Incidents caused by unappreciated OSS maintainers or underfunded OSS projects
github.com
github.com
If this was a commercial vendor that went out of business, we wouldn't be discussing it. It would be a failure in the procurement process that didn't detect (and risk manage) the supplier's insolvency.
The same due diligence should apply to open source projects. The benefit of open source is that it makes code escrow (and follow-on maintenance) a lot easier.
If you rely on something you should try to ensure that it survives and trives. Especially if you are raking in money as a result of using that something.
Due diligence is a measure of the size of the risk. Eventually, the risk will outweigh the cost of checking. Some firms will track the cost vs risk and act based on that, others wait until it explodes.
e.g. The company is using software stack "D", and is launching a new business. They have no money. If they get sued, they close up shop and move on.
They have a successful funding round and get an injection of $100m. This hits the news, and they are immediately hit with a lawsuit alleging copyright infringement through their use of "D" (GPLv3 perhaps?).
Somewhere between launch and funding there was a point where the cost of diligence (detecting the license problem) would have dropped below the risk adjusted settlement cost (remediation + lawyers fees + lost sales), hopefully allowing the lawsuit to be avoided.
Then again, it might never have crossed below. Knowing that line is an acceptance of the risk. That's also perfectly valid.
A more apt comparison would be if a vendor didn't want to support an obsolete product anymore and so they remotely rig it to intentionally take down their client's business portal when they try to update instead of just not being available anymore.
(And of course, that's the analogy, many of the items on this list don't hold up to it, as is the case with all analogies)
Those are all risks associated with using a vendor, regardless of whether or not you are paying for the software. If your business relies on it, it should manage those risks (insurance, escrow, business processes, paying for support, etc).
The project disappearing/bankruptcy is only the easiest to point to.
Open source is fine and using it is great. I trust many dev teams, but not all. Many languages (JS, Python, Rust, Go) have a super extensible, developer-friendly library of open source components for you to reuse, but this model also encourages relying on these tiny libraries often written by volunteers with no time to prune and maintain their own dependency tree.
Personally, I try to just grab the code I need from small projects (with a link back to the library of origin) rather than add the dependency. This makes license management more difficult (as the source code usually comes with license terms) but packages like left-pad are better off in some kind of helper folder than in the dependency graph.
I tried reasoning with the founder about how, as a build engineer, I find that highly disturbing, but they don't see any trouble with that.
Wouldn't recommend, for that reason alone. Tidelift may be a better option here.
Most libraries rarely need the kind of maintenance work that justifies paying people full-time on them. It's often the case that a library is written and then done - future development may be maintenance type work (supporting newer versions of whatever), or increased coverage of the library's use cases. For all this, Tidelift and Paydevs are a good fit.
But most projects that really need continuous chunks of money are going to be end user apps, adapters/sdks (i lied, those are libraries, but they're more visible and often against a moving target), web services, infra services, etc.
For those, I recommend taking more ownership of the finance and setting up sponsorships via Open Collective (https://opencollective.com/)
Source: I run my own open collectives, have corporate sponsorships through there, I've helped several OSS projects monetize, created my own successful open source startup, etc.
If you're an open source maintainer and need advice on this, feel free to email me and AMA (see profile)
People too antisocial to live in our neighborhood... don't. There would have to be a solution to those people. They probably don't drag us down too much so they might not matter, either WRT neighborhoods OR source code.
I don't mow my lawn because my neighbor sends me micropayments for it or I have some elaborate and weird "HOA"-like contractual obligation to mow my lawn, I just mow it because that's what homeowners do around here and I moved here to fit in with them so obviously I don't mind, its good exercise at worst and almost hobby recreation when I'm planting flowers in the springtime. Likewise I do a pitiful amount of FOSS stuff but more than nothing, because that's what 'my people', and the people I like to hand out with, do.
Don't have a day job doing ONLY corporate work or ONLY FOSS work, do some of each. And don't expect a paycheck for the volunteer work. When I help pack boxes of food for hungry people at church I don't expect much of a paycheck either, but its just something I do with some of my spare time.
