“Facebook has taken the name of my open source project ”
github.com
github.com
Let me guess how this will go
1. This issue will get traction on HN and maybe Twitter
2. Facebook engineers responsible will apologize, tell us they meant no harm
3. Facebook will change the name of the project and give it back to it's rightful owner, maybe even reinstate their Facebook account (although unlikely)
4. In 3-6 months the very same thing will happen and we'll go back to step 1
Hopefully at one point the engineers at Facebook (at least the ones that hang around HN) will realize what their employer does to the open source ecosystem and finally leave the company. This is not the first case, and will not be the last case of similar things happening. But when you're getting a large salary that is hard to get elsewhere, I guess it's really hard to leave.
Edit: HNers please! Don't fill the issue with any more comments as it's likely to be locked and not really achieve anything more than that (specifically looking at you " dsignr")
I don't think that's fair. If you didn't want to stoke internet drama, the thing to do would have been not to submit it to HN in the first place. Having submitted it, it's unsporting to put the onus on others to de-escalate, and singling out a particular user feels particularly distasteful.
Edit: also, comments like these stoke further escalation:
https://news.ycombinator.com/item?id=25103613
https://news.ycombinator.com/item?id=25103873
Please don't use HN for this, and please don't target people personally. That's leaving the path of curious conversation: https://news.ycombinator.com/newsguidelines.html
One of the most important phenomena in tech, especially at the large-scale system (technical) & open source (social) levels, is emergent behavior: your complex system will likely react in ways you'd never expect. The HN guidelines keep this in mind and are designed to inspire curiosity and humility.
However, the quoted moderator narrative appears to pin the blame on the OP; there's a non-zero affect of "you should have know better."
Should he? A ton of posts like these get squashed or ignored, some much less thoughtful ones get celebrated, and the attitude towards big companies like Facebook or Google has changed over the years. COVID has additionally made people behave in unexpected ways. It's really hard to predict the reaction of the crowd these days.
I have been deeply disappointed with the HN moderation in the past few months. At the very least, a "you should have known better" message should be delivered in private and not posted as conspicuously as this one.
"label-actions" is a name straight from the github nomenclature, and a (very) quick look at the code and syntax suggests this isn't a fork.
I could totally believe the inspiration came from the older project, but I could also believe it didn't, and I'm not so sure the OP should own the name.
Short answer, it was copied from author then changed. Commit here: https://github.com/facebook/react-native/commit/f9c2157141b8...
Apparently one of the Facebook developers reimplemented everything from scratch in his own account and then changed config files in the React Native repo to use his own implementation.
If it was a clean-room implementation then there's nothing wrong with that. Apart from reusing the name, but that's another discussion.
Please see Hector’s response: https://github.com/facebook/react-native/issues/30395#issuec...
Except potentially trademark infringement (common law tradmark rights are acquired automatically - but the name is pretty generic), and potentially still copyright infringement if Oracle wins Oracle v. Google and there is enough creativity in the sequence structure and organization of the api for it to be subject to copyright/not fair use...
I was wondering about that, because there are obviously many open source projects out there who share a name, some owned by companies, some by individuals. Here's a Google GitHub Page that talks about OSS trademarking in general: https://google.github.io/opencasebook/trademarks/#common-law...
> Primarily, an unregistered mark must be: (1) used in commerce, and (2) used prior to the alleged trademark infringement. It may be counterintuitive that the “use in commerce” requirement does not necessarily mean a profitable or profit-seeking use. In fact, as the following case clarifies, the term “use in commerce” is used as a reference to Congress’s authority to regulate trademarks under the U.S. Constitution’s Commerce Clause rather than an intent to limit trademarks to profit-making activity. Where a developer released open source software under the name Coolmail, the court rejected the argument that the lack of direct profit from releasing software under the GNU General Public License rendered the original Coolmail name unenforceable as a trademark, holding that distributing software for end-users over the Internet satisfies the “use in commerce” requirement.
Does facebook habitually copy stuff without attribution?
Github issues is itself a forum and cross-linking forums like this, especially with the explicit goal of mutual pile-on amplification causes problems. The solution is to not make such submissions to HN (and to flag the ones that appear).
* taking the name of an MIT licensed thing which is entirely not covered by the License and I’d at least consider that bad form.
* A breach of the MIT license by the Facebook engineer - specifically removing the license and passing it off as their own work.
So the author is not - as you seem to imply - complaining about someone using their software under the MIT license.
How different does one project's code have to be from another similar project before you can claim copyright and slap your own license on it?
If a dev simply copied the entirety of someone's code and simply renamed some variables, could they claim it's their own original work (without worry of legal recourse)? I'd figure not, in which case, how much of a difference is different enough?
That's why reimplementations of license-encumbered software have to be careful to have one team study the software that is to be reimplemented and describe what it does and another teams reads this specification and implements the substitute without ever looking at the original software.
