npm · Go · GitHub Actions · PyPI

Fixes for the abandoned packages you still depend on.

One confirmed bug. A test that fails on the original. A minimal fix. The same API. No surprises.

Some of the most-used packages and actions haven’t shipped in years, while real crash reports and fix PRs sit unmerged. 360 Bench takes them, fixes the confirmed bugs with tests, and republishes them as drop-in replacements: @fitzyracing/* on npm, fitzyracing1/* on GitHub (Go modules and Actions) and fitzyracing-* on PyPI. Every original author is credited.

  • 13drop-in forks
  • 4ecosystems
  • 1failing test per fix, minimum
  • 0package names taken

How it works

From abandoned to fixed, without changing your code.

  1. Spot

    A widely used package or action hasn’t shipped in years while real crash reports and fix PRs sit unmerged upstream.

  2. Prove

    The bug is confirmed and linked to an upstream issue, then captured in a test that fails on the original.

  3. Fix & republish

    The smallest fix that makes the test pass, published as a drop-in fork under a fitzyracing name, with the same API.

  4. Point home

    If a maintainer comes back and ships the fix, the fork points people back upstream, happy to hand it all back.

The rules Four promises, every fork.

  • Only confirmed bugs.

    Every fix links to an upstream issue and ships with a test that fails on the original and passes on the fork.

  • No surprises.

    Same API, same output wherever the original didn’t crash. No new dependencies beyond what a fix needs (for example audioop-lts on Python 3.13+). Anything else that changes, such as published upstream master commits, is listed in the fork’s README.

  • Credit stays.

    The original LICENSE, author and contributors are kept.

  • Upstream first.

    If a maintainer comes back and ships the fix, the fork points people home. 360 Bench is happy to hand it back.

On the bench

The forks

Each one replaces an upstream project and fixes only what’s listed. Copy the swap-in snippet and you’re done. Full details are in the 360 Bench README (opens in a new tab).

npm4 forks

Install one directly, or fix it everywhere in your dependency tree (for example inside ajv, eslint, Material-UI or react-bootstrap) without touching your code, using npm 9.9+ overrides in your package.json. Yarn uses "resolutions", pnpm uses "pnpm": { "overrides": { ... } }.

npm3.1.4

@fitzyracing/fast-deep-equal

Replaces fast-deep-equal (opens in a new tab)

Upstream last release
3.1.3, June 2020
Upstream usage
~265M/week
License
MIT
What’s fixed

No more a.valueOf is not a function crash on Object.create(null) objects or on data with a toString/valueOf field. Invalid Dates now compare equal. Ships TypeScript types.

package.json overrides
"overrides": {
  "fast-deep-equal": "npm:@fitzyracing/fast-deep-equal@^3.1.4"
}
Install directly
npm i @fitzyracing/fast-deep-equal
npm2.0.4

@fitzyracing/progress

Replaces progress (opens in a new tab)

Upstream last release
2.0.3, Dec 2018
Upstream usage
~69M/week
License
MIT
What’s fixed

No more RangeError: Invalid array length on NaN or missing content-length totals and on streams without columns. Handles a non-numeric width, and interrupt() works on piped output.

package.json overrides
"overrides": {
  "progress": "npm:@fitzyracing/progress@^2.0.4"
}
Install directly
npm i @fitzyracing/progress
npm4.4.6

@fitzyracing/react-transition-group

Replaces react-transition-group (opens in a new tab)

Upstream last release
4.4.5, Aug 2022
Upstream usage
~66M/week
License
BSD-3-Clause
What’s fixed

No more TypeError: findDOMNode is not a function on React 19 when no nodeRef is passed (Transition, CSSTransition, SwitchTransition, TransitionGroup, ReplaceTransition). React 16.6 to 18 behave exactly as 4.4.5.

