How GitHub replaced SourceForge as the dominant code hosting platform
graphite.dev
graphite.dev
[0]: https://neverworkintheory.org/2022/04/21/decline-of-sourcefo...
[1]: https://news.ycombinator.com/item?id=31110206
As my memory recalls it, that triggered an exodus to Google Code, and whilst GH was gaining traction it was somewhat in their shadow. When Google announced they were going to kill Code that was the blessing for GH.
This was a mortal sin for them, and rightfully so, whereby it became impossible to recover the damage to their reputation. Like, what were they thinking? Did they know they were doomed and just wanted one final ad sale? It’s just an egregious abuse of whatever dwindling power they had which permanently destroyed what little trust that the developers had for them - the same group of people that provided the only real value (for free, even) that SourceForge held.
They'd been recently bought by a shitty company called DICE that also owned ummm... CNet or Download.com, or some other similar place with lots of downloads for Windows users:
* https://en.wikipedia.org/wiki/Dice.com
* https://en.wikipedia.org/wiki/SourceForge#Adware_controversy
That company already served ~malware~ sorry "bundled third party offers" with their windows downloads, and figured they'd be able to copy-n-paste that approach to popular OSS downloads.
That's not how it played out however, as some of us actually give a shit about things like that. ;)
/. is a faint shadow of what they once were.
TBF, it wasn't just Dice. At that time, CNN and Yahoo (I think) nuked their trollgard- er, comments, and they all went to slashdot. It became the place to go, for top-quality Nazi ASCII art.
So if their calculation was that all of open source would stay on their platform with them adding malware, they were wrong. But if the calculation was that a long tail of random small and semi-orphaned projects would stay there after the big popular projects had all migrated, providing them with essentially free revenue for a very long time, they were kind of right.
Enter the DevShare program, a Faustian bargain if there ever was one. It whispered sweet nothings into the ears of developers, promising them a slice of the pie if they let these third-party gremlins hitch a ride with their creations. But here’s the twist – SourceForge, in a move that would make Machiavelli blush, didn’t always wait for a nod of approval. They shadow-copied projects, dolled them up with their unwanted baggage, and pushed them onto the unsuspecting masses as the real deal.
Who masterminded this descent into madness? The suits at SourceForge under the banner of Dice Holdings, who else? Names weren’t named, but the open-source warriors and keyboard knights didn’t need a who to channel their fury at the sacrilege committed against their digital Eden.
But as the adage goes, "It's always darkest before the dawn," and so it was for SourceForge. By 2016, under the new flag of BIZX, LLC, a wind of change blew through its realm. The DevShare program, that deal with the devil, was slain, laid to rest in the hopes of resurrecting the platform's lost glory. The new overlords vowed a return to the old ways, a purge of the parasitic practices, aiming to restore faith in the digital congregation and bring back the prodigal programmers.
SourceForge’s saga is a testament to the eternal battle for the soul of the internet, a reminder that even in the digital age, the pen (or the code) is mightier than the sword (or the adware).
Over time, the nuances of the word "prodigal" have expanded, and it can now be used in a variety of contexts to describe any sort of excessive or wasteful behavior, not just financial. Additionally, it can sometimes be used in a positive light, emphasizing generosity and abundance rather than waste.
When MS also announced they were closing that and offering a tool to migrate to GitHub, was when GitHub (and Git) truly became the biggest remaining option.
The other aspect of SourceForge's decline was that they doubled down on the sketchy site feeling right as acceptance of such sites was on the decline, the likes of mediafire, zippyshare etc were being replaced with cloud storage providers and download aggregators were losing popularity (in part due to also becoming very sketchy and prone to pushing malware). They might've been able to get away with it a few years earlier. I remember that back then it wasn't a huge deal to follow a mediafire download link from somewhere that seemed reliable enough, whereas nowadays it'd be an immediate red flag due to the abundance of more legitimate seeming file sharing options.
Google was already using GitHub ("To meet developers where they are, we ourselves migrated nearly a thousand of our own open source projects from Google Code to GitHub.") and added an "export to GiHub" button on google code. Maybe if you were .net you went to codeplex but most everyone else (including Google) went to GitHub, if they weren't already there.
https://opensource.googleblog.com/2015/03/farewell-to-google...
