25 ms·
Radicle: Open-Source, Peer-to-Peer, GitHub Alternative
- Berry141 3y ago[dead]
- lionkor 3y agoSo it uses git, right? The readme should make that clear.
- sebastinez 3y agoyeah, the underlying storage layer is git. There is more information on https://radicle.xyz/ https://radicle.xyz/ about how it uses git
- gsaslis 3y agoYes, radicle is built on top of git and even uses git as its storage backend for its own data model. [1] has more details on how Radicle depends on git. [1] https://app.radicle.xyz/nodes/seed.radicle.xyz/rad:z3trNYnLWS11cJWC6BbxDs5niGo82/tree/0001-heartwood.md https://app.radicle.xyz/nodes/seed.radicle.xyz/rad:z3trNYnLW...
- EGreg 3y agoIsn’t git already open source and peer to peer? So this is just a web interface to git? Like gitlab?
- pure-orange 3y agoits an open source alternative to github, not git
- viraptor 3y ago> and peer to peer? https://news.ycombinator.com/item?id=39601209 https://news.ycombinator.com/item?id=39601209
- est 3y agoThis looks like a fine project for its purpose, but I think git is already open-source and p2p. You don't need sh<(curl) a bunch of binaries, instead simply connect to another git server, use git commadns to directly pull or merge code. What's missing in git is code issues, wikis, discussions, github pages and most importantly, a developer profile network. We need a way to embed project metadata into .git itself, so source code commits don't mess up with wikis and issues. Perhaps some independent refs like git notes? https://git-scm.com/docs/git-notes https://git-scm.com/docs/git-notes
- e12e 3y agoFossil has a few of these.
- codetrotter 3y ago> What's missing in git is code issues, wikis, discussions, github pages and most importantly, a developer profile network. Radicle adds issue tracking and pull requests. Probably some of those other features as well. On mobile there are buttons on the bottom of the screen in the op link, click those and you get to the issue tracking tab and the pull request tabs etc
- 9dev 3y agoBut that’s not what parent meant. Those things should be embedded in the git repository itself, in some kind of structure below the .git/ directory. That would indeed make the entire OSS ecosystem more resilient. We don’t need a myriad of incompatible git web GUIs, but a standard way of storing project management metadata alongside version control data. GitHub, Gitea, Gitlab, and this project could all store their data in there instead of proprietary databases, making it easy to migrate projects.
- gsaslis 3y agoYes, this is how radicle stores this data. ; ) https://app.radicle.xyz/nodes/seed.radicle.xyz/rad:z3trNYnLWS11cJWC6BbxDs5niGo82/tree/0003-storage-layout.md https://app.radicle.xyz/nodes/seed.radicle.xyz/rad:z3trNYnLW...
- colesantiago 3y agoIs this the same Radicle that issued a crypto token ($RAD)? If so, I'm glad that it completely failed and they decided to focus on the actual product of a 'P2P GitHub'. Although stay away from their 'drips' crypto thing, looks like a tax and accounting nightmare for individuals and businesses.
- toastal 3y agoCan this handle patch stacks or is this just another pull/merge request model with all the flaws that entails?
- cloudhead 3y agoIt can handle them, though we haven't built that much tooling around them. However, unlike GitHub, updates to PRs (Patches in Radicle) are non-destructive, just like Gerrit[0], and code reviews are tied to specific revisions of patches. This is in my opinion one of the biggest flaws in GitHub's model. [0]: https://www.gerritcodereview.com/ https://www.gerritcodereview.com/
- dancek 3y agoThat's indeed the biggest flaw in the Github PR model. I've been hoping for a gerrit-like code review experience in a Github alternative for years. I'll be sure to try Radicle.
- killerstorm 3y agoI see no information about properties in README.md, and ARCHITECTURE.md is empty. What are the capabilities? If a node is down, would other nodes step in? Where's stuff stored? How is it replicated?
- cloudhead 3y agoSee https://docs.radicle.xyz/guides/protocol https://docs.radicle.xyz/guides/protocol
- viraptor 3y agoThis should cover it: https://app.radicle.xyz/nodes/seed.radicle.xyz/rad:z3trNYnLWS11cJWC6BbxDs5niGo82/tree/0001-heartwood.md https://app.radicle.xyz/nodes/seed.radicle.xyz/rad:z3trNYnLW...