Upstream refs #918 (opens in a new tab)

Note On React 19 without nodeRef, the child of a transition has to accept a ref (a DOM element, a forwardRef component, or a function component that passes ref on). Details (opens in a new tab)

package.json overrides
"overrides": {
  "react-transition-group": "npm:@fitzyracing/react-transition-group@^4.4.6"
}
Install directly
npm i @fitzyracing/react-transition-group
npm2.0.2

@fitzyracing/fetch-event-source

Replaces @microsoft/fetch-event-source (opens in a new tab)

Upstream last release
2.0.1, Apr 2021
Upstream usage
~3.6M/week
License
MIT
What’s fixed

No more ReferenceError: document is not defined or window is not defined in Node.js (also Bun and web workers): document is only used when it exists, and fetch and the retry timers fall back to globalThis when there is no window. Nothing changes in the browser: the same visibilitychange handling, parser, retries, callbacks and types.

Upstream refs #39 (opens in a new tab) #20 (opens in a new tab)

Note If you also depend on it directly, npm requires the override to match: do the aliased install first, then use "$@microsoft/fetch-event-source" as the override value. Details (opens in a new tab)

Install under the old name
npm i @microsoft/fetch-event-source@npm:@fitzyracing/fetch-event-source@^2.0.2
package.json overrides
"overrides": {
  "@microsoft/fetch-event-source": "npm:@fitzyracing/fetch-event-source@^2.0.2"
}

Go1 fork

Keep your imports (and fix it for dependencies that import the original too) with a replace in your go.mod, or switch your imports to the fork.

Gov3.0.2

github.com/fitzyracing1/cron/v3

Replaces github.com/robfig/cron/v3 (opens in a new tab)

Upstream last release
v3.0.1, Jan 2020
Upstream usage
imported by ~5.6k modules
License
MIT
What’s fixed

No more panic: runtime error: slice bounds out of range [:-1] when a spec is only a timezone prefix (cron.ParseStandard("TZ=0"), "CRON_TZ=Asia/Tokyo", ...): these now return an error. It is v3.0.1 plus this fix only; every spec that parsed before parses the same way.

Upstream refs #554 (opens in a new tab) #470 (opens in a new tab)

go.mod replace
replace github.com/robfig/cron/v3 => github.com/fitzyracing1/cron/v3 v3.0.2
Switch imports
go get github.com/fitzyracing1/cron/v3@v3.0.2

GitHub Actions2 forks

Same inputs, no outputs, same API calls. Change only the uses: line. For the strictest setup, pin the full commit SHA of the release instead of @v1.

GitHub Actionsv1.1.4

360 Bench Add Labels

fitzyracing1/action-add-labels@v1

Replaces actions-ecosystem/action-add-labels (opens in a new tab)

Upstream last release
v1.1.3, Aug 2021
Upstream usage
~15.6k dependent repos
License
Apache-2.0
What’s fixed

Declares using: node24 instead of node12, so runs no longer get the forced-runtime deprecation warning now that GitHub removed Node 20. Current @actions/core/@actions/github with no Node deprecation warnings. Follows GITHUB_API_URL, so it works on GitHub Enterprise Server.

Upstream refs #459 (opens in a new tab) #483 (opens in a new tab) Node 20 removal (GitHub changelog) (opens in a new tab)

workflow uses:
-      - uses: actions-ecosystem/action-add-labels@v1
+      - uses: fitzyracing1/action-add-labels@v1
GitHub Actionsv1.3.1

360 Bench Remove Labels

fitzyracing1/action-remove-labels@v1

Replaces actions-ecosystem/action-remove-labels (opens in a new tab)

Upstream last release
v1.3.0, Sep 2021
Upstream usage
~10.7k dependent repos
License
Apache-2.0
What’s fixed

Declares using: node24 instead of node12. Current @actions/core/@actions/github with no Node deprecation warnings.

Upstream refs #413 (opens in a new tab)

workflow uses:
-      - uses: actions-ecosystem/action-remove-labels@v1
+      - uses: fitzyracing1/action-remove-labels@v1

PyPI6 forks

The import name is unchanged, so your code stays the same. Uninstall the original first, then install the fork (the order matters, because both own the same files). pip can't swap a dependency for a differently named package; if another package pulls in the original, uv can drop it with an override.

