Gitea blocks PR from community, charging $$ for open-source contributions
github.com
github.com
> Unfortunately, they have already merged a version of this code into the private gitea repo and are charging $$ for it. So Gitea Ltd. (owners group) has no incentive to review and merge this in an open source repo, even though the open source community has funded and developed it.
> This is a cynical take, but I have raised these concerns in private channels and there has been no evidence to refute it. If Gitea Ltd. wants to focus its efforts on the private fork and to make money, that is fine with me, but unfortunately, they also decide what gets merged here, so there is a massive conflict of interest (cough open core). Since Lunny has blocked it and refuses to say why, it appears we are stuck.
> I have asked them to commit publicly to not merging code in their private codebase that is still open for review upstream, but that hasn’t been well received, leaving me and some other members of the community pretty disheartened.
I mean obviously that's fine legally, it's MIT licensed, and also his company contributes code to Gitea. But, it seems rather hypocritical to complain about the maintainers of Gitea having a private Enterprise repo for profit, when the person complaining does the exact same thing.
[1] "AllSpice Hub is based on a fork of Gitea, so you get all the power and functionality of Gitea, but with the hardware specific features that let you see schematic changes instead of binary blobs." https://allspice.io/post/which-git-clients-work-for-hardware...
Gitea's stance regarding why certain features are Enterprise-only is quite reasonable: "Many features, and enhancements are prevented from being included in the Gitea project due to high upfront costs, and lack of resources to maintain them. This leads to them not being developed or accepted into the project. With this offering, we are able to provide a version to paying customers with a support contract, allowing us to develop and maintain these features for the Gitea project." https://docs.gitea.com/enterprise/faq#why-is-this-a-paid-off...
That certainly sounds like it would apply to this particular PR, which is a 4000-line diff affecting 144 files, and with a 350+ comment discussion history spanning over 16 months. Review, cleanup, and long-term maintenance for this sort of PR are faaaaar from free. I can understand 100% why this would be an Enterprise-only feature, and complaints about the maintainers' profit motive in that context seem utterly ridiculous to me. Especially when the commenter is complaining about a "massive conflict of interest" when not mentioning his own extremely similar conflict of interest.
It may be expensive; that’s why there was a community-funded bounty placed on it.
If the complaint is that Gitea is too complex to maintain for free, then great, start a company around it to fund a private fork. But then you shouldn’t be allowed to stop the community from merging their own crap in their own fork that they maintain and care about. Since Gitea LTD is the gatekeeper of both repos, that is the conflict of interest.
It's not clear yet that the Enterprise version of this feature is the same code as this PR, right? Do you have evidence otherwise?
> It may be expensive; that’s why there was a community-funded bounty placed on it.
How much was the bounty, who funded it, and who receives it? I don't see any information about that on the PR or the linked issue.
> you shouldn’t be allowed to stop the community from merging their own crap in their own fork that they maintain
If the community really maintains it 100%, then they would all be maintainers and by definition they would be able to merge it already. That doesn't appear to be the situation here.
> Since Gitea LTD is the gatekeeper of both repos, that is the conflict of interest.
Do you really think it is accurate to say Gitea LTD is merely gatekeeping and not actually doing a ton of work to steer and maintain this project?
And since the complaining commenter is CTO of a company who benefits from being able to include this feature in his company's own private fork, doesn't he have a conflict of interest as well?
Absolutely not, and I never made that claim.
> How much was the bounty, who funded it, and who receives it?
I happen to have some inside knowledge here, that at least Allspice and Copia provided parts of the bounty. Some of that is mentioned in the thread but the transparency could be better.
> Do you have evidence otherwise?
That was the thrust of the submission. I tried to link the fragment but I don't think Hacker News allows that and erased it: "Unfortunately, they have already merged a version of this code into the private gitea repo and are charging $$ for it. So Gitea Ltd. (owners group) has no incentive to review and merge this in an open source repo, even though the open source community has funded and developed it."
As for conflicts of interest, perhaps. Who knows the actual extent of it? Posting here is intended a matter of visibility rather than activism; that's why I'm so surprised that the thread was closed on grounds of brigading, since that was neither the intended nor the actual effect.
