6 ms·
Re: Why Host Emacs Packages on GitHub? (Microsoft vs Freedom)
- tetris11 2y agoThe network effect really is important if you don't use email for patches and want to capture an audience greater than your typical zealot coder (of which I am one). Github makes it easy for non-coders to submit documentation, test their changes, and genuinely be part of something that they are not an expert in. Sure there are disadvantages there too in terms of the quality of the submissions, but the benefits of a busy community outweigh the drawbacks of too many PRs in my opinion
- jackdaniel 2y agoShouldn't we call it a "network prison" in that case? :)
- tetris11 2y agowell it's one where the inmates can leave, but have to come back out of solidarity to the other prisoners :-)
- Arnt 2y agoIt's not a prison, you can leave whenever you want and take with you everything that's supported outside github. Git clone and go. The features that attracted you to begin with still attract you, though, so maybe you don't want to. Compared to e.g. moving a team from one mail server to another, moving from github is remarkably simple.
- jackdaniel 2y agoThank you sensei, I think that I do understand now.
- xandrius 2y agoWhy wouldn't this possible on, say, GitLab or Bitbucket?
- vmfunction 2y agodon't forget CodeBerg
- tetris11 2y agoAll of my new stuff is on GitLab. I have seen zero interest in any of my projects, even the ones that were carried over from Github (which are archived). It could just be that I am a dull coder, but I'm leaning more on the notion that discovery is hard in GitLab.
- rcarmo 2y agoThis, and worse: I’ve stopped using libraries that migrated to GitLab in my own personal projects, because I just can’t be bothered to check for updates there, or deal with the UX, or log in to report bugs because I don’t really want to create another account. I remember when SourceForge was a thing, and GitHub was just tremendously superior feature-wise and community-wise, with new issues and PRs for stuff coming in daily. GitLab, Codeberg, etc. may have 90% feature parity, but they’re not anywhere near the ease of interaction. (I’ve also set up a Gitea instance on my NAS to mirror my own stuff, some GitHub projects that might be controversial—like emulators-and stuff from GitLab and Codeberg. And guess what, I seldom use that as well to keep track of external projects.)
- xandrius 2y agoSounds like you don't have w GitLab account and don't visit it frequently enough to get used to it? I mean we can't really complain when alternatives exist, have 90%+ be feature parity but they are slightly different in terms of UX. Isn't that basically summarising FOSS? You trade a bit of UI/UX for the freedom and openness.
- cnity 2y agoThis presents a false dichotomy (Github vs email patches), when there exist a whole host of self-hosted options (Gitea for one).
- madeofpalk 2y ago> This was the case even when SourceHut was the “official” source and GitHub was a mirror (I also have a GitLab mirror, which probably never received a single contribution): the vast majority of the contributions were on the GitHub mirror, while SourceHut was adding friction to my maintenance work.
- heinrich5991 2y agoThe grandparent does not present a dichotomy, let alone a false one. It says that when you are not using email patches, the network effect of the platform (like Gitea which you present as if it was explicitly excluded by the grandparent) is important.
- croes 2y agoBut the network effect could lead to something like the next xz backdoor
- Mashimo 2y agoIf xz would have been hosted another place, what could have been prevented?
- xandrius 2y agoThat maybe fewer people would have even known about it and therefore decreased its importance as a target? /s
- croes 2y ago>The technical reason for not opting for such alternatives is that I will not be getting enough contributions there. Yes. Sudden interest from multiple people in certain pull request raise suspicions if you only have a contributions.
- probably_jesus 2y ago[dead]
- perihelions 2y agoI think the root thing I disagree with in this essay is whether (GNU definition) freedom has anything to do with successful, thriving economic markets. No; they're completely orthogonal. The logic of this article might suggest Shenzhen is the freest place on earth—a fast-moving, healthy marketplace with a vast diversity of economic actors to transact with with low friction. Yes, but also no. - "Freedom and diversity go hand-in-hand. We empower people to express their individuality. The cumulative effect is a richer corpus of shared resources, from which we can all draw from to elevate our experience." This is like a definition of wealth, not of freedom.
- trueismywork 2y agoWealth is often necessary for meaningful freedom.
- pasc1878 2y agoBut not sufficient
- ants_everywhere 2y agoMy general point of view is that FOSS software is a public good, and that we should aim to maximize the availability of that public good. This point of view contrasts with other views, for example I don't see much value in ideological purity for its own sake. For that reason, I think it's a bit foolish to dissuade people from hosting on GitHub as long as Microsoft is subsidizing bandwidth and hosting costs. You might as well stick MSFT with the bill. But if you go that route, you do kinda have to keep your eyes open to the real possibility of an eventual rug pool. Or even just that MSFT will make incremental cost saving changes that render some uses of GitHub increasingly unusable over time.
- jampekka 2y agoShort term maybe. But Github has already a kind of monopoly on git web interfaces. Package managers (e.g. npm) already have preferential treatment for it, and adding "github" to a search term is quite a standard way to search for source code. My guess is that sooner or later we'll see EEE. GitHub will slowly get more and more tied with MSFT technology (already ongoing), and at some point MSFT will want to start squeezing profits with their lock-in one way or another. IMHO Microsoft shouldn't have been allowed to buy GitHub. In general it's really not a good situation that so few megacorporations dominate the software industry. But the regulation is broken.
