6 ms·
Easy for people who have zero packages and no pressure to say. Don't contribute to OSS and you have no problems. If these huge companies profiting off OSS work
by tjholowaychuk 8y ago
Easy for people who have zero packages and no pressure to say. Don't contribute to OSS and you have no problems.
If these huge companies profiting off OSS work actually contributed financially and with time, maybe maintainers would happily remain maintaining.
- zeroname 8y ago> Easy for people who have zero packages and no pressure to say. If you have this "no warranty, no responsibility" attitude then how can you have pressure to maintain anything? How does that translate into pressure to hand off the project to strangers? Nobody asked for that. > Don't contribute to OSS and you have no problems. Yes, please don't contribute if you have this kind of attitude. It's harmful. If you can't maintain the package, deprecate it. Don't hand it over to an unvetted entity. If we can just agree on that M.O. we'll have a much better situation. > If these huge companies profiting off OSS work actually contributed financially and with time, maybe maintainers would happily remain maintaining. Ifs and buts and sugar and nuts. They don't contribute, they never have and they probably never will, you are responsible for your packages even if you are doing it voluntarily.
- tjholowaychuk 8y agoDozens of emails / notifications, people pinging / bothering you on multiple platforms, multiple emails, etc. It's stupid to blindly trust someone's code, regardless of who they are of if they are the current maintainer, that is not how you build secure software. If you want to start some organization which vets people for maintainers go for it, but don't expect maintainers to do it, I can guarantee you that thousands of maintainers do not. You're responsible for what ends up on your servers.
- zeroname 8y ago> Dozens of emails / notifications, people pinging / bothering you on multiple platforms, multiple emails, etc. Two options: 1. Stop supporting the package, mark it as deprecated, ignore/delete the spam 2. Hand over project to a stranger, endangering all of your users One of these options is irresponsible, the other one isn't. I'm not asking anyone to do something for me, I'm asking them to not do something for the sake of sanity. > It's stupid to blindly trust someone's code, regardless of who they are of if they are the current maintainer, that is not how you build secure software. I agree, but both of us know that pretty much the entire Javascript ecosystem is exactly that stupid. Let me ask you: What have you personally done to vet your dependencies? Have you used Babel or any of the other popular Javascript packages that have a huge dependency tree? If you have, chances are you are effectively blindly trusting all the developers in that tree. You're not checking every single commit that goes into it. > If you want to start some organization which vets people for maintainers go for it, but don't expect maintainers to do it, I can guarantee you that thousands of maintainers do not. I don't expect that they do, I expect that if they fuck up that their reputation takes a hit. That would some incentive for not fucking up. Instead, there isn't even any consensus that this guy fucked up. He's taking no responsibility whatsoever.