37 ms·
Why we’re changing to the AGPL license
- jph 6y agoGood choice IMHO and good explanation of your learning curve, and how to create the values you want. The AGPL and GPL are both well worth a look if you're building a software project. Similar to the authors, I recently helped a group move from MIT to GPL-2, for the same kinds of reasons: open collaboration among all users.
- markosaric 6y agothank you! i guess you can say that we were a bit naive about this whole permissive license thing so it now feels better to have some of the protection that AGPL brings
- corty 6y agoI agree. Picking too open a license is a danger for OSS-based corporations, which the original article explains nicely. Glad they recognized the problem and fixed it, instead of succumbing to the Scylla and Charybdis of BSD-style openness and closed-source copycats.
- emptyparadise 6y ago>This is the best way to future-proof the project against bad actors, including ourselves if we become evil at some point. By allowing open source forks and competitors to exist, we are opening ourselves up to healthy competition and accountability from the open source community. Major respect for recognizing that and not doing anything like dual licensing or CLAs (at least as far as I can tell).
- markosaric 6y agothank you! the easy / "obvious" choice was to close source but this was not really something we wanted to consider. we're in the privacy first space and we want to stay fully open source. AGPL should hopefully protect us better from similar commercial threats in the future
- jarofgreen 6y agoHello, can you confirm exactly what you are doing here? If it's AGPL with no CLA or anything, how are you doing "They can purchase a commercial license to remove the copyleft restrictions"? EDIT: Asking because I'm genuinely interested in this issue and am currently making license choices myself - not trying to have a go!
- markosaric 6y agoFor now we just changed to AGPL as a defensive move to avoid these threats. It was an unplanned move that we didn't even think about few days ago. Next step is really to consider what we want to do in the future and if necessary add a CLA before we merge next contribution. We never planned to do any commercial licenses (we're focused on our Cloud offering) but it seems like a valid option in case of these corporations who want to resell our product but not open source their modifications.
- jarofgreen 6y agoI see. I would definitely urge you to consider this very soon: AFAIK you can't do any commercial licenses with AGPL without A) some form of dual license and CLA or B) just never accepting pull requests from anyone. But also, does this also apply to your own cloud hosted offering? Without sorting this out, all the software in your cloud hosting product now has to be fully open-source. And I get that's your philosophy, but would there not be any tiny bit you want to keep closed - maybe the anti-fraud stuff around your billing system, for instance? This seems a key point that I'm very interested in, so sorry for pushing!
- Conan_Kudo 6y agoAGPL doesn't work the way you think it does. An anti-fraud system service can easily communicate with Plausible over a network connection through an IPC interchange (HTTP, gRPC, etc.) without triggering that issue. The extension to Plausible to support that itself would be AGPL, but the anti-fraud service itself would not have to be.
- Hitton 6y ago>Major respect for recognizing that and not doing anything like dual licensing or CLAs It's nice, but in my opinion there is nothing wrong with doing it either. It might be even good thing if it ensures stability of the developer. If it turns out the original developer with dual licence/CLA is no longer good, community can continue from the AGPL version on its own and if the original developer wants to incorporate these new community changes, the AGPL will "infect" the dual licensed version.
- wegs 6y agoMy opinion is that we've been burned by this enough times that it ain't worth it. Most recently, Oracle rolled back Java. If I'm buying into an open ecosystem, it's because I want an open ecosystem. I don't want a use-open-to-gain-market-dominance-and-than-milk-customers ecosystem. AGPL is ideal for things I don't need to link proprietary code to. What I most want is a plausible, paid, AGPL competitor to GSuite.
- jarofgreen 6y ago> So how can a corporation commercialize a FOSS project without open sourcing their modified code? They can purchase a commercial license to remove the copyleft restrictions and in that way support the original project. Looks like they are doing something like dual license? Can the company comment and clear this up?
- pwdisswordfish4 6y agoIndeed. That would also require CLAs unless they aren't taking in outside contributions.
- wegs 6y agoIt looks like they are doing one license, AGPL, without CLAs. They provide a hosted service. Others can also provide hosted services, They can't get a competitive advantage with proprietary "value-adds." Usually, the authors have significant reputation and branding advantage, so unless they f- up, competitors are bottom-barrel low-cost providers. AGPL without CLA is whom I tend to gravitate to.
