8 ms·
Open sourcing our Android and iOS apps
- ocdtrekkie 10y agoThis is pretty awesome. Just because an app connects to a single website/service doesn't mean there isn't a benefit to being open! It's good to be able to trust (and verify) the software running on our devices.
- dublinben 10y agoPeople can also learn from, and build upon the code that they've written.
- IgorPartola 10y agoThis. There is really no downside to doing this, and lots of potential upside. I honestly think most companies could do this with zero effect to their bottom line.
- wmichelin 10y agoIf your code is bad, then there's risk of making security vulnerabilities more visible. Not that that's a good reason to avoid open sourcing, but it's a reason.
- IgorPartola 10y agoWhich is also a good reason to open your code and let those that know better help you fix it.
- Alupis 10y ago> Which is also a good reason to open your code and let those that know better help you fix it. This is a fantastic mentality, but unfortunately doesn't really play out in reality. I'm a huge Open Source fanboy, but we need to be "real". How many people are really going to read every line of every open source program? Very-few-to-none is the real answer. Massively popular software gets eyeballs, but few others do. Most of us just use the software and trust/hope someone else reviewed it for security et al. The problem with that is, we are all trusting/hoping someone else did a review, but that someone else is trusting/hoping someone else did a review.
- IgorPartola 10y agoHow many of the people that do review your code would exploit it vs reporting it to you? Combine it with a bounty program, and chances are you will get useful feedback at a fraction of the cost of a full on audit.
- Alupis 10y agoI agree with the sentiment of your post, however I believe it is based on an ideal world, which we don't live in. > How many of the people that do review your code would exploit it vs reporting it to you By nature, attackers would be reviewing your code as well. > Combine it with a bounty program The overwhelming majority of Open Source software was created-by and is curated-by a single person who makes negative profit by working on the software for free in their spare time. Even some of the most popular projects are still total losses for their curators. You're not going to get bug bounty programs here. For example, take a look at Crosstool-ng[1] (a popular project used to build cross-compilers for various architectures). Companies and individuals are all using this project to build cross-compilers that they trust to build other software with. A bug in Crosstool-ng could propagate into bugs in the compiled software it produces. Bryan Hundven does most of the heavy lifting on this project by himself, and as far as I know, he's paid nothing for it. You're not going to get a bug bounty program here either. Heck, it's doubtful even a project as large as the Linux Kernel would be able to afford an ongoing bug bounty program. They're trying with the Linux Foundation and the Core Infrastructure program, but how many years before did it have none of that? Essentially, these programs only work for commercially-backed software, which is only a small sliver of open source software. [1] https://github.com/crosstool-ng/crosstool-ng https://github.com/crosstool-ng/crosstool-ng
- IgorPartola 10y agoBut I am specifically talking about companies with closed source apps and services open sourcing them, not tools that are already open. Examples are Uber, AirBnB, and Groupon, not gpg or OpenSSL.
- 10y ago
- bigiain 10y agoIf widely used and critically important open source projects like OpenSSL can have latent security bugs lying in them for years (Heartbleed?) - I don't think it's practical to assume "the open source community" will security-audit and send pull requests for your "open sourced" product app. If you want your code security audited, pay a reputable firm to conduct an audit. Throwing it up on Github and thinking "the good guys" will spend time looking and contact you for free when they discover problems is misguided at best.
- V-2 10y ago> This. There is really no downside to doing this, and lots of potential upside. I honestly think most companies could do this with zero effect to their bottom line. And - if the code is good, clean, modern - attracting talented coders that way. Showing me such code is million times more convincing than all the usual slogans
- exclusiv 10y agoNot that it would be easy to compete with Kickstarter anyway, but what about enabling clone competitors?
- krschultz 10y agoThe apps don't really matter. I was the Android lead at Gilt and we often talked about open sourcing our app. We ended up open sourcing our iOS one (https://github.com/gilt/cleanroom https://github.com/gilt/cleanroom). We were a company with a thousand employees, most of them not writing code. If you wanted to compete with us, copying our app was 5% of the overall effort, and what would you really get from our app that connects to our (closed source) backend anyway? The upside was enormous in terms of recruiting, retention, and keeping engineers excited. Kickstarter is in an even better position. Their defendable advantage is the network effect of being the go-to place for crowd sourcing.
