The fact that pretty much all open source software right now is passion projects means that people are pretty free to aim at ideals, throw things out and iterate/try new ideas. I think open source as we know it exists because there's no money, but it's also limited in scale, and you still need to depend on companies like windows, adobe, google, etc because development just can't reach that scale.
Adding money could absolutely destroy the current good things, but it's also totally possible that the good things could persist while making more projects viable. My dream is to work on useful open source libraries during the day so I can work on fun stuff, art, games, etc. I intend to build from those in my free time, rather than work on the libraries in my free time. But I get that people are scared of losing what we currently have. I don't think we'll know without giving it a go (obviously there are other obstacles to this too, like accounting, taxes, legal questions, etc).
Back to the article, I feel like it's making sweeping arguments about a very specific implementation of bounties. AFAICT what happened leading up to this is
- WASIX put out a bounty for WASIX implementations in other software
- Some people started rolling forward with it in the Zig bug tracker, WASIX (?) publicizes this on twitter/reddit
- Zig maintainers said no
- Debate in the issue tracker
- Zig maintainers said no more discussion
- Bunch of deleted messages
I might have missed something. It seems like the main reaction is about Zig's name being used for WASIX promotion/a 3rd party trying to exert control over Zig development, which doesn't entirely seem related to the bug bounty or bug bounties in general. WASIX put out the bounty and did the publication, they're a bad actor and this could have happened largely the same way entirely without the bounty too.
The points in the article don't seem related to bug bounties. Highlighting a few:
> you end up with a quickly bitrotting artifact
This happens with all MRs, bounty or not. "Upstreaming" is an implicit contract where you write something you want per the maintainer's specifications and in exchange they maintain it afterwards.
> Instead of scouting for a suitable candidate, you’re letting battle royale dynamics pick a winner for you
Non-bounty issues frequently have people taking them who aren't capable of producing a mergeable solution. I'm not sure why a bounty would make this worse - you could easily argue that in order to get the payout people would be more careful to take work they can actually complete, or that people who are capable are can now afford to devote their time to it.
> You instead penalize any form of thoughtfulness in favor of reckless action (eg a solution just needs to pass a test suite)
The maintainers decide whether something gets merged or not, and I've never seen a project that says "We'll merge anything that passes our test suite". Maybe I missed something here...
> Instead of spreading unease to all the people involved, it would be preferable you instead learned how to do business properly.
This feels like an attack directed at the WASIX people and not a general statement.
That said, there's very very little bounty driven development ATM. I think it's hard to extrapolate consequences at this point in time.