Sunsetting Jazzband
jazzband.co
jazzband.co
The real gap is that there's no natural mechanism for projects that are critical infrastructure for many companies to capture even a tiny fraction of the value they create. pip, Django, and the whole ecosystem that Jazzband helped steward are worth billions in aggregate business value. Their maintenance costs a few thousand dollars a year in volunteer time.
I don't think licensing changes alone fix this. Companies have legal teams that can route around them. What might actually work: large package registries (PyPI, npm) implementing a voluntary but strongly encouraged funding mechanism where companies self-report their usage and contribute to a foundation pool. It would need to be opt-in and friction-free, but even 10% adoption from mid-sized companies would transform the economics.
Indeed, but it also failed due to the same reason: a bus factor of 1 in terms of who administrates the whole thing.
Each project could have multiple maintainers, but Jazzband itself (e.g.: the infrastructure, org, etc) had a single person responsible, and this didn't scale.
I don't mean to bash on the person who took charge on this BTW, I'm merely describing the situation. I greatly appreciate the enormous effort taken during so many years!
a) volunteers
b) brief windows in which corporate decision makers are driven by ideology and good intentions, where those decisions carry momentum or license obligations (see Android, and how Google tries to claw it back)
c) corporations attempting to shape the larger landscape or commoditize their complement, see Facebook's work on React, or contributions to the Linux kernel
Of the above, only (a) or rarely and temporarily (b) are interested in collective wellbeing. Most of the labor and resources go into making moats and doing the bare minimum to keep the shared infrastructure alive.
Now companies selling LLM coding agents enter the scene, promising to eliminate their customers' dependence on the commons, and whatever minimal obligations they had to support it. Why use a standard solution when what used to be a library can now be generated on the fly and be part of your moat? Spot a security bug? Have an agent diagnose and fix it. No need to contribute to any upstream. Hell, no upstream would even accept whatever the LLM made without a bunch of cleanup and massaging to get it to conform with their style guides and standards.
Open source, free software, they're fundamentally about code. The intended audience for such code is machine and human. They're not compatible with a development cycle where craft is not a consideration and code is not meant to be read and understood. That is all to say: yes, it is unrealistic to expect companies to donate anything to the commons if they can find any other avenue. They prefer a future where computer programs are purchased by the token from model providers to one where they might have to unintentionally help out a competitor.
This is misguided. Maintenance of LLM code has a far greater cost than generating it.
> They prefer a future where computer programs are purchased by the token from model providers to one where they might have to unintentionally help out a competitor.
I don't think that's even a thought. The thought is that "no one can tell me no".
In corporate reality they don't care. They have their product, requirement. As it starts to rot it's easier to rebuild than to maintain.
If you can ask for an LLM with a skeleton crew team now they can do it all again in five years time with the next level of LLMs.
It was true, but I'm not sure if it's still true in the age of LLMs. Maybe we are moving into the era of disposable software.
Services are what the majority of devs already work on and maintain. There's almost no incentive for anyone to use LLMs for that outside of startups. They do indeed last a long time because the code is as fundamental to the recurring revenue of the business as their legal or accounting or marketing. Devs make changes according to the evolving needs of the business, and "productivity" isn't as much of a priority as accuracy and reliability. The implementation details are very relevant to the business, especially for B2B services that need to meet compliance requirements.
Products, however, have always been disposable code written by people being thrown into a meat grinder. I don't think LLM-generated code is better, but it's probably not that much worse either.
I agree. I'm just observing what they're doing.
> I don't think that's even a thought. The thought is that "no one can tell me no".
I doubt there's any one thought driving things. I didn't mean to imply the existence of some grand strategy or scheme. The preference I speak of isn't of any person, it's the direction pointed at by incentives and circumstance. Companies will make decisions to steer clear of helping competitors. Separately, they signal great interest in replacing costs spent on labor with costs spent on services. See the transition to cloud. The result is the preference of a world where code is like gasoline, purchased from a handful of suppliers for metered cost.
For the next generation of OSS, it would be wise to stand together and introduce a new licensing model: if a company builds a product using an open-source library and reaches a specific revenue threshold (e.g., $XX million), they must compensate the authors proportional to the library's footprint in their codebase and/or its execution during daily operations.
The MIT license and other "pushover" licenses was built in the pre-LLM era.
I don't think it is fit for purpose anymore since now maintainers are getting burnt out and most code is now being generated from OSS.
A new OSS license for the AI age must be made for newer libraries, projects and existing projects that want to change licenses.