This would most definitely not be enough. That would basically make all licenses useless - commercial and noncommercial alike. The MIT license is no different than any other license in that regard.
In case of the MIT license, whenever I copy any code (files or parts), I always place a comment right next to the section, pointing to the source of the copy and containing the license of the code/copyright marker. Honestly, what’s the cost? My ego doesn’t take a hit from admitting that I found and adapted something useful. The possible uses of the code are unaffected. License situation is clarified for audits. The original author gets credit for their work. There’s only upsides.
Regardless of the validity of this claim, the past decade of watching Big Tech Companies make tons of money on the back of Free Software has pushed me away from the X/MIT-style licenses and back to the (A)GPLv3. For a while I was swayed by the arguments that they're "more free" due to fewer individual restrictions, but I've since realized how many definitions of the word "free" we're operating under and that I have a different one than many of the MIT License advocates. I would prefer a smaller user base comprised of people each willing to make a small sacrifice (GPL requirements) for the overall benefit of collectively-singular Humanity.
This is important: one can build a service around an open source project and make money without paying or asking for a specific license. People doing this still need to give the code to their users if they request it with the same rights, and will be incentivized to contribute back upstream if they need to adapt the code to provide their service because it is less costly than maintaining an ever diverging fork, which is great! Do sell commercial services around my GPL code!
A commercial license is only needed to allow building proprietary software based on the GPL code, but it is only possible to provide one if the project has no other contributors than the one selling the commercial license, or those contributors sign a CLA.
MongoDB got raked through the coals when they tried making a license with this purpose. They ended up having to backtrack [1]. I don't understand people's desire to give these billion-dollar corporations everything for free.
[1] https://hub.packtpub.com/mongodb-withdraws-controversial-ser...
Edit: Instead of downvoting this, how about actually explaining why apparently this is such a terrible idea.
I don't believe this at all. Data to back your statement?
Yeah, that's right :)
It's a common, recurring statement and I'm sure people have good reasons to believe it. I can guess what that thinking might be, but there's no substitute for asking.
The list is not at all up to date, and very incomplete, but it's better than nothing. You can see that there's quite a few well-known infrastructure projects there.
Is it? What hat are you pulling this number from?
You don't have to search for very long before you realize how much government-funded research and code has improved our life. Department of Energy labs, National Science Foundation, DARPA, Apollo Space Program, Human Genome Project and more are all publicly funded and responsible for some of the biggest "real breakthroughs" in human history, and that's just projects from the US.
Choosing AGPL is a great way to isolate yourself from any collaboration with that community
Edit: I love political downvotes
Btw this topic is inherently political, to treat it differently means to have no wish for a fruitful discussion about it.
This is interesting. GitHub has an Actions marketplace but it doesn't seem to be namespaced like the rest of GH is. This sets up a potential for a naming conflict where first-to-register wins, much like Internet domain name capture in the early days before registrations could be challenged by trademark holders.
For the time being, it looks like developers should come up with creative names for their Marketplace add-ons to help avoid conflicts. With sufficient creativity, these may be subject to trademark protection; and creators might be able to leverage laws including DMCA to prevent such squatting.
OTOH, "label-actions" is pretty generic and IMO it was only a matter of time before someone registered it in the Marketplace -- if not by Facebook, then by someone else.
I would assume that the dev simply had a similar idea and put it on GitHub actions before you did?
Edit: Actually looking at your repo it hasn't seen any update since 2019, GitHub actions were released about a month later. Why did you expect this developer to hold off from publishing if you hadn't done it already?
Use a different name than the project you're taking inspiration from. I would have thought that was open source 101.
On top of that, GitHub Actions have been up since November 2019 and as such, OP had around 11 months to register his project. The name being generic it's only expected that someone ended up taking it.
Now the only thing that makes people all up in arms is that FB is the employer of the dev that did this. Since we all hate Facebook, we support the underdog in this. Repost the exact same post while removing the name of the company and it would not even be close to trending.
There are things that are wrong with how these big corporation operate, but this is not one of them. This is more akin to a small shop called "Play Store" not registering a domain name and then making a post on HN when Google registers it for Android.
There is a subset of the open source community that seems to default to the MIT license and then act surprised when their project is used in a way that is not what they had in mind.
Here's how I'd guess this entire process went:
1. FB appsec: "wtf are you doing referencing this guy's Github Action in our codebase? We don't own that and if he chooses to change something we get hacked"
2. FB employee: "okay fine I'll fix it"
3. FB employee: creates official version for FB to use, that can't be mutated outside of FB oversight
(And to be clear: I agree that FB at least socially behaves wrong, if there is a legal mechanisms however is questionable)
(Posted in another thread on same discussion).