The only real question at the time was whether Git or Mercurial (or for a brief period of time Bazaar if I remember correctly). While Mercurial itself was clearly superior to Git, it had no equivalent to GitHub.
If GitHub had chosen to build their workflows on Mercurial instead we would likely be talking about HgHub right now instead.
There existed BitBucket (it still exists, but as far as I am aware they switched to offering Git hosting).
That happened in 2015. Everyone was already on GitHub by then. GitHub had surpassed in usage Sourceforge, Code, and CodePlex from 2011. Also CodePlex didn't had Git support until 2012.
Also the main advantage of git was local copies, so the source code was more safe. And speed SVN was slow for large repos. At my first place we had an SVN server in the server room, when it's hard drive crashed no one could work for a day :)
Still people hated git first because it was much more complicated with it's branches, PRs etc
Bundling adware with software was not the death knell for Sourceforge, it was a death rattle - though the corpse is livelier than I’d have thought ten-plus years later.
It's just one of the examples where somebody came along offering pretty much the same thing but just with a different focus (code/collab), and arguably also relevant a cleaner, fresher look.
My dad runs his company accounting on GnuCash, and I sometimes help him set up a computer, and it is always startling that SourceForge even exists. (It's still the official download[1].)
[1]: https://sourceforge.net/projects/gnucash/
P.S. I think you meant "death knell" but it's all good, we all understood. :)
You are correct, I garbled it with "[death] bell toll" (specifically thinking of "for whom the bell tolls.")
Death rattle refers to a rattling noise produced in the lungs with one's dying breaths.
Both applicable, death rattle is a little bit more appropriate though, because it's an action that sourceforge took.
Later, one day someone said in a group of Linux developers, "So, Linus made a version control system...", kinda amused. I didn't know whether Torvalds was actually going to use it for Linux, and didn't even consider that it might be adopted by pretty much all software developers of any kind.
It was even named "git", like it was aggressively trying to be unmarketable.
But at some point, GitHub emerged, and grew a very favorable reputation. Then they sold out.
Ah, finally someone recollects the original.
People look at me funny when I tell them it wasn't an Microsoft creation.
Kind of preferred Google Code over GitHub for a while. Or at least until it had enough functionality and/or tools to support it.
Almost feels like it's time again for a shift...but it will probably be a while
That might help a little with the transition, ready for when MS does one of their crazy moves and people suddenly want to switch.
In reality, I think there was (and still is, albeit small) market for alternative hosting, and there definitely were niches where SourceForge was better at (downloading binaries, for example). If SourceForge didn't misplay their hand, it's entirely possible Github won't have the near monopoly on open source hosting they have now.
(Well, lots of people still are, but Git usage grew quite fast)
The company, and Sourceforge's leadership, lost all tethering to the community that fostered them, and the firm got passed around from buyer to buyer like a blunt at a Phish concert.
At the time, GH was pretty much the best expression of hosted Git out there.
The thought from the original growth of OSS was that it would be more about the community than the code. So OSS would be a series of communities that would each have their own "identity" for their community. There were big OSS foundations like Apache and Eclipse. Sun had several like java.net, OpenOffice.org and netbeans.org. Gnome had their own place etc.
Like Sun, other enterprises like HP, Oracle and IBM were setting up their own communities for their projects and to collaborate with partners.
And then as the post touches on there were sites like SourceForge, Tigris.org, Google Code and Microsoft had something too (CodePlex?). These sites were places projects might spin up if they did not belong at one of the other foundations and wanted a place to host their code for free. Of these SourceForge was often used for distribution of binaries due to its vast mirror network and often that was all that was hosted there and the project was elsewhere.
Anyway, until GitHub sprang up and started to consolidate all the OSS in one place, I do not think anyone else was even really trying to do this. Obviously the rise of git played a big role in this. This change fueled the growth of OSS but it did kind of come at the cost of losing out on some of the community aspects that existed before in the mailing lists and forums of these other places. Now collaboration all happens in PR's and Issue and is often just between a small handful of people.
Github was so accessible that it made possible what otherwise would not have been.
1. Are logistically harder.
2. Don't have an existing community.
If you want to create an OSS project with greatest adoption, you're best bet is GitHub.