- lftherios 3y agoHi HN. I am the co-founder of the project. If you are interested in how the protocol works under the hood, start here: https://docs.radicle.xyz/ https://docs.radicle.xyz/ Docs are still WIP though.
- paul_h 3y agoYour gossip protocol isn't the gossip protocol of Hashgraph/Hedera https://hedera.com/learning/hedera-hashgraph/what-is-gossip-about-gossip https://hedera.com/learning/hedera-hashgraph/what-is-gossip-..., is it?
- throwaway220033 3y agoHow much budget was spent on Radicle, how many people did work on it, how long you've been building it and who is using it ?
- cloudhead 3y agoI won't reveal anything about our finances, but the current code base is a little under 2 years old. We've worked on the general problem for over 4 years in total though. The team is around 12 people, split between protocol, cli, tui, web and content. The product is set to launch this month, so we're just starting to onboard users, but many people in the community are already using it, and we've been using it internally for about a year.
- throwaway220033 3y agoMy question wasn't about your "current codebase". It was about Radicle. It was launched 6 years ago, and for some reason it's always about to onboard the first users when crypto is on hype :) An idea doesn't take off -- totally normal, but how on earth can you fund Radicle for such a long time with no users? You can even throw it away and rewrite it! What's the source of funding for Radicle ? Asking because you seem to be best at getting the idea funded, not really actualizing it.
- 3y ago
- mikepapadim 3y agoHow is this related to the $RAD coin?
- bordumb 3y agoFrom a technical standpoint, Radicle (P2P git protocol) is not related to $RAD. $RAD is the token of the organization that has been funding Radicle over the years.
- throwaway220033 3y agoI hear about Radicle every time crypto market goes up. Is anybody seriously using it ? This got down-voted so fast! :) Serious question though: how much budget was spent on Radicle, how many people did work on it, and who is using it ?
- k__ 3y agoFair question. I'm working in the crypto industry and I had the same impression. Last time I heard about Radicle was the last bull market. Then it was silent in the bear, which is kinda strange, since everyone is always saying, bear markets are for building and Radicle certainly is a builder tool.
- bawolff 3y agoI wish people would define precisely what they mean by "peer to peer" (or more commonly, "distributed"). Its such an ambigious term now it can mean anything when used as a buzzword.
- cloudhead 3y agoI haven't seen the term misused very often - the way it is defined in Radicle and most other peeer-to-peer systems is how Wikipedia defines it[0]; specifically this part: "Peers are equally privileged, equipotent participants in the network". So a peer to peer system is one where all participants are "equally privileged in the network". This usually means they all run the same software as well. [0]: https://en.wikipedia.org/wiki/Peer-to-peer https://en.wikipedia.org/wiki/Peer-to-peer
- bawolff 3y agoI mean, that definition doesn't fit with supernodes ("seed" nodes in your design) but that is a nitpick. I guess im mostly just wondering what are the properties you are trying to accomplish. Like there is talk of publicly seeding repositories that are self-certifying, but also using noise protocol for encryption, so what is the security model? Who are you trying to keep stuff secret from? It is all very confusing what the project actually aims to do. Mostly all i'm saying is the project could use a paragraph that explains what the concrete goals of the project are. Without buzzwords.
- cloudhead 3y agoI've answered the use-case question here: https://news.ycombinator.com/item?id=39601588 https://news.ycombinator.com/item?id=39601588 But yes, we're not officially launched yet and the website is going through a rewrite to offer more clarity, thanks for the feedback. Re: seed nodes: they are running the same software and work the same way as regular nodes, the only difference is how they're deployed (with a public IP address vs. behind a NAT). But yes, a little bit of asymmetry is needed because of NATs/IPv4. Re: properties: mainly we need to provide encryption and self-certification to enable a similar user experience as GitHub/GitLab/etc. on a an untrusted peer-to-peer network. Additionally though, Radicle offers a level of censorship resitance and disruption tolerance that GitHub cannot offer.
