Sponsor the open source projects you depend on
thanks.dev
thanks.dev
This implementation is clearly for-profit. I want to directly tip open source projects using a system that doesn't involve other third parties taking a significant cut.
What are your fees?
Tips at time of donation. You decide.
If payment is required to use a service then that payment is not a "tip" - it is a "fee". Anything over the required payment would be a "tip". This FAQ answer implies that the required payment is zero, which, it turns out, is false.There is absolutely nothing wrong with charging a fee for a service, but there is something wrong with lying about it.
Agreed, but percentage-based fees can quickly become an unfairly large part of payments. I love the idea of this project, but I'd prefer there to be a 5% or X dollars minimum, so that if 5% is more than X dollars, then it doesn't force 5% minimum. If I'm donating $500 to 45 projects, then each project on an even split is getting $11, but thanks.dev is getting $25 even though their service isn't actually in use by my app/service. Seems unfair to me.
The remaining ~$10 will go to thaks.dev to cover operational costs, administration and other expenses.
I don't expect them to work for free. If you think it's unfair, contact the developers directly to see if you can wire them money (to avoid PayPal fees). If it's too much work, you can pay services like thanks.dev that does the work for you.
(And now I'm realizing that American tipping culture may be playing in to differing expectations here...)
EDIT: I see they have now updated their wording.
Surely they are not making a transaction for every patron/maintainer combination, but rather batching the payments.
Otherwise yes this is a Stripe charity :)
It's literally public information
$25 refers to the 5% fee of the total amount ($500) that the site takes. I said that more than half of that fee is used to pay Stripe.
The platform itself is also a project on the platform, where the donation happens
GitHub sponsors isn't too bad, they take a 3% cut (and the CC takes another 3%). But you're effectively donating to Microsoft, which feels icky.
A payment system is never simple and if it's more than a standardized "funding.txt" format it will have running costs and someone has to cover these. How much this system should charge is debatable, but it should probably be higher than 0%.
What does this mean? Using this service is letting the merits dictate. It doesn't stop anyone building a competitor.
This only works in a system where humans do not need money to live. This is not our system. In a capitalist system, for better or for worse, if you don't own a means of production you must work to get money because you need money to live.
We should recognize the value of work, and if it is useful, pay for it. It is only normal in such a system. I wish we were in a commons-based society, that all resources and production would be decided by workers in quantity and distributed based on needs, but that's not our system.
The problem comes from people believing they should be paid for willingly giving away the fruits of their labor.
I only use FLOSS and don’t feel I’m missing out at all.
I would love to live in a system where everyone is actually free to do whatever they want with their time, all day long, all year long, but that's not where we live today. What kind of people has enough time and energy to devote hours of their lives to something that is not their primary way of earning money ?
I too use only FLOSS, and only put out project under copyleft licenses, but that doesn't mean I'm blind to the structures in which we live in.
> Thanks.dev presently supports itself through a voluntary tip percentage that, if more than zero, gets deducted from donation amounts along with a Stripe payment processing fee prior to distribution.
I also think they should allow manual addition of projects. E.g. I use Syncthing but that won't be found in my Github/Gitlab scans. I can donate via Github too but would be easier if I can have one place to control all such donations.
[0]: https://www.theregister.com/2023/04/07/thanksdev_open_source...
I'm seeing comments from two separate accounts, but when you look at their about, they seem to be the same person:
https://news.ycombinator.com/user?id=qwerki https://news.ycombinator.com/user?id=armini
Sponsors have a slider that allows them to adjust their tip from 5% to 100% of their monthly donation. We figured minimum 5% would cover our compute & merchant fees but left it to the community to decide what we should get. We thought this was the most aligned approach with open source. Totally open to other ideas and suggestions though.
So no, if you're taking a minimum of 5%, then any reasonable person is going to assume that you've already deducted the processing fees, not covering them out of that 5%.
I don't think you're being open and honest here.
The text may be imprecise, but it's a long way from dishonesty. In my opinion dishonesty requires a motive, and I don't see it here. If the 5% did not include fees, it would perhaps be different.
In a perfect world, Stripe and the credit card companies could waive the fees for donations, but that is not the case.
Someone has to actually cover those fees.
I agree it is not simple, but it proves it is doable.
At some point the dance isn't worth the peanut.
Sorry, someone donating $10,000 to their favorite FOSS doesn't want an intermediator to take in $500 just for making the transaction.
Even more so when the actual transaction infrastructure is not going to be their's anyway, but some banks or Stripe or whatever.