The tar-pit I'm afraid of: How do you emigrate Github PR and Issue databases in some format that any of self-hosted Forgejo, or public Codeberg, Gitlab et al understand and can present to visitors?
On top of that it's yet another site I have to sign up with if I want to interact with the community.
I'm also mindful of the risks of centralization. Discord and its lack of external archives is a prime example of how that can be harmful. I'm just not sure if that risk outweighs the costs and annoyances.
Google, with its ‘Don’t Be Evil’ mantra now a quaint echo from a bygone era, morphs the internet into its own playground. Each search, a breadcrumb trail, lures you deeper into its labyrinth, where your data is the prize – packaged, sold, and repackaged in an endless cycle of surveillance capitalism. The search engine that once promised to organize the world’s information now gatekeeps it, turning knowledge into a commodity, and in its wake, leaving a trail of monopolized markets, squashed innovation, and an eerie echo chamber where all roads lead back to Google.
Meanwhile, Microsoft, the once-dethroned king of the digital empire, reinvents itself under the guise of cloud computing and productivity, its tentacles stretching into every facet of our digital lives. From the operating systems that power our machines to the software that runs our day, Microsoft's empire is built on the sands of forced obsolescence and relentless upgrades, a Sisyphean cycle of consumption that drains wallets and wills alike. Beneath its benevolent surface of helping the world achieve more lies a strategy of dependence, locking society into a perpetual embrace with its ecosystem, stifling alternatives with the weight of its colossal footprint.
Together, Google and Microsoft architect a digital Panopticon, an invisible prison of convenience from which there seems no escape. Their decisions, cloaked in the doublespeak of innovation and progress, push society ever closer to a precipice where freedom is the currency, and autonomy a relic of the past. They peddle visions of a technocratic utopia, all the while drawing the noose of control tighter around the neck of democracy, commodifying our digital souls in the altar of the algorithm.
The moral is clear: in the shadow of giants, the quest for power blurs the line between benefactor and tyrant. As Google and Microsoft carve their names into the annals of history, the question remains – will society awaken from its digital stupor, or will we remain pawns in their grand game, a footnote in the epic saga of the corporate conquest of the digital frontier?
There are other places to go, without hosting your own: GitLab and BitBucket are two possibilities.
Honest dumb question, how is Google benevolent in comparison to MS these days?
Slapping the Google name over the DoubleClick business model was the greatest swindle ever pulled, and people STILL don't see through it.
Citation needed
In my opinion a little bit more care must be taken here:
The "don't be evil" slogan was in my opinion both a blessing and a curse for Google: a blessing in that people initially trusted that Google does not intend to do something evil; a curse in the sense that when they started doing things that were considered "evil", it lead to a massive reputation damage for Google.
The closest thing to PRs that I knew was reviewboard, and that was a bolt on to SVN, not an actual proper integration
I would argue it's the other way around. Mercurial is a better source control system, and was a close contender with git back then. However, GitHub winning the hosting war and also being all in on git is what cemented git as the leader. Bitbucket was hosting both and with a more generous free plan, but they didn't win the social and UX fight so git became the de facto standard since that's what you used on the cool good new platform.
Also.. aggregators like freshmeat.net used to exist and did a huge amount of work patching these disparate communities and individual sites together into a single cohesive display of "open source."
My point, since you replied to my post, was simply that prior to GitHub, none of the other sites for OSS were trying to achieve the same goal. The goal was to establish a specific OSS community for a set of projects. SourceForge was a bit of an outlier in that a lot of projects used their distribution network, if they were not part of a foundation like Apache or Eclipse that had extensive mirrors setup.
SourceForge was never the main development and collaboration site for any of the major efforts happening around OSS.
But prior to that, I don't remember it feeling scammy at all, it was just the place to go for software. After that, the very same look and feel had been tainted, and now felt like a trap. Still does.
There were mailing lists, issue-trackers, forums, and similar things but each page load took like five seconds and the site was ugly.
I switched from using it after it got a reputation for wrapping downloads with malware, or with "toolbar helpers", etc. I'm sure the projects had to sign up to it at the start, but it always felt abusive.
Back then there was some discovery options, but of course I browsed freshmeat[.net] back in the day to see announcements of new releases, or new projects.
