7 ms·
If I have an OS project and someone submitted a Pull Request with something they cannot really publish. Like a piece of proprietary code from their work. Withou
by splix 5y ago
If I have an OS project and someone submitted a Pull Request with something they cannot really publish. Like a piece of proprietary code from their work. Without a CLA, I have full responsibility if I accept it, so their lawyer can easily sue me for that piece of code.
I mean, that actually happened to me a few years ago, and their lawyers forced me to completely delete the whole project, just over a few lines of someone's code. So as for me, CLA gives at least some additional protection against lawyers trying to shut down some competing OS project.
- drekipus 5y agoForgive my ignorance, but why couldn't you work to replace it, or at least revert the commit? If it was completely open source, they would have to prove that you accepted code maliciously, ie: knowing that the code was proprietary and for unfair advantage, etc. Do you feel like they were bluffing? Because I definitely do.
- phendrenad2 5y agoLawyers will always ask for the most favorable outcome for their client, which in this case was the GP deleting the project. Had the GP gotten their own lawyer (or even "call their bluff" by letting them either take it to court or GTFO), I'm guessing they could have kept the project. (Of course, if GP knew before merging the code that it was someone else's code, then things are likely different, and going to court might not be favorable)
- judge2020 5y agoThey could argue that the git commit history being immutable means that they have to delete the entire repository to remedy the existence of the proprietary code being available for download. The best way to continue would be to either rewrite history (eg. with BFG) or fix it, destroy the git history, then start from scratch.
- splix 5y agoI think it was not about those lines, and they didn't want to listen. I believe the court would rule to just "revert it" but I didn't have money to go to court anyway. I'm not sure that I would spend money on lawyers if I had a CLA, but at least it would give me a leverage in conversation.
- graton 5y agoCurious. How would the CLA protect you? Couldn't the same situation occur even if the contributor had signed a CLA.
- greenshackle2 5y agoThat is answered in the article: "CLAs shift the legal risk for copyright infringement, patent infringement or other bad acts, intentional or otherwise, from the project (the entity best positioned to defend a legal claim, and often the one most directly benefiting financially), to the contributor"
- graton 5y agoOkay. But still if a person contributes code that is not their code, even if they sign a CLA, and it ends up in the project the project can't say "not our problem they signed a CLA". The project would still need to remove the offending code.
- splix 5y agoIt would give me a leverage and that would be a totally different conversation. Though I understand that if lawyers want to destroy something they can do it regardless the CLA or anything. It's just the game of who spend more money in court.
- RyJones 5y agoAs someone that has a huge bet on DCO - for you, as a contributor, is DCO better?
- splix 5y agoThat's an option too. Though as for me it's the same efforts for a contributor. Unless you require the CLA physically signed on paper. Otherwise there are GitHub addons that do CLA just with one click once after making a first Pull Request.
- RyJones 5y agoI'm thinking more `git commit --amend -s ...`
- krageon 5y agoYes, but with a CLA you will never actually get to merge most pull requests. No random dev that thinks "well I can upstream this patch" is going to read through, understand and sign a random document for you.
- splix 5y agoI require CLA now and had never experienced a single developer refusing to sign it