- bayindirh 2y ago> My guess is that sooner or later we'll see EEE. They're using every open repository to train CoPilot and sell your code and derivations of it $10/pop. Do you need any more steps?
- Dalewyn 2y ago>sooner or later For some context it's been 6 years since Github was acquired by Microsoft and over 12 years since Microsoft first made their appearance. I think Microsoft has a great track record here, EEEs in other ventures aside. https://en.wikipedia.org/wiki/GitHub#Acquisition_by_Microsoft https://en.wikipedia.org/wiki/GitHub#Acquisition_by_Microsof...
- 2y ago
- eviks 2y ago> I do not blame SourceHut, as they clearly state they are still in alpha The decision to stick to the clunky email interface isn't due to stage name
- posix86 2y agoUnlreated: Is the title correct english?
- thaumasiotes 2y agoYes, it's correct English. There's nothing unusual about it. The verb is infinitive with no particular subject. "Why choose one when you can choose both?" - https://www.reddit.com/r/Kanye/comments/ph6sab/why_choose_one_when_you_can_choose_both/ https://www.reddit.com/r/Kanye/comments/ph6sab/why_choose_on... "Analyzing Systems: Why Do It That Way?" - https://digitalcommons.georgiasouthern.edu/cgi/viewcontent.cgi?article=1008&context=savannah https://digitalcommons.georgiasouthern.edu/cgi/viewcontent.c... "Why be afraid when God is always showing the way?" - https://www.archstl.org/popes-message-why-be-afraid-when-god-is-always-showing-the-way-1836 https://www.archstl.org/popes-message-why-be-afraid-when-god... Despite the lack of a subject, it can trigger reflexive pronouns: "Why limit yourself to just 3 wishes?" - https://www.brainzmagazine.com/post/why-limit-yourself-to-just-3-wishes https://www.brainzmagazine.com/post/why-limit-yourself-to-ju...
- defrost 2y agoYes, particularly as a blog post (with the context of continuous ongoing discussions) Re: is a longstanding abbreviation for * In the Matter of ... * With Regard to ... * In Reference to ... and the article discusses matters arising from the asked question "Why host on Github?".
- Dalewyn 2y agoI always read Re: as Regarding: (and also Fwd: as Forwarding:), thanks to email.
- thaumasiotes 2y agoI assume it's short for in re, which is sort of Latin for "on/in the matter [...]". Actual Latin uses de to mark the topic of a disquisition (compare de corona, the Latin translation of Demosthenes' speech "on the crown"); I'm not sure why we say in re. It appears to be an early modern legal usage.
- lrvick 2y agoI made the same excuses in the past, and I could not even keep making them to myself seriously after a couple years of watching Microsoft censor various repos. At some point people put code on GitHub before it had "network effects". If a package is useful enough, people created accounts on GitHub to get help or contribute. Maintainers need to stop rationalizing away their -choice- to centralize code on GitHub. We do not need governments to help here. The political votes that matter are every repo that someone chooses to not host on GitHub, or at a minimum mirror elsewhere. The more useful your software with fewer alternatives, the more "network effect" power you wield to get someone to sign up for something besides GitHub. I started Stagex, which is as far as I know still the only oci-native, deterministic, multi-signed, and full-source bootstrapped Linux distribution that exists. If you want easy deterministic containerized builds of software without trusting any single human in your compilation path, Stagex is the only option. My shameless plugging aside, I chose to host this exclusively on Codeberg in spite of the major financial sponsors all being on GitHub. Already we have 8 contributors and the ~200 most common packages needed for most python/tcl/perl/lua/c/c++/go/rust software with more language support in progress by volunteers. We built Stagex to ensure a fully open and transparent supply chain for any software to be built with, and that starts with using a Git host that shares these values. Codeberg also donated unlimited free CI/CD via woodpecker as is available to most projects that apply since their funding is exclusively for social good. We will self host eventually when forgejo supports federation so our instance can still get contributions from Codeberg users. Git was built to be decentralized and that is never going to happen under Microsoft. I know it is harsh but if you have a popular project and exclusively host on GitHub, you are why we are in this monopolozed-network-effect situation, and you have the power to change it. https://codeberg.org/stagex/stagex https://codeberg.org/stagex/stagex https://sfconservancy.org/GiveUpGitHub/ https://sfconservancy.org/GiveUpGitHub/
- agile-gift0262 2y agoI agree with many of OP's points, but I don't think OP is addressing the suggestion of using Codeberg, which I believe is a reasonable alternative to GitHub. It provides a GitHub-like experience, so it solves the OP's problems with SourceHut. Regarding discoverability, I doubt anyone finds projects through GitHub's search or discoverability features, but rather through a search engine like Google or DDG and online communities. So the project should be similarly discoverable if the source was in Codeberg. The main friction point I can see is that many won't have a Codeberg user, so they'd need to sign up in order to collaborate, while most already have a GitHub account.
