10 ms·
Open Source is one person
- StellaMary 1y ago[flagged]
- speakingmoistly 1y ago[Relevant xkcd.](https://xkcd.com/2347/ https://xkcd.com/2347/) It's interesting to see the periodic rediscovery of "capitalism + technology relies on unpaid, voluntary labour", or as the author puts it, "Open source, the thing that drives the world, the thing Harvard says has an economic value of 8.8 trillion dollars". The one flaw that I see in the author's analysis though is that they don't seem to account for whether the packages accounted for by their source have dependents or monthly downloads. There's *a lot* of dead code out there. When excluding abandoned packages, I bet the picture is still grim, but it might be less so.
- sorrythanks 1y agohalf way down the page: > So now, let’s look at the number of maintainers for projects with over 1 million downloads this month.
- speakingmoistly 1y agoFair point, I glossed over that part a bit fast. It does go in the direction I thought it would though. I'd be curious to see (or to take) a look a little deeper at what those thousand of packages are.
- thisoneworks 1y agoYou can frame the "unpaid voluntary labor" as "creative work" and it would start making a whole lot of sense. "Creative work thrives despite being unpaid in capitalist society."
- socalgal2 1y agoI’d state that as capitalism + technology provides enough surplus money and time that people can work on hobbies
- EdiX 1y ago> capitalism + technology relies on unpaid, voluntary labour You are falling into the breadtube trap of faulting capitalism for a societal issue that has nothing to do with it. Did capitalism force people to have productive hobbies? Would you prefer a system, other than capitalism, that prevented people from having productive hobbies? Often times this error relies on the assumption that capitalism is what's preventing us from having an "idealized" version of communism that I've heard aptly described as Gay Luxury Space Communism, where anyone can do anything they want and society just magically pays for it. The problem is that GLSC isn't real, we'd need ~infinite resources to do it. I personally blame this problem on charities. This is the type of problem that charities and foundations should solve but there is no safeguard for charity money actually going to the charity's cause of action, instead the moment you create any kind of non profit it transforms into Non Profit (inc) and all the money it received goes to (1) professional non-profit people for the job of raising money and redistributing it, (2) shuffled to other non-profits, (3) thinly disguised political activism.
- tracker1 1y agoI wish I could +1 this many times over. Mozilla and Wikipedia are two great examples of this... so much of the expenses are diverted to busy work and so much less to the added value to society.
- wolvesechoes 1y agoIt is funny how you recognize the "breadtube trap", yet you are so invested in the "no alternative" ideology.
- EdiX 1y agoMaybe it would help if you articulated it even a little bit.
- blueflow 1y agoIf they had done an activity check they would have seen that half of all projects have zero maintainers.
- ysofunny 1y agosoftware once "perfected" (working well enough long enough) needs NO maintenance. No cleaning. No calibrating/tunning. updating is a systemic issue, not a per-project matter
- blueflow 1y agoMaybe we need a Linux distro based on "inactive" software and look how reliably it performs.
- BirAdam 1y agos/inactive/stable/ Well, when you talk about a distribution there's a different issue. The entire Linux ecosystem is constantly shifting with each package releasing new versions, and therefore everything else must be updated to accommodate the changes in the dependency tree. You could get away with some stuff being only stable versions, but things like mesa, x11, chrome, etc... would still be constantly changing as would their dependency trees.
- ii41 1y agoI was once forced to use older (but not deprecated) LTS Ubuntu and I hated it. New software come out and you're gonna want to use them (often forced to use them), and they of course use newer dependencies. I had to do the distribution maintainer job and package a bunch of software myself.
- marssaxman 1y agoWhat sort of work do you do? I only use LTS distributions, and this is not a problem I have encountered, so I wonder what accounts for the difference in our experiences.
- andersmurphy 1y agoI find it more concerning that the DoD uses node. I might be wrong but npm etc feels like a very large attack surface.