- EdJiang 10y agoYeah, definitely! Another cool example is the pre-alpha for Linode's new management UI: https://github.com/linode/manager https://github.com/linode/manager
- tthbalazs 10y agoI had a chance to see Brandon from Kickstarter talk about their functional approach at the Functional Swift Conference in Budapest. I highly recommend watching it! https://www.youtube.com/watch?v=A0VaIKK2ijM https://www.youtube.com/watch?v=A0VaIKK2ijM
- goblin89 10y agoThanks for the link. Watching so far, many of the points Brandon makes vaguely resonate with how I approach structuring my code, but knowing the common vocabulary (f.ex. the term ‘co-effect’) enables me to communicate how and why I do things, and ultimately to improve. Out of curiosity, how much were the tickets and how early was it sold out? I was in Budapest right at that time to attend our remote team meeting, and I’m cursing myself for not knowing about this conference.
- unsoundInput 10y agoKudos to them. Compared to the web it's rather cumbersome to poke into packaged and released mobile apps, so I really appreciate access to the source of a real world app for learning and comparison. The Android codebase looks very modern and well structured. I think it makes great use of many of the goodies (gradle, rxjava, retrofit, dagger, android support lib, ...) and learnings (bring your own MV*; use Fragments when you need them, stick to Activities if you can) that is state of the art in Android development. I think it's a great thing to skim through if you are interested in developing for Android or to compare it to you own app. I can only assume that the same is true for I iOS. I'll certainly check it out should I start developing for that platform.
- fareesh 10y agoWas thinking about this the other day, now in the context of this release it comes to mind again - it would be kinda cool if it was a common practice for tutorial folks to make a repo where they forked the entire thing and placed comments all over which were links to videos that broke down those sections in an easy to understand way.
- V-2 10y agoYeah, they sort of rolled out their own MVVM implementation, based on RxJava and RxLifecycle. On Android MVVM is more difficult than MVP in my opinion (the most popular choice, not counting spaghetti projects), mostly because the platform doesn't provide the "glue" needed to bind viewmodels to the UI layer. At first glance it looks like they did it without overengineering, which is another trap as far as these matters go. Clearly a work of very good experts
- Plaastix 10y agoThat "glue" can be Android's Databinding library. I've used it to bind ViewModel data to views. Works really well.
- V-2 10y agoI'm aware of it, but last I checked it didn't seem production-ready and lacked features. I believe they updated it at some point, but other than some talk at Google IO not much came out of it - even the docs didn't reflect it back then. Perhaps it's up to the task now, I admit I'm not looking it up regularly.
- shmerl 10y agoGood! I try to avoid closed applications on my mobile devices if possible.
- dblock 10y agoFor anyone reading their post, we're so humbled by Kickstarter mentioning the tiny Artsy for having inspired some of this work. If you're interested in the open-source by default conversation and need some ammo to bring this to your team, start at http://code.dblock.org/2015/02/09/becoming-open-source-by-default.html http://code.dblock.org/2015/02/09/becoming-open-source-by-de...
- SimonSelg 10y agoThis is awesome! Open source production apps are always useful.
- afro88 10y agoThis is a really great example of how to do it right when it comes to Swift, MVVM, Reactive Cocoa, Testing, CI etc. Lovely code and architecture!
- mwcampbell 10y agoI wonder if they've considered using something like React Native or Xamarin so they can share some of that functional-style code between the two platforms.
- melling 10y agoThey use Swift Playgrounds to do a lot of development: "Swift Playgrounds for iterative development and styling. Most major screens in the app get a corresponding playground where we can see a wide variety of devices, languages, and data in real time." https://github.com/kickstarter/ios-oss/tree/master/Kickstarter-iOS.playground/Pages https://github.com/kickstarter/ios-oss/tree/master/Kickstart... I've recently bought into this development method too. It's not quite what Bret Victor dreamed up, but it's a big step in the right direction.
- j_s 10y agoIs this similar to Xamarin Workbooks? https://developer.xamarin.com/guides/cross-platform/workbooks/ https://developer.xamarin.com/guides/cross-platform/workbook...
- ohstopitu 10y agoLast year when I was working on a startup's mobile app for Android, it was almost impossible to find good quality code that was open sourced. I am really happy that Kickstarter has released their android app as open source - would definitely be a great learning experience!
- Plaastix 10y agoThere are quite a few "sample" open source projects that demonstrate best practices and various Android architectures. However, they are not fully fledged production applications like the Kickstarter app.
- ohstopitu 10y agoThat's the entire issue, I've seen quite a lot of "sample" apps that do one thing (like nav bar, or fragments, or animations etc.) But each of htem brings their own libraries, and don't explain what what's necessary and it's left to the user ot decide to how stitch all of this together. Don't get me wrong...I'm happy for the demo apps (they had made my life a lot easier), but a production grade app is a whole different ballgame.
- dublinben 10y agoF-Droid is full of "real" apps that are completely open source. You can look at any of them to see how they work.
