7 ms·
Everything moving forward in this space is great. Ideal world - You declare your stack, from OS, distributor up to all dependencies used. Non-profit/individua
by hnedeotes 6y ago
Everything moving forward in this space is great.
Ideal world - You declare your stack, from OS, distributor up to all dependencies used.
Non-profit/individuals non-profit don't pay anything.
Everyone else/companies pay $0.01 per dependency, per month.
Each package (at each layer) describes its own dependencies. So a docker image, installing ubuntu (ubuntu declares its own dependencies - libc, curl, git, whatever), running npm, and all node packages, and you take a bill of cost from this "bundle". If dependencies share dependencies it only counts as 1 no matter how many times it's repeated in a single setup.
If there's 1million servers running linux, that's 10k for the linux foundation per month. Probably there would need to be a tiering of cost/distribution, as a left-pad node package isn't worth the same as a linux distribution, and companies with + a certain threshold should perhaps pay more.
The benefits would be that people would stop installing 10.000 npm libs as they gets expensive fast, so people would try to write more comprehensive libs and the quality would go up.
You don't need to poke holes in the idea, it's basically an open ocean, but it would be nice to see something totally automated like this.
- atomashpolskiy 6y agoEasier to add OSS tax into the social security payments. The difficult part is collecting usage analytics so that funds get distributed "fairly".
- zrail 6y agoUBI and universal healthcare would make this a complete non-issue, as well as benefiting the arts and humanities.
- scaladev 6y agoTBH I have absolutely no desire to pay taxes for yet another JavaScript framework. I'd be happy to set aside, say, 5% of my monthly salary to be divided between the applications and libraries I actually use. (I do something like this, but manually and pretty unfairly, because it's difficult to cover thousands of projects with any meaningful sum as I don't have billions in my banking account). The OS of my choice has this: https://pkgstats.archlinux.de/ https://pkgstats.archlinux.de/ although it would probably be easy to inflate these numbers if your income depended on it.
- prepend 6y agoThat sounds very confusing and requires invasive license auditing to enforce. You can also do this by just paying into a commercial stack. The beauty of OSS is that it’s easy to use and reuse. I’d rather just pay Microsoft than use a scheme where I pay by the number of dependencies. Also, not that I release a ton of packages, but I do contribute some here and there. I would not contribute to commercial packages where my labor benefits some org. And I would still release packages under a permissive license that allows for reuse without any compensation to me.
- hnedeotes 6y agoJust for sports. > I’d rather just pay Microsoft than use a scheme where I pay by the number of dependencies. So you wouldn't want to support OSS, you would rather support a company. > I would not contribute to commercial packages where my labor benefits some org. That would be your call for sure. > And I would still release packages under a permissive license that allows for reuse without any compensation to me. This would be your prerogative as well. Let's pretend we have in place the infrastructure. A place where anyone can submit a bill of usage, and do payments, and this holds the payments and a person can register their software there. For your use case it would have even the possibility of you redirecting the funds you don't want into other projects. Perhaps a badge on your profile, "redirector", "open hands", wtv. Let's imagine that every piece of software besides a "readme.md" file, has a file describing its dependencies. NPM would be able to do this like they can build a dependency graph. Your OS would be able to do this because each programs/lib would be able to do this/provide their own. Let's say there's a piece of software that can pick all these little files and coalesce them into a single one. Now you could build a "package" of what it would cost you, see what is in there and then just make it part of your monthly payroll. There's no bureaucracy. If you are a company using software and not paying for it, you would be under breach of contract and could be sued legally.
- prepend 6y ago> So you wouldn't want to support OSS, you would rather support a company. If I’m paying for it, it’s not open source. I’d rather pay a single company with a “simple”license, than something that costs me more when someone uses a leftpad package than just writing their own. I don’t want to have to have cost decisions factor into my design at that level. Having the legal support to plan out if I’m under breach or not is expensive. One of the things I like about OSS is I can avoid that. Paying and still having that threat is the worse of both worlds. Also, unpredictable prices are really hard in my org. Having my payroll vary month to month on what’s happening is really hard. Do I pay based on when I compile? When I run? What if I want to have 10 test environments, so I pay times 10. What if I need to archive and might never run it, but need to make sure I can run it, do I pay. Etc etc. There’s a million different permutations based on project needs that vary by people. With OSS, I can clearly plan and address all these. With commercial licenses, I usually can since I get a perpetual license per seat or cpu or whatever. This new scheme would be really complex and include a lot of latent risk, and require that I’m constantly open to audit by some org. And audits are expensive to receive and support. No thanks, I’ll just skip using it and use OSS versions.
- hutzlibu 6y ago"Everyone else/companies pay $0.01 per dependency, per month." Yup. Open ocean. Because that just creates incentive to make a looooong dependency list. Also, don't you think the complexity of packages are very different and it is therefore not fair, to make them all equal?
- hnedeotes 6y agoOf course, but even $500 per month is more than $0. > Yup. Open ocean. Because that just creates incentive to make a looooong dependency list. Well, perhaps no? Since those things don't get into your list by themselves I would think that it would incentivise the opposite. If whatever lib you're using has 100 dependencies, one for left-pad, the other for right, one for switching underscores for hyphens, this would make someone come and say, I can make this with much less cruft. But still, if the dependencies are repeated across dependencies they wouldn't increase. So if you use 2 packages that both use say "curl", for your "bundle" it would still be only 1 entry for curl.
