4 ms·
I believe this is a big problem with git or any of the current repo gui providers. A repository should not be able to be forked if it doesn't have a SPDIX licen
by intertextuality 7y ago
I believe this is a big problem with git or any of the current repo gui providers. A repository should not be able to be forked if it doesn't have a SPDIX license. Or at the very least users should be able to turn off forking ability in the repo settings.
It's usually not an issue but I have run into some small repositories that had no license, meaning I could -not- fork and modify for myself or a PR, legally. But this is not obvious at all unless you look for the license file or a manifest file.
- jdsully 7y agoGitHub require you license public repos to allow others to fork it. Whether they can use it for a specific purpose is still questionable - but clicking the fork button on github is allowed. They agreed when they uploaded the code. Note that this is governed by GitHub’s TOS and supersedes anything in the License file.
- intertextuality 7y ago> If you set your pages and repositories to be viewed publicly, you grant each User of GitHub a nonexclusive, worldwide license to use, display, and perform Your Content through the GitHub Service and to reproduce Your Content solely on GitHub as permitted through GitHub's functionality (for example, through forking) So I can "perform" and "reproduce" content through forking, solely on Github. But I couldn't clone it, nor make modifications to my fork, if I read that correctly. It makes little sense and could be avoided altogether by disabling forking for un-licensed repositories. Or by simply giving all new projects a default (with an opt-out option for no license or alternate licenses).
- jdsully 7y agoIt makes more sense if you understand the license is about protecting GitHub and not you. A disabled fork button unless the repo did a positive action would dilute the whole concept. The fork feature is key to the whole thing and is what made them different.
- mlindner 7y ago> Or at the very least users should be able to turn off forking ability in the repo settings. This is absurd. You don't have to use the "fork" button to copy a repository. It's as simple as cloning it and pushing it. Such a restriction servers no purpose at all.
- intertextuality 7y agoObviously such an implementation would disable cloning as well.
- tlrobinson 7y agoWhy bother putting it on GitHub then? I expect to be able to git clone anything I find on GitHub. It's on you to determine how you can legally use the code.
- jcims 7y agoGitHub would obviously also have to make the repo private as well, and then get into the business of interpreting and potentially defending the compatibility of their service against various licenses before making it public. That's unsustainable.
- ajhurliman 7y agoThe onus is on the end user to make it private.
- nailer 7y agoJust thinking aloud, but GitHub could warn, when setting up new projects that don't have an OSS license, that the user may wish to make the repo private.
- HenryBemis 7y agoI have a small iOS app, not too big, a few thousand lines. My idea was to use Github, but then I didn't want to go through the cost/effort, and I am using my own version system, AWAY from everyone. The only way for someone to get my code is: a) laptop gets hacked b) laptop gets stolen (disk is encrypted), c) backup gets stolen (carbonite is encrypted) d) Apple gets hacked. Git should not bother people with a bunch of different alerts (imho). A COMPANY (apologies for the caps) that has been working on code for "a few years" and doesn't do the MINIMUM to protect their Intellectual Property (IP)... well that is suicide. Don't they pay someone with GRC/Audit/Security skills to put some sense into them????
- fsloth 7y agoUh, if you don't wan't to fork, don't make it public in the first place? Code escrow is another thing, but that does not mean everyone needs access...
- intertextuality 7y agoThe two aren't necessarily mutually exclusive, although yes I would agree with you. -In the case- of a repository being public without a license however, forking and related things should still be disabled to prevent licensing headaches.
- atq2119 7y agoThis shows a fundamental misunderstanding of how git works. The main point of putting something on GitHub is to allow people to git clone it. Every git clone is a fork of the project. If you don't want something forked, don't put it on GitHub.
- intertextuality 7y agoI understand how git works. I'm discussing the edge case scenario where someone uploads something but doesn't add a license. In that case, forking and cloning should be disabled, at the least.
- arbie 7y agoIIUC, you are suggesting that GitHub make new repos private by default, unless a permissive license is set. This seems a reasonable balance.
- soulofmischief 7y agoIt's antithetical to their business strategy. They charge for premium accounts to give access to private repos. Nothing wrong with that, but OP should probably try out Gitlab if he wants an enterprise-level solution for free.
- notimetorelax 7y agoLaws are different in different countries, e.g. it is not against the law to consume pirated content in Switzerland, but is illegal to share it further. So, if I have a pet project for my personal use then I can pretty much use anything I can find on the internet.
- isostatic 7y agoBy hosting on github aren't you sharing it further?
- deleted 7y ago[deleted]
- michaelmrose 7y agoNeither git nor github can automatically discern how the law applies in context in 195 nations without consulting a lawyer and honestly neither can you. Unless you want to pay thousands of dollars per repo presumably everyone is going to continue not giving a damn. If you don't want people to clone a repo don't upload it to a public github repo. If you are thinking of cloning realize that the ability to clone it gives you zero legal rights. Anyway you cannot fix legal complexities with technology in this instance.
- Kinnard 7y agoThis could be a problem for ricardian contracts and/or smart contracts
- krageon 7y agoThose don't solve anything, because the core problem is a human one. It needs to be legal in all the countries that they might apply to, and that still requires a lot of expertise. The person you are responding to says "this is a problem technology can't fix", I assume this is the reason.