- rezashirazian 10y agoThe iOS app looks like a treasure trove, I can't wait to download it and dissect it. It'll be interesting to see how they integrated playgrounds into their development cycle. I just wish they had upgraded to Swift 3.0
- john_gaucho 10y agoThis is great. I hope they also provided good documentation / commenting. This can be a fantastic learning tool for programmers at all stages. Kudos to kickstarter.
- perfmode 10y agoWhat's the purpose of Android's ApplicationGraph interface? https://github.com/kickstarter/android-oss/blob/888a3746835835016fc1a1bb32d8e2a90b8bffce/app/src/main/java/com/kickstarter/ApplicationGraph.java https://github.com/kickstarter/android-oss/blob/888a37468358...
- adhil 10y agoLooks like they're using Dagger2 (https://google.github.io/dagger/ https://google.github.io/dagger/) for dependency injection.
- krschultz 10y agoThis is very exciting. There simply aren't a lot of open source "full scale" Android apps. Most of what you find are quick sample apps which simply don't show the complexity inherent in most professional apps. The largest other ones I'm aware of are Github, Google I/O, and some of the AOSP apps.
- 120bits 10y agoI'm not a mobile app developer by profession. But I always wanted to start learning and developing real world apps. The problem I always ran into the tutorials and demos, that they are mostly limited(i.e not close to solving real world problems). I think browsing their code, will give me a good start. And I would know how it's done right! Thank You!
- ywecur 10y agoI have the same problem. If anybody has any good resources, please let me know.
- wapz 10y agoTruthfully, I think you're better off with the tutorials and demos. Good ones will split up how to achieve what you need to achieve. Diving into a huge app like this will be confusing to figure out how everything is working. If you are already familiar with Android/iOS, then I think looking at these bigger projects can really piece everything together (but you wouldn't start with say rxjava and rxlifecycle on your own before understanding Android).
- BuuQu9hu 10y agoLots more open source Android apps on f-droid: https://f-droid.org/ https://f-droid.org/
- nodamage 10y agoHaving looked through this project I would not recommend using it as a basis for learning how an iOS app is "done right", as they've deviated from standard iOS/Swift paradigms significantly. In particular, the use of ReactiveCocoa and MVVM creates an app that is structured completely differently from a "traditional" iOS app. They've also used (abused?) Swift's ability to define custom operators which results in a lot of code like this: self.youLabel |> authorBadgeLabelStyle |> UILabel.lens.textColor .~ .whiteColor() |> UILabel.lens.text %~ { _ in Strings.update_comments_you() } Which again is very different from regular iOS/Swift code. That said, I think this project is interesting to look at from the perspective of "this is what it would look like to go all-in with ReactiveCocoa and MVVM". It's kinda like Twisted in Python: Twisted code looks very different from normal Python code, cause once you start using Twisted, it becomes Twisted all the way down.
- stirner 10y agoOpen sourcing a client is pretty useless when the bulk of the logic happens inside a company's server somewhere.
- EGreg 10y agoDoes this mean we can clone it now or does the license prohibit that?
- alexashka 10y agoiOS Project does not build - Xcode 8.2... There is a guard statement with no else clause, that's the first error I got. I didn't bother looking further because... a guard without an else could never compile, so what am I looking at? I'm getting flashbacks from my last workplace where people merged in code that didn't compile and then went 'oh really? let me fix that real quick'... Code wouldn't compile in master but the codebase... everything had to be clever. We can't just have a model, a network request to fetch/update for it, a view controller and view cells. A few storyboards and of course no bloody tests - it's a phone app. No, we need protocols everywhere we can fit them, third party libraries - ones that haven't been out a few years (Reactive whatever), a third party library to make a basic GET request (Alamofire looking at you), a CSS styling library, a JSON to Model library, list goes on. What we don't need is folder structure that lets you know this is the initial VC, the two folders beneath it are the 2 possible places you can go, the sub-folders in there are the places you can go from that VC and on and on. Let's just dump all VCs in one folder, all cells in another. Nevermind that in 90% of the cases, that one cell is only ever used in that one tableview - no need to group those together. I don't know - maybe it's just me - I'd rather I download a zip, open the project, click that triangle and it runs - this thing makes me jump through hoops, and it still doesn't work... And nothing makes sense, unless you go learn reactive cocoa - based on the amount of files/code, a clear waste of time.
- perfmode 10y ago> Download the Xcode 7.3.1 release. The app requires a different version. https://github.com/kickstarter/ios-oss/blob/master/README.md https://github.com/kickstarter/ios-oss/blob/master/README.md I concede. There are issues getting the dev environment configured.