Can you please link to whatever part of this bounty is public? I just expanded searched the PR comments for "bounty" and absolutely nothing came up, and likewise on the issue linked from the PR.
In any case, if the bounty is coming from companies other than Gitea Ltd, and it presumably will be paid to the PR submitter (and not to Gitea Ltd), then how does this bounty help compensate for the massive amount of time Gitea Ltd employees spend on code review and long-term maintenance of this huge PR?
> That was the thrust of the submission. I tried to link the fragment
That quote is an unsubstantiated claim from the commenter making the complaint. It might be accurate or it might not. As a neutral third party I have no way of evaluating that, as no evidence has been presented. Personally, I haven't flagged this thread, but I can absolutely understand why others did so, given the complete lack of any concrete evidence of the main thing being claimed here.
One does not preclude the other.
> And since the complaining commenter is CTO of a company who benefits from being able to include this feature in his company's own private fork, doesn't he have a conflict of interest as well?
He isn't controlling what goes into community repo, so that's irrelevant.
If they've merged that code but refuse to make it available in the community version - when it's been contributed by the community - that's one (very uncool) thing. It's slightly different if they already have the feature from homegrown code and they don't want to merge a second version in the community version which causes additional maintenance headaches for them.
Gitea was already controversial in the sense - why leave a perfectly good closed source solution (GitHub) to another closed solution?
I think, for anyone seriously into self-hosting their source codes - https://forgejo.org is the way forward.
That said, I'd like to see more information before we jump on the outrage bandwagon. The only thing we have here is a PR that was blocked by a maintainer who's not very communicative and the speculation of a random participant in the PR discussion that they're intentionally blocking the merge because of a conflict of interest with the enterprise version. That's not a lot to go on, and there are other possible explanations besides malfeasance.
edit: we (the project and the company) are also receiving advice from several major open-source foundations on what establishing a foundation for the project would look like.
[0] This announced Gitea Cloud but gave no explanation for why a second for-profit was created instead of just using the already-controversial Gitea Ltd: http://web.archive.org/web/20231127091431/https://blog.gitea...
CommitGo, is the largest contributor to Gitea, and has contributed Actions in its entirety to the project. If the goal is to keep code away from the project for profit, that would be the one.
The priority of the company is to ensure the continued success of Gitea.
Public shaming might be a good tool for this kind of thing in general but maybe in this case it was premature.
If somebody wants to embrace YOLO with their $$ project and be a bit more cautious with their OSS project, that's ok.
I'm just pointing it out because I think it's going to be a tricky balance to strike. How can we, as a community of people who care about free and/or open source software tell the difference between:
- a good faith effort to inform the wider community of a maintainer who is behaving badly
- a bad-faith contributor pressuring an overworked maintainer to include a malicious commit
I think you're the former, but I'm rather worried about the latter. And I'm interested in strategies for telling the two apart.
We can’t rely on everyone to follow our schedules, so if there’s a desire we should take the lead on getting it done instead of dragging each other down. As such, I didn’t post this to shame anyone, mostly to provide an onus for switching to a fork. (Or I should say, another onus, since there are already a few reasons to not contribute to Gitea, mostly coming down to size of the project and inertia preventing refactors or redesigns.)
I suppose they could merge it, copy it under the MIT license, and then remove it, which overall seems kind of silly, but it would at least get your PR merged. Plus, this trick would look really bad from a PR perspective.
After all, nobody is currently prevented from maintaining Gitea with the linked PR merged. The problem is that the major community maintainer is prevented from merging it due to a conflict of interest. License juggling won't help with that.
Your proposed "trick" does not seem to achieve anything - the code is still not present in the main ditribution, no?
My proposed "trick" was just to illustrate that it's futile to make a contribution MIT licensed for some people/purposes and not others. I think we're in agreement on this.
> So clarification here: you asked me about that, but I haven’t been able to respond to you due to my illnesses and I’m just getting back on my feet now. So it’s not that it hasn’t been well received, it’s that I’ve been physically unable to respond to you.
[0]: https://github.com/go-gitea/gitea/pull/24257#issuecomment-23...
> Unfortunately, they have already merged a version of this code into the private gitea repo and are charging $$ for it.