- pachico 3y agoWhat are the most common use cases this provides a solution for?
- cloudhead 3y agoIn the long term, this is intended as an alternative to collaboration platforms like GitHub and GitLab for people/organizations who want full control of their data and user experience, without compromising on the social aspect of these platforms. The first three paragraphs of the guide has a longer motivation: https://docs.radicle.xyz/guides/user https://docs.radicle.xyz/guides/user
- greatNespresso 3y agoCongrats on launching ! Reminds me of another similar project, nest.pijul.com but using pijul instead of git
- cloudhead 3y agoThanks, we haven't officially launched though! Pijul is a great project indeed :)
- shackra 3y agoany plans for adding localization to the UI?
- cloudhead 3y agoWe're a small team, but if there is enough demand for it, then yes.
- 2color 3y agoIt's been fascinating watching Radicle evolve over the –what seems to be– last 5 years. I attended the workshop at Protocol Berg 2023 and think they built something really powerful and novel. Perhaps the most exciting aspect is that even the collaborative aspect of the protocol is local-first which means you can submit patches and issues without internet and that your team isn't on HN every time GitHub is having problems.
- deleted 3y ago[deleted]
- taxmeifyoucan 3y agoNice to meet a fellow Protocol Berg enjoyer in HN!
- shackra 3y agois there any plans to support this use case: offering repositories only to a set of nodes? I can imagine people wanting to collaborate in private but not wanting to be on Github.
- cloudhead 3y agoYes, these are what Radicle calls "private" repositories. They are invisible to the rest of the network, and only shared amongst trusted peers. Note that they are not encrypted at rest, which means they cannot be stored on intermediary nodes that are not part of the truste set.
- singularity2001 3y agoThe best approach to building a GitHub Alternative would be to build a GitHub for Data (merge SQL changes etc) and then extend that to GitHub for Code and later to GitHub Alternative for anything.
- saurik 3y agoFrom their documentation: > It’s important to only publish repositories you own or are a maintainer of, and to communicate with the other maintainers so that they don’t initialize redundant repository identities. Based on my experience with people taking my code and shoving it onto GitHub--as well as separately in my demoralizing general experience of putting random little "please for the love of all that is holy don't do X as it will cause problems for other users" notices in the documentation or even as interstitial UI (!!) of my products and watching everyone immediately do exactly that thing as no one reads or thinks (or even cares)--a large number of people aren't going to honor this request in the documentation... and, frankly a large number of people aren't even going to see this in the first place as the home page tells you how to push code but you only find this "important" request in the "user guide" that people definitely do not bother to read. It thereby seems quite concerning that, apparently?!, this system is designed in a way where doing what feels like a very reasonable thing to do--just pushing whatever open source code you are working on, based on the instructions on the home page--is going to interact with something about this protocol and how things are stored that something important enough to have this separated boxed "important" statement in the documentation is going to get cluttered and maybe even confusing over time :(.
- cloudhead 3y agoI don't think there's anything "special" here. You have the same problem currently where finding the canonical location of a repository is done via some out-of-band social network or website. On GitHub, you also can look at the stars to give you extra confidence, and on Radicle the equivalent is the seed count for a given repository.
- saurik 3y agoThen why does the documentation say this is "important"? GitHub certainly does not have a notice anywhere saying "it's important to only publish repositories you own or are a maintainer of" (...well, I guess it could be buried deep in some user guide I never read, lol).
- 3y ago
- birthdaycollage 3y ago[dead]
- anthk 3y agoThere should be a way to run git over i2p. Also, git over yggdrasil should be easy because there are just ipv6 addresses. And, in the worst case, I think 6to4 tunnels would work.
- mhitza 3y ago> There should be a way to run git over i2p. https://geti2p.net/en/blog/post/2020/03/06/git-over-i2p https://geti2p.net/en/blog/post/2020/03/06/git-over-i2p see "Third: Set up your git client tunnel" But like most things in the I2P ecosystem, not seamless.
- anthk 3y agoAs long as it runs with an i2pd service in the same easy way as irc/usenet or email, I'm sold.
- cassianoleal 3y agoWhy does this website try to connect to localhost on http://127.0.0.1:8080/api/v1/node http://127.0.0.1:8080/api/v1/node ?
