4 ms·
as much as I feel for the maintainers here, this sort of (again) puts the spotlight on our collective dependence on a handful of individuals basically working f
by laszlojamf 4mo ago
as much as I feel for the maintainers here, this sort of (again) puts the spotlight on our collective dependence on a handful of individuals basically working for free _with no backup_.
Most normal organizations stagger vacations to avoid these things. Most normal organizations _have_ to do this, because their customers require it. Here, we're all customers of curl, but not really. It's a weird, IMO unhealthy, twilight zone that isn't good for anybody.
And it surprises - and saddens - me that not even friggin curl has the financial muscles to have somebody on-call for one month...
- necovek 4mo agoYou'd be surprised to learn this about free and open source software, but if a maintainer is unavailable, you have both full rights and full source code to... wait for it... fix it yourself (or pay someone to)! There is something unhealthy in this relationship only if you project "no warranty" into unrealistic expectations.
- ValdikSS 4mo agoThis is true for the majority of open-source projects, but the most serious ones, on which a lot of software/businesses/infrastructure depends, are controlled by foundations or some kind of other management entity. cURL also offers paid support and also paid access to the rock-solid (LTS) version, with guaranteed response times, and the blog post states that there's still people to respond to these.
- IshKebab 4mo agoYou don't really though. Sure you can fork it and fix your issue, but then what? Are you going to maintain your fork in perpetuity? Are you going to patch all the software that depends on the code you fixed to use your version instead of upstream? Are you going to get your users to do that too? In most cases this is extremely impractical.
- spiffyk 4mo ago> but then what? Then you send the patch upstream, they incorporate and maintain it for you. Congratulations, you just FOSSed.
- swiftcoder 4mo ago> Then you send the patch upstream, they incorporate and maintain it for you Firing patches upstream is still adding burden to the (likely already over-burdened) maintainers. In an ideal world, if you want a patch upstreamed, you would be contributing to upstream maintenance (or at least donating to the upstream maintainers)...
- spiffyk 4mo agoFair, but it is less of a burden than just submitting a report with no proposed fix. Also, submitting quality patches regularly seems to be a good way to eventually become a maintainer, provided that both sides are interested (cURL generally is – at least that seemed to be the vibe at the last year's cURL Up event I attended).
- deleted 4mo ago[deleted]
- necovek 4mo agoI believe both are valid: sometimes upstreams are not set up for donations, and sometimes your org will make it easier to submit a patch or to financially sponsor a maintainer.
- megous 4mo agoYes, you can maintain your fork for perpetuity if you can't/will not get your changes upstream. Why is that a problem? If you're using any complicated FOSS professionally and you have SLA with your customers to say fix issues within day or two you don't have a choice anyway.
- Nnnes 4mo agoThey do. > Everyone with a paid support contracts will of course still get full and appropriate service even during this period.
- ed_elliott_asc 4mo agoThey do, he said at the end if you have a support contract then they will respond and deal with security issues. I guess the whole point of the article is to show that people should buy a support contract if they need support.
- 4ndrewl 4mo agoIt does. The article clearly says that if you have a paid support contract they will be on-call as per usual.
- Imustaskforhelp 4mo agoThe thing which bugs me is that OpenAI (which is an unprofitable company) is spending around what 100k$ per month for an completely AI generated slop called Openclaw. (All because of Hype) I have seen there to be an more influx of open source software as people are starting to create more software with vibe-coding and other things and just open-sourcing it, which while good in OSS'ing it but its mostly less valuable as compared to the curl codebase which was created by hand and over the years improved itself. Yet the funding is going towards making more and more (OSS/non-OSS) AI slop by people, companies and dare I say countries yet we are unable to take the same wealth and money into, say, the curl project (and the likes) There is also an visibility issue. We all know curl and this is the state of curl. Imagine all the projects which we all don't know that much about or aware about going through same issues.
- l23k4 4mo ago>The thing which bugs me is that OpenAI (which is an unprofitable company) is spending around what 100k$ per month for an completely AI generated slop called Openclaw. (All because of Hype) For whatever reason, real people seem to desperately want Openclaw regardless of it being AI generated slop. OpenAI is certainly not wasting the money they're spending on Openclaw, even if I personally wouldn't want to touch that particular piece of software.
- Imustaskforhelp 4mo ago> For whatever reason, real people seem to desperately want Openclaw regardless of it being AI generated slop. I can agree with it but I am unsure how much the desperation is out of FOMO or out of real use-cases. Surely curl has more use-cases and projects relying on it than OpenClaw. The demand seems to be generated out of hype rather than sustainability. Openclaw project isn't even an year old and from my time hearing about it, it isn't safe or sustainable in any fashion and it seems that the hype around Openclaw has now started to slow down as I hear less about it (which to me is actually a good thing imo) but it shows what the market reality of these tools currently are (at the moment).
- 4mo ago
- deleted 4mo ago[deleted]
- simooooo 4mo agoI wonder how far we are from the agents just maintaining the packages
- inigyou 4mo agoWe have some packages like that, starting with rsync which distributions are having to roll back because it turned into a pile of garbage overnight.
- bawolff 4mo ago> And it surprises - and saddens - me that not even friggin curl has the financial muscles to have somebody on-call for one month... Is it that they can't or don't want to. I'm sure curl is popular enough that it could attract a co-maintainer if it wanted to. Of course there is a cost to that. Software projects done effectively by a single person are often more focused and designed more coherently. I'm not sure curl would be as good a product if there were multiple maintainers with potentially conflicting visions.
- andylynch 4mo agoThey do. You just seem to expect that it will somehow be free.
- simjnd 4mo agoAnd I'm assuming you're not going to pay for them to have that someone on-call, even though you're worried about this scenario
- eviks 4mo agoConsumers, not customers
- serial_dev 4mo agoReminder: ‘the software is provided “as is”…’. It’s not their problem that you, or anybody else, think you are owed 24/7/365 emergency support.