So if they can be trusted at face value, "a version of this code" means it's the same code, and would be an incorrect way of describing "an analogous feature with an unrelated implementation". But they could be making a mistake, of course.
I added more details here for the curious: https://news.ycombinator.com/item?id=41489578
Considering the supposed evidence was deleted, I'm not just going to take your word for it (next time, use archive.org or similar). But either way, I don't care. The software works very well for me, and stroking an egomaniac or two's ego is a small price to pay for that.
I'm relatively confident it was on archive.org and has been purged by the Forgejo team. There's only one entry on archive.org and it's a month after the event.
And I agree—the software works and I use it and I'm less sketched out by Forgejo than I am by Gitea. I'm just explaining why I'm not going to sink anytime into contributing to their project.
Yes, the 3k+ LOC, 144 file PR is 1 year old and still not merged. Join the club.
But it's likely the paid Enterprise edition has merged this already, and now the same entity has an incentive to block this from the OSS version.
Says who? A random commenter on the thread who's not even the submitter of the code?
The reviewers of the OSS code are still heavily incentivized to block this PR. Worse, if they knew a similar feature was being built for enterprise and this would never be merged into the free version, they be wasting months of contributors' time and effort.
"Blocking" would suggest to me that the PR is rejected but still ends up in the closed-source codebase, which isn't the case at all.
@dang I flagged this because we're at risk of brigading a community over a nothingburger.
Is this fact, or just speculation? I read the start and the end (though not the 175 items in the middle), and all I see is a vague block by a maintainer and speculation that it's because they have a similar feature in enterprise.
Stall may have been a better word, although this PR has been crawling along for over a year now, with little response from the maintainers. If something is neglected for long enough it’s topologically equivalent to blocking it.
That is literally in bad faith.
This is a PR that was funded with a bounty with the idea of contributing to open source.
Now is a great time to switch to Forgejo :-)
I'm not sure how to write the subject that way, within character limits, but there is zero outrage at charging $$ for OSS contributions, so the subject seems very "meh".
After all, millions of companies do that.
Switch to the fork of the fork - brilliant. Especially when the fork fork doesn't seem to do much except bicker and merge controversial PRs on occasion.
What controversial PRs have they merged? I haven't heard about that and it makes me a bit nervous, but I'm not finding anything obviously wrong searching for it.
Someone on HN linked a discussion where Forgejo was appointing a moderator [0] and had received pushback. A critic of the decision had said something along the lines of "this person has severely abused authority in this community in the past and I'm not comfortable with them getting new authority". They went back and forth for a bit with the maintainers, but by the time the link ended up on an HN thread they'd edited out the critic's comments with a warning not to post ad hominem attacks. At the time you could still read the critic's actual comments in the edit history and it was clear that they were being very reasonable.
A few weeks later I went back to that thread and the entire discussion with the critic was gone. The moderator was appointed, and all record of the dissent was eliminated. If you go to that issue thread now, there are 10-12 comments that I read before that are now missing, and it looks like this person was appointed without dissent.
That sketched me out, and I've been very cautious of Forgejo since. I trust Gitea even less, so I stick with Forgejo, but I wish I had better options.
https://codeberg.org/forgejo/forgejo/pulls?q=&type=all&sort=...
Not sure what your claim about "doesn't seem to do much" is based on.
I agree the name isn’t great. Very awkward to pronounce using English phonetics.
But anecdotally, I have seen a lot less red tape contributing there and a lot less bickering than on Gitea, which is perhaps too big for its britches. Just a lot of discussion and very hard to get things done on the Gitea side.
https://github.com/go-gitea/gitea/pull/24257#issuecomment-23...
The years go by and the beggar attitude of open source users gets more and more tiring.
Expecting your volunteer contributions to not get paywalled is not a beggar attitude…
Gitea specifically has a track record of taking advantage of the good will of open source contributors, which is why the forgejo fork exists.
> When you submit a PR to a business’s intellectual property, it’s still theirs.
Nope, contributions do not "belong" to the receiving project unless explicitly agreed so. They were created under a license, and are (usually) reciprocally licensed to the project. The owner is and always was the contributor.
To call someone a beggar for asking for their code back is beyond belief.