The hidden assumption is always that if paid corporates had not relied on free FOSS their paid for code would be higher quality... Naah they'd probably get powned twice as much its just they wouldn't be able to outsource the responsibility for bad code to some other organization. Fundamentally at the end of the day every org in the link "made more money" because of FOSS than they would have lost if they wrote inferior non-FOSS copycats of the FOSS code.
Some FOSS projects will require people working on them full-time.
I think a better, long-term approach would be to make FOSS work sustainable.
I'll take it if someone makes it free, of course. but I'll be damned if I'm going to pay some insignificant tax to support it!!
If someone depends on your lawn mowing for their business, and they require it to be on a high level of quality I would expect no less of a payment for that
And everyone who sold their home for a profit did.
And everyone who is now making their home available as a traditional rental is.
And everyone who provides their home as a short-term (vrbo, airbnb, etc) rental is.
Nah, they sold you land, a commodity. They don't care if you tear the house down to put in a parking lot (though your city probably does).
> And everyone who sold their home for a profit did.
> And everyone who is now making their home available as a traditional rental is.
> And everyone who provides their home as a short-term (vrbo, airbnb, etc) rental is.
And those people are the ones who own said lawn.
Imagine if Walmart/Amazon/Google decided to open a shop on your lawn without compensating you.
That is not how developers work. They very much do care if you tear down your house and put in a parking lot, because unless you bought the last lot in the development, they still have more land in the area to sell, and your actions could decrease the value of that land.
It might look like some smaller packages are just toys, but people take them seriously.
Mowing the lawn as often as most suburban americans do is a pretty awful thing for a breadbasket of environmental reasons (pollution, noise, soil quality, biodiversity, …). And yet.
Also, the american lawn really sucks. That's kind of another topic, but it's still a worthwhile plug to this excellent video: https://www.youtube.com/watch?v=6tfao7CZ0xQ
The other hidden assumption is around building your own or selecting existing tools. We used to call that 'Build or Buy', but there's no demand for proprietary tools in a landscape full of Free ones. There's often not even demand for new Free tools in a landscape chock full of mediocre options. So the choice has been taken away and replaced with a false one. It's reinvent the wheel or use unsupported software and never ever complain about it where anyone can quote you on it. Or do without, which puts you at a competitive disadvantage with the rest of your industry.
But you might get jaded if VPs of fortune 500 companies were turning up for the free food.
- "PayDevs is "Monetization as a Service" for open source libraries. At paydevs.com, we provide closed registries for OSS maintainers to publish their compiled software libraries (or built packages). We restrict access to these registries and collect a contribution from private and corporate users to fill a money pool that is distributed each month based on the number of users a library has."
Gamification of contributions… shoehorning projects into other projects that get funding.
Forks just to try to rake in contributions.
Just free avoids a lot of problems, but certainly isn’t problem free.
So right now I mostly fund smaller projects because it feels they need it more, but at the same time I think I should also consider how important some piece of software is to me, or how much I depend on it, which gets really hard as soon as you don't just include "visible" software, but also libraries. I guess I'd have a really bad time without a jpeg library, for example. But that leads into your point about rewarding contributors. Ideally, every project that receives donations will fairly redistribute a share of it to every contributor and library they depend on, but that seems absolutely impractical to get right, especially for larger projects.
Also, should you take the complexity of a project into account? Not to diminish the work of the folks behind eg libjpeg-turbo, but a jpeg encoder/decoder isn't exactly rocket science, so should they receive less than for example libx264?
So yeah, I think this is a fairly deep topic that you can put a lot of thought into, and even get a bit philosophical about. Interested to hear other people's approach to this.
Examples: Python Software Foundation, Haskell Foundation
In practice this seems to work well.
On the other hand I know more incidents caused by overfunded corporate OSS developers who have taken over projects and justify their existence by manically rewriting the code base for no reason.
Many of these incidents are covered up. Contradicting the corporate politicians is dangerous, because often they have installed dozens of other developers who always agree with them and are ready to libel dissenters.
OSS funding is a hard problem. OSS was best when it wasn't funded at all.
Extraordinary claims require extraordinary evidence. This vaguely conspiratorial comment about things "they" have done is a problem.
