Live data from Hacker News

Faker.js is now a community controlled project

fakerjs.dev

161–170 of 357 posts

Re: Faker.js is now a community controlled project

#161

Earlier quoted context omitted.

I'm sure 6.6.6 threw a spanner in the works for folks who didn't lock deps. Not great. But Marak's one of us. This feels a lot bigger than that. I don't have a direct line on what happened to him, or where it took him, mentally or otherwise. But the hints so far aren't great. To one of us. I think the responses from the platforms---GitHub, OpenCollective---get folks thinking, whether they feel it that way or not.

What GitHub did was completely reasonable. They mitigated harm to their users on their own infrastructure and property. They did not change his code. They just took down his malicious code that caused harm. The vast majority of people on HN would never purposely harm strangers. Most of these strangers are fellow developers ie “Us”

I understand some of the imperatives GitHub's people must have felt. I've advised folks providing open source infra under drama, though I can't talk details.

I'm sure the people who got burned on builds had bad days. It's not fair to blame them entirely, for not locking deps. It is fair to point out this isn't the first time builds have broken, with npm or other repositories. Nor the most widespread in effect. Does this count as a crisis?

If anything, I suspect a crisis of faith. Seeing bad things can come of `npm install`, and those bad things might be intentional or just plain weird, instead of well intended but accidental, can make people anxious. Publishers to npm don't just disappear or malfunction. Their faults can be byzantine. But there are defenses against them.

On the maintainer side, like it or not, we all have an editor when it comes to publishing on GitHub. But it matters how invasively that power gets wielded, and how heavy-handed it's perceived. This episode suggests to me that the threshold for intervention in the name of user interest's pretty low.

That's based on the information I have. Perhaps GitHub will share more on the blog.

Re: Faker.js is now a community controlled project

#162
post #70

Earlier quoted context omitted.

Does it matter what Open Collective thinks if most people believe this is immoral?

Define "most" people.... To me, this is like the left-pad incident and npm. There was a vocal minority who denounced npm for looking after the greater good, maintaining continuity and transferring the project to someone else. In this case, since the author also deleted the project, the proper way to maintain continuity for the sponsors seems to transfer it to the new community of folks who are interested in maintaini…

You have to let the supporters make that decision.

You can make that decision easy, you can automate a lot of it, you can inform, but you can’t change which project the funding is going to without explicit consent.

And yes, for these purposes, the new fork should be considered a new project. It is a completely different situation than if the project itself decided to change maintainers, etc.

This is really a crazy situation where the original maintainer blows up the project. The best scenario would be for the original authors to hand over the project in some capacity. But that seems pretty unlikely.

To put it in different terms… this was not a SQL UPDATE. The was a DELETE. You don’t just change foreