7 ms·
For now we just changed to AGPL as a defensive move to avoid these threats. It was an unplanned move that we didn't even think about few days ago. Next step is
by markosaric 6y ago
For now we just changed to AGPL as a defensive move to avoid these threats. It was an unplanned move that we didn't even think about few days ago.
Next step is really to consider what we want to do in the future and if necessary add a CLA before we merge next contribution.
We never planned to do any commercial licenses (we're focused on our Cloud offering) but it seems like a valid option in case of these corporations who want to resell our product but not open source their modifications.
- jarofgreen 6y agoI see. I would definitely urge you to consider this very soon: AFAIK you can't do any commercial licenses with AGPL without A) some form of dual license and CLA or B) just never accepting pull requests from anyone. But also, does this also apply to your own cloud hosted offering? Without sorting this out, all the software in your cloud hosting product now has to be fully open-source. And I get that's your philosophy, but would there not be any tiny bit you want to keep closed - maybe the anti-fraud stuff around your billing system, for instance? This seems a key point that I'm very interested in, so sorry for pushing!
- Conan_Kudo 6y agoAGPL doesn't work the way you think it does. An anti-fraud system service can easily communicate with Plausible over a network connection through an IPC interchange (HTTP, gRPC, etc.) without triggering that issue. The extension to Plausible to support that itself would be AGPL, but the anti-fraud service itself would not have to be.
- jarofgreen 6y agoYes - I was thinking of internal code, not an external service. But yeah, knowledge of what would or would not be covered by AGPL seems crucial here.
- Conan_Kudo 6y agoYou'd probably want to be able to communicate with multiple anti-fraud systems anyway, so I would expect it to be something plugged into Plausible and not part of Plausible itself.
- blackorzar 6y agoHello markosaric, Have you thought on requiring contributions to be dual licensed MIT + AGPL? This would avoid you the need of a CLA because you can use MIT to incorporate the contribution to your cloud solution and/or to sell a license to a corporation that would like to keep their modifications closed. This would also lower the barrier to contributors due they don't need to sign the CLA.
- camkego 6y agoThis is an insightful comment about how to achieve certain uses without CLAs, nice to learn about this.
- markosaric 6y agothanks! that's a good point and makes sense to do!
- markosaric 6y agoDo you have any examples of projects doing this? Thanks!