- angio 3y agoIf you run their service locally it displays the connected account and you can interact with the app.
- polski-g 3y agoFairly arrogant to assume port 8080 is unused for other things on localhost.
- _flux 3y agoIt's just the default, it can be changed. And it wasn't free on my host me either :). Indeed 8080 is maybe not the best port to select for this app, because it is more likely used than "some other" port.
- actionfromafar 3y agoMaybe that is where you would have your local copy of Radicle running?
- gsaslis 3y agolocal-first [1] software ;) That is the default port for `radicle-httpd`: an HTTP API that would allow you to authenticate (using your public/private key pair, that is stored on your machine), so that you can perform actions on the web-based interface as a specific user, through your local radicle node. [1] - https://www.inkandswitch.com/local-first/ https://www.inkandswitch.com/local-first/
- hahnrobert33 3y ago[dead]
- Zuiii 3y agoSupport peering over the Tor network like what briar does. That way, all peers can fall back to tor when they're behind restrictive firewalls.
- cloudhead 3y agoWe've designed Radicle with Tor support in mind, via Socks5 proxy!
- Luker88 3y agoThis looks wonderful, I'll read more on details and follow the project! Does this suffer from the code search problem, or are there plans to somehow introduce that? The main problem of decentralized and federated code management projects is that I still go to github (not even gitlab) when I want to see what other people do, how they use a lib or something, and I can search issues, too. So we obviously can't have each of our small servers serve code search requests from all the world's developers. ...a sync-and-search-only project is probably a job for someone like the EFF, or non-profit orgs that already have sufficient funding... has anyone heard any talks in that regard?
- megamix 3y agoWhat about codeberg.org?
- Hendrikto 3y agoWhat about it? It‘s an almost completely different product. Codeberg is like GitHub.com, GitLab.com, or sr.ht: a centralized hosted solution.
- megamix 3y agoAh I see, I've not worked with any, however I do become curious about anything labeled as "Github alternative". I know this movement since Github started with their "doubtful code scanning" that people are looking towards alternatives. Not the least: good job!
- kkoyung 3y agoThe software behind Codeberg is Forgejo, which is a fork of Gitea. The team of Forgejo is working on a federation protocol based on ActivityPub. Once it is done, it will be able to exchange data with other Forgejo servers and any server supporting that protocol. So, we may expect that Codeberg will transform from centralized to federated. sr.ht chooses another approach. You only need an email to submit codes, file issue, join discussion, etc. From perspective of source hosting, it is centralized. But, from perspective of project collaboration, it is decentralized.
- _flux 3y agoFederated is nice, but with Radicle you don't need a server with publically accessible IP, so you can pull and push with just a node running on your laptop—though I understand there still need to be some nodes with publically accessible IP due to NAT and it doesn't seem Radicle is (yet?) doing NAT punching/STUN/TURN. Well, at least you don't need a name or a certificate for the server, I assume its id works as its cryptographic identity.
- themusicgod1 3y agocodeberg are censors. People should be migrating elsewhere. https://codeberg.org/themusicgod1/codeberg-is-corrupted-dont-use-it https://codeberg.org/themusicgod1/codeberg-is-corrupted-dont...
- alberth 3y agoGenuine question ... isn't there an inherent latency issue with Peer-to-Peer? and as such, it makes for a poor user experience on the web. (when you're just downloading files over P2P, this isn't an issue or noticeable - but when you're interacting with a web site, it is) EDIT: why the downvotes? I'm just asking a question.
- cloudhead 3y agoIt's a good question, I don't know why you're downvoted. Because the synchronization protocol (backed by Git) is operating in the background, web frontends are always just querying local data, so it's actually quite fast. You can try browsing the linked repository and see for yourself.
- throwaway220033 3y agoEven a slightly critical comment gets downvoted instantly in this thread, I wonder why ;)
- ryscheng 3y agoCongrats on the launch! I’ve been following this project and I’m really excited to see how much it has matured. For projects currently on GitHub, what’s the best way to migrate? Is there a mirror mode as we test it out?