This phrasing is just inappropriate, and the situation you cite is an extreme.
> many would find this shady and wont want to deal with them
What's the point of armchair prognostication? We'll find out, and their pricing isn't fixed in stone?
Nothing stops you there to put 100% into one of those and 0% on the others.
There are some gas stations in Massachusetts that have a slightly lower cash price because they don’t have to pay that fees and pass along the savings. Most businesses nowadays just fold that fee into the price.
If they are upfront about how much I’m ok with it. Otherwise you can send a check, but no one is using that option.
tea.xyz will not have fees once it goes live with its funding protocol for open-source software.
People will sign praise your work, tell you how much they depend on it, and how it changed their lives. Others will ask you tricky questions that really ought to be asked to a lawyer.
...and they still won't donate a cent. I get about 70 cents per thousand unique visitors. About one in every 14,000 visitors donate. Affiliate income is roughly 100 times that without trying.
Let me put it differently: with the same traffic, donations barely cover my groceries, and affiliate income is a comfortable salary.
I'm at peace with that. I make free things for a reason. It's just something to keep in mind when suggesting donations as a business model. Doubly so as an alternative to ads.
Another tidbit: praise people who create the things you use. It feels so good to know that people use and love the fruits of your labour. I've become lavish in my praise after experience the effects of it.
If instead there is some way to capitalize the timing of the user experiencing "wow this makes my life so much easier!" to remind them with a low-friction shortcut to make a donation, this short-circuits the cognitive process that previously require the user's mind to go out of its way to invoke their "oh, I should probably donate" sense of reciprocity.
As reviled as impulse-driven microtransactions are, I think there is much for open-source projects to learn from and wield in an ethical manner.
Right now it seems there is a false dichotomy between being either [be unethical and leverage user impulse] or [be ethical and off-putting to the user].
There is no reason why an understanding of the psychology in friction-reduction can be utilized ethically to encourage "impulse-reciprocity".
A model that might be worth analyzing is the streamer-donation UX flow -- yes it can be used irresponsibly to encourage parasocial obsession, but in the hands of the responsible it is a facilitation of healthy engagements with the audience
Similarly I understand (from an interview with the developer) that the eBook software Calibre gets a significant number of donations from users via the giant donate button in the toolbar.
I do agree, having a "tip jar" option for donations is rarely as successful as the above methods though. Not diminishing your personal experience. Just saying it's possible to change the way things are done, and get more.
If I didn't care about user experience, I could earn more from donations, but I could also earn much more from affiliate links.
As it is, I just list a few options when I happen to mention a products. There is a tip jar at the end of every guide, and in my email signature.
Tipping in the real world is easy. You just leave some of the money you have on you. Tipping online is a far more deliberate process, unless you're already processing payments.
If I actually pitched products, I'd make even more.
I have no insight but I could imagine that GitHub are going to offer something similar based on that data at some point in the future.
For us the "top" developers on that page are people with 150+ repos that we depend on that I have never head of before. It turns out that they are all tiny JavaScript libraries that we depend on in some repository that's not part of our real product.
I'm happy to sponsor them as well but it'd be cents not euros per month compared to libraries that do the "heavy lifting" for us. At the moment we hand-pick things, also not ideal.
All of that text to say: This is a hard problem, I have no idea how to solve it but I applaud you and everyone who's giving it a shot.
A 5% flat fee is too much for me though, if it had a cap then it'd be different.
In some cases we depend on a library indirectly, because we use a wrapper to match it to our stack. An old school example is we use bower, and want to use the uglify library. Someone has made an uglify-for-bower wrapper, that's like 20 lines of code, so we depend on that. But all the meat, and where I would like the money to go, is the uglify maintainers, one level down.
I'm not saying those people making the wrappers haven't brought us some value. But it's less than the underlying library.
Github falls prey to this. My guess is thanks.dev also would? But at least it has a "boosting" option, I just don't want sindresorhus to scoop up all the money...
That doesn't stop us from sponsoring some projects, it's just a manual process and having this automated would be great. Not sure if thanks.dev can do it but at the moment I'd probably like to exclude the whole JavaScript ecosystem and just include one or two libraries that I _know_ we're using.
And I'd like a similar thing as thanks.dev but for non-code-dependencies. Let's say our devs are using Kubernetes, Kind, Visual Studio Code, VLC etc. - they are not dependencies of our code but it'd be good to have those sponsorships also managed in a single place.
