3 ms·
Given it was open source you could see that happening? You could just like, choose the dependencies you wanted to use. Like vote with your wallet or something.
by hnedeotes 6y ago
Given it was open source you could see that happening?
You could just like, choose the dependencies you wanted to use. Like vote with your wallet or something.
- sokoloff 6y agoIf there's a non-trivial amount of money at stake, I can 100% see that happening. I'd bet a nearly unlimited amount of money that it would happen. Find a way to get something into a popular Linux distro and you can micro-split the downstream dependencies over time. “Every time I apt-get update && apt-get upgrade -y, my monthly bill goes up; I better stop doing that...”
- hnedeotes 6y agoYeah definitively. But when I wrote that, I meant you as an individual consumer wouldn't need to worry about that. Or someone who writes libraries or packages. Only if you were running a for profit business. The remaining would have to be on trust of the community running the packages but I can definitively entertain the idea of it not working as expected.
- sokoloff 6y agoI'm both an individual consumer and a professional working for a for-profit business in most computing circumstances at home. Same for my permanently working-from-home freelancer spouse. My network gear and proxmox server and TrueNAS and Synology all run open-source software and all four of those support both personal and for-profit activities to different degrees. The Plex container is clearly fully personal, but the Unifi controller and backups use cases are mixed, and the standalone Ubuntu container is fully for-profit, all running on a mixed Proxmox. Which ones get charged and which ones are free?
- gervwyk 6y agoYeah. I Agree with you. Also been thinking about a similar concept for a while. For the negative effects some have mentioned, one could also argue the possibility of a positive effect to make things more open and result in better quality / funded / open projects. As an idea an addition to this could be a community trust score where users also get to vote on a few aspects of a project, like ‘is it well maintained?’, ‘do you understand changes in version updates?’ etc. maybe bad examples, but a few simple metrics which can give a project a good or bad rep based on what the maintainers does as presented by the community - not just nit-picked twitter quotes. Yes, these will need to be crafted carefully so that maintainer cannot game them but the result could be projects getting paid well for doing things that builds trust and makes the project more accessible. Of course I could just look at the PR history and issues etc before I use a new package, but I would trust community feedback more than my 30 min deep dive. Today we only have very vague metrics like npm popularity or github stars, which is very hard to accurately judge what package to choose or not.