- cloudhead 3y agoThanks! There is no mirroring built-in yet, though this is something we're looking into. It should theoretically be as simple as setting up a `cron` job that pulls from github and pushes to radicle every hour, eg. git pull github master git push rad master
- miohtama 3y agoGood work! The main value capture at Github is issue tracking, PR reviews and discussion. Maybe not today, but is there an automated way to migrate these over in the future?
- maninak 3y agoYup, you can do this today! There's already this tool https://github.com/cytechmobile/radicle-github-migrate https://github.com/cytechmobile/radicle-github-migrate, built and maintained by the community, and which is already quite capable.
- gsaslis 3y agoIn addition, in order to migrate your GitHub issues to Radicle (which the above doesn't cover), there's this command-line tool [1] that should get you most - if not all - of the way there. Migrating GitHub Pull Requests (PRs) to Radicle Patches is somewhat more involved, but that should still be possible (even if it involves some loss of information along the way, due to potential schema mismatches) ... [1] - https://github.com/cytechmobile/radicle-github-migrate https://github.com/cytechmobile/radicle-github-migrate
- ryanb0973 3y ago[flagged]
- willsmith72 3y agoThanks Mr Ryan bot
- OSI-Auflauf 3y ago> p2p, signing, local first, yadda yadda curl | bash is the recommended way to install.
- themusicgod1 3y agodamn you're not joking
- unintendedcons 3y ago[flagged]
- perihelions 3y agoThat's a neat name! If "seeding" is the word for distribution in a peer-to-peer network, then a "radicle" (not a "radical"!) must be named after: - "In botany, the radicle is the first part of a seedling (a growing plant embryo) to emerge from the seed during the process of germination.[1]" https://en.wikipedia.org/wiki/Radicle https://en.wikipedia.org/wiki/Radicle
- philsnow 3y agoGoing to be pretty confusing between Radicle and Radicale ( https://radicale.org/v3.html https://radicale.org/v3.html )
- rapnie 3y agoMuch less so than Amazon and Amazon, Meta and meta, and Threads and threads.
- falcor84 3y ago>a "radicle" (not a "radical"!) I'll just mention that etymologically both "radical" and "radicle" come from the Latin "radix", meaning "root".
- deleted 3y ago[deleted]
- 3y ago
- chefandy 3y agoTheir monetization strategy is pretty critical for people who’d sink their time into the service and entrust it with the code for long-running projects. So… how do they plan on making money off of this? If they can’t or won’t say, what sort of projects do they imagine they’d attract in spite of that? (e.g. ephemeral ones? Data sets about current events?) Downvoters: do you not think their monetization strategy is important to potential users? Surely their investors didn’t throw that money at them out of the goodness of their hearts, and surely it’s apparent how that could affect their users in the long run.
- beardicus 3y agothis is a very VC-brained comment to make on a peer-to-peer open source project. let's instead ask if there are any single points of failure to the protocol and service, and if so, are those sustainable regarding developer time, effort, and compensation?
- chefandy 3y ago> this is a very VC-brained comment to make on a peer-to-peer open source project. let's instead ask if there are any single points of failure to the protocol and service, and if so, are those sustainable regarding developer time, effort, and compensation? Crunchbase said they raised at least 12m as a “fully decentralized code repository”. I’d say presenting your open source project without saying it’s VC-backed is the only “VC-Brained” thing happening here.
- couchand 3y agoIncredible. They throw some indie-sounding buzzwords out and that's enough to make the business model unimpeachable? Over the past few decades we've seen many cynical capitalists riding the wave of "peer to peer open source" for personal gain. It's absolutely within scope to discuss how a company's business model may affect their ability to deliver on the supposed mission.
- chefandy 3y agoI imagine the person responding to my initial comment just didn't realize it was a VC-backed business rather than a regular FOSS project. The repo readme doesn't seem to indicate otherwise, so I can see why they'd have gotten that impression.
- clot27 3y agoMy question isnt related to radical but P2P in these sense in general, Why should I store someone else's data and why should someone else store my data? doesnt it make it easy to access?
