New GitHub Terms of Service
github.com
github.com
Solely to allow us to provide the Service and to host
the Content you upload to the Website without violating
any rights you have in it, you grant GitHub and our
successors a nonexclusive, worldwide, transferable,
fully-paid and royalty-free license to use, reproduce,
display, modify, adapt, distribute, and perform the
Content in connection with rendering the Website and
providing the Service.
This appears to let Github take any software repository hosted there, and use it under this license to provide features to the github website. So they could take AGPL licensed software and modify and use it without complying with the source disclosure requirements of the AGPL because they have been provided this other more permissive license. It's essentially a free BSD license to everything on Github, for Github alone.Also, "the Service" is defined as any product or service Github provides, so this could be expanded into any business.
The "transferable" in that also might let Gihub contract with some other company to provide part of "the Service" -- perhaps in an entirely unrelated business than the current Github website, and transfer the license to any free software they like to that other company.
I don't know if it was intended to be used this way, and I am not a lawyer so I could be misinterpeting it, but I will not be hosting any software on Github if they adopt this TOS, without consulting a lawyer.
(The current TOS has nothing like this in it.)
Virtually every website that allows users uploads had a provision like this so that you cannot upload a copyrighted work and then turn around and sue them for infringement.
Here's what bitbucket says:
>Subject to the terms of this Agreement, you hereby grant to Atlassian a non-exclusive, worldwide, royalty-free right to (a) collect, use, copy, store, transmit, modify and create derivative works of Your Data, in each case solely to the extent necessary to provide the applicable Hosted Service to you and (b) for Hosted Services that enable you to share Your Data or interact with other people....
Only "in connection with rendering the Website and providing the Service", i.e. they can display it in the web UI and syntax highlight it and whatnot.
The idea that they'd want to save a few thousand bucks by stealing someone's proprietary code to run Github.com itself is simply silly - it'd risk their reportedly multi-billion dollar valuation.
Isn't there a (theoretical) concern for someone hosting GPL'd frameworks/servers/etc. on GitHub, that GitHub might want to use to replace or build their services?
This is the wording that concerns me most, because the Service is defined as:
> The “Service” refers to the applications, software, products, and services provided by GitHub.
Thus, GitHub could legally use this to use any software hosted by them, so long as it entered their stack at some point.
Contrived example:
They could use a modified Linux kernel at the bottom of their stack, and refuse to give anyone access to the source. Breaching the AGPL, but it doesn't apply. Simply because the Linux kernel is mirrored on GitHub.
Sure, if they wanted to risk billions of dollars of valuation for no good reason. After such a thing was discovered, how long do you think folks would continue hosting their private proprietary projects there?
Doesn't change the fact that the wording is troubling.
"This license does not grant GitHub the right to sell your Content or otherwise distribute it outside of our Service."
And "Service" is defined as "anything github is doing", so distribution inside the Service could involve any number of entities.
> The “Service” refers to the applications, software, products, and services provided by GitHub.
If you focus the sentence on the "provided by" phrasing, then anything they take using their new TOS, would have to somehow be involved in directly forwarding something on to customers, as it needs to provide something. So they couldn't use it for anything internal only, such as say, a spreadsheet program, because the user doesn't directly benefit. They could however use a code auditing tool, as they could claim they are providing a better product to the public by auditing. It's a little bit grey, but there are limits.
Not to say that I agree with the new TOS, as I have some serious doubts about using it, and it does make me consider removing some of my projects from GitHub, though they are working on the wording still. We'll see.
We've gotten a few questions about this wording, and we'll revise it to clear up confusion. Thanks for the feedback.
We have absolutely no intention of taking any of the code people store with us or using it for our own purposes. As we said, this is solely to allow us to host your content without violating your rights.
> Researchers may scrape public, non-personal information from GitHub for academic research purposes, only if any publications resulting from that research are open access.
> Archivists may scrape GitHub for public data for archival purposes.
> It is prohibited to scrape GitHub for spamming purposes, including for the purposes of selling GitHub users' personal information, such as to recruiters, headhunters, and job boards.
How about a level of indirection?
Alice the Archivist scrapes GitHub and compiles a compendium of names / emails. She then publishes this information in bulk for anybody who'd like to use. Alice's cousin Roger the Recruiter downloads the archive and does what he does best. Alice isn't selling anything, she's just providing the information bundled up. Roger isn't getting it from GitHub, he's getting it from the public feed (say via Bitorrent or a public data set posted somewhere).
Joke aside: Working in a library I guess ?
Like 4chan has archives of posts, same concept I think.
It's completely unenforceable, and there are millions of loopholes like the one you just said that will let them skate around the restrictions both legally and in action.
This seems like an addition because of the "GeekedIn leak"[0] of a bunch of scraped GitHub data from Nov of last year, but I just don't get what it's trying to do. Bad actors are just going to ignore it like normal (or find loopholes) and good actors weren't doing this in the first place.
Personally, I wish they left out the "what you can do with the data" and focused their ToS only on the "how you are allowed to scrape it". Give solid limits on amounts and speeds and other various aspects of the scraping, make them restrictive enough to prevent a service like that from working, then provide a point of contact so that an "archivist" can be allowed to do more on a case-by-case basis.
[0]https://www.troyhunt.com/8-million-github-profiles-were-leak...
I've seen many very cool, creative, and useful tools pop up on top of GitHub and sites like it, and I just fear that changes like this will have the (perhaps unintended) side effect of shutting them down.