- deleted 1y ago[deleted]
- lantry 1y agoThe DoD is a huge organization, so I'd guess they use almost everything.
- kube-system 1y ago> The DoD is a huge organization That's an understatement if there ever was one. https://en.wikipedia.org/wiki/List_of_largest_employers https://en.wikipedia.org/wiki/List_of_largest_employers
- chamomeal 1y agoWoah that’s insane, I didn’t realize it was THAT big. And that’s not even counting the zillions of contractors and consultants. I live in the DC area and I know a ton of people who work for places that contract for the DOD, and only like 2 people who actually work there
- spott 1y agoThat is including all us military personnel, which puts it into perspective a bit.
- ARandomerDude 1y agoI think I'm even more amazed that Walmart has almost as many employees as the DoD.
- tracker1 1y agoThere's a reason it's the largest budget item outside entitlements. There's a lot of money flowing into DoD (and Military Industrial Complex vendors).
- ChrisMarshallNY 1y agoI've heard good things about work done by this guy Linus. I'm pretty sure that I've used his work. I think he comes from a country that borders Russia, so should we be worried? I've done OSS for decades; mostly by myself, but sometimes, in teams of volunteers. If anyone has any experience, working in teams of volunteers, it can be ... challenging. It can definitely work, but not as often as you'd think. If it works, there's usually some "BDFL," or a common goal that has everyone on the same beam. In my case, it was usually the latter.
- tarvaina 1y ago(Off topic.) Not only that, but Linus's parents were politically active communists and young Linus was a pioneer (like a boy scout but for communists). His father also lived in Moscow for several years on two separate occasions.
- lo_zamoyski 1y ago> Linus was a pioneer Being a Young Pioneer or joining the Komsomol was not officially mandatory, but it functioned as a gatekeeper for any kind of advancement. Party membership operated the same way. So, by themselves, they don't tell you whether the person in question is a communist.
- rauli_ 1y agoNot in Finland which has never been a communist country. His parents were just political activists who forced young Linus to participate in that as well. Linus has said that the experience made him very apolitical person.
- lo_zamoyski 1y agoAh, whoops! I mistook Linus as the name of the Russian developer in question, whose name is actually Denis. (The whole first name thing in software circles kind of irritates me.)
- poulpy123 1y agoThe title of the register article is completely disgusting > Putin on the code: DoD reportedly relies on utility written by Russian dev then in the article: > Hunted Labs told us that it didn't speak to Malinochkin prior to publication of its report today, and that it found no ties between him and any threat actor.
- actionfromafar 1y agoAren't Russian developers on average more susceptible to the "wrench attack" though?
- em-bee 1y agothey would probably still fake their identity to hide their tracks.
- ChrisMarshallNY 1y agoMany of them don't live in Russia. Some of the best engineers that I've worked with (in the US and Europe) are Russian. I've also been quite impressed with other former Iron Curtain developers. A lot of Chinese folks I've worked with have been good. I know that some nations are known for threatening the relatives of expats, to get them to work on their behalf. Not very nice. But state-sponsored Russian (or other nations, as well) is definitely something to be concerned about. I suspect a number of folks are concerned about the influence of American programmers. The CIA is known for using fairly innocuous employees of NPOs. My father was one.
- kube-system 1y ago> Many of them don't live in Russia. Well Malinochkin does. His GitHub profile says he is located in a suburb 30 minutes from the Kremlin. Of course, there's a lot of smart software engineers in major cities all around the world.
- oneshtein 1y ago
- aniviacat 1y ago> So while NPM has over 4 million single person projects, they have about 900,000 maintainers for those 4 million single person projects. This will be an important data point at the end. Am I missing something or was it not, in fact, an important data point at the end?
- gamerdonkey 1y agoI didn't see it explicitly stated, but I think it supports the "overworked" part of this statement: > Open source, the thing that drives the world, the thing Harvard says has an economic value of 8.8 trillion dollars (also a big number). Most of it is one person. And I can promise you not one of those single person projects have the proper amount of resources they need. If you want to talk about possible risks to your supply chain, a single maintainer that’s grossly underpaid and overworked. That’s the risk. The country they are from is irrelevant.