You can go and see the original repo here: https://github.com/dessant/label-actions And the "copied" one here: https://github.com/hramos/label-actions
I didn't look too much at the code, but at first glance it doesn't seem copied. The API might be the same or similar, but that's a different discussion, as is for taking the same name.
At the same time it feels important on its own. I’d be interested in a follow up post that would focus on just that.
But also agree it was offtopic for the Github issue. Keep that focused on the naming and IP issue.
Aside from just criticizing the actions of Facebook here it seems strange to me that GitHub so famously (due to its 'Fork' button imo) has a "user/repository"-style namespace for code but that their "Marketplace" has a flat namespace of only your app[0] name. According to its front page they are "tools to improve your workflow", but I just feel out of the loop and honestly slightly confused about what this is or why I would want to use it. I guess I'm officially old now. Oh well, back to neovim :)
[0] https://docs.github.com/en/free-pro-team@latest/developers/g...
It's kind of a weird move to open the issue at facebook/react-native rather than hramos/label-actions.
https://github.com/facebook/react-native/commit/f9c2157141b8...
It seems to me that the connection to facebook/react-native is tenous at best. Even the connection to Facebook at all seems pretty weak; yes the engineer works at Facebook, but if this had been an official Facebook OSS project that they wanted to publish themselves, surely they would have done so under the facebook org?
It looks to me like this is just something an engineer at Facebook did as a side project.
Facebook Engineer works on something and then uses it on a Facebook project. To me I would take that as something that came up during Facebook meetings and that Engineer actioned it. If they talked and planned a robbery during work time and did the robbery on a weekend and Facebook got all the goodies from the robbery. Would that not implicate Facebook in the robbery?
Yes, they would be implicated to a degree, but it would be a stretch to say that Facebook robbed something, rather than saying that a few Facebook engineers robbed something. Also, in what sense did Facebook "[get] all the goodies from the robbery"? The action on Marketplace doesn't mention Facebook at all, so other than using the action (which doesn't require anyone to publish it to Marketplace), which goodies exactly did Facebook get?
Different degrees, same principle as you know.
> Yes, they would be implicated to a degree, but it would be a stretch to say that Facebook robbed something, rather than saying that a few Facebook engineers robbed something.
If that happened. Facebook as an entity would be investigated.
> The action on Marketplace doesn't mention Facebook at all, so other than using the action (which doesn't require anyone to publish it to Marketplace), which goodies exactly did Facebook get?
That would be having it work they wanted it to work.
That's a consequence of the engineer implementing the same idea, not of publishing it to Marketplace.
If the developer worked at a random unknown company nobody would be paying attention to this. Perhaps the original author wouldn’t have posted his (rightful) claim.
https://github.com/facebook/react-native/commit/f9c2157141b8...
You’re totally in your right to demand license compliance of course. I’m just saying that is hard to blame it as a concerted effort by several individuals. Doesn’t seem to be the case here.
Note that the repo name also stays the same when a github project is forked.
True, github repos are namespaced and github marketplace isn’t. Perhaps this is the core of the issue.
Then again, this looks like an issue of github marketplace. In this light FB’s actions seem unrelated.
When you work for a company, they own your code and anything and everything you do, so it doesn't matter. Facebook is responsible for it.
Those clauses exist to give the upper hand to companies when it comes to claiming rights over the creation of potentially competing IP. Not to become liable of everything an individual does. That would be nuts.
Depends on a contract. I worked in once place that specifically said every line of code you write during employment belongs to the company. Even on own PC, during non-working hours on bank holiday during personal holiday. One guy ended up in troubles after the contributed a bug fix to Eclipse STS, which we were using at work.
California's law only covers things which are not related to the company's current or future anticipated business. For a company like Facebook or Google that covers so much ground that the law may as well not exist.
>https://law.justia.com/codes/california/2011/lab/division-3/...
It says:
>(a) Any provision in an employment agreement which provides that an employee shall assign, or offer to assign, any of his or her rights in an invention to his or her employer shall not apply to an invention that the employee developed entirely on his or her own time without using the employer s equipment, supplies, facilities, or trade secret information except for those inventions that either:
> (1) Relate at the time of conception or reduction to practice of the invention to the employer s business, or actual or demonstrably anticipated research or development of the employer; or
Here's why I think so: commits coming from Facebook in facebook and facebook-experimental github orgs have additional metadata fields like "Reviewed By:", "Differential Revision:", "fbshipit-source-id:": https://github.com/facebook/react-native/commit/864cdf338369...
Commits in hramos/label-actions repo don't follow this pattern: https://github.com/hramos/label-actions/commit/28c4884562c2a...
If you look at the Facebook React Native project, you can see the commit where they switched from the OP's tool to their own version.
> I haven't seen a reach out from you so far but my apologies if I missed it.
Sounds like the GitHub issue OP didn't try to contact the engineer directly first.. might've been an easier way to resolve this?
lol, this is the same bot being discussed in the post right?