- maninak 3y agoThat's a great Q. Radicle can support a federated model, where known major seeds are connected with multiple smaller clusters. Radicle supports also completely self-sustaining and disconnected clusters of nodes networked between themselves within that cluster. And of course any other network topography in between. There's a promising active proposal to establish a dedicated new Radworks Organization tasked with solving the incentivization and reward problem for seeds. https://community.radworks.org/t/discussion-rgp-22-start-the-radicle-seed-network-rsn-org/3479/2 https://community.radworks.org/t/discussion-rgp-22-start-the... Additionally, similar to how one can "star" a repo on GitHub, one can "seed" a repo on Radicle. "Starring" a repo is often a toast of support, akin to an emoji reaction, with little more effect other than that, but in Radicle "seeding" a project, goes beyond incrementing a vanity metric: it actively supports propagating that project across the Radicle network. The count of seedings per repo can also be used as a differentiator between original and "copy-cat" ones.
- _flux 3y agoI wonder how discoverable (for normal people) these repositories are. It looks like https://app.radicle.xyz/robots.txt https://app.radicle.xyz/robots.txt doesn't exist, so it seems like fair game for search engines, and indeed a search on Google and DDG for site:app.radicle.xyz does give some results. Maybe not that high up yet if not using that site filter, perhaps the ranking will improve? Tools for integrating CI support with this would also be nice to see. Ultimately a loop with while true; do wait_repo_update; git pull && ./run_ci.sh; done but something nicer that you could only limit to pushes by trusted identities. And then finally artifact storage. But maybe Radicle doesn't need to solve everything, in particular as a distributed network for sharing large binaries is going to get some undesirable uses pretty fast..
- zlatan_todoric 3y agoWe are actually working on a number of CI integrations and building our own native one, for our needs.
- mdaniel 3y ago> building our own native one, for our needs. I realize I'm just some rando on the Internet, but I'm begging you please don't introduce Yet Another CI Job Specification ™ I'm sure you have your favorites, or maybe you hate them all equally and can just have a dartboard but (leaving aside the obvious xkcd joke) unless you're going to then publish a JSON Schema and/or VSCode and/or IJ plugin to edit whatever mysterious new thing you devise, it's going to be yet another thing where learning it only helps the learner with the Radicle ecosystem, and cannot leverage the existing knowledge It doesn't even have to be yaml or json; there are quite a few projects which take the old(?) Jenkinsfile approach of having an actual programming language, some of them are even statically typed I also do recognize the risk to your project of trying to fold in "someone else's" specification, but surely your innovation tokens are better spent on marketing and scm innovations, and not "how hard can it be" to cook a fresh CI job spec I likely would have already written a much shorter comment to this effect, but having spent the past day slamming my face against the tire fire of AWS CodeBuild, the pain is very fresh from having to endure them thinking they're some awesome jokers who are going to revolutionize the CI space
- andrewfromx 3y agoand I thought I was cool for knowing about https://codeberg.org/ https://codeberg.org/
- circusfly 3y ago1. Lower left, device isn't connected? What device? 2. Domain ends with the nonsensical .xyz, my email server would block all email traffic from them. 3. The default dark theme isn't readable by about 40% of the human population. It can be changed to a light theme, that's nice, but the light theme is some sort of puke light purple. 4. "Run the following command and follow the instructions to install Radicle and get started." I have to use your custom tool called "rad"? No thanks. Even though GitHub is owned by Microsoft, I'd rather use it.
- jprd 3y agoOff-topic: This reminded me of NESticle. https://en.wikipedia.org/wiki/NESticle https://en.wikipedia.org/wiki/NESticle
- PH95VuimJjqBqy 3y agowell that's a name I didn't expect to see coming into this thread, lmao. so many good memories of that software but for some reason I'm remembering a red theme.
- LegibleCrimson 3y agoTHANKS SHITMAN!
- danielvaughn 3y agoPedantic, but this seems like a git alternative, not simply a GitHub alternative.
- webstrand 3y agoThere appears to be a git remote helper in the repo, so this will work just fine with standard git.
- deleted 3y ago[deleted]
- Retr0id 3y agoThis could enable development of projects like forks of Yuzu, with reduced risk of DMCA interference.
- fwip 3y agoUnfortunately, it's developed by crypto-brained guys.