- gsliepen 1y agoAnd even in projects that are maintained by more than one person, it's usually just a single person responsible for most of the commits.
- joshdavham 1y agoThis is the exact reason I decided to avoid 11ty for my personal website and instead went with Jekyll [0]. [0] https://github.com/11ty/eleventy/graphs/contributors https://github.com/11ty/eleventy/graphs/contributors
- vitonsky 1y agoHuh, I just checked stats on ecosyste.ms It looks they consider as maintainer only those people who listed on package.json, not a real number of contributors on github or anything. So all conclusions in this post is based on wrong assumption and incorrect data interpretation. That's all you need to know about it. I think you could list random people on github in your package.json to looks cool in eyes of stats cultists.
- em-bee 1y agothat and, i would argue that npm in particular is filled with lots of small projects and only very few large ones simply by the nature of the ecosystem. it is the wrong place to look. something better would probably be to eg count the contributors on github, or, on npm, analyze project dependencies and distinguish projects that are directly downloaded vs those that are loaded as a dependency. arguably, dependencies can be replaced by the developers of the project using it, so a developer of a dependency disappearing is less dramatic than if you use that project directly. technically speaking, if you have a large project with many contributors, every contributor is often still only responsible for one small part of the project. linux kernel drivers and subsystems most have their dedicated developers. and very few of them each.
- 0cf8612b2e1e 1y agoleftpad was a minuscule project that could have been created by anyone. Yet its deletion caused chaos. There are certainly load bearing projects of moderate complexity that are still single person efforts.
- em-bee 1y agoright, but the problem here was the deletion of the module, not the disappearance of the maintainer. in the later case the module would have remained, and if it would stop to work because of some incompatibility in a future js, people would replace it
- 1y ago
- hermannj314 1y agoThe DoD is very efficient at finding something they are getting for free and convincing everyone it's in their best interest to pay a team of contractors for it.
- kube-system 1y agoThe city of Troy kind of got fucked that one time by free shit.
- IAmBroom 1y agoCome on, tell me you don't want a pony!
- BirAdam 1y agoThis reminds me of the observation that adding people to a project doesn't necessarily increase productivity that much...
- kube-system 1y agoI feel like there's a lot of misunderstanding of this issue in the software community, because primarily, supply chain risk isn't a software or engineering issue. It's a governance issue. Someone doesn't have to be a bad actor for a project to have supply chain risk. Nor do all who evaluate supply chain risk have the same security posture and evaluate risks the same as others might. The DoD likely has a very different set of risks they evaluate against for their security posture than you do. Most supply chain risks are not an indictment of somebody's code or somebody's character. A lot of one person projects are risky just because they're only one person. Having a bus factor of one is a supply chain risk in and of itself. And while most people don't prepare for war while choosing their packages, it's not unreasonable for a military to do so. During a war, the ability for people to govern themselves and their own projects often changes dramatically, even in democratic countries. It is entirely routine for countries to require cooperation by the force of law in war time, even the US can and has forced private companies to cooperate with war efforts. This is probably not in the security posture calculation for most of us. But it is for some.
- conartist6 1y agoHuh? The DoD would not have used the package if they hadn't read every line, locked it down for updates, and were ready to patch it themselves if needed. Can you really imagine in a war they'd be like "damn, if only there were a second person we also don't trust at all to do this work for us cause otherwise we'd just be SOL"
- moron4hire 1y agoI don't know where you're working, maybe you work in some secret lab where everything is air-gapped and not even the pigeons are allowed within a mile of the facility. In which case, what the hell are you doing commenting on a public message board? That is absolutely not how DoD works. The vast majority of code is contracted out. Nobody from DoD side is reading any of the code. It's all a series of affidavits and audits for configuration management process. Vendors assert everything's cool. Failed audits lead to fines or revocation of access. And the audits check up on documentation and config. They don't dig into code. At no point in time is anyone, anywhere, in this process reading every single line of code. Not even A single line of code. I doubt they even read the Software Bill of Materials we're supposed to generate, because I've never heard any feedback on any of it.