There is a clear need for regulatory action to prevent further abuse from market leaders.
This feels like using HN to brigade an individual at best, and people might accept it because they opened the issue against Facebook and not the individual.
> The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software.
Where do you see the original copyright statement in this obvious derivative?
Edit: The FB developer has since replied and has agreed to attribution. I guess this complaint is resolved.
I think it's clear their intent was to reproduce the tool at Facebook and then cast a shadow over the old tool, discouraging its use.
To me, that feels malicious.
This other project doesn't even seem to be registered as a GitHub App. I think we must have extremely different definitions of the word "malice".
Jesus I'm going to be afraid to call anything straightforward from now on in fear of invoking the wrath of "the community".
So if you wanted "MIT unless you're FANG, in which case you get an even more liberal license", you could do that with dual licensing. On the other hand if you want "MIT unless you're FANG, in which case all rights reserved" you're going to have to come up with some custom license.
Doing both of these when there are still some unknowns can cause unnecessary harm.
It’s not like this is some widely useful tool, it’s just donated additional GitHub sharecropper functionality. Why is it that important that he receive credit for doing free work for Microsoft to improve their bug tracker SaaS?
I think this author is trying to make the MIT license do something it was not designed to do and is not generally understood to do. I think he chose the wrong license if he wanted his work to legally require his permission to be copied.
I'm not even sure what parts of the license he thinks have been broken. (The idea that it's even possible to violate terms of the MIT license is I admit somewhat new to me).
Elsewhere in the thread, commenters suggest the violated clause is: "The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software."
But I have never before seen it suggested that the MIT License is in fact "viral" like the GPL, that it requires derivative works to also be licensed MIT. The license is usually understood as quite the opposite, and often used intentionally because of that. If that's what you wanted, you chose wrong with MIT license.
Generally when I personally see code with an MIT License, I understand that I am able to copy whatever I want from that project to my own projects, I thought that was the point of it. Do y'all not do the same?
Copying ideas or a name does not seem to me to be "a copy or substantial portion of the Software"; but even aside from the particular license terms, the worse part for this argument is they are generally not protected by copyright at all.
> has reimplemented the app with almost the same features and configuration syntax using GitHub actions
Reimplementation? So nobody is alleging actual code got copied? "Features" are not generally even copyrightable at all, it doesn't matter what license you use.
Whether "configuration syntax" is copyrightable or not... I guess the author is taking the Oracle side in Google v. Oracle, on copyright protection of APIs. But if you believed your "configuration syntax" was copyrightable and you wanted to require people to ask your permission before copying it -- you really ought not to release it under an MIT License.
Even apart from licensing, in general I don't think "features" or "configuration syntax" are or ought to be protected by copyright at all. I'm sorry, yes, people can copy them from you.
If the David and Goliath roles were reversed, I have a hard time believing a large corporation alleging someone had violated copyright for cloning "features and configuration syntax" -- for something released under the MIT license in the first place -- would get any sympathy at all. We (software devs) have generally supported the right to clone software, for good reason.
Re-using the name is certainly rude. I am not sure if it is actionable. The rest of it... it's not even about open source, its about that cloning software has always been allowed (although Oracle v. Google may be about to change that, which will be a disaster).
You are allowed to take and copy it to your project. You just need to retain the notice along with it - IANAL but I usually just copy the licence in a code comment along with the copied section (or file). I usually include a pointer to the original source for audit purposes. That doesn't make my project MIT licensed, but that part of the code that I lifted without substantial modification remains MIT licensed, even if I make my project closed source commercial. There's no way around that - I cannot claim it as my own since I have not written it. Same for public domain code.
Usually these kind of scenarios boil down to the fact that a lot of corporate devs (even ones that participate in open source) do not really understand open source from a community perspective. They understand it from a corporate perspective and it's this that causes some rub. Where big, multi-million dollar companies think, "A fork is a fork and that's part of open source ethos!" they lack the relative introspection to see how Amazon's fork is relatively different from kodah's, especially if you put a business case behind it. This lack of mindfulness largely gets perceived as an affront on the open source community and it's values.
This was a GitHub issue bot, I doubt this is an instance of Facebook trying to strong-arm competition. It's more likely that Facebook had a need for this, this engineer wanted the code in GitHub actions for some reason and quickly wrote it. Seems reasonable and fully within his rights working in FOSS. What was missed by corporate governance is attribution for where the code was inspired by. Sure, you likely can't get in legal trouble here, but ethics say you should document where your inspiration came from.
Launching a new product using the extremely unique name of an existing open source project this is not.
Shame on Facebook, again!
I really like MIT, but the idea a billion dollar company can take my project and actually impede me is too much.
@facebook facebook locked and limited conversation to collaborators 3 minutes ago
ruh roh..