The only model I've seen work in reality is open core (aside from the very few projects that have been successful with patronage)
People have been saying this since the 80s. Reality is that without open source, this industry would be tiny compared to what it is. So many times open source has enabled an entire sub industry (i.e. ISPs in the 90s, Database, SaaS in the 2010s, now AI). And most of it is someone solving a problem that was worth solving for their own use, and for whatever reason made no sense to commercialize by selling licenses.
> on the backs of ten thousands of now-burnt-out maintainers.
Money isn't the motivation for most "free" open source. If it was, the authors would release as commercial software and maybe as "source available". That someone can use open source to build businesses has been the engine for the entire industry. In other words, the thought that maintainers quitting maintaining is some problem that can be fixed if we only paid them is non-sequitur. A lot of it is that people age out, get bored with their project, or simply want to do something else. Not accepting money for maintaining open source is a good way to ensure it stays something you can walk away from and something where the people attached to the money have zero leverage.
I do think that a lot of maintainers struggle with pushy and sometimes nasty people that take the fun out of what is a "labor of love."
> exploiting entities have never shared substantial or equitable profits back.
If I want to make money, I sell commercial software, SaaS or PaaS.
> they must compensate the creators proportional to the library's footprint in their codebase and/or its execution during daily operations
One of the more interesting uses of open source is to level the playing field. For example, there was a time when database was silly expensive. Several open source products emerged that never would have been viable commercially without the long term promise of "free" and the assurance of having source code. To have a license with a cost bomb on it would just ensure that people would use another choice.
Especially as the cost of producing code drops, the value of libraries decreases.
Does it? If the cost of slop that (1) no one understands, and (2) no one can be sued for if it misbehaves drops to zero, what have we gained? A "library" is code plus reliability and accountability. (Yes, GPL disclaims liability, but that's why consultants exist.)
I'm not saying all libraries will go to zero values, just that their value is decreasing.
If you want to make money, make commercial software and sell it. It's funny to see people complain about people taking what they gave out for free, it's like having a lemonade stand with a huge sign saying "free" and being surprised people take the lemonade.
Oh, by the way, when you use it and are dependent on it, give me big bucks.
Companies optimize for profit, all else be damned, no matter the damage they cause to the world around them.
In that sense, I fully expect companies to extract all value they can from Open Source without paying not contributing nothing in return.
The world would be saner if more people understood that.
> 60% of maintainers are still unpaid.
That's actually not as bad as I would have guessed.
Not sure what exactly prevented him from accepting more people into the role of "roadies"...
I would say that having roadie level access is equivalent to having access to Django core. I have never seen a recent Django project that isn’t pulling something from jazzband
Despite this I think it’s important to highlight that even in that world jazzband had a lot of infra so that projects could do things like releases cleanly and safely (we aren’t doing direct project releases to pypi but going through jazzband infra to do the release). So release maintainers have a lot less access despite releases “coming from” Jazzband
Maybe it could be mitigated by having some kind of council and requiring m out of n signatures to do anything?
I know that people on HN hate Bitcoin, so I'm always a bit vary to use it as an example.
But I think that in such cases having something similar to Bitcoin multisig could help.
It’s not so much about decision making as it is about the practical reality that people at that level basically need at least read access to a lot of secrets.
You could say “maybe jazzband can infra its way out of those problems” but that’s a looooot of work! “N out of M consensus on making a GitHub API request to set who is a maintainer” * every single action roadies need to do
It’s not just about bad actors either. Imagine a jazzband roadie getting credentials stolen via some npm-y attack. Obviously this problem exists in the project in the current form but _that problem gets worse just onboarding people_
Maybe jazzband can't infra their way out of the problem, but maybe we can create some tools that will help orgs that encounter this problem in future...
... that's a software engineer in me talking. I have no idea how to organize communities, but I may know a thing or two about making software. And when you've got a hammer in your hands everything starts looking like a nail...
In most corporate environments while it might make sense to do N of M in the high security case it's not really a thing that people will jump for for the first... uhhh 10k employees of a company's lifetime.
As an N=1 example, I myself have some experience with various Django packages including some Jazzband ones. Around 7 years ago I looked at this organization, thought about volunteering to be a "roadie", and specifically decided not to do so due to the terminology. I'm pretty sure that something like "Looking for trusted co-maintainers with a history of FOSS contribution" would draw in more folks than "Looking for roadies".
If you're going to say "well no one complained", guess what, I didn't either. People will just quietly decide to not volunteer due to stuff like this; leading to a shortage over time.
Summary: Branding and acknowledgement matters, so check carefully what you call the volunteers that you're expecting tens of hours of free work from.
Is my best guess. The GP is perhaps referring to ghostty repo adding helper files for Llm agents to operate as a cursory look at issues to placate issue submitters.