Github won for being useful and awesome, but also SourceForge lost because of self-sabotage, stagnation, and neglect.
(Wasn't there a buyout at some point? With Slashdot/others being bought by Dice? I know SF.net has changed hands a couple of times, but that was the first one I remember in 2012 or so? That probably didn't help)
Not a lot of surprise something else was able to outcompete them with new ideas.
Management and IT didn’t understand why they would want these things. Very few companies internalized these practices and usually learned the hard way to adopt them.
So back then these were somewhat new and radical ideas. But along comes GitHub, focusing on massive ease of use, and outsource an annoying hassle of most dev teams.
At the same time it was becoming more common to use open source libraries at work. But only sporadically and cautiously. I remember the work to get Boost (C++ lib) approved by legal. And that’s an extremely mainstream library. Often you would have to purchase or just write a lot of foundational code yourself.
So making a hosting solution with all these bells and whistles, but easy to learn, while also making it possible to discover code was fundamentally life altering for software engineering.
- lightweight site, no ads
- either had tons of features sourceforge didn’t or sourceforge’s site was bad enough I never noticed the features
- gave me, and companies, a reason to create an account and actually engage with it—I think maybe sourceforge was one of those sites that required login for larger downloads (hazy recollection, may be wrong) but I certainly never used it for anything else, if I had an account. GitHub? Issue tracker on repos for software you use, free hosting even just for unimportant junk repos (all I’ve ever had, myself), maybe sending the odd PR, having an account is nice and they didn’t even need to break out the stick to make it nice (though now they have, because normal and non-aggressive use of their site will get you rate-limited very fast without an account—jerks, forcing me to log in even if I’m just searching for something real quick and don’t need any logged-in features)
- LAME mp3 : https://sourceforge.net/projects/lame/
- KeePass : https://sourceforge.net/projects/keepass/
(Some people keep asking the KeePass developer to move to Github but he doesn't want to because "I'm not going to maintain a version control system." : https://sourceforge.net/p/keepass/discussion/329221/thread/9...)
Any other notable examples besides those 2?
Edit: or downvote, sure!
"I won't do work to have a VCS"
Yikes.
Lazarus, I think.
I spent part of today choreographing the first part of a massive 30,000,000 LOC SVN to Git migration for my employer with ESR's (phenomenal!) `reposurgeon`. Never underestimate the long tail of database usage, even code data. (Any port in a storm, of course, I'll take Subversion than no VC at all any day of the week.)
Learning this aggressively and increasingly niche skillset is why I wrote https://andrew-quinn.me/reposurgeon/ earlier this week. I had trouble even finding SVN repos in the wild to practice conversion on.
Subversion:CVS was like NVMe-SSD:HDD, and Subversion:Perforce was like SATA-SSD:HDD.
Git:Subversion is more like RTX2080:RTX3080, or, say, '78 Datsun 2080Z:'93 Acura Integra.
BETTER, yes, sure, yes.
OMFGIGOTTASWITCHNOW!!!!, not really.
I'm glad to see that the article includes this in their history.
And as bonus, it well matched the timing of social-networking rising..
(Apart of srcforge doing shit itself..)
Let's not forget git came up. It may have a lot of sins but it's better for distributed work. Utility libs and software switched to git, other devs got used to it and started to use it themselves...
Then a few git hosting solutions showed up. That not only allowed hosting public projects but you could also host your private commercial (or just private) projects on them. Either free or for pay.
Then github offered unlimited private repos with unlimited users for like $9/month. That was before the MS acquisition.
End of story...
…
I mean, yes that's literally the idea, but you do see why it's not happening?
I emailed the support email explaining the situation, and within a few hours got a reply from Chris saying that he’d fixed my repo, along with some advice about how to avoid this issue in the future.
A byproduct was the naming/addressing of projects was built around a person (or company), then the project - usera/project1. Anyone else could take/fork their own project1 - userb/project1, userc/project1, etc. Interested in project1? You could look at various versions/forks of it through the perspective of different users, because the user was first, not the project.
