4 ms·
Most of the arguments against the use of a CLA in this essay feel like legitimate but generic laments of the complexity surrounding software licensing and emplo
by csnover 5y ago
Most of the arguments against the use of a CLA in this essay feel like legitimate but generic laments of the complexity surrounding software licensing and employment contracts, not actually relevant to whether or not most projects should adopt CLAs.
CLAs can be written to be confusing (like anything), but in my experience they are no more confusing than open source licenses themselves. Suggesting using Apache License to avoid the confusion of a CLA is particularly weird to me since that is a long and complicated license compared to the most common OSS licenses.
Bad process can also make CLAs hard, but that’s not any fundamental problem with the concept of a CLA. As someone who also worked on improving the CLA process for a non-profit OSS foundation, I can say with confidence that the administrative burdens are insignificant when your process isn’t broken. It feels to me like saying “you probably shouldn’t use code linters” as a blanket rule because some projects use some uncommon coding style.
Even after reading this I don’t really understand why the author seems to think that CLAs mostly exist to shift liability toward third parties. It’s not as though the project still gets to use the IP-infringing code just because the person who put it there signed a CLA, and it’s not as though the absence of a CLA keeps all parties from being sued. The legal entity that owns the project would probably be able to avoid any claim of wilful infringement, but I can’t think of any other way that a CLA shifts legal blame. (However, IANAL.)
On the other hand, I’ve been involved in OSS projects where a contributor didn’t sign a CLA, contributed code, then became acrimonious after some of their other ideas were rejected and threatened to sue the project if their code wasn’t removed. While it would’ve been extremely difficult for them to do so, it created a lot of problems that simply wouldn’t have existed if there were a signed CLA to point to.
The fact of the matter is that the long tail of OSS projects are not owned by big megacorps with endless pockets for lawyers; most are either part of 501(c)(6) non-profits like the Linux Foundation or just solo developers, and for those projects having a CLA is probably even more valuable.
- krageon 5y agoA CLA is much like a CoC: It is an indication that the maintainer(s) of the repository are not busy with writing good software, but busy covering themselves because of all the hostile people they see around them. It tells you to not participate in the community, because to them your contribution isn't nice and welcome. It is a potential threat that must be mitigated.