- hutzlibu 6y agoIf money is involved, fraudsters will get involved. You want to argue with people that their long dependency list is totally unneccecary? That will become the norm, if this is the metric on how much income everyone would get. The higher the number of packages - the higher the pay. Does not reflect reality, where one package can be a million times more complex, than simple 100 packages.
- imtringued 6y agoCompanies optimize for cost. If a package scams you by having too many dependencies then you simply don't use it.
- ddevault 6y agoLinux is one of the world's most popular open source projects and represents the collaborative efforts of tens of thousands of software engineers. $10,000 per month might pay for two full time engineers. Thankfully, that's not what OC is proposing.
- hnedeotes 6y agoThat was an example, with an explicit note about it. Geez. Nothing would prevent people or companies to further invest, donate or write love songs about it. 10.000 would still be 10.000 more than 0 right or is my math wrong?
- ddevault 6y agoA platitude can often be worse than nothing at all. You've "solved" the problem, and now we can all go back to ignoring it. I'm more interested in real, scalable, sustainable funding solutions, than in continuing to give FOSS devs whatever crumbs may fall off of the SV dinner table. I'm certainly not going to pat anyone on the back for it.
- hnedeotes 6y agoSure, let's just move forward with the cake then.
- eeZah7Ux 6y ago> $10,000 per month might pay for two full time engineers A good kernel engineer is paid well above $60K a year.
- eeZah7Ux 6y agoThe last thing we need is to reward libraries by popularity and quantity rather than quality. Just like in academia and industry, our work should be reviewed by peers with relevant and proven experience. The fact that some thing of NPM installs, github stars and reddit upvotes as a measure of merit says a lot about the immaturity of the software industry.
- hnedeotes 6y agoThis would be rewarded by usage?
- temac 6y ago> Non-profit/individuals non-profit don't pay anything. > Everyone else/companies pay $0.01 per dependency, per month. I don't get that dichotomy? People can do what they want, no? So are you simply saying that individual would be far less likely to fund open source software, while companies and assimilated would? Or you would just want it to be mandatory for companies? If the latter, that would be completely incompatible with Open Source.
- hnedeotes 6y agoYes, imagining what I was saying it would be mandatory if your company was making a profit while using software that agreed to this. The difference would be if you're setting up a blog to share your permaculture posts, you wouldn't need to pay, or something like that. If you as a software author didn't want you could always put that the cost to use your package was $0?
- deleted 6y ago[deleted]
- HeyLaughingBoy 6y agoWhat if the company was losing money? What if the permaculture blog was monetized by AdSense or something else?
- temac 6y agoThere is not even a "what if" to apply; it would be fundamentally contrary to Open Source and Free Software (violates freedom 0) And I've nothing against people who want to invent new models. Just: this can't apply to the whole current Open Source / Free Software corpus and ecosystem. And this new model will never be able to mix. Payed license does not need to be created anyway. This already widely exist and this is just proprietary software. And among proprietary software, there are also licenses that are incompatible between each others. And proprietary licenses that don't require monetary paiement from individuals. So does creating new proprietary licenses that would be obviously incompatible with Free Software licenses, and probably incompatible with most other proprietary licenses, would achieve anything interesting? I doubt it.
- benatkin 6y agoThat isn't ideal at all. That's gittip - people forced to publicly receive contributions whether they want them or not.
- hnedeotes 6y agoWell perhaps this vapourware platform would have an option for you to redirect whatever funds to somewhere else? (while making it clear on your package page that you were doing so)
- wolftune 6y agoYou are thinking of tip4commit. Gittip later became Gratipay and then closed (but the fork at Liberapay still exists). Gittip never collected contributions for people who didn't first sign up. Gittip/Gratipay did other reckless things, but that's a separate matter.
- IncRnd 6y ago> Non-profit/individuals non-profit don't pay anything. >Everyone else/companies pay $0.01 per dependency, per month. This isn't going to be both scalable and sustainable. You will find that people will calculate the cost of this vs. the cost of being a non-profit. It also isn't going to work where a small dependency gets the same payout as a more complicated dependency.
- hnedeotes 6y agoSo, if 0 is sustainable, this would also be? You mean they would become a non-profit so they wouldn't have to shell 50 bucks a month? The dependency values wouldn't need to be $0.01. Maybe if the theory about free markets is true, then it would somehow be guided by the invisible hand, and we would let linux charge the amount of $0.10 per month. With 1M commercial servers that would be 100k per month. Not faang salaries I know. Maybe left pad could be paid in bitcoin, so we could have like fractionality towards infinity.
- dv_dt 6y agoIt's interesting to look at other copyright collective approaches in other copyrightable works like music. Though I'm sure the exact models actually shouldn't be followed, it bears looking at, with ASCAP being an interesting example. https://en.wikipedia.org/wiki/American_Society_of_Composers%2C_Authors_and_Publishers https://en.wikipedia.org/wiki/American_Society_of_Composers%... https://en.wikipedia.org/wiki/Copyright_collective https://en.wikipedia.org/wiki/Copyright_collective
- deleted 6y ago[deleted]