PyPI0.25.2

fitzyracing-pydub

import name pydub

Replaces pydub (opens in a new tab)

Upstream last release
0.25.1, Mar 2021
Upstream usage
~17.8M/month
License
MIT
What’s fixed

No more ModuleNotFoundError: No module named 'pyaudioop' on from pydub import AudioSegment on Python 3.13+ (depends on audioop-lts there only, with a working Python 3 fallback). No SyntaxWarning: invalid escape sequence. Built from upstream master, so it also ships the maintainer's merged but unreleased fixes. Python 3.9+.

Upstream refs #725 (opens in a new tab) #839 (opens in a new tab) #863 (opens in a new tab) #867 (opens in a new tab) #801 (opens in a new tab)

pip (uninstall first)
pip uninstall -y pydub && pip install fitzyracing-pydub
uv override
[project]
dependencies = ["fitzyracing-pydub", "...the package that depends on pydub..."]

[tool.uv]
override-dependencies = ["pydub; sys_platform == 'never'"]
PyPI2.4.18

fitzyracing-fs

import name fs

Replaces fs (PyFilesystem2) (opens in a new tab)

Upstream last release
2.4.16, May 2022
Upstream usage
~1.5M/month
License
MIT
What’s fixed

import fs no longer fails with ModuleNotFoundError: No module named 'pkg_resources' on setuptools 82+: no pkg_resources or setuptools needed, and fs.* extensions and fs.opener plugins are still found. geturl(..., purpose="fs") returns osfs:///tmp/x on Python 3.14, as on earlier versions. Python 3.9+.

Upstream refs #577 (opens in a new tab) #597 (opens in a new tab)

pip (uninstall first)
pip uninstall -y fs && pip install fitzyracing-fs
uv override
[project]
dependencies = ["fitzyracing-fs", "...the package that depends on fs..."]

[tool.uv]
override-dependencies = ["fs; sys_platform == 'never'"]
PyPI0.2.3

fitzyracing-rank-bm25

import name rank_bm25

Replaces rank-bm25 (opens in a new tab)

Upstream last release
0.2.2, Feb 2022
Upstream usage
~8.7M/month
License
Apache-2.0
What’s fixed

BM25Okapi([]) (and BM25L, BM25Plus) raises a clear EmptyCorpusException instead of ZeroDivisionError: division by zero; it still subclasses ZeroDivisionError. BM25Okapi no longer gives a term in exactly half the documents an idf of 0 (so matching documents scored 0): it gets the same epsilon * average_idf floor as more common terms. That is the only score change, and no score goes down. The sdist builds again under PEP 517. Python 3.8+.

Upstream refs #36 (opens in a new tab) #39 (opens in a new tab) #43 (opens in a new tab) #56 (opens in a new tab)

pip (uninstall first)
pip uninstall -y rank-bm25 && pip install fitzyracing-rank-bm25
uv override
[project]
dependencies = ["fitzyracing-rank-bm25", "...the package that depends on rank-bm25..."]

[tool.uv]
override-dependencies = ["rank-bm25; sys_platform == 'never'"]
PyPI0.3.14

fitzyracing-bert-score

import name bert_score

Replaces bert-score (opens in a new tab)

Upstream last release
0.3.13, Feb 2023
Upstream usage
~420k/month
License
MIT
What’s fixed

No more OverflowError: int too big to convert with DeBERTa-v3 (including microsoft/deberta-xlarge-mnli) and other models whose tokenizer declares no maximum length, with fast tokenizers on transformers 4 and every time on transformers 5. These inputs are encoded without truncation, as the slow tokenizers did, so you get the same scores 0.3.13 gave with its default slow tokenizer on transformers 4. Also fixes evaluate's bertscore metric.

Upstream refs #205 (opens in a new tab) huggingface/evaluate#739 (opens in a new tab)

pip (uninstall first)
pip uninstall -y bert-score && pip install fitzyracing-bert-score
uv override
[project]
dependencies = ["fitzyracing-bert-score", "...the package that depends on bert-score..."]