- ksec 6y agoUnfortunately there are lots of companies with Zero AGPL policy. I remember there were some BSD/MIT + No Business Clauses license. I wonder if Plausible discovered someone else selling software based on their code? Although my guess is that it shouldn't matter much? Most people would want Hosted Analytics. So Open Source is only there for insurance.
- Nokinside 6y agoThat's not unfortunate. That's perfect. Zero AGPL policy means that they can purchase a commercial license to remove the copyleft restrictions. For small or midsize companies AGPL + full copyright ownership is usually the optimal solution.
- eeZah7Ux 6y ago> Unfortunately This is a deliberate choice from companies that want to exploit open source without giving back to the ecosystem.
- markosaric 6y agoYeah, seems like we got on the radar of some corporations recently. One company was promoting a proprietary, privacy first alternative to GA, we checked it out and several features/elements looked pretty much exact replicas of Plausible. The other was that we got approached to help someone build a direct competitor based on our self-hosted code. They were upfront that they didn't want to pay us and they didn't want to contribute back to the project. They did offer us publicity to their "tens of thousands" of customers!
- echelon 6y agoThe AGPL was a good defensive extension of the GPL, but the landscape has shifted and it's falling behind. We need an AGPL++. AGPL tries to target hosted services, preventing cloud companies from taking open source components without contributing anything back. But you know what the AGPL misses? Our data. We need open source licenses that require the systems that make use of them to provide data export and the right to be forgotten. We should encode the GDPR into our licenses. This would prevent Facebook from taking open source and using it to lock away our data. We should also fight back against embrace, extend, extinguish. Apple is trying to take over computing and prevent us from running our own software on our own devices. We should prevent them and anyone else trying to do this from using our software. No right to compute on your platform? Fine. No rights to open source software. We have to defend computing and open source, otherwise we'll all wind up using thin clients to access walled silos. And we'll be renting the access, too.
- chaosite 6y agoI agree with you that this is a problem, but I don't see how you can fix that with licensing. I mean, I guess you can add a clause that says "you can't use this software if you do things that the author doesn't like with it", but the point of the FSF software licenses is that they don't limit what you do with the software in any way, just how you can distribute the software itself. This is like trying to stop child porn using the license for encryption software.
- BuildTheRobots 6y agoThe GPL is all about protecting user freedoms. AGPL extended this to not just count for devices in your possession but to systems you remotely interact with. Adding a clause that says you must allow users their own data as well as a copy of the source code doesn't seem like a completely out there extension of those protections.
- chaosite 6y agoThe GPL is all about protecting a users freedom to use their software in any way they'd like, and correctly notes that users require access to source code in order to do that. Quoting verbatim from the preamble, "the GNU General Public License is intended to guarantee your freedom to share and change all versions of a program--to make sure it remains free software for all its users." It doesn't really discuss other sorts of freedom. I'd also note that RMS is famed for having (and sharing) many opinions, many of them specifically on the sorts of freedom we're discussing now, yet no such language has ever appeared in the FSF's licenses.
- andi999 6y agoSo tell me, this only applies to newer versions, doesnt it?
- sokoloff 6y agoIANAL, but: Yes. The rights afforded users to prior versions are covered by the license(s) of those versions. It would be a bad situation indeed if I could license my code under an OSS (or even commercial) license and then summarily revoke all those licenses by relicensing the code under new terms.
- shp0ngle 6y agoYes.
- jlgaddis 6y ago> The change will affect corporations that want to take our code and use it to create and sell proprietary tools that directly compete with us. Yes, folks, if you don't like the idea of a corporation taking your ("software-as-a-service") code and using it to create and sell proprietary products, then maybe don't license your code under the MIT License (or any of the others which explicitly allow exactly that)! I apologize for stating something that's common sense but apparently, as they say, "common sense ain't so common". The MIT License is my preferred Open Source License but the AGPL is completely acceptable, too. In fact, if you (intend to) form a legal entity and sell your code as a SAAS product, the MIT License is quite likely NOT the license you should choose! I don't blame these guys a bit for switching to the AGPL now but I can't stress enough that selecting the proper open-source license is an important decision for any "serious" project. Please make sure that you understand exactly what the terms of your chosen license really mean before you decide on it -- and if your stated goal is to "grow a sustainable open-source project", well, the MIT License (and similar) is almost certainly not the best choice. -- ETA: Also, props to Plausible for choosing the AGPL as the license going forward. As mentioned, going closed source would have been the "easy choice". Alternatively, you could have selected something like the "Commons Clause" or one of the other recent "open-source but not actually open-source" licenses. In my opinion, the AGPL was absolutely the best choice. I've never used your product -- or even heard of it before now -- and probably never will but thank you for your contributions to open-source nonetheless!