- lrvick 2y agoCodeberg supports account creation and sign-in with GitHub login, so there really are no excuses IMO. One extra click for any existing GitHub user to comment on a Codeberg repo.
- deleted 2y ago[deleted]
- jasode 2y ago>Codeberg supports account creation and sign-in with GitHub login, so there really are no excuses IMO. One extra click for any existing GitHub user to comment on a Codeberg repo. Your simplification of the steps is incorrect. I just did this "sign-in with Github" workflow and it's not just 1 click. After using Github to authorize Codeberg, it still requires new users to enter a valid email. Codeberg then requires verification of that email address by the user clicking on the url in the email. (And the email address step above also adds more behind-the-scene steps for me since I always create email aliases for every service to manage spam.) Not sure what friction is removed by signing in with Github rather than just registering a new account email address directly with Codeberg.
- lrvick 2y agoNot having to set another password. That is the biggest PITA that makes people groan when creating new accounts. Passwordless FIDO2 is of course the best solution, not OIDC.
- deleted 2y ago[deleted]
- firemelt 2y agothis is the reasons why I kinda doesnt like it when an opensource package hosted on gitlab I mean idk if gitlab still foss or opensource company its just have same vibe like redis terraform or any other VC backed open source that try to search for the money
- bayindirh 2y agoI don't think the author is painting a correct picture here. Yes, SourceHut has a different modus operandi compared to GitHub, GitLab, Codeberg et. al when it comes to merging patches. However, this doesn't invalidate Codeberg/GitLab as a viable primary repo and patch collection path. If the author is so adamant on network effect advantages, they can host a mirror on GitHub with an appropriate README.md pointing folks to right direction. If the author needs to write a long post to validate themselves about using GitHub, there's no need. At the end of the day, what you say to others doesn't matter much. The biggest wisdom is to not lie to yourself about why you're doing something.
- deleted 2y ago[deleted]
- cess11 2y agoThere are many software collectives offering Gitea or similar for free or almost free, so there has to be a good reason for giving away one's code to MICROS~1.
- brabel 2y agoProtesilaos is a legend and I agree with everything he's said on this post. I myself put all my projects on GitHub because of visibility and the free CI to run tests on Windows/Mac/Linux which is a godsend... but I also normally keep an alternative upstream on all my projects with https://www.opencode.net https://www.opencode.net (it's as easy to do that as adding a new remote with git) so I feel like I have zero dependency on MSFT, all the services they provide to me for free are just "nice-to-have" things. But they are very nice indeed. The only danger I see is that GitHub becomes so widespread that other tools start only integrating with it (instead of using pure "git" integration). People are saying NPM already does this (I don't know, I don't do NPM)? That's a real danger, but hopefully other projects will have the common sense to not fall into this trap. For now, at least, I feel like that's not been a big problem.
- sourcepluck 2y agoWonderful article. Protesilaos does great work, and doesn't indulge in popularity contests, or shy away from uncomfortable realities as he sees them (which apparently is difficult for some HN readers). Keep it up, Prot.
- crabbone 2y agoI want to comment on comparing things that seem similar, but aren't. In particular, OP wants readers to believe that taking drugs developed by "big pharma" is the same, or is morally equivalent to hosting one's project on GitHub. The problem with this is that the relationship between the drug manufacture and the drug user isn't the same as with the repository service and the user, and in a very important way. * By using the drug the user doesn't contribute anything back to the manufacturer beside the monetary compensation. The equivalent of repository service would've been a drug user who agrees to run experiment for the company developing the drug in exchange for the drug. Such things do happen, especially in desperate cases... but, certainly aren't the norm of pharma company vs drug user relationship. * Pharma companies are heavily regulated, with lots and lots of drug users protections in place. If a pharma company is found to have walked back on the safety or other promise about a particular drug -- there's a good chance they'll be taken to court, and, hopefully will have to pay reparations. GitHub, on the other hand, makes no promises to the non-paying customers, and, like a famous jedi, will force choke you when they alter the deal they made with you, while telling you to prey they don't alter the deal any further.
- csdreamer7 2y agoA lot of you are not taking about the biggest reason to avoid GitHub. Having the rug pulled from you. Terraform? Remember that? VMWare? Redis? What happens when a company stops providing a good deal? With GitHub you have lock in to the way they do things. So many of you complained about CentOS and then go lock yourselves in to far worse when you have CentOS Stream which was mostly good enough. You have a perfectly good option: GitLab. Yes, parts of it are closed source, but most of you will be perfectly fine with the open source stuff. You can move your repos over to a self hosted option for your independence with ease. Most of you do not care about that because you want to seem like you have a lot of activity on your GitHub. I do not blame you. I literally had an employer reach out to interview me directly because of my GitHub activity. His job offer was absolutely terrible but it was nice for them to do that this time. But most of you also want to entertain the idea of moving up in the world from a simple coder. A tech lead, a tech business owner, vc startup, run a nonprofit, etc. Then you care about the rug being pulled from you, either because it means less money for what you want to do or it is a massive hassle to move, and this is an excellent way to prevent that.