8 ms·
You may finally use JSHint for evil
- ricardobeat 6y agoThe project has been "rewritten from scratch" [1] in order to sidestep the legal requirement of preserving the original license (from JSLint, which it was forked from), against both the original authors' wishes [2]. A whole lot of post-rationalization of how the unconventional license caused the project to slow down: http://mikepennisi.com/blog/2020/jshint-watching-the-ship-sink/ http://mikepennisi.com/blog/2020/jshint-watching-the-ship-si.... Certainly not due to ESLint's extensible design, customization options, better error messages, ES6 and JSX support and adoption by multiple mainstream libraries. Legal implications aside, it's still sad to see that 'do no evil' is so hard to agree with. [1] https://jshint.com/relicensing-2020/index.html https://jshint.com/relicensing-2020/index.html [2] https://github.com/jshint/jshint/issues/1234#issuecomment-23187063 https://github.com/jshint/jshint/issues/1234#issuecomment-23...
- gizmo686 6y ago> Developers from the Debian and Fedora GNU/Linux distributions independently concluded that they could not include JSHint due to licensing concerns. Without knowing anything else about the project or its competitors, I would absolutly expect that being excluded from major repostories would hurt its adoption.
- jcfields 6y agoThe part that explains why this clause (originally written by Douglas Crawford in the JSON license) is a problem for free software: > If you’re not versed in legal matters, that probably seems like an odd restriction. By rejecting JSHint, are people admitting that they want to do evil? And is that clause actually enforceable, anyway? > The answer to the second question is “no,” and that helps answer the first question. Legally-conscious objectors aren’t betraying their own dastardly motivations; they’re refusing to enter into an ambiguous contract. Put differently: they’re not saying, “I’m an evildoer,” they’re saying, “I don’t understand what you want.” This consideration disqualified JSHint from inclusion in all sorts of contexts.
- draw_down 6y agoI think people who create works should choose whatever license they see fit for their work. It doesn't really matter what the license is. If that later proves a hindrance for the specific aims of others, well. Actions have consequences.
- ricardobeat 6y agoAs an admirer of the WTFPL it's hard to sympathize. The lawyers can still play their games in court, it's free software either way. The fact that a couple central entities get to decide what qualifies as 'real' open source is the most concerning part.
- sedatk 6y agoWTFPL isn't ambiguous though.
- duskwuff 6y agoYep. WTFPL, while profane, is unambiguous in its permissivity. It is perhaps ill-advised in its lack of a warranty disclaimer, but that's a problem for the developer, not for the end user.
- jahewson 6y agoThere’s a couple of other central entities which do actually decide what gets to qualify as a legally binding agreement and the WTFPL likely falls short of pleasing them.
- nemothekid 6y ago>The lawyers can still play their games in court, it's free software either way. That isn't true at all. If someone takes GCC, makes some changes and re-releases GCCv2 as closed source, there's no open source boogeyman that will force GCCv2 developers to release their code. It's up to courts, and by extension lawyers. Free software implicitly depends on lawyers to hold up the contract of Free Software. If lawyers tell you "this contract is unusable because of this clause" then you don't have free software, you have a weird proprietary license. The entire point of free software licenses is to define rules for lawyers to play "their games in court". It's worthless otherwise.
- dang 6y agoOk, we'll change the URL from http://mikepennisi.com/blog/2020/you-may-finally-use-jshint-for-evil/ http://mikepennisi.com/blog/2020/you-may-finally-use-jshint-..., which has the catchy title but is just a summary page, to the post you linked to, which seems to have the most information. Off-topic side note: Blog post series are a problem for HN because usually only one element in the sequence gets attention, meaning readers only get part of the story. Alternatively, more than one thread gets attention, but then the discussion is split and we run into the problem of follow-up posts [1], i.e. the exponential decay of interestingness under repetition [2]. So from an HN point of view it's best to just make one long article on a given topic—but that's just the local perspective. [1] https://hn.algolia.com/?dateRange=all&page=0&prefix=true&query=by%3Adang%20follow-up&sort=byDate&type=comment https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que... [2] https://hn.algolia.com/?dateRange=all&page=0&prefix=true&query=by%3Adang%20can%27t%20predict%20from%20sequence&sort=byDate&type=comment https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...
- geofft 6y agoIt is my religious belief that we all do evil, at least a little bit, at least sometimes, even if we wish to do good. As St. Paul said, "For I do not do the good I want to do, but the evil I do not want to do—this I keep on doing." That means that I cannot, in good conscience, use software that requires me to agree that I'm not doing evil. If your conscience is confident that your use of JSLint involves no evil - that you are sinless and blameless - I'm happy for you. Unfortunately I cannot say that of myself. (And if your conscience lets you say that of your employer and all your co-workers, I really want to know where you work.)
- Zarel 6y agoI disagree with the implication that the "do no evil" clause in the license should be no big deal. Imagine the library had some code like: if (get('http://example.com/am-i-evil') === 'yes') { fs.delete('/', recursive: true); } And the author assured you "oh, it's just a joke, it's no big deal, we just want you think think about not doing evil, but we wouldn't ever actually use that to delete your hard drive". Imagine your security team's reaction if you told them those exact words. The license clause is pretty similar from a legal perspective, so of course your legal team would freak out. I think this also makes it clear why the problem doesn't have anything to do with wanting to be evil, but with not wanting to trust someone else's definition of evil.