- franciscop 6y agoYup, the MIT is also my favourite license and I use it in all of my libraries. For products/websites that I might want to sell in some sort in the future, no. Well, maybe if it's a small "demo" project, but not generally.
- holtwick 6y agoWhy not EUPL? It is probably a good choice for a European based company and has comparable features. https://github.com/holtwick/briefing/issues/75 https://github.com/holtwick/briefing/issues/75
- johannes1234321 6y agoIf I am not mistaken the EUPL is copyleft and inspired by GPL. In the case here it's however about AGPL. AGPL has the extra thing, that source has to be given not only to somebody who received the software, but also to ones who access it as service via network. (There is some legal debate on the exact details) EUPL afaik doesn't have such a clause, but it's relevant for somebody who builds a "service" and wants to prevent others from running a private fork of it.
- holtwick 6y agoI'm not a lawyer, just a coder. I was under the impression, that offering a network service is also defined as 'distribution': https://choosealicense.com/licenses/eupl-1.2/ https://choosealicense.com/licenses/eupl-1.2/ I guess under (1) the "providing access to its essential functionalities" part is relevant: "‘Distribution’ or ‘Communication’: any act of selling, giving, lending, renting, distributing, communicating, transmitting, or otherwise making available, online or offline, copies of the Work or providing access to its essential functionalities at the disposal of any other natural or legal person."
- deleted 6y ago[deleted]
- deleted 6y ago[deleted]
- mtlynch 6y agoOne downside they don't mention is that the license restricts who can contribute to your project. When I worked at Google (2014-2018), it was easy to get permission to contribute to open source projects as long as the license was BSD, MIT, or Apache 2.0. The more restrictive licenses like GPL 2 or AGPL, I think Google either flat out denied or you had to do a lot more work to get permission. Now that I work for myself, I much prefer not having to ask anyone for permission to contribute to open source, but I generally default to MIT/Apache2 unless I have a reason to do otherwise, out of consideration for employees at Google or other corps who may want to participate in my project.
- slim 6y agogenuine question : why would you ask for permission ?
- sascha_sl 6y agoMaybe that's a concept unknown outside that bubble of software developers, but lots of companies stipulate this in contracts; maybe you don't want to risk getting fired in case you don't (want to) maintain perfect opsec for... a side project?
- jlgaddis 6y agoAt Google, et al, because that's what you agreed to do when you accepted the job.
- _msw_ 6y agoDisclosure: I work at Amazon where I build infrastructure servies for AWS Since Amazon is frequently lumped in with Google et al., I think there is common belief that they are roughly the same. Amazon has an Outside Activity policy that covers some employees (certainly all tech employees). For the vast majority of outside work activity that triggers the policy, you simply fill out a notification form that logs an affirmation that the activity does not trigger further review. The license of open-source software that you want to contribute to on your own time is not part of the policy that would trigger further review. In other words, so long as developing that software is permitted by the outside activity policy, you are free to develop and make software available under AGPL on your own time while being an Amazon employee.
- MattyMc 6y agoDoes anyone know the details on switching licenses? For example, how it affects previous versions? Can the copyright owner switch licenses at anytime? If there’s a resource in this I’d love to read more, too.
- tsss 6y agoIn the case of MIT license you can change the license of future and past versions as long as you have no other copyright holders (i.e. contributors) but that won't help you much unless nobody has actually made use of that license on previous versions. They retain that license and can still publish it under MIT even if you do not. I think revocation of the license is only possible when the terms were violated.