“Best” is subjective yet I don’t disagree. But what you don’t mention, which I think is important to mention here, is the proliferation of OSS that other vital, closed source software (often monetized) depends upon. OSS has always powered vital software, I’m just making the point that it’s increasingly, alarmingly common.
“Alarming” because the OSS developers often feel they should be compensated if their work is monetized and/or powers other vital software. There is a license for this, but it’s difficulty and complicated to enforce. And it’s not surprising for someone to license their work as “do whatever you want with it” at first, only to change their mind later when they see it used in FAANG products. But then it’s too late, and bitterness and anger creep in.
Take the anger and bitterness of a generation+ of OSS developers and you have our current predicament :(
Or you can fork the project and ignore the politics altogether; FLOSS licenses will always protect your right to do this. Open source is a do-ocracy.
The closest example I can think of is firefox seemingly getting worse every version since they removed native extensions.
Some of them could've been caused by underfunding, if a maintainer would have preferred to spend more time and care on their project but had to some other work to make ends meet, and got sloppy with their OSS project.
Yikes. Everyone is absolutely free to ignore security wherever they wish on their personal projects, but that just means I won't let any such code anywhere near a production codebase.
I wonder how many other projects have also been kept out of the OSS realm for the same reasons.
Recently this has been my thought... that my future projects should be AGPL from day one.
To the existing ones, especially the successful one... if it does get too much for me, I shall relicense.
> Recently this has been my thought... that my future projects should be AGPL from day one.
If that means that companies can't use it, because that would mean, if they use it they would be required to open-source their managed SaaS solution ... that's a feature?
It prevents corps running their own version without sharing those changes back, and it forces corps to think carefully about whether they are willing to invest (their time and effort) in the OSS projects that they consume.
I doubt it would mean that they have to OSS their SaaS offerings. Most likely things are all implemented as little services and the boundary of what they'd have to OSS at most is one of those. More it forces them to be a better and more mindful consumer of OSS.
Some developers at $BIGCORP may think they’d be fine using an AGPL library/utility in one spot, but legal gets nervous, so they recommend management shut it down to avoid lawsuits.
https://www.theregister.com/2017/05/13/gnu_gpl_enforceable_c...
BTW, the AGPL network clause triggers on modification, not on distribution (which the AGPL has the same provisions for as the GPL) or public performance or something else.
If something is a derivative work for the purposes of the AGPL, then it's also a derivative work for the purposes of the GPL, or any other copyright license.
But isn’t that just a matter of setting your own boundaries? Someone demands somethign you don’t want to deliver you say “no” and that is it. If they are unpleasant about it you block or filter them.
You don’t own them anything. Not legally, and not morally. Just say no.
Or if you feel like it today say yes, and when the circumstances change say no. No biggie. You didn’t promise anyone anything. Any expectation on their part is a figment of their imagination.
Just don’t wrap yourself into pretzels over other people being unreasonable.
Left-Pad: dev deleted their software name in a package manger. Nobody demanded any maintenance, however intentionally screwing other people over is entirely different. Dev could have just never touched left-pad again and everyone would have been fine with it.
log4j: That was a maintained package, so i don't really see the comparison at all.
So yeah, no requirement to maintain your software. Taking a positive action to screw other people over is going to get those people mad at you. You're free to do nothing, you're not free to intentionally cause problems without hurting your reputation.
But even if you say NO to the vast majority of requests, it generally requires some real time and effort to address each one. If the originator does not feel like 'maintaining' a project and their is no financial incentive for doing so; then I think that can be a big barrier for many projects and can prevent them from being open sourced to begin with.
But you guys think it’s okay to have a social contract on enjoying that software? Isn’t that being a little precious?
People don’t get paid for play. So we collectively need to decide if open source is for fun or adulting. You can’t have your cake and eat it too, and insisting on it is going to get us labeled as narcissists. They label everything as narcissism these days, but still.
You publish the software under a permissive free license and then make a pikachu confused face when people start using it according to the said license.
What the hell did you expect would happen? If you wanted to get paid for software, why did you instead tell everyone that it can be used for free? If you want to get paid for maintenance, then why are you doing it for free, instead of setting up some kind of a bug bounty, when you only react after payment? Just add a bot that automatically adds payment link to new Github Issues or whatever you use. If you don't want your software to be used for making money without paying you, then add this explicitly to your LICENSE. It's srsly THAT simple.