- Lazare 6y ago> Legal implications aside, it's still sad to see that 'do no evil' is so hard to agree with. I disagree that you can ever put the legal implication aside when discussing license terms. The legal implications are the entirety of what's being communicated by a license, which means you're basically saying "if you ignore what these words mean, nobody should disagree with them". That's very true! It is easy to agree with something if you ignore what it means. And?
- iandanforth 6y agoWriting software is not a neutral act. You are morally responsible for its uses. Restricting those uses is both a responsibility and a good. Circumventing this restriction is itself an immoral act.
- tkzed49 6y agoSo if I just write "you're not allowed to do bad things with this" in the license agreement, I'm covered?
- nathanaldensr 6y agoNo, you're not. This is an argument that doesn't hold water. Why am I morally responsible but none of the abstractions below my code are not? What about chip manufacturers? The developers of CPU instruction sets? Compiler developers?
- iandanforth 6y agoThey are. Why wouldn't they be? We put people in jail for distributing potentially harmful tools to people who are known to desire to harm others. This is not a new or controversial idea.
- umvi 6y agoName one tool that has not been used to kill someone or commit an immoral act
- iandanforth 6y agoThis attitude disturbs me, it tries to absolve responsibility by denying the possibility that responsible behavior is possible. That's not just obviously false, whole troves of law cover exactly this point, individuals and corporations have responsibility that follows their products.
- umvi 6y ago
- jancsika 6y ago> The Software shall be used for Good, not Evil. It's so funny because Crockford is one of the most persuasive speakers and coders on avoiding ambiguity, on readability over coders desire to "express themselves" in code, and on making language design decisions based on research. He then takes a step outside his area of expertise and chooses to express himself with an ambiguous license created without consulting anyone who has domain expertise in software licensing.
- ptx 6y agoHe also made some strange linguistic choices in his latest book[1]: "The word for 1 is misspelled. I use the corrected spelling wun. The pronunciation of one does not conform to any of the standard or special rules of English pronunciation." [1] https://howjavascriptworks.com/sample.html https://howjavascriptworks.com/sample.html
- knolax 6y agoSide note but that is the best typography I've ever seen in an HTML document.
- mhh__ 6y agoThere are a few latex mimicking CSS styles with a similar vibe, I suggest having a look at those
- ChrisSD 6y agoIt is quite amusing that he thinks the English language has "rules" as though it were a well designed programming language.
- erikerikson 6y agoThe rules of a language are its conventions.
- dgellow 6y ago
- ed25519FUUU 6y ago> The Software shall be used for Good, not Evil. I get that software developers add these things to licenses in good humor, but lawyers have no humor unfortunately. If you want your project to be used in a serious way, it's better to leave the ambiguous phrases out of your license and choose something standard.
- easton 6y agoWell, JSON is used in a serious way, in fact I doubt you can use most web applications (and many desktop apps too) without your machine parsing some json. And... https://www.json.org/license.html https://www.json.org/license.html
- umvi 6y agoBut JSON isn't software, it's just a specification. Any text that matches the specification is JSON, whether it is binary, a string, printed on a piece of printer paper, etc. So what does this license mean, exactly?
- thephyber 6y agoThe JSON License was created to cover the original Crockford JSON parsing and linting libraries.
- kelnos 6y agoThat license does not cover the JSON spec; nearly all JSON parsers are not distributed under that license. I assume Crockford's original reference implementation of a JSON parser is released under that license, and not much else.
- Rebelgecko 6y agoMy employer specifically forbids us from using the json.org license because it's not considered FOSS
- gjs278 6y agowho cares? if they want to be stupid, let it hurt their company.
- runarb 6y agoI have found it funny that Douglas Crockford apparently gave IBM this exception: "I give permission for IBM, its customers, partners, and minions, to use JSLint for evil." (for JSLint, which JSHints was forked from): https://web.archive.org/web/20170722132351/https://dev.hasenj.org/post/3272592502/ibm-and-its-minions https://web.archive.org/web/20170722132351/https://dev.hasen...
- oefrha 6y ago> ...licensing concerns. That’s why Ubuntu users can’t download JSHint via sudo apt-get install jshint. Okay, this is misleading. You can install tons of non-free packages using apt from the official archive. They are in the multiverse section. http://archive.ubuntu.com/ubuntu/pool/multiverse/ http://archive.ubuntu.com/ubuntu/pool/multiverse/
- yongjik 6y agoSorry for commenting on the formatting instead of contents, but how could someone say "The following graph shows how many times JSHint has been downloaded from npm each week over the past five years" and then present a graph with four data points? Frankly that makes me doubt the author's central piece of evidence (that JSHint gets much fewer downloads than ESLint). * Graph from this URL in case it changes again: http://mikepennisi.com/blog/2020/jshint-watching-the-ship-sink/ http://mikepennisi.com/blog/2020/jshint-watching-the-ship-si...
- acemarke 6y agoHere's a better set of charts, using the `npm-stats` site: https://npm-stat.com/charts.html?package=jshint&package=eslint&from=2015-01-01&to=2020-08-04 https://npm-stat.com/charts.html?package=jshint&package=esli...
- TallGuyShort 6y agoI've also had customers dig their feet in because I depended on this library: https://dst.lbl.gov/ACSSoftware/colt/license.html https://dst.lbl.gov/ACSSoftware/colt/license.html. Exactly when what you're doing is considered a military application is ambiguous. Have an obscure DoD contractor as a customer? Uh oh - can't use this...