- cmeacham98 6y ago> For example, how it affects previous versions? It does not affect older veraions - unless the previous license has a provision for this (and I doubt many people would be willing to use software with such a license). > Can the copyright owner switch licenses at anytime? Yes, but many open source projects are made up of many copyright holders due to external contributors.
- jarofgreen 6y agoThe copyright owner can switch license on any future versions of the software at any point. But the complication is that if the software project is made up of contributions from 100 different people, it's not immediately clear who the copyright owner is. In the worst case you might have to get permission from all 100 people before you can switch. This is the problem contributor agreements were designed to solve. Of course, some people call this a feature and not a bug.
- kevincox 6y agoIANAL but I believe that you can always switch to a strictly more restrictive license because doing so is effectively licensing new changes with the new license. You can't switch to a license that is less restrictive without agreement of the owners because that would require granting additional rights to the existing code.
- sudhirj 6y agoJust to be clear, the AGPL still allows a company to take the the software as-is, without any modification whatsoever, and run it for their customers as a hosted service, right? That's why MongoDB had to add a new clause into the AGPL and make the SSPL? Why didn't Plausible go straight to SSPL?
- firepoet 6y agoI don't know why, but you might find this interesting: https://hub.packtpub.com/mongodb-withdraws-controversial-server-side-public-license-from-the-open-source-initiatives-approval-process/ https://hub.packtpub.com/mongodb-withdraws-controversial-ser...
- LaGrange 6y agoGPLv3 has an explicit permission to link with AGPL, but not SSPL - that means that if you're using SSPL, you can't link it with any GPL code.
- jlgaddis 6y ago> ... the AGPL still allows a company to take the the software as-is, without any modification whatsoever, and run it for their customers as a hosted service, right? Yes. In fact, they are even free to take the software, modify it, and run it for their customers as a hosted service. The key difference, however, is that the license requires that they must also let their user's download the source code of their version. -- In "Why the Affero GPL" [0], the FSF specifically mentions: > The GNU Affero GPL does not address the problem of Service as a Software Substitute (SaaSS). (Here, "Service as a Software Substitute" is the FSF's term for what the rest of the world refers to as "Software as a Service". According to the FSF, it "defines the bad practice more clearly and says what is bad about it.") Another of the FSF's articles, "Who does that server really serve?" [1], explains the problems with SaaS with regard to open-source software. -- [0]: https://www.gnu.org/licenses/why-affero-gpl.html https://www.gnu.org/licenses/why-affero-gpl.html [1]: https://www.gnu.org/philosophy/who-does-that-server-really-serve.html https://www.gnu.org/philosophy/who-does-that-server-really-s...
- orlandohill 6y agoThe Polyform Project's Shield and Perimeter licenses would have been better choices if they had wanted to stop other companies from selling hosted versions of Plausible. https://polyformproject.org/licenses/ https://polyformproject.org/licenses/
- marcan_42 6y agoIt's too bad they went with the AGPL, which is a vague and problematic license. For example, by a strict reading, it would seem that you can make changes, add the relevant functionality to link to the changed source code, then stick a proxy in front that removes the link and be in the clear. It also seems you could give the modified version to someone, and they could offer a service based on it without forwarding the source offer to end users. It's also unclear regarding upstreaming, and the "virality" of the source distribution requirement. As far as I can tell, for non-CLA projects, effectively there is no way for upstream to be exempt from the AGPL article 13 provisions, which means any AGPLed project that takes contributions needs to build in the source code offer functionality into the canonical version or else they'd be violating their own license (read: that of every other contributor, which is why this is a problem). Additionally, unless the software is written so that it can package its own source as-running and distribute it to every user, using the AGPL puts your users at risk unless you make it a proper click-through license that users must agree to before usage. Due to its nature, the AGPL is an EULA, not a free software copyleft license. Unlike other open source licenses, it is not a mere copyright license. Users need to be aware of its provisions of it, as they are liable for violations not strictly only by distribution, but also if they just run AGPLed software and happen to make a trivial modification, like editing a single template. This is, in concept, going into the "you shall not run this software on more than X cores" proprietary territory, because it makes the critical change of imposing on requirements outside of distribution, so users need to be aware of it just like they need to click-through proprietary EULAs. The AGPL really is not a good license. I wish people would stop treating it as a magic cure for the "SaaS loophole". Using it has deep consequences for your users and how the software must behave, and it isn't legally tested in a way that guarantees it even will protect you how you think it will. I hope people using it know what they're getting into. Here's a personal example of an AGPL problem, and how I violated it (as far as I can tell) by doing nothing out of the ordinary. I run dspam on my mail server. dspam is AGPLed (I did not know this). I use Gentoo Linux, so I just installed it, but due to politics/inertia Gentoo considers the AGPL as default-accept (which is supposed to be reserved for licenses that are free enough that users need not be concerned about), so I was not prompted to accept it during package installation (like I would have for proprietary packages). Unfortunately, Gentoo is a meta distro. They also carry patches for dspam. This means that by installing dspam, I was patching dspam and compiling it, thus triggering AGPL Clause 13. This means I was liable to make dspam source offers to all my users. Unfortunately, the definition of "user" is unclear, and it could encompass "anyone who sends me email through SMTP which gets delivered through a dspam filter" (or at least "anyone who has an inbox filtered with dspam", which includes a few other people on my server). Obviously I was unaware of all of this, and did nothing other than "emerge dspam" and configure it. So now I have potentially violated the AGPL (as have all Gentoo dspam users).