And don't give me that "evil corporations make money on free software" bullshit. I remember it were the devs themselves who pushed for the use of OSS for their own convenience, back in the day the use of OSS was a hard NO in most enterprise shops, somewhere it's still is.
Throwing a tantrum just cuz people use the software the way that YOU explicitly told them to is plain stupid.
- FOSS is high quality because really talented people with drive work to build the best they can, across global boundaries
- FOSS is also high quality because it's an almost perfect market - discoverability is high, transfer costs low and so the best becomes dominant
- There is also a lot of bad FOSS code out there.
- Lots of FOSS like lots of proprietary code is just bloated.
- There needs to be some maintenance - but equally some ... it used to be called systems integration.
- I think the layer of for profit, not for profit and charitable work should focus there - systems integration. Imagine a world where a ISV gets "certified" on say a Python MatPlotlib, with at least two employees having made accepted pull requests. or something.
Now we have a layer of companies that have profit and cash flow and an interest in maintaining those foss projects. Not merely using them for free.
Some real numbers on this would be nice to have too. If you've seen any research in this area please share.
Do you have any sources for this? It doesn’t seem right to make a vague statement (a large chunk) which sounds bad, nor a somewhat less vague conjecture (maybe the majority?) without sources.
In my very limited experience, any developer who is significantly supporting OSS with code contributions is a high contributor for their employer, and if they don’t always do the agreed-upon number of hours/week for their employer, I doubt it’s far off. So I disagree with you anecdotally, which doesn’t matter much, and I question your sources, which matters more.
I am curious if there is actual data on the number of man-hours that are spent on open source per year, and how many of those are funded by corporations. My guess is that it is less than 1%.
there needs to be a massive shift and appreciate more the work of volunteers, contributors and benevolent
until then, these problems will amplify
and i'm not talking about github sponsors since it's opt in, and it's more of a popularity check than anything else
i'm talking about that dude who will randomly appear to send a PR that fixes something important, the dude who decide overnight to open source his work but is agoraphobic, that other dude who help write documentation, that other dude who help triage issues, countless hidden people who never are rewarded
We can improve it, sure, but let's ask why it works to begin with, and then improve on that. I don't think money is an issue.
Careful — some societies a while back "thrived" by relying on slavery. OSS is not slavery, but drawing conclusions just from apparent thriving is dangerous. (Other analogies: recent bubble collapses from the housing market & dotcom before that — those seemed to "thrive" too, before the bubble collapsed.)
> […] let's ask why it works to begin with, […]
One thing I'd throw on that list is people trying to build a name and reputation hoping to get hired in the future. This includes bright youths fresh out of high school, but also PhD students whose thesis delivery is turning into a dreading life change. They're running on borrowed time, and if it doesn't work out it's both them and their projects that are screwed.
Have you thought that maybe (a lot of) people make OSS for the fun of it?
There's not really a problem with FOSS software, as I see it. It's okay to disagree with it's principles (or even for the purposes of a single project), but the concepts of public licensing are completely moral and just. If we frame this as a money problem, corporate FOSS benefactors will build us a money pit. That's not what Free Software (capital F) needs.
Construction industry in Quatar thrives so well, specially thanks to the construction of their brand new football stadiums for the world cup
Manufacturing industry thrives to well in Asia, specially thanks to their ability to mass produce cheap Nike shoes
Do you endorse kids labor and slavery, is it compatible?
And i never mentioned "money", it's funny that you thought about it yourself
I can understand that it is hard to seek VC funding if you have to split the money with the real contributors, and not just that idea dude
I’d say evidence is to the contrary. This message wouldn’t be possible without open source working on multiple devices at every layer of the network.
I think the problem of funding open source well, that is a different problem and has a lot of the same problems getting anything funded does. Not every piece of code can have an enterprise built around it, and that means there will be no one to even look at bugs.
