11 ms·
My best understanding from reading this is a) where possible and b) where necessary. This is the Linux Foundation, so it must put OSS and community first, surel
by amouat 3mo ago
My best understanding from reading this is a) where possible and b) where necessary. This is the Linux Foundation, so it must put OSS and community first, surely.
People talk about contributing financially, but how and to what end? Most projects aren't set up to accept or utilise donations. That said, I would say we should be providing all OSS projects with significant access to AI in order to review their codebases and PRs and hopefully relieve some of the maintenance burden. I know there are some initiatives in this area already.
- unsungNovelty 3mo ago> This is the Linux Foundation, so it must put OSS and community first, surely. Linux Foundation is run by the said called corporates from the list. So is Rust Foundation. Linux in itself is safe cos Linus controls it. Not the rest of the projects LF controls.
- limagnolia 3mo agoSo far, the Linux Foundation, from what I have seen, has pretty darn good track record of keeping the projects under its umbrella open source, even going against corporate sponsors to do so. For a recent example, see the recent NATS tuffle. (And I should.recognize that Synadia, finally, did the right thing and backed down).
- xyzzy_plugh 3mo agoTo add to this, I've experienced all sides of the LF and they are the only organization I trust at this point. Donating a project to them is A Good Thing. There's bureaucracy of course but the mission is clear. Highly recommend working with them in any capacity.
- RustyRussell 3mo agoUm, the Linux Foundation is an industry body, not a user or community group. You seem confused?
- limagnolia 3mo agoI am pretty sure that these industries use the open source projects the Linux Foundation maintains. So it is pretty clear the Linux Foundation is indeed a user community group, too.
- izacus 3mo agoThese are also some of the largest Linux code contributors as well.
- amouat 3mo agoNo, not really, and I don't think you need to be snarky. It may be an industry body, but it runs multiple community conferences and projects which support Open Source. A notable example in this case being the OpenSSF https://openssf.org/ https://openssf.org/ The LF is not perfect, but I would expect them to come from an OSS and community angle on this.
- LtWorf 3mo agoRemember when google set up a whole project to find vulnerabilities but never sent any fix and unpaid developers were basically having to fix things that an entire team of people was hired to find… yeah maybe they could have just made an offer to some maintainers instead of burning them out?
- oneshtein 3mo agoThey are contributing back, which is a good thing. Other companies just fork, fix, and forbid to contribute back.
- LtWorf 3mo agoBurning out maintainers isn't "contributing back".
- limagnolia 3mo agoDo you have any examples of Google submitting vulnerabilities and refusing to assist maintainers create a patch when asked to do so?
- finnthehuman 3mo agoWasn’t that a story with ffmpeg a few months ago? And people were getting roasted for even the suggestion that google should contribute patches?
- Dylan16807 3mo agoPeople were getting rightly roasted for calling google a leech when A) google does donate money to ffmpeg and B) that bug was in a weird format google almost certainly has disabled so they're not reporting it to get free labor.
- limagnolia 3mo agoFrom the horses mouth: "Michael Niedermayer, a leading FFmpeg developer, tweeted, “I am the main developer fixing security issues in FFmpeg. I have fixed over 2700 Google OSS fuzz issues. I have fixed most of the BIGSLEEP issues. And i disagree with the comments FFmpeg (Kieran) has made about Google. From all companies, Google has been the most helpful & nice.” https://thenewstack.io/ffmpeg-to-google-fund-us-or-stop-sending-bugs/ https://thenewstack.io/ffmpeg-to-google-fund-us-or-stop-send... Sounds like Google has been very helpful and nice.