- tziki 6y agoAs someone who's been trying to figure out a good open source license for my software, I've had to remove AGPL from consideration. This is because I want companies to be able to use the software for their internal use but not be able to create a user-facing product out of it. For AGPL, anything it links to must also be AGPL licensed. If a company such as Microsoft wants to use my project internally, they'd be taking on a huge liability. Does this mean any project that depends on my project needs to also be APGL licened? Further, the terms on APGL are somewhat vague in a good-hearted attempt to prevent exploitation. What counts as 'use over a computer network'? If Microsoft developers use network disks to access my software are they screwed? For now I'm (somewhat unhappily) considering MIT the only option.
- jfk13 6y ago> but not be able to create a user-facing product I don't see how the MIT license would help you achieve this.
- garmaine 6y ago> This is because I want companies to be able to use the software for their internal use but not be able to create a user-facing product out of it. Why do you think the AGPL can’t do this?
- tziki 6y agoThe reasons I've listed are the same reasons I've heard from people in the industry on why large companies don't generally allow AGPL.
- garmaine 6y agoOk, well just so you know, that's industry FUD. Anything that is internal to the company will never have to have its source code revealed. No external users, no distribution clause, full-stop.
- corobo 6y agoCould you not do them an enterprise license that removes whatever restrictions? They're not struggling for cash
- eznit 6y ago"We have relicenced our software under a more restrictive licence" does not seem like something to celebrate.
- karterk 6y agoI was faced with the GPL vs AGPL dilemma when I started working on Typesense (https://github.com/typesense/typesense https://github.com/typesense/typesense): I wanted to protect future potential commercial interests without stifling the spirit of open source collaboration and development. I asked around for advice and eventually just chose GPL over AGPL because a lot of legal teams seemed allergic to AGPL and some companies even had a blanket ban on it. I also thought that the greatest risk for my project was not an existing or future competitor: it was death by obscurity. To that end, I did not want to slow down adoption by choosing a license that screamed "$$$" or made somebody's legal team uncomfortable. In any case, if a big company wants to copy you, they will and can with the resources they can throw at it. On the other hand, there are popular projects that do use AGPL (MongoDB) so it might not be that big of a deal in the real world :)
- enriquto 6y ago> I asked around for advice and eventually just chose GPL over AGPL because a lot of legal teams seemed allergic to AGPL and some companies even had a blanket ban on it. So, in other words, you succumbed to F.U.D. (Fear, Uncertainty and Doubt).
- thecureforzits 6y agoOne look at the comments in a typical HN thread about FOSS shows how good a job the big players (Google, Apple, Microsoft, etc) have done turning what was a threat into an asset. We literally now have people proclaiming how great it is to be able to work without being paid as if it were a badge of honor.
- oefrha 6y agoNo, they succumbed to the certainty that companies in general are allergic to AGPL, which might be a result of FUD, but the FUD wasn’t what they succumbed to.