EDIT: further... github really put the control back to individuals. anyone could start anything, vs trying to get ideas committed in to a project. Some of this is the nature of distributed vs centralized, but github still made it convenient to just get ideas out there. Setting up a repo takes a few seconds - my memory was sourceforge took a lot longer - wasn't there some review process where you'd submit your project then it was approved for your use?
Github smartly made it user/project so the same project name can exist any number of times, and it is only the top level user/organisation that needs to be reviewed.
Unlike GitHub, where the source code is front and center, SourceForge always prioritized showing a project introduction page with screenshots and a big download button for the end user. SourceForge is where non-developers went to download cool freeware. It was like F-Droid for Windows. It was meant to be the official website for the projects it hosted, which is why it didn't host forks.
But the market for end users who download executables from random websites has been shrinking rapidly for two decades. Nowadays, either you're a developer and care about the source code, or you're an end user and just want to install that app from your favorite app store. Not to mention that most active open-source projects these days are made for other developers and not end users, so there's no point hosting them on a platform designed for end users.
> Git was custom-built for distributed democratized development
and doesn't mention how github and gitlab too severely lacks in this aspect?
Drupal, like a decade before git already, allowed multiple people to work on the same issue. This was reviewed by the community and then the committers and then it got merged. You still can't do this on Github and only through some drupal.org magic does it work on the Gitlab instance the Drupal Association has.
Some democracy.
But (in retrospect), I don't think it's really that complicated. SourceForge, back in the day, had a really atrocious UI. As a highschooler navigating CVS and SVN repos for the first time, it was really difficult to figure out how to even download source code (this was especially horrific with CVS on Windows), let alone contribute in any meaningful way. Discussion on these sites required you to sign up for a mailing list. I think Gmail was just barely a thing, but prior to that as a student I would have been stuck with some awful Hotmail account or similar. Anyway, the hurdles were high and therefore this selected for "serious" contributions (or people willing to put up with a lot of obstacles). SourceForge may have supported some sort of bug tracker, but I don't remember ever interacting with a project that used it, so in practice people were splitting their various components (code, mailing lists, bug tracker) between several different sites.
Ignore Git for a minute. GitHub, if nothing else, had a really slick UI. That UI put code front and center, so it was (finally!) obvious what sort of project you were actually looking at. I think it can't be underestimated how much this uniformity makes code easier to browse, as compared to the vast gulf in difference in quality between the best and worse homepages of open source projects prior to this.
For fun, here's one that I authored back in the day. The home page here is actually kind of informative, but you can see how if this is all you get, the results are going to be all over the place:
https://ip-interfaces.common-lisp.dev/
Beyond this, GitHub offered a permissionless collaboration. In the bad old days of open source, I could clone a repository, and I could write patches, but the cost of setting up forks was prohibitive. This is one of the things I didn't "get" at the time, but GitHub made it practically (and socially) acceptable to just fork whatever you needed, change something, and submit it. Or not, it didn't matter. Whether you intended for your experiments to be useful to anyone else or not, it dramatically lowered the cost of starting and maintaining those experiments. And that I think dramatically changed the face of open source software (for the better).
It had docs, issues and source code sections back then, but I can't remember if some of those features were spurred on by GitHub adding them first.
Do you know if there is a free and open-source software version control like Git but for UI? I know in Figma there is version control, even branches. But I'm thinking about something not proprietary and not attached to a tool.
And a more fundamental question, knowing Git, do you think that a version control for UI it is possible like what Git does for code?
One of the truly genius moves that Github made, was to put projects behind each account namespace. It's my view that this is one of the core things that made GitHub so attractive to people.
Github also came out around the time Git was maturing just enough, and subversion wasn't really pushing into collaborative features.
Now we see tools like Gitlab starting to get the abilty to customize and integrate with other things.
The only thing I like better about Github is the dashboard for managing MR's/issues/notifications. Gitlab still hasn't managed to figure that out. Gitlab CI was also miles ahead of Github CI for a long time. Github is better now, but CI is one of the few things that really locks you into a vendor. Plus, Gitlab had much better enterprise pricing options for a long time. I'm not sure what it's like now. I don't have any numbers, but I suspect that Gitlab has more market share when it comes to locally hosted deployments.
As a contributor it's a little harder, more so for stuff with non standard processes like sourcehut or cgit.