Finally, let’s talk about volunteering. Most often volunteering is doing something that doesn’t get cash budgeted towards it. You go in doing something necessary but unbudgeted because you want to… and with no reward other than knowing you made something work. Maybe you even give up something you could be doing with time instead of volunteering. Manning the directions kiosk at the hospital, picking up garbage in a neighborhood, nailing the roof onto a house the owner can’t afford to buy, putting letters in envelopes, and answering the phone at a fundraiser are all examples of this. You know what you are getting in to and you know what you are getting paid. No injustice in it at all. And for a lot of people it’s the most important thing they do.
https://www.fossjobs.net/ https://github.com/fossjobs/fossjobs/wiki/resources
It's a hobby, not a job. If it's becoming too much of a distraction - just...stop doing it?
Sounds good, I'll just remove my libraries from npm... (oh wait, that's left-pad)
Okay, plan B, I'll hand it over to a random person... (oh wait, that's event-stream)
Like the internet will collapse without left-pad?
But it's nauseatingly entitled to just expect people to pay a person for their hobby. Pick a different hobby if it upsets you? There are other things a person can do with their time.
You made a good point for asking for money instead of providing free work by the way.
Having maintainers be well paid will not magically make your software bug free. Google pays their devs, their software still has bugs.
I wonder if the real problem it solves is a bunch of corporate types are starting to feel the ethical pressure of leeching off open source, and a nominal fee is the only way they understand the concept of giving back.
Let volunteers be volunteers.
If you see it as volunteer work, then yes you should not be paid, but you should also not provide services to wealthy organizations as they don't need it and can pay for their own needs.
If this is a hobby, then why are you putting your code on GitHub? you should just share it with small communities you enjoy hanging out with. And don't provide any services unless you personally know the requester and like them.
If this is more like art (think music), then you want to make it big, you want to share the code far and wide and for it to become popular, you help out developers from big companies (like record labels) hoping they notice you and pay you some day.
I personally think open source can take any of those forms as it's more about how the person works and their aspirations.
I'm confused. The vast majority of code on github pretty obviously falls into this category.
And quite frankly its pretty condescending. Would you tell someone who enjoys gardening to only do their backyard lest other people see it? For that matter, who are you to tell people who they can and cannot "provide services" to. Do you also object to people acting in local community theater?
> If this is more like art (think music), then you want to make it big, you want to share the code far and wide and for it to become popular, you help out developers from big companies (like record labels) hoping they notice you and pay you some day.
Similarly, how many artists have you met? Some do actually yearn for that sort of thing, but most are not in it to do that.
As for being condescending, I found your comments only considering the volunteer side of open source equally so, and I am a big fan of answering in a tit for tat manner on the internet.
I have met a bunch of artists, and all of them wish to make a living from their art. I have yet to meet one who only wants it to be a hobby.
--- edit: I for got to respond to this
"I'm confused. The vast majority of code on github pretty obviously falls into this category."
And that is obviously causing a lot of friction between the professionals there to do a job and the hobbyists (a person can wear both hats at different times). Both sides would be better off not being on the same platform. My argument is that the hobbyists should get out of the botanical gardens (to keep going with the gardening analogy) and take their stuff to a community garden or home to their front garden.
A weird example given many botanical gardens do rely on volunteers.
> As for being condescending, I found your comments only considering the volunteer side of open source equally so
I personally was previously employed doing open source work. I have no problem with people making money off open source if they want and are able to, just with the idea that it should automatically be the aim.
> I have met a bunch of artists, and all of them wish to make a living from their art
"Making a living" and "being discovered" are very different things. But if you really think every artist wants to do art professionally, you should umm, meet more people.
> And that is obviously causing a lot of friction between the professionals there to do a job and the hobbyists.
How so? I have yet to encounter any friction.
Although i suppose it also depends on what you mean by "professional doing a job". Even professional open source does not look like a real software job. There are no SLA's or garuntees from a professional open source project unless you pay for that seperately, so what even distinguishes professional open source from amateur open source.
> Both sides would be better off not being on the same platform.
Why?
More to the point, although there certainly are some open source projects with big $$$ involved on github, the really famous ones tend to be not hosted on github. E.g. linux is not on github.
> My argument is that the hobbyists should get out of the botanical gardens (to keep going with the gardening analogy) and take their stuff to a community garden or home to their front garden.
The phrase "corporate appropriation of the commons" comes to mind.
So, have a good day, and sorry for getting you excited.
The Log4J incident?