3 ms·
Two observations. - This does not work beyond OSS projects. This is literally a compliance leaders nightmare. I just don't know who is touching the code, how a
by bitlad 3y ago
Two observations.
- This does not work beyond OSS projects. This is literally a compliance leaders nightmare. I just don't know who is touching the code, how and where ahead of time, no background checks etc.
- Secondly, this feels like a nice way to "growth hack" you Github stars and fake some metrics for VCs. Your pitchdeck can 100s of contributors and 1000s of stars without really creating much value.
- hzia 3y agoCurrently most of dev bounty platforms do start with OSS, but we only started doing that last year. Because of that, 90% of users of our commercial usage today is still close-source, and biggest customer base are from heavily regulated industries like insurance, finance, and even commercial banking, with 2 of them having > $15B each under management. Now, as you pointed out, we had to implement and background checks, audit logs and have direct full-time relationship with devs through our subsidiaries. But what made the biggest difference was our security tooling like GitSlice, which along with dev environments cuts down majority of risk exposure. I would be really curious why you think something like this wont work for private repos?
- bitlad 3y agoThere can be two reason why it is working. - They might be running shadow IT - Security and compliance is not their priority. Since you have implemented BG and other controls. My follow up question is are these devs in that case EOR or contractors whose payroll is processed via you. Your org starts to look like deel, remote or midsource. The whole PR assigning to junior devs feels gimmicky, no? However, there are two problem statements you are solving. I agree with the first premise, remote junior devs will get better opportunities and confidence when they do this exercise. I think the second part of value generation, I think risk is too high for a closed source org.
- hzia 3y agoWe enable EOR + BR + MDM setup on the enterprise plan. Plus, MDM is usually gimmicky given most devs for these clients work in a virtual environment anyways (so the code never leaves their infrastructure). IMO if we fail as a company, it will be far more likely because of inability to deliver high quality PRs instead of inability to get through compliance.
- alfalfasprout 3y agoI imagine that it only works for the typical type of work that gets outsourced anyways-- very tightly scoped work in codebases that don't actually require deep integration with production systems or anything all that critical. I have yet to have a super positive experience with the quality of work of offshore contractors either internally hired or via an external consulting company.
- hzia 3y agoDo you think outsourcing (“gets outsourced anyways”) still happens for most tech teams? IMO, just like you mentioned, teams are so scared of outsourcing that this happens less and less. I agree that this works for well scoped tickets that only depend on the code and testable on a staging environment. Anything outside of that needs in-house devs (or contractors) to get done.