[tool.uv]
override-dependencies = ["bert-score; sys_platform == 'never'"]
PyPI1.0.2

fitzyracing-rouge

import name rouge

Replaces rouge (opens in a new tab)

Upstream last release
1.0.1, Jul 2021
Upstream usage
~640k/month
License
Apache-2.0
What’s fixed

Unrelated texts no longer share a phantom empty word: whitespace-only sentence segments (the " " in "cat. ") were counted as an empty "" word, so "the cat. . dog" vs "a bird. . fish" scored rouge-1 f=0.25 instead of 0. All other inputs score exactly as in 1.0.1. ROUGE-L no longer hits RecursionError on long sentences (upstream PR #69, merged but never released).

Upstream refs #77 (opens in a new tab) #69 (opens in a new tab)

pip (uninstall first)
pip uninstall -y rouge && pip install fitzyracing-rouge
uv override
[project]
dependencies = ["fitzyracing-rouge", "...the package that depends on rouge..."]

[tool.uv]
override-dependencies = ["rouge; sys_platform == 'never'"]
PyPI0.0.6

fitzyracing-transformers-stream-generator

import name transformers_stream_generator

Replaces transformers-stream-generator (opens in a new tab)

Upstream last release
0.0.5, Mar 2024
Upstream usage
~360k/month
License
MIT
What’s fixed

Works on transformers 4.41+ and 5.x: no more ImportError: cannot import name 'BeamSearchScorer' (4.57) / 'DisjunctiveConstraint' (5.x) on import, and init_stream_support() no longer breaks every model.generate() call on 4.41 to 4.56. do_stream=True streams through transformers' public generate(streamer=...); beam search with streaming raises a clear ValueError. On transformers 4.26 to 4.40 the 0.0.5 code runs unchanged.

Upstream refs #15 (opens in a new tab)

pip (uninstall first)
pip uninstall -y transformers-stream-generator && pip install fitzyracing-transformers-stream-generator
uv override
[project]
dependencies = ["fitzyracing-transformers-stream-generator", "...the package that depends on transformers-stream-generator..."]

[tool.uv]
override-dependencies = ["transformers-stream-generator; sys_platform == 'never'"]

Fields marked with an asterisk are required.

1 About you

Only included in a public GitHub issue if you choose.

Your role

2 The project

Ecosystem

Links to upstream issues and error messages help the most.

Rough numbers are fine.

3 Interested in a partnership? (optional, pick any)

No fixed terms. Any equity or partnership terms are agreed project by project, after a conversation. Submitting is not a commitment by either side.

4 Send it

Private. Opens your email app with a message to Fitzyracing1@gmail.com, ready to send.

Public. Opens a pre-filled issue on fitzyracing1/360-bench that you can edit before submitting.

FAQ

Questions, answered.

Something else? Email Fitzyracing1@gmail.com or reach out on X at @fitzyracing1 (opens in a new tab).

What counts as “abandoned”?

A package or action that’s still widely used but hasn’t shipped in years, while real crash reports and fix PRs sit unmerged. There’s no magic cutoff date: what matters is a confirmed bug that hurts a lot of people and nobody left to merge the fix.

Will you take over my package name?

No. Forks publish under 360 Bench’s own names: @fitzyracing/* on npm, fitzyracing1/* on GitHub (Go modules and Actions) and fitzyracing-* on PyPI. Your package name, repository and registry entry stay yours. The original LICENSE, author and contributors are kept and credited.

What if the original project comes back?

Upstream first. If a maintainer comes back and ships the fix, the fork points people home, back to the original. 360 Bench is happy to hand the work back.

How does equity or a partnership work?

Case by case. There are no fixed terms and no standard numbers. Some maintainers just want the bug fixed; some want maintainership back after the revival; some are open to talking about sponsorship, paid support, or an equity position in exchange for reviving the project.

Whatever the shape, any equity or partnership terms are agreed project by project after a conversation. Submitting a project is not a commitment by either side.

What does it cost?

Nothing. The fixes are free and open source. Every fork keeps the original project’s license, and this index is MIT.

Do I have to change my code?

No. The API stays the same. On npm you can swap the fork in everywhere in your dependency tree with overrides; in Go, a replace line in go.mod; for Actions, change only the uses: line; on PyPI the import name is unchanged (uninstall the original first, then install the fork). Each project card has the exact snippet.