Things like CommitPrint [https://commitprint.com/], or Commits.io [https://commits.io/] come to mind.
GitHub has an API. Use of an API is not 'scraping'. The act of scraping involves pulling full HTML pages and parsing out data. Because scraping and API usage are different, there are different ToS for each.
I suggest that useful tools are sticking to the API.
If Alice's archive gets no traffic, and Roger's recruiting firm does 40% of their business using Alice's data, and Alice and Roger get dinner together every week, Alice seems to be doing something wrong.
Even on his own, Roger is still scraping Github. The defense "It wasn't me, it was the Python program that was in the wrong!" is just as ludicrous as trying to hide behind the fact that Alice's archive is scraping the site itself. They're putting limitations on the information, not limitations on how computers are allowed to talk to each other.
Sure, in hindsight, it'll all be obvious..
They're not trying to keep you from scraping, they're trying to keep you from using the data in ways that would be distasteful to their users.
There is, unfortunately, precedent. So GitHub can say, "Only scrape if you do x, y, z."
But... You can't access the TOS without first requesting the data.
Consider it.
You cannot request and view data but in a way acceptable to the TOS.
You cannot view the TOS without first requesting and viewing the data.
> GitHub employees do not access private repositories unless required to for security or maintenance, or for support reasons, with the consent of the repository owner. [...] If we have reason to believe the contents of a private repository are in violation of the law or of these Terms, we have the right to remove them.
So, basically, GitHub says that there's a possibility for them to remove a private repo because of a hunch that it violates ToS, without actually looking at it to make sure?
If they wanted to give themselves free reign to remove repos they would say something like "we have the right to remove private repos at any time, for any reason, at our sole discretion."
That is much needed. Does anyone know what the new default contributor license is?
It makes me so unreasonably happy to see that added to the terms of GitHub..
I'm not a lawyer but, I wonder if your terms of service can passively force a licensing agreement like this and still hold legal muster. We're talking about much more than simply licensing GitHub to display your code if you don't license it otherwise. Here GitHub is essentially causing you to enter into agreements with unrelated third parties on an opt out basis. Unless there are warnings about what you are about to do, seems like it could cause problems for both the licensor and licensee.
Some say a default license is needed, but there is a default license position: which is you are not licensed to use the code unless granted permission to do. When I don't select a license, it seems more natural for GitHub to simply block forking and repo access to anyone other than the owner and allowing only the unlicensed code to be displayed per an agreement with GitHub. That only requires that the GitHub user and GitHub have an agreement rather than the GitHub user and an unrelated third party. Or explicitly force a license choice on repo creation: pick one or upload something. That too, would get past this without forcing a license which, to me at least, looks problematic.
One of the benefits in addition to being able to read fossil source code and being able change/style the web interface however I want is that I don't have to worry about staying up to date on Terms of Service changes I really have no say in.
Edit: failed to mention fossil can import/export to/from a git repository[3]
[1] 2-clause BSD license: https://www.fossil-scm.org/xfer/artifact/f99187d1905883d3
[2] cgi script: http://fossil-scm.org/xfer/doc/trunk/www/server.wiki#cgi
[3] import/export git: http://fossil-scm.org/xfer/doc/trunk/www/inout.wiki
Gogs/Gitea are great for individuals as a single drop in file, but it is a hosted service.
If you're willing to drop git and use fossil, it comes with the benefit of pretty much everything any hosted git solution has, as well as not needing to run a service. It has ticketing and wiki inbuilt. The only thing a hosted solution might supply is CI/CD.
If you're going well with fossil, with it's ability to integrate with git repos, I don't think you're going to find anything else that feels as good.
I like being able to have complete control over the web interface. I like that it's lightweight, unlike say Gitlab, yet provides a full website. I like that the bug tracker is part of the repo rather than part of a company's proprietary infrastructure.
The biggest advantage, by far, is that it's not Git. I agree that Git is good for a lot of projects. It's an unnecessarily complicated beast for small projects with a couple of collaborators, neither of whom are willing to spend hours dealing with weird commands to handle a repo that got messed up for unknown reasons. Fossil, unlike Git, is version control that others are willing to use.
You actually can delete a password using shunning, but it's not a regular part of the development process. (I only mention that because many potential users are scared off because they misinterpret not being able to change history.)
If you release a side project or a startup and you can't afford a lawyer like GitHub probably does, what are the solutions?
For ToS specifically, termsfeed.com is pretty good.
I've seen several SaaS using iubenda.com for ToS and Privacy Policy. Do you have an opinion on this service?
Of course you should actually abide by your own policies. You can even search for common phrases[0] to see how many templates are out there.
0 - https://www.google.com/search?q="We+use+regular+Malware+Scan...
Legal: https://github.com/catalyzeio/legal Policies/Compliance: https://github.com/catalyzeio/policies
I don't want to take my personal github credentials to work, and my employer doesn't use paid github services.
The effect is that if when I'm at work I come across a bug in a project hosted on github, I probably won't report it.
https://help.github.com/articles/github-terms-of-service-dra...
eg project repo page
Using the GitHub API (as intended) wouldn't be scraping.
Here is a diff:
https://github.com/lgommans/terms-of-services/commit/32e5aef...
As you can see from that diff, comparing the documents in diff form was just confusing, so we didn't try.
We hope to provide future updates in PRs with a diff.