I’m surprised gmail spam filters didn’t catch this.
I worry that someone may be trying to incorporate a sophisticated supply chain attack. Step 1. Troll maintainers, Step 2. Find someone to maintain who can accept malicious code. Step 3. Track where this goes
> Also, I will consider turning it over to an interested party, but I will require at least one recommendation from a Node.js core contributor that I can vet with the people that I know on that team.
Maybe not a perfect solution but it's something. Granted, a new fork might become popular but people could rightly call it into question given this statement.
Maybe. I had not considered that, but it might be right.
There are mitigations of such an attack although you will have to be careful; such mitigations might not really stop it if you are not careful.
I also worry that "hey reminder that" really doesn't do much on the internet, except maybe give the troll their moment in the spotlight.
Granted, as I say in my other comment, I don't have an magical solutions to this kind of thing :(
There are 7 billion people and at minimum, tens of millions of them are massive assholes and idiots.
I mean, there is though?
"Just get over it", "need thicker skin", "the cost of doing business in open source", etc.
You did it in your own comment even. Making excuses for shitty behavior, as if it's some natural law like gravity.
What do those sentences mean, if not suggesting that the maintainer is the one who made the wrong decision (by taking offense to the email)?
They mean that I don't see really any value in your framework of 'fault' vs not. We are still left with the question of 'what do you do'.
For a project of this magnitude, I don't think the maintainer made the wrong decision. But just because someone else is at fault does not mean that every decision by the other party in response is a good one.
My point was: I don't think this post will serve as a reminder to be nice to OSS maintainers (as the original comment I replied to was saying), because the majority of comments I see are some variation of "toughen up" directed at the maintainers.
Statistically speaking, the likelihood that there's an asshole somewhere that you'll run into in the course of your lifetime is near 100%, so it is some natural law like gravity. Do you have a proposal for a solution to this problem, or are you just calling people victim blamers for acknowledging that these people exist?
If someones only contribution to the conversation is blaming the victim of harassment for not have thick enough skin, they shouldn't be surprised to be called a victim blamer.
The maintainer can decide what to do about it. Whether or not that is the wrong decision is a different issue. (Anyways, there are many other reasons why it might not be maintained, than only due to receiving such a email message; e.g. because you are injured or because you have other work to do (which is what is mentioned in the README.md file anyways), or whatever other reason that maybe other people don't necessarily know.)
Nevertheless, some people who will maintain the project (not necessarily this one, and not necessarily) should do so even if people send such bad messages. That does not mean that everyone will; what they decide to do about messages they receive is their own choice. This is why FOSS is important; you can fork the project and make your own modifications, if you disagree with the maintainer.
It made me realize that fundamentally these are just people, people generally are helpful and nice, and they also like hearing positive things said about them. It was a good lesson to learn at a fairly young age.
[1] To be clear I was extremely polite, no criticism was tossed their way!
The important context is the app had its own custom keyboard. I used the app personally, and recommended it to a customer to solve a problem they were having. It turned out that the newest version would not work because it had removed some of the Fn-keys.
I e-mailed the developer to ask for some guidance. At the time I figured it maybe had something to do with the viewport size, and was just trying to diagnose the issue. (I had an iPad mini, while the customer had purchased I think a 9th gen iPad. I wanted to know if a different device would solve the problem.)
The guy e-mailed me back and was like "Oh, yeah, I changed that last week while making the new keyboard layout. I'll revert it and push out a new build." - I had a similar epiphany at that point where it was like "this guy is a dev just trying to navigate tradeoffs and ship the best app he can." - Also the tradeoffs are never as straightforward as one would think.[1]
I suspect a lot (most?) of apps in the App Store and the Play Store fall into this category, just like most repos on Github. People are putting their projects out there; obviously they're not immune to criticism, but I think it's important to remember that most of these people aren't Tim Cook, they're not making a living promoting stuff and taking shit people throw, they're just engineers sharing code with the world.
> Also the tradeoffs are never as straightforward as one would think.
Yep, completely agree; the obvious "solution" is to make everything configurable, and that can work to some extent, but then you risk an "oops I reinvented interpreters" moment, and then you made the app impossible to use for non-geeks. There's almost never a "correct" way to do it to satisfy everyone.