- tonymet 3y agoisn't git already the open source, p2p Github alternative? coders will do practically anything to avoid learning `git rebase` . ( don't read too deeply on this chaps)
- LegibleCrimson 3y agoIt is if you don't care about any of the other things that Git brings to the table. I fail to see what `git rebase` has to do with issue trackers, project boards, wikis, repository notifications, or any of the other things that GitHub does. I use git forges as well as `git rebase`. Neither of these things precludes the other.
- tonymet 3y agoGCM glorified commit messages
- LegibleCrimson 3y agoI find them useful, as do many others. They can do many things that commit messages obviously can't. You can technically coordinate many of the other things through external tools like email, but email sucks, and there is real value to having them all in one place. Obviously, I'd rather have all these things part of the repo itself, like with Fossil. What's what Radicle is trying to do, it looks like.
- always2slow 3y ago>Installation > >The easiest way to install Radicle is by firing up your terminal and running the following command: > >$ curl -sSf https://radicle.xyz/install https://radicle.xyz/install | sh Ah.. my high hopes were immediately dashed by the trash that is curl-bash. What a great signal for thoughtless development, if this project catches on I can't wait to watch the security train wreck unfold. Maybe someday we'll get an "Open-Source, Peer-to-Peer, GitHub Alternative" that doesn't start with the worst possible way to install something.
- zlatan_todoric 3y agoHere you go [0] - the project hasn't launched yet and there are bits and pieces to be dealt with, the current focus is a bit somewhere else. You can also build from source [1] with Rust's cargo. [0] https://files.radicle.xyz/latest/ https://files.radicle.xyz/latest/ [1] https://app.radicle.xyz/nodes/seed.radicle.garden/rad:z3gqcJUoA1n9HaHKufZs5FCSGazv5 https://app.radicle.xyz/nodes/seed.radicle.garden/rad:z3gqcJ...
- always2slow 3y agoThanks but... no thanks, you've missed my point entirely. Why would I want to run peer to peer software built by developers whose security stance starts with curl-bash? Would you curl-bash a webserver? an email server? No? Probably even worse for your source code repository then right?
- LegibleCrimson 3y agoThe problems with curl-bash are overblown. You are pretty much exactly as vulnerable running pip install, npm install, or cargo install. Not that curl bash is great, but it's not uniquely horrible when the goal is to run some unvetted code on your machine. If you care about security, you have to either vet the code or trust the source. When you install through your package manager, you're trusting the maintainers. When you install from curl bash, a random website, or any unvetted software source, you are electing to trust the developers or site directly.
- 20after4 3y agoI'm curious why dual license with both the MIT and Apache licenses. This is not a criticism, and I could be wrong about this, but doesn't the mit license allow anyone to essentially bypass any extra responsibilities provided for in the Apache license? Specifically I'm thinking of the patent license grant provisions. I don't think the MIT license has anything to say about patents. And if that is the case then why not just license it MIT?
- contrarian1234 3y agoA bit of a naiive general question, but why are these things not layered on top of existing technology? You already have Bittorrent for distributing files P2P. We "just" need an extra layer for discovering new updates/patches so that files can dynamically update/grow. These two problems seem fundamentally decoupled. The "git forge" aspect seems to be another fundamentally separate layer on top of that
- cloudhead 3y agoWe tried. At first we built it on top of IPFS. It was much too slow. BitTorrent is interesting but we need a way to have mutability (repos change all the time). So we built the networking layer ourselves and the forge on top of that.
- contrarian1234 3y agoIf you built a mutable bittorrent layer yourself (like ipfs but better), then why not make it its own separate thing? If that's what you've managed to pull off, that's like a way bigger deal than a p2p gitforge (not that that isn't super cool in itself) I guess architecturally why does it need to be coupled to git and a git forge?
- cloudhead 3y agoIt's optimized for certain workloads around code collab, so for now we don't want to oversell it. It doesn't have to be coupled with Git, though Git is very efficient at synchronizing changes. The protocol currently can be used for other things than a forge, but having an application influence protocol development is very helpful.
- hossbeast 3y agoI really want to have the problems this solves.