3 ms·
Sorry to hear that this has been your experience! What exactly was the issue for you? It’s true that there are lots of open PRs. We’re a small team and often bu
by aeneas_ory 3y ago
Sorry to hear that this has been your experience! What exactly was the issue for you? It’s true that there are lots of open PRs. We’re a small team and often busy with customer requirements which doesn’t allow us to get some community PRs over the finishing line (finish tests, refactor code, fix remaining bugs, do security reviews, …).
Sometimes, PRs are not aligning with an architecture or API principle which is when they often go stale. This is why we generally require design documents for changes or additions to APIs.
Saying that the open source is second class is a false accusation in my view:
- Over 1500 PRs merged in Ory Kratos alone: https://github.com/ory/kratos/pulls https://github.com/ory/kratos/pulls
- Very active contributor and commit frequency: https://github.com/ory/kratos/graphs/contributors?from=2018-05-27&to=2023-08-08&type=c https://github.com/ory/kratos/graphs/contributors?from=2018-...
- A growing community and footprint
Also, we do offer support contracts for self hosted environments - this is relatively new though: https://www.ory.dev/support/ https://www.ory.dev/support/
It is true though that have to balance open source work and things that people pay us for. It’s the only way to ensure that Ory open source, for which we have a deep commitment, continues for a long time.
Hope this makes sense!
- Sytten 3y agoI think it would be fair to say that kratos was not the priority in 2022 in terms of code you can see not much was commited (https://github.com/ory/kratos/graphs/code-frequency https://github.com/ory/kratos/graphs/code-frequency) so I might have had a bad first impression. A few issues on kratos that I consider relatively important are still missing / nobody from Ory is giving their input so it's hard to make progress and I would not take my time to contribute if I dont know if the owner are going to merge it. An example that comes to mind is the OAuth email auto-verification or the search of users that is still super basic (we only recently got the filter of identifiers).
- vinckr 3y agoI would say that Ory Kratos made huge improvements in 2022, and the code graph is just looking like that because there was much more foundational work going on in 2021. In 2022 it was mostly adding features, fixing bugs etc, but the API and system was generally stable already. from the top of my head some of the features added in 2022: - verification and recovery codes - import of MD5-hashed passwords - integration with Ory Hydra - device information in session - session management APIs - session metadata - blocking webhooks - many improvements to OIDC mappers - session refresh - opentelemetry tracing - complete rewrite of docs - import identities including hashed passwords - custom email templates - passwordless with webauth - 1:1 compatibility Ory Network and Ory Open Source Of course there was a huge amount of bugfixes and smaller improvements going on already. 2023 also already saw a ton of work being done on Ory Kratos including the 1.0 stable release. Of course there is still much to do, and feedback like yours also helps! If you are looking to contribute its always recommended to talk to the maintainer before you start coding - then we can let you know if its realistic to be merged or not. Search is a not a trivial thing to implement, on the one hand it is needed in some form, on the other hand Ory Kratos should not bloat too much. Anyway, thanks for the feedback, will take it into consideration :-)