- pwdisswordfish4 6y agoThis is something to consider, although even the GPL has its detractors (people "allergic" to it). Personally, I'm a fan of GPL and copyleft, and I don't like that it's so maligned and misrepresented. A lot of the foment about hardships and "unsustainable open source" are attributable to the cultural meme that MIT is the only acceptable choice, which leads to people acting against their own best interests. It feels like a very /r/LeopardsAteMyFace situation. On the other hand, memes being what they are, even as a fan of copyleft, I have to acknowledge that perception does matter, as you mention. So in the choice between GPL and AGPL, the truth, which you really have to deal with, is that you are going to be turning people away by choosing the latter—and not just in the sense that it turns away the people that it's supposed to. If you want to go with AGPL but are concerned about the dampening effect on your prospects and never being able to get off the ground because of it, then maybe go for GPL, and as soon as your project has reached critical mass, has momentum, etc, then take the opportunity to reconsider and go from GPL->AGPL. Like, as soon as possible; when there's any momentum at all. It's also why you might consider MPL2. It's compatible with the GPL and LGPL by default, and it has an MIT (or Apache) feel, but it's essentially GPL at the file scope. And since it isn't branded with the letters "GPL", you can avoid the reflexive "nope" from potential contributors and clients. The main thing, though, is that relicensing can be easy. Hell, you can even start off under MIT until you reach n > 1, migrate to MPL2, using it as a stepping stone to GPL, and then go full-fledged AGPL, with no CLAs or big relicensing effort required at any step of the process.
- DoreenMichele 6y agoWe’ve had approaches from large corporations that want us to help them so they can sell Plausible Self-Hosted to their tens of thousands of clients without wanting to contribute anything to our project. They offer publicity in return. Something that needs to be said a great deal more frequently than I see it being said: Corporations are not your friend and they routinely prey upon smaller entities, chew them up and spit them out. This is par for the course. It is not some weird anomaly. I have never gotten around to successfully putting together a compendium of examples, which frequently frustrates me because it seems fairly hard to google (at least for me) when I want to talk about this and post an article or two to support my assertion. Small shops routinely talk like getting "some big client" is the small business equivalent of "winning the lottery." Oh, my god. This is generally the exact opposite of the truth. Small businesses routinely learn this the hard way and many of them either actually go out of business or get smarter and harder just in time to merely have a near-death experience, business-wise. Small businesses routinely have to change their policies after their first brush with being screwed by some large company. This is the norm. This is the norm. This is the norm. This is not some weird anomaly. This is not because you did something stupid or naive. This is how big companies become and remain big companies in far too many cases. I"m not trying to vilify big companies. Doing business means dealing with the public and making money at it and that's what they know how to do. I worked for a time at a Fortune 200 company. It was a growth experience and I don't regret working for them and I don't think they are evil. But when you leave your little cocoon of friends and family and venture forth into a relationship to The Public, this is what you run into and that's their forte. So learn from them. Grow. And, yes, spread the word because more individuals need to hear this early and often so fewer small businesses get eaten. I think we have a top-heavy system and we need to do more to protect the survival of small shops and medium shops and micro shops. The degree to which big companies prey upon those companies is part of why our economy is so unstable.
- kyaghmour 6y agoI've come to view use of AGPL as an admission of failure or proof of lack of understanding of how to build a business around open source software. While AGPL is sold as a means for protecting against abuse of a party's good-faith open source work, it defacto signals a transition to a bait-and-switch business model. Most large companies do open source to commoditize the cost of non-differentiating software. How you create value over and above what large companies are already willing to do in such an ecosystem is tough, and few have been able to build as non-services-based value prop. Open source software contributions, be it directly through lead maintainership or indirectly through contributions to 3rd party projects, are best viewed as marketing. You have to have something else to sell.
- mwcampbell 6y agoSelling proprietary licenses to companies that want to go proprietary with your software is a perfectly valid business model. It also helps to set up well-aligned incentives for actually producing good software. Consider this comment by open-source licensing expert Kyle Mitchell [1]: > The value of software lies overwhelmingly in the software. Charging for anything else perverts incentives. Charging for features? Make it hard to add features. Charging for configuration? Make it hard to configure. Charging for training or documentation? Make it hard to understand. Charging for hosting? Make it hard to host, monitor, tune, &c. Not charging at all? Slurp up personal data on users, and charge for that. [1]: https://news.ycombinator.com/item?id=23967773 https://news.ycombinator.com/item?id=23967773
- kyaghmour 6y agoI won't claim any expert status, but I've butted heads with RMS and Eben Moglen a few times. Have a look at Matt Asay's OSCON 2016 presentation "Lessons learned from 15+ years in open source", he breaks it down fairly well: https://www.slideshare.net/mjasay/oscon-2016-lessons-learned-from-15-years-in-open-source-matt-asay https://www.slideshare.net/mjasay/oscon-2016-lessons-learned...
