I would also have concerns signing a CLA that doesn't ensure the code will stay available under a free license, but I don't think that's a very common case.
So, no more CLAs for me. If they require a CLA (that lets them relicense my work) then I'll just never contribute to them.
https://www.schneier.com/blog/archives/2014/05/friday_squid_...
My main stance, for now, is dual licensing. Any commercial use requires a license. Any other use is free. Both are perpetual, come with source, and allow modifications. Core staff of paid developers do most work. OSS contributors get free licenses, name recognition, and possibly gifts (esp money) for big contributions. Any improvements to the software must be sent back to software owner that redistributes it under the same license. Contract requires this happen post acquisition. If company stops meaningful updates or wants to abandon it, product is released under full OSS license and that's in the contract. Company is also a non-profit, public benefit, or just private with certain structure that helps force this.
What do you think of such a setup? Again, main point is to force any user to be contributing to its development or maintenance while ensuring it stays available and has key FOSS benefits. Would you contribute to such a dual-licensed, carefully-setup piece of software?
Hint: They'll just rip out your code.
I know it may be shocking, but companies are going to do what they want. Replacing the code of even hundreds of contributors, given a bunch of full time engineers, is just not that big a deal.
This is even more true when, as here, the project almost entirely made by a small group of engineers (which is the case for a lot of projects).
Legal infrastructure will not solve these problems for single projects.
Additionally, even companies that have "good" CLA's find ways to be evil.
Doing things like threatening other companies over the "compilation copyright" they claim they own on the work, etc.
So yeah. Bottom line: CLA's, no CLA's, whatever, none of it is loophole or problem free, and there is no simple solution to these problems.
clearly, the issue is whether the contributions amount to a substantial enough part of the software that the ripping out isn't feasible.
Also, if you build up a community and then violate their trust, you lose the community. It's not a great strategy.
They didn't plan on it. Plans changed.
"clearly, the issue is whether the contributions amount to a substantial enough part of the software that the ripping out isn't feasible."
Having legally supervised tons of these processes for open source projects (most trying to relicense things after discovering their licenses were hurting their communities):
It's always feasible. Actual code is often not that important. Knowing what code to write is often important. (I know there are beautiful unique snowflakes who think otherwise ;p)
"Also, if you build up a community and then violate their trust, you lose the community. It's not a great strategy. "
Sure, but you assume "random people kibitzing on hacker news" represents their community.
For all you know, the actually community is entirely in favor!
Again, IME, having helped projects through these processes, there is often a huge difference in opinion between the people kibitzing on the sidelines and those who actually contributed meaningfully.
My experience is that people who contribute meaningfully are often more sympathetic and understanding of various situations. People who are kibitzing from the sidelines are often more ideological.
There are other factors, but a medieval CLA definitely didn't help their cause.