There may even be some use in having a standard format to define those kind of things so they can be machine readable. i.e. I'd like a repo that contains a file with the tools we rely on that can then be used for sponsorship purposes. Like a SBOM for internal tooling.
It can't have a cap if payment gateway processing fees are percentage-based.
"A payment processing fee of 0.5% + 0.20c is collected on the total donation. We take an additional fee of 4.5%, up to a maximum of $10"
There, done.
Stripe's payment processing fee is 2.9% + 30¢ in the US.
It might be that it is this expensive to run, I don't know. It just seems unfair to me that the platform would get 5% and "only" 95% are distributed to the projects. I do understand that everyone has a different definition of "fair" and I also don't know what I'd be willing to spend. It's something I'd need to think about.
Slightly offtopic, but every month when my Patreon donations get processed Patreon sends me this STUPID email with "Tweet your receipt!" Honestly, it's so pathetic. It's like giving food to a homeless person while filming it so I can post it on Twitter.
Yes I realise it's an option and I don't have to (nor do I) click it.
Just a note which probably isn't worth your time to act on, but using this service as a maintainer in Finland is illegal unless you can offer a geoblocking feature that can block any Finnish supporters from routing money to Finnish maintainers. This is due to our Money Collection Act which prohibits soliciting any donations except for very strict circumstances which aren't really applicable here. Might be worth a note on the page if you have extra time, since this is not know by many Finns that I've talked to.
That’s a pretty neat idea.
I wonder if it would be possible or even desirable to try and get some automatic measure of “how much” you depend on a given project, to weigh the split. Probably that would be really difficult to capture. Anyway the current idea is already pretty cool.
The formula is explained in https://thanks.dev/static/how.
If this takes off people will be inventivized to make lots of small dependencies that are likely to be needed in tier 1 (or tier 2).
The trick will be to find a bug in a first dep of webpack for example, fork it and fix some bugs there then convince webpack to switch to you.
Algorithmic decisions can be gamed.
I suggest instead the app lists the deps, and you choose how much to give each one.
Re gaming the system you're totally right. Although slightly unintuitive, we've also heard the opposite from maintainers. That they'll be motivated to remove the silly one line packages from their dependency trees due to the imbalance of value they provide vs extract.
We also prune self dependencies, circular dependencies and a few other cases to keep things level. Hopefully we'll be at a stage to open source our codebase soon and can better leverage community feedback in this space :)
The FAQ has a section titled "What happens if I don’t claim my balance?", but I think this only applies to people registered at thanks.dev. I'm not even sure that thanks.dev would be able to reliably contact developers that / maintainers in all (most ?) situations.
If I decided to sponsor my project's dependencies with say 100 USD and none of the developers are registered with thanks.dev – which seems like a reasonable assumption, especially as thanks.dev appears to be a young project – I wonder what happens with the money. The money can't be allocated.
Does thanks.dev just keep it? Is it "stored" until it can be allocated? And if this is the case: From the information on allocation it seems that all of the money will be distributed between all eligible developers (possibly 3 months after devs don't claim their balance)? If so, what if there is only one (transitive) dependency that is registered with thanks.dev?
"Webpack receives close to $200k in funding per year via OpenCollective but its direct dependencies receive minuscule amounts of funding, and there are 80+ of them."
♥
Emojis are Unicode, not ASCII (I think, not an expert myself).
We should also be able to use arrows ⇒, the trademark symbol ™, whatever this is ∴, or maybe this ℜ.
But we can test it, maybe HN supports Unicode Emojis but nobody is using them...
EDIT: I was listing some Unicode Emojis here, but you were correct, they were removed after posting. At least the ASCII symbols show up :)
"payment": "iban", "data": "IBANCODE"` or
"payment": "link", "data": "https://..." or
"payment": "cryptoCoin", "data": "0xb3..." and so forth.
Of course, the problem is there are many different ways of giving thanks, so a protocol is required, that's the hard part actually in this space, standardization.The worst case here is a lot of fraud for the people who shared their details.
[1] https://www.greenpeace.org.uk/news/succession-greg-sue-green...
these things are still possible, you don't even have to know as much detail as this person gave out
Consider using Monero for such a purpose. I've gotten paid in Monero. It pretty much just works.
Unfortunately, I cannot use this right now, because Maven dependencies can't seem to be found, and neither can Cargo dependencies. I decided to test it with an app that uses a mix of ClojureScript and Rust. There is a shadow-cljs.edn file at the root level of the folder, but those dependencies are not picked up. Neither are stuff in a package-lock.json. There is a Cargo.lock file in a subfolder, but that does not seem to be scanned either.
