Dev corrupts NPM libs 'colors' and 'faker', breaking thousands of apps
781–790 of 1001 posts
Re: Dev corrupts NPM libs 'colors' and 'faker', breaking thousands of apps
#782Earlier quoted context omitted.
Bad faith?
"this software comes with no warranties" ?
I would say that github is actually taking a stance that's reasonable of an "OSS author's union", if it existed - penalize one bad actor to recuperate the standing of all of us.
Re: Dev corrupts NPM libs 'colors' and 'faker', breaking thousands of apps
#783Should I get paid for my multiple contributions to faker (I don't think I should)? I've submitted several PR's for generating data all of which were accepted. Even back then the maintainer was barking about money... Honestly the project would be better off forked. He did not write this library entirely by himself, at this point I just see him as holding other committers contributions as hostage. It's a bad look, why…
How many other maintainers are getting increasingly annoyed at the users of their code? Entitled users demanding changes to fit their use cases, megacorps using the code for free, other megacorps forking the code and launching it as a commercial service, we've been hearing for years about the problems of being an OSS maintainer. Focusing on the troubles of this one person is a mistake. Of course the more "unbalanced"…
I don’t think this is right. It seems very sustainable as evidenced by 30+ years of sustained OSS development.
It seems very sustainable as we live in a time of the best OSS software ever produced with more high quality software than ever produced by ideological volunteers.
I’ve seen statements similar to yours and they just seem so at odds with reality.
Re: Dev corrupts NPM libs 'colors' and 'faker', breaking thousands of apps
#784Re: Dev corrupts NPM libs 'colors' and 'faker', breaking thousands of apps
#785Earlier quoted context omitted.
GitHub ToS allow terminating accounts for malicious behaviour, which I'd argue that purposefully breaking downstream code is.
That seems like a bit of a shaky ground to stand on for GH. If someone publishes code for themselves, and at no time asks anyone to take it as a dependency, then at a later date they change that code in a way that breaks other people's use of it, do GH then take over the account?
Re: Dev corrupts NPM libs 'colors' and 'faker', breaking thousands of apps
#786Earlier quoted context omitted.
Let's not start claiming people are planning terrorist acts without any proof. Those claims are extremely hard to get rid of, especially on the internet.
Here's the proof: https://abc7ny.com/suspicious-package-queens-astoria-fire/64... Another article: https://www.njhomelandsecurity.gov/at-a-glance/9-21-20
Unless there is other evidence, you’re just blindly speculating as to his intent.
Re: Dev corrupts NPM libs 'colors' and 'faker', breaking thousands of apps
#787Earlier quoted context omitted.
It seems completely insane to me to give away work and then expect compensation for it.
But completely sane to base your project on a package of code you don't control? Or to lock up his Github account for exercising his prerogative onto his own code? His behaviour is unusual, but that, you know, could change easily. It could become the normal just like that. Puff.
Yes, certainly. I think this is sane because with OSS you can control it if you need to. Until then use what exists. It’s sane to use Linux in my project even though I don’t control that. I suppose it’s also sane to use Windows even though I don’t control that.
Re: Dev corrupts NPM libs 'colors' and 'faker', breaking thousands of apps
#788Earlier quoted context omitted.
Eh that's not true. I use Gentoo so trust me most things are run by little dictators of their own little fiefdoms. I'm talking about not just the kernel but all the various other things from libraries to servers to tools and everything in between.
OK, but none of those little fiefdoms are "Linux".
Re: Dev corrupts NPM libs 'colors' and 'faker', breaking thousands of apps
#789Earlier quoted context omitted.
How many other maintainers are getting increasingly annoyed at the users of their code? Entitled users demanding changes to fit their use cases, megacorps using the code for free, other megacorps forking the code and launching it as a commercial service, we've been hearing for years about the problems of being an OSS maintainer. Focusing on the troubles of this one person is a mistake. Of course the more "unbalanced"…
> This model of software development is unsustainable. I don’t think this is right. It seems very sustainable as evidenced by 30+ years of sustained OSS development. It seems very sustainable as we live in a time of the best OSS software ever produced with more high quality software than ever produced by ideological volunteers. I’ve seen statements similar to yours and they just seem so at odds with reality.
The big question is what happens when a maintainer wants to retire and a successor can't be found? Or (as in this case), when a maintainer gets so annoyed by their users that they refuse to continue co-operating with their user base.
We don't really have an answer for either of these questions yet, and we won't bump into them until maintainers get old or angry. But we have been predicting that this problem will happen.
Now we're bumping into this problem, it's our new reality. What's the solution?