As a maintainer there can be much more significant differences around bundled features like CI systems and issue trackers. (Though I am of the opinion that where possible, CI should just be calling makefile steps or your language's tooling equivalent)
However, I agree that this is ultimately not a huge barrier.
Despite that, it's clear that users won't cross that barrier. As a project maintainer on not-github, you'll get less attention, less feedback, less contributions on other platforms. I think there's a bit of a relation to how sticky services like search engines are despite 0 barrier to switching.
So that's something that you will need to weight up when choosing a platform, regardless of whether you as maintainer have difficulty doing the switch or think others do.
Maybe maximising contributions isn't an important goal for you, but I can see why many projects before have made that decision.
Of all the forges, Sourcehut arguably has the most standard processes - mailing lists for issues, and git-send-email for contributions. I especially love the latter, because it means I don't have to register and create a repo fork etc. just to contribute a patch.
> ...as a market matures, solutions become specialized and modular. We've already seen this begin to happen in a few areas of "social coding." Jira and Linear offer modular issue tracking, while Jenkins and Buildkite offer modular CI solutions.
Those modules existed a long time before GitHub. Bugzilla was an issue tracker in the 1990s. Popular CI tools like Jenkins and Travis launched around 2010 while GitHub Actions didn't exist until 2018.
a more interesting question is why did Github win out over Bitbucket (I know the answer to this also, it begins with Mercurial and ends with "Atlassian buys them", but in the middle it gets into interesting questions about source control systems, issue trackers, etc).
GitHub not having anything like that made it way more useful.
During SourceForge’s decline, most OSS projects were either very prolific, general purpose libraries or full software packages, all of which had most of their infrastructure sorted. There were a number of other platforms, now mostly forgotten, that tried to acquire the displaced market shed from SF’s former userbase. Almost every one of the new platforms wanted to just be a better SourceForge, but none of them wanted (or thought to) to tackle the problem of git hosting as their primary product they were selling to users - which ultimately proved to be what the market wanted. OSS devs with a project likely already had an issue tracker, website, discussion forums, etc, and they didn’t want to spend their day in a CRUD app manually managing releases and fielding support requests on a platform that different from what they setup already. GitHub offered public git repository hosting with a modern look that was betting on companies buying commercial-oriented features as a monetization strategy, rather than ads. Eventually, a-la-carte features such as issues, discussions, and wiki were added, but were able to be toggled at the project-level.
Meanwhile, SourceForge was too busy cramming more ads in, cluttering layout, trying out asinine social media integrations, and ultimately, accelerating their (at this point) well-deserved) death by packaging malware/adware in software distributions. It was easy to see in the moment (and even more in hindsight) how much of a loser strategy this was for SF. It’s almost comical how spectacularly they fucked up their own market share with short-term thinking and outright stupid ideas. Not much love was lost here by the end.
Without GitHub, npm would not have been successful (which itself inspired other package managers), CI/CD would either be a bigger mess or dominated by a single vendor (which enabled fun stuff like infrastructure-as-code), coding in general would not be as accessible, and git itself may not have won out as heavily as it did.
GitHub’s success is a good case study in a startup being at exactly the right place at the right time, with the right product. The result wasn’t the mass migration of prolific projects immediately moving in, rather it enabled this back-pressure of micro-OSS projects to thrive because now it became viable to build a library that does one thing really well without the admin work of managing a full-blown OSS project. A number of projects eventually moved in, but the driving force to adoption, in my opinion, were the tiniest projects that ultimately proved this platforms viability.
People always say this but it just isn't even remotely true. Even if we ignore the "obvious" issue of, well, issues and other important project data that isn't part of your git repository, if you try to "pack up and leave" you will rapidly find that your github.com URL is now distributed around the entire internet as if it were your home page and is even embedded into other peoples' build scripts as the core problem was never the data you are hosting but is actually the identity and address of that data. The reality is that GitHub using git is no different from any other hosting platform, such as Instagram or YouTube. Yes: your content on YouTube is "merely" a bunch of video files and those video files could just as easily be hosted on any other video hosting provider as video files are about as boring and standardized and portable as can be imagined, yet obviously we wouldn't say anyone can trivially "pack up and leave" their decade of investment into a popular YouTube channel.