6 ms·
The problem is the rug-pull itself, not that the rug isn't there. I don't have an opinion on Datastar, as I'd never heard of it until this article, but over th
by cameronh90 1y ago
The problem is the rug-pull itself, not that the rug isn't there.
I don't have an opinion on Datastar, as I'd never heard of it until this article, but over the past year or two there have been a _lot_ of open source projects that have been converted to proprietary licenses, very often after being invested by VCs or PEs. It's happened to me a number of times now where the license for the features we were using went from open source to proprietary with 5-6 figure cost.
Developers gotta eat, I get that. But often the reason I'm using one of these components is it's a hobby or low value project where it simply doesn't bring in the income to justify paying for a license. If I had known this would happen, I would never have used it in the first place, used an alternative, or maybe just never bothered with the project. But now you're in an awkward position where the choice is either pay-up or re-do a bunch of work.
- sergiotapia 1y agoI think it's totally normal and correct to have a license where a company like Amazon can't come in, steal the volunteer work of hundreds of developers, slap their logo on it and sell it. I'm sure open source purists do not like this, but the world is the 1980 anymore. It's been 45 years. Things need to adapt. Open source needs to adapt.
- sarchertech 1y agoYeah we really need to normalize licenses that protect against that. Even GPL doesn’t because everything is SaaS now and companies will just isolate the GPL code to one micro service. AGPL might prevent this but there aren’t a lot of cases that have been litigated. And if they don’t modify the source then then it doesn’t do much IIRC. But “open source” was in control of big business from the start. The open source consortium was a late 90s attempt to co-opt the free software movement and turn it into something business friendly. Tim O’Reilly funded it to start and now it’s funded by big tech companies.
- crote 1y ago> I think it's totally normal and correct to have a license where a company like Amazon can't come in, steal the volunteer work of hundreds of developers, slap their logo on it and sell it. Why shouldn't this to apply to every company - including the one ostensibly shepherding the open source project? I would argue that employing a bunch of core developers doing 10% of the work doesn't entitle you to be the sole entity to monetize the work of the other 90% of the community, but I don't think anyone has come up with a proper license to defend against that yet. Open source indeed needs to adapt, but I don't think the source-available or open-core models we are seeing these days is the right solution. If you really want to prevent third-party entities to profit off your work you'd need to go for something like the AGPL, but that is for obvious reasons not exactly a popular choice.
- evanelias 1y ago> Why shouldn't this to apply to every company - including the one ostensibly shepherding the open source project? Because that's simply not how copyrights and trademarks work. The licensor doesn't need to abide by the terms of the license, by definition. The purpose of a license is to grant rights from the licensor to the licensee. > employing a bunch of core developers doing 10% of the work doesn't entitle you to be the sole entity to monetize the work of the other 90% of the community Very few of these cases are 10% company / 90% community. If anything, it's usually the other way around. Not to mention the huge amount of time spent on code review and ongoing maintenance of third-party contributions. > I don't think anyone has come up with a proper license to defend against that yet. That wouldn't really make sense; a software license isn't going to remove rights from the licensor. More realistic solutions are things like intentionally not having a CLA (effectively preventing the project creator from relicensing) and/or reassigning copyright and trademarks to a foundation.
- ianbutler 1y agoThere was no rug pull! (And the term isn't even being used correctly) They talked in their community decided the set of features caused a support burden and for versions later on they would put them behind a pro tier to help pay for the extra costs for supporting them. You can keep using your current version! You can even fork at that version. Calling it a rug pull is so entitled.
- cameronh90 1y agoLike I said, I haven't heard of this project until now, so I don't know the wider context, but it may be that some of the people who are reacting negatively to it have been burnt in the past by the many other projects that have gone down this route: project starts as open source, then it goes open-core, then over time more of the dev effort naturally moves into the proprietary part, then sometimes eventually they change the license for the open part too. Forking is often impractical in reality as a solo dev or small team rarely has the resources to keep up with security fixes. I'm entirely happy to pay for things, do pay for many things, as well as donate to the authors of projects I use, and whatever this library is seems reasonably priced. Nevertheless, I'm pretty reluctant now to use open source libraries unless they're backed by a foundation, given how many times I've been badly burnt.
- ianbutler 1y ago> Forking is often impractical in reality as a solo dev or small team rarely has the resources to keep up with security fixes. Right, then as you've stated your recourse is not to use the library! That's fine and good and means the ecosystem works as intended.
- imiric 1y ago> There was no rug pull! [...] You can keep using your current version! You can even fork at that version. Calling it a rug pull is so entitled. This is a dishonest perversion of the commonly accepted definition of a "rug pull". I'll copy what I said in a previous thread: When Redis changed licenses to SSPL/RSAL, users were also free to continue using the BSD-licensed version. Was that not a rug pull? Same with MongoDB, Elastic, HashiCorp, etc. These are quintessential examples of the "OSS rug pull". The idea is that users were relying on a functionality to be maintained (the "rug"), and the Datastar developers decided to continue maintaining it behind a paywall (the "pull"). Nobody is claiming that developers physically took the feature away from users, as that would be ridiculous. But users of these features are now forced to either maintain it themselves, wait for someone else from the community to fork and continue maintenance (which has its own set of issues), or pay up. You can argue how it's "only" a few hundred lines of code; criticize "incapable" developers who can't check out a Git commit or do maintenance work they previously didn't have to; that the features don't require maintenance at all; and come up with other defensive arguments. But none of it matters. The size of the "rug" doesn't matter. It's the principle and precedent it sets for any users who were potentially interested in the project. To say nothing about putting essential features like a bundler and debugging tool behind a paywall. These are not "Pro" features.
- jen20 1y agoIf the rug isn’t there, how can it possibly be pulled? All free licenses make each commit free - forever. If a library does what you need today, use it! If the terms become unacceptable in future, fork it and maintain it yourself, or hope someone else will. Note this can even happen with free software (GPL2 to 3, for example). No one is entitled to the future work of someone else without paying though. You very definitely are the entitled one here.
- evanelias 1y ago> It's happened to me a number of times now where the license for the features we were using went from open source to proprietary with 5-6 figure cost. In those cases, prior to the project going commercial, did you contribute nontrivial code to the project and/or financially sponsor the project? I could see being upset in those situations, but in most cases I find the answer is no. > If I had known this would happen, I would never have used it in the first place, used an alternative, or maybe just never bothered with the project. If you had used an alternative, the same scenario could have played out with the alternative. Realistically, what are the "never have used it" / "never bothered" scenarios? Presumably you chose the project because you needed it for something; that implies the never-bothered alternative is essentially just writing something from scratch instead. Which you can still do now. And you can use the last FOSS version of the project as a starting point, which saves a tremendous amount of time. So how exactly were you burnt by a supposed "rug pull"?