used to render web content, likely from various different sources if you subscribe to many RSS feeds
- the well-documented security issues of Electron, including the aforementioned WebP vulnerability