- axelpacheco 1y agoAnother case of power law distribution being all around us. I wonder how many commits of the 1M+ downloads projects maintained by more than one person, were done by just one person?
- didgetmaster 1y agoHas anyone seen any stats on what happens to a single maintainer project when said person is hit by a bus (or meets some other demise)? With that many data points, there should be enough of them by now to study it. Is the project taken over by another, single developer? Is it replaced by a similar project? Does it just go away?
- gausswho 1y agoI would love to see a diligently researched episodic series, every episode covering the transition of a popular open-source library/tool/app/site from one maintainer to the next. And that's why I don't run Netflix.
- IAmBroom 1y agoNo, but I would happily pirate that.
- ebiester 1y agoI think this is in the realm of a YouTube series. I mean, what's stopping you from doing it?
- idiotsecant 1y agoOther than it being a lot of work?
- gausswho 1y agoAny maintainer pairs want to reach out? I'll give it a shot.
- saadatq 1y agoYou should pitch this to David Gelb / whoever is responsible for Chef’s Table on Netflix
- ashleyn 1y agoClosest example I could think of would be Hans Reiser/Reiserfs. It's a more sordid story than just getting hit by a bus, though. Ultimately the project just died.
- unit149 1y ago[dead]
- andai 1y agoOpen Source is just a guy, and The Internet is just his computer.
- andai 1y ago>It’s not until I change downloads to 1 billion downloads that we see 1 package maintained by 1 person, and 9 packages maintained by more than 1. Which one is that?
- dzonga 1y agothe west or those with largely liberal viewpoints who think in black and white vs seeing the world as grey are gonna cost the west a lot. we already saw this - with 'cancel' mafia. because russia or i.e putin invaded ukraine doesn't mean the whole russia is bad. or you shouldn't interact with russia at all. no one stopped interacting with usa after they invaded iraq. just because russia doesn't give a shit about lgbtq rights doesn't mean russia is a bad country. likewise just because china runs an explicit authoritarian system - it doesn't mean its a country - china bad. trump and his idiotic gvt kinda recognize this - but they're also doing it the wrong way. anyways - trade with enemies / friends alike as long as they're benefits to be realized.
- lern_too_spel 1y agoYou are not familiar with how Putin thinks. https://en.wikipedia.org/wiki/Foundations_of_Geopolitics https://en.wikipedia.org/wiki/Foundations_of_Geopolitics
- mikeytown2 1y agoDrupal isn't one person last time I checked; but yes this is correct for almost all projects
- ivanjermakov 1y agoToo bad the notion of completed/finished/done software is very weak. In theory, there it nothing wrong with an OSS project made by one person. I would like to see the LOC these one-person projects with >1M downloads have. I suspect most of these are a simple Node/browser/OS API single-file wrappers that are simple to get right and treat it as complete. At the same time such projects are easy to verify upon adding as dependency. Lately, I've just copy-pasted relevant parts of a library to my project because adding it as a dependency has a cost. I doubt this is a common practice though, especially in NPM land.
- tracker1 1y agoI think it can go both ways... I've definitely copied code into a project more than once. I've also directly written the following line of code into a lot of places, just because of import overhead and convenience when needed. const sleep = (ms) => new Promise(r => setTimeout(r, ms)); I also with push for just straight SVG with JSX instead of the massive charting libraries everyone seems to bring in... similar when I seem moment.js ... I don't know why more people don't generate/refer to the resource usage outputs. If anything comes close to the base React or MUI libraries, it gets yanked if at all possible. Or at LEAST load it async and only where necessary.
