Why did you relicense it under Elastic License 2.0 from VSCode’s MIT?
A better alternative would be proprietary extensions under a different license like Microsoft does.
Why did you relicense it under Elastic License 2.0 from VSCode’s MIT?
A better alternative would be proprietary extensions under a different license like Microsoft does.
We talk a bit about why we chose the Elastic license here: https://positron.posit.co/licensing.html
We have thought pretty carefully about what kind of functionality works well in extensions (in fact, we build and maintain a number of extensions!) and came to the decision that the more integrated data science experience we wanted to make required forking.
Also, are you using Open VSX, and what’s your take on the recent malware extension story?
We do use OpenVSX, yes, like the other forks, and our company is a major sponsor of OpenVSX. Security around the extension ecosystem is a pretty messy, complicated issue both for the proprietary Microsoft marketplace and OpenVSX. For example, the recent Amazon Q story! I currently think about it as conceptually fairly similar to the risks of using packages from PyPI or npm.
There is no doubt that your company maintains a lot of high quality open source code.
But in this case Posit is re-licensing Open Source code, with a "source available" license.
Posit is free to help itself to VSCodium, but not the other way around.
I do hope Posit will one day reconsider this.