However, I am able to verify there exist dependencies, in each of these files, that are actively seeking for funding and use GitHub sponsors.
Alternatively, for multi-project repos you can add a thanks.yaml file to the root of the repo with a `maxDepth: 2` value inside it. Unfortunately, deep scanning the entire repo looking for files would be prohibitive due to GH rate limiting hence this approach.
Please keep me posted. I'm also available on Discord if you need anything.
I see on the website that CLJS isn't supported; that's fine. But the NPM dependencies not being detected does intrigue me. I'm going to follow up with you on Discord if that's fine
https://github.com/fossjobs/fossjobs/wiki/resources#patronag...
deep-equal has 43 packages (& 17m weekly downloads) that are mostly (is|has)-* packages or redundant wrappers like for-each and object-keys (https://npmgraph.js.org/?q=deep-equal) and you’ll find this package included in a lot of upstream libraries. Ask for a banana and get a gorilla and forest... Luckily many have moved to fast-deep-equal (0 dependencies), but there are a lot of other examples of this sort of thing.
But dependency tracking is hard and all of these platforms only scratch the surface. For example, I've never seen a solution that detects C libraries used from other languages, let alone the dependencies of these libraries. Then there are build-time dependencies which are hard to detect. Here's an example of a complex dependency chain:
redmine -> ruby-commonmarker -> libcmark -> re2c
Wake me up if someone offers a solution that detects chains like that.Take money, don't wait for people to give you money for the free value that you provide.
While many have been (trying to) do their best, it's unfortunate that many got richer on the back of the people they were supposed to help. Sometimes with local accomplices who also benefit from the grift.
I guess the main take away would be that transparency and accountability are paramount if you want to be part of such an ecosystem, especially as a middleman for money transactions.
[0]: https://landportal.org/node/100425
[1]: https://humanglemedia.com/the-dark-reality-of-corruption-lac...
Not a great start for delivering me basic information on what this even is.
Reminder that Microsoft GitHub and GitLab do not have a duopoly on decentralized (self-hostable) version control. Products like this feed into folks feeling compelled to join big, proprietary services.
- They already understand what kind of code base it is and already do dependency scanning for security issues
- They have payment details
- They have the "verified" payment method of a person / project (If sponsoring is enabled)
For me the library has been good enough for my own use for a very very long time. I mostly neglect it unless there's some critical issue (which there hasn't been for a very long time — but clearly infosec world knows this lib exists as when I do make changes with crap commit messages I get emails asking what the implications are). I don't improve it at all as my time is better spent on my day job.
I've often thought that there's room for improvement such as a DOM style sanitizer to validate HTML input rather than just a SAX style sanitizer, perhaps formatting of output in addition to sanitising input, transformation rules to allow a safe embedly type thing, etc.
When I got the initial donation I was surprised, first ever bit of support for open source software I'd written (as this was not written on company dime).
Even at $10 per month it is motivating enough to think someone values it. If it accrues into something significant then I may actually feel motivated to improve it rather than just support it.
Interesting is that I'd regard this OSS lib as successful by usage as sourcegraph says 803 projects use it — but given that a fair number of those are things like Hugo which in turn have thousands of forks and many more thousands of instances of use, well it does appear that this sanitizer is to safe HTML in Go what https://xkcd.com/2347/ illustrates. Originally it was written for my own use and it's now used by virtually everything in the Go world that makes a website.
Perhaps people don't know this and libraries like it exists though? Perhaps they import some web framework and this came with it? Well, for that awareness thank you to thanks.dev
Of the models I've seen so far for supporting individuals who create OSS code this one stands out by highlighting dependencies. Likely the solution is a blend of things... a commission type system for rare engineers and skills (i.e. https://words.filippo.io/pay-maintainers/ ) and thanks.dev for the long-tail of those who have done things and you want to use it long-term. There are also companies who create OSS software, and if you value their work and don't want what they produce to go behind Enterprise differentiation then perhaps pay for their services too.
I can donate to some and rotate each month, but how about the rest, and dependencies?
There is just so much software there that seems hopeless (although there are also billions of users).
The way the OSS communities works is not money but value creation. There are all sorts of value people get out of creating things for each other. People like the recognition and appreciation they get for their work, the satisfaction they get out of doing a thing, the interactions with others, etc. Plenty of ways to get value from creating stuff for others. And sometimes people actually get paid directly or indirectly to work on a thing. It's fine. I'm not against that. Just don't expect/demand me to pay for a thing. And I won't do so either. That simple promise is why OSS works. We both end up getting some value if we work together. And we might even get paid indirectly. For example I have a consulting career and I dabble in startups. So my motives are not entirely altruistic.
