3 ms·
The problem is more so maintenance. The expectation of FOSS is that the users and maintainer work together to resolve bug fixes/features/security issues. Howe
by securesaml 9mo ago
The problem is more so maintenance.
The expectation of FOSS is that the users and maintainer work together to resolve bug fixes/features/security issues.
However many companies will dump these issues to the maintainer and take it for granted when they are resolved.
It's not a sustainable model, and will lead to burnout/unmaintained libraries.
If the companies don't have the engineering resources/specialization to complete bug fixes/features, they should sponsor the maintainers.
- strongpigeon 9mo agoIt’s OK to say “No” or “Pay me and I’ll do it right now” to companies doing this.
- Dilettante_ 9mo ago(And on the flipside, nothing is owed for a bugfix the maintainer made out of their own free will. Again, a gift.)
- securesaml 9mo agoThe problem is lots of open source is unmaintained/insecure, and there aren't any security engineers on those open source libraries. For the library to be secure, there needs to be funding, not by magic and expecting maintainers will do stuff on there free will.
- overfeed 9mo agoThe person needing a feature can do implement it themselves or pay for it. They may even share it, in the spirit of open source, but they probably don't have to (depending on license conditions).
- Dilettante_ 9mo agoIs your perspective here "these things need to be useful/stable/secure, how do we make them/create incentive for them to be what we need them to be"? Because my view is more like "open source is a sprawling wild garden and occasionally a tree bears fruit, and anyone gets to have some for as long as it does." The assumed base state we're looking to augment via open source software being: "Fully working software"(Augmented: free) vs "No software" (Augmented: yes software)? Like, what you seem to want is business, plain and simple. Pay a guy, have your specs filled, get guarantees. That would be expecting open source to fill a role it just isn't made for.
- securesaml 9mo agoCorrect, maintainers can say that and get shamed. And it leads to unmaintained libraries, since companies don't want to pay. At some point, is open sourcing your work a liability?
- carllerche 9mo agoHelp normalize saying no? As an OSS maintainer, the sense of entitlement many have is quite frustrating. After years in OSS, I have built up a thick skin and am fine saying no, but many aren't.
- edwinjm 9mo agoI’m sure many companies like to pay. It’s probably the cheapest way to solve a business problem. It should be the norm. If a company wants to have a bug fixed or a feature added, they should pay. And GitHub should make it easy to do so.
- bigstrat2003 9mo ago> Correct, maintainers can say that and get shamed. And then they can shrug and move on with their respective days. If I open source something it's a gift to the commons, not a promise to work on it for free in perpetuity. I don't really care if someone tries to shame me for that, as there's nothing to be ashamed of.
- bloppe 9mo agoI always chuckle at indignant GH comments on OSS projects. There should be a subreddit dedicated to them. Like a specific kind of r/choosingbeggars
- ImPostingOnHN 9mo agoIf you look at the issue list for any significant open source project, it's probably of nonzero size. That's a way of saying "no": just don't do it. Maybe you're overloaded, maybe you just don't feel like it. It's totally normal, and different projects have different levels of resources, some with none anymore.
- carllerche 9mo agoI 100% agree with this. It also is 100% OK to fork aggressively and patch yourself.
- eddd-ddde 9mo agoA company finding a bug and opening an issue on an open source project _is_ contributing. What happens next is completely irrelevant. The maintainer can 100% decide to just ignore the issue or close it. Opening issues doesn't create unmaintained software. In fact it helps.
- lifetimerubyist 9mo agoNo the expectation of FOSS is that code is provided AS-IS with NO WARRANTY because that’s what it says in the license.
- jandrewrogers 9mo agoPeople's expectations are not constrained by the license. They are free to exercise a sense of entitlement beyond the terms of the contract and empirically they often do. The license does not prohibit them from engaging with the authors or maintainers for any reason whatsoever, including requesting free labor. You could perhaps add a clause in the license that restricts this behavior but then it would no longer be FOSS.
- majorchord 9mo agoPerhaps they simply meant the legal expectations are constrained by the license.
- lifetimerubyist 9mo agoThey are free to have a sense of entitlement or to try and engage with the project maintainers/owners but there is nothing that obligates them to reciprocate anything at all.
- dwaite 9mo ago> The expectation of FOSS is that the users and maintainer work together to resolve bug fixes/features/security issues. This depends a lot on the users, and then somewhat on the maintainers. I have seen a lot of end-user facing software where people do not understand that features and fixes do not magically materialize - that there is a person on the other end likely working on this in their free time, with their own prioritization on how they will use that limited time.
- ssdspoimdsjvv 9mo agoYou, as a maintainer, are free to ignore any such expectations and do what you want. There are no obligations. You only risk disappointing people (or corporations), and losing Github stars. If that leads to unmaintained libraries, that probably means the open-source model doesn't work for this project. And that's fine.
- vlad-roundabout 9mo agoThe software can't have a price, but the service of maintaining it and adding someone's desired features can.
- nextlevelwizard 9mo agoWhat are these many companies? And how are these mysterious companies forcing you to work on their issues? If you have companies name and shame them, but often these are just hypotheticals or few entities.