3 ms·
The problem is CLAs. They are a much higher barrier to entry for a lot of contributors. No, they're not all the same, but they make it harder. Each CLA needs t
by SuperQue 5y ago
The problem is CLAs.
They are a much higher barrier to entry for a lot of contributors. No, they're not all the same, but they make it harder. Each CLA needs to be reviewed and approved by company lawyers. It's kinda like creating a brand new OSS license that way.
To use a concrete example, the Google open source CLA is awful. At my previous job our lawyers refused to sign off the Google CLA. One of my engineers wrote a patch that we wanted to get upstream. Since, it would be generally useful.
Basically, the patch could never be merged, because we had a legal stalemate between us and Google.
I would highly recommend using https://developercertificate.org/ https://developercertificate.org/ instead. This is what we use for Prometheus. It's also used for GPL projects like Linux. It's simple, standard, and used widely.
- __david__ 5y agoDoes clause (d) allow the project to relicense its code? Because as far as I understand, that is the reason that GNU tends to have CLAs on their projects.
- SuperQue 5y agoI'm no expert in these things, but here's my understanding. AFAIK, it's up to copyright assignment for re-licensing. For example, contributing to Prometheus assigns all copyright to "The Prometheus Authors". The DCO just attests that it's OK to do this. So, I don't think there's anything for or against re-licensing in DCO, it's just out of scope.