I wonder: will people find a way to exploit it? E.g. create a simple but useful dependency that uses 100 sub-dependencies, all by the same author? Will larger, more self-contained dependencies lose out to small ones?
Excuse the crappy looking site (been busy trying to actually deliver all the shit on that page), but I believe that F/OSS can be sustainable:
https://nimbusws.com/#sustainability
All it takes is contributing a small % of revenue back. I'm not decided that 10%-30% will be the final # (can a business give that much and still compete?), but then also some of me feels that it should actually flip at some point (30% for nimbus, 70% for F/OSS project) if most of the value is actually the F/OSS project (i.e. the project is so high quality that all we do is mostly run it and upgrade it happily).
Right now only the Redis service is available (object storage is coming soon (tm)), but kick the tires:
https://nimbusws.com/app (register @ the bottom!)
One thing we haven't figured out is how to pay library authors. dunno what to do, but early idea is some % contribution and letting people calculate allotment (ex. 5% of your 20% revenue donation must go to libs, but you pick which libs you depend on get the most).
Much confusion that this domain isn't for the Nimbus weather station.
Ah, the cloud! Is there anything it can't do?
Thanks for the kind words -- I do have to make it real, and make sustainable profit first before my aims mean anything, but at least I think I'm pointing in the right direction.
> Much confusion that this domain isn't for the Nimbus weather station. > Ah, the cloud! Is there anything it can't do?
Well looks like there might be a name change in the future... That might be a legitimate confusion point.
TIL of the nimbus weather station: https://www.rainbird.com/golf/nimbusii
It's like a Bloomberg Terminal for weather...?
I agree, there's value being brought by both sides of this equation -- F/OSS developers for building something valuable, and Nimbus for providing it, making fixes/upstream contributions when necessary, etc.
The problem with the current state of things is that the value capture is ~0% for F/OSS projects. Maybe 15%-30% is too high, but it needs to be appreciably above 0% for F/OSS to flourish.
> There should be the same difference as between standard on-the-shelf products and custom products made for the industry, that fit a particular purpose.
Would you mind expanding on this? Are you advocating for open core? It's not that I want to provide an enterprise version of 10/100ss of software -- more that I think there's value in them as a service (use Postgres, but avoid getting a degree in Postges administration).
The idea is to do just enough hacking that makes the service more reliable and sustainable to run without manual ops burden -- that's the differentiator for Nimbus (along with know-how).
On the other hand, for a smaller firm, this might probably be just a one-to-one talk/convincing an executive. If you can't convince one, try another. If you can't convince any, take it as a flag with the color of your choosing.
For example:
https://anonymoushash.vmbrasseur.com/2022/10/27/open-source-...
I understand the idea, but giving it a better legal framework than "it's a donation. but not really" would definitely help.
From what I understand, you're not 1:1 giving the money to some maintainer that's chosen but you'll distribute it according to code usage etc, so you won't be a payment provider, but it counts as revenue for you and you give the money to maintainers, right? Are you invoicing or do you go the github route?
Pretty soon after that I moved over from Gmail to Fastmail[1], again it was a service that took my money so that I was the customer not the product being sold.
Thanks for building this!
Platform owner are registered as devs, who you can tip like any other devs. Hence their "cut" is not taken automatically from every transaction
What I'm saying is it depends.
I can donate to some and rotate each month, but how about the rest, and dependencies?
Any ideas?
Please note the donation will be kept in PENDING state for 5 days to allow time for full dependency analysis, adjustments via boost and/or exclusions. In this time we'll be reaching out to the other projects in your dependency tree to onboard them.
Please ping me if you need anything. Many thanks again!
Thanks for building this and I'm looking forward to seeing how it develops.
I will add my voice to the "allowing this service full access to my repos is uncomfortable" crowd, there's a couple of my clients that have stricter NDAs which has meant those repos have been excluded. But you'll figure that out when you do.
Cheers and enjoy the product launch :)
The next biggest difference is that it distributes micro-payments up to 3 levels deep into the dependency tree. We've noticed majority of people sponsor the top of mind projects, but the deep nested dependencies don't get any love. This automated approach should fix that.
Don't hesitate to ping me if you have any other questions please (email in profile).