- enriquto 6y agoI'm really happy to see my favorite license get more and more widespread usage! There's already quite a few "famous" free software packages using this license. Go, AGPL!
- alien_ 6y agoI did a similar move last year when I changed the license of my AutoSpotting project to OSL-3, after my MIT code was taken by two startups that built products using it without contributing anything to the development efforts.
- ystad 6y ago> The change will affect corporations that want to take our code and use it to create and sell proprietary tools that directly compete with us. I don't get why folks who are scared of competitors start with a permissive license in the first place. They could have easily foreseen this. Think about competition who have invested time and PRs back to this.
- veridies 6y ago(Understandable) naïvité, and a lack of awareness of the downsides. Articles like this on Hacker News help other people who might be thinking of making a similar mistake.
- vsnf 6y agoThere are a few comments in this thread expressing distaste for dual licensing. Can anyone explain what the reasoning behind this might be?
- jabl 6y agoDual licensing requires copyright assignment, and creates an uneven playing field, with the one owner and then a bunch of contributor peons who sign away all their rights so that the owner can make money. Who'd want to contribute under such terms?
- zokier 6y agoIs the analytics script that's included in every page also AGPL? Does that mean that the combined work of page+script must also be AGPL? Or are the exculding it from the license change?
- markosaric 6y agowe'll keep the script itself on MIT just to avoid any possible confusion in the future.
- pimterry 6y agoWith my open-source product I'm in a very similar place, and I do _mostly_ the same thing. My product (https://httptoolkit.tech https://httptoolkit.tech) is a debugging proxy app. The codebase is broken up into a few modules: a desktop shell, a UI, a backend component for the UI, plus a standalone proxy library and a bundle of smaller libraries that do everything from detecting & launching browsers to reparent react components around the DOM (if you're interested, they're all on github: https://github.com/httptoolkit/ https://github.com/httptoolkit/). All of this is open-source, with some premium features behind a subscription (but even those are open-source, it's just you'd have to fork it to remove the subscription checks, and it's not worth the time of any professional to maintain their own fork of the whole project). The core product is AGPL, but nothing else. More specifically, product-unique components are AGPL (the UI, the backend, etc) where there's no clear case for ever reusing them other than duplicating/forking the product, but everything else is kept under permissive licenses, mostly Apache 2. This is mainly because AGPL really limits practical freedoms in business contexts: It's harder to get sign-off to contribute to (A)GPL libraries, even in a one-off script nobody wants to risk using an (A)GPL library and it would become much harder to find contributors. So far I've found this has worked pretty well for me, and I'd recommend it to others, including Plausible. Put only the core product-specific components under AGPL, but keep everything that might be useful to somebody building a completely different product under more relaxed licenses wherever you can to ensure you can fully engage with the open-source community.
- kevincox 6y agoNote that this is very restrictive for some interpretations of the AGPL: https://opensource.google/docs/using/agpl-policy/ https://opensource.google/docs/using/agpl-policy/ IIUC the intent was to ensure that modifications to Plausible are released as open source. However it isn't clear if this also affects tools that use a API or even just Plausible being used internally for a company. The AGPL does have wording saying that in the case software is joined together only the original work has the AGPL requirement, however it is unclear what the difference is between modifications to the original work and other code that uses that original work. FWIW this is non-specific enough that I am not completely comfortable using Plausible personally anymore. Of course you company's legal team may have a different opinion.
- sadfev 6y agoAGPL is a fantastic license. Best for dual-licensing, you still keep your development in the open but you can monetize the code too.
- DreamScatter 6y agoSeveral of my repositories are AGPL also https://github.com/chakravala/Grassmann.jl https://github.com/chakravala/Grassmann.jl