- sgbeal 1y ago> Too bad the notion of completed/finished/done software is very weak. FWLIW, this simple definition suffices for me: software is complete insofar as it requires no changes to do what its maintainers would like to do with it at the current point in time. "Complete" software frequently changes to "incomplete" as the desires of the maintainer(s) change(s), and may just as quickly revert to "complete" as changes are made. This definition does not consider the desires of non-maintainers because there's _always_ at least one such person who wants a given pieces of software to do their one weird thing (which the maintainer(s) will not ever add).
- ozim 1y agoAfter reading. For a person that calls out how people are not smart the author takes quite of mental shortcuts to make his point work. NPM downloads are not equal to amount of projects as people plug in their CI/CD to download package on each build. Then assuming just by sheer number that there must be something critical in the set or at least super important. Without putting effort to track at least one in some way. That’s at least lazy especially if you call people „smart”. Then throw up some numbers thinking you’re the smart one.
- lofaszvanitt 1y ago"Open source, the thing that drives the world, the thing Harvard says has an economic value of 8.8 trillion dollars (also a big number)." Yeah, but the maintainer almost never sees anything from it. And most of the people cannot monetize oss based projects, because they don't have the expertise for it. OSS is the biggest farce ever. Same when people say patents are evil. Ridiculous. A handful of people spoon fed this universal bullshite to people and they believed it. Remember people that proper governments plan tens of years ahead. In this context, OSS was first, so AI systems would have ample source code to be trained on.
- deleted 1y ago[deleted]
- phkahler 1y agoMost the stuff on github is something one person wrote, stuck on there, and nobody uses. Then there's a bunch of things that are one person, but some small number of people use or have used it. Most big OSS programs have more than one person behind them. The vulnerable things tend to be dependencies of larger projects - small, but useful enough to get used in larger things.
- mathisd 1y agoThe visualisations could be improved by binning number of maintainer 1 / 2-10 / 11-n or by plotting cumulative distribution (ie. x% of projects have less than y contributors)
- tracker1 1y agoEven that would be mis-representative... I know of many packages with contributions from hundreds of people, but the bulk of the work was still 1 or 2 primary maintainers based on commits.
- firesteelrain 1y agoI can see how the article seemed like an advertisement for Hunted Labs. I have talked to them and it’s a good product especially if you care about where you are getting your software from as part of a supply chain analysis.
- pabs3 1y agoIt seemed like an advertisement for the incompetence of Hunted Labs to me, from them: > "This serves as another powerful reminder that knowing who writes your code is just as critical as understanding what the code does" If who wrote some code matters to you, then your supply chain management is simply insufficient.
- firesteelrain 1y ago> If who wrote some code matters to you, then your supply chain management is simply insufficient. I am not following. Source country is absolutely a thing when certain industries look at open source. That’s what Hunted Labs does
- pabs3 1y agoIts completely irrelevant if you are doing things properly.
- firesteelrain 1y agoCan you elaborate?
- pabs3 1y agoThe whole article is refuting their point.
- BobbyTables2 1y agoI wonder. A lot of single person GitHub projects are just people’s “hello world” or other personal experiments. Single file webserver written without “if statements” or other absurdity. Not sure about NPM but a lot of PyPI projects are likely similar. Just now I hit “browse projects” and got this: https://pypi.org/project/helloworld-eduardo/ https://pypi.org/project/helloworld-eduardo/ Nobody even extremely drunk would even think of using that stuff in a product…
- johneth 1y agoJust FYI: I got a modal in Chrome asking "Did you mean opensource.google? Attackers sometimes mimic sites by making hard-to-see changes to the web address." I'm sure there's nothing you can do about it, but thought you might want to know.
- giancarlostoro 1y agoReminds me of what was it... Heartbleed? Then everyone realized its a library mostly maintained by one underfunded developer? Critical piece of software, underfunded.
- voidmain 1y agoThey stopped before looking at the number of commits by person in the projects with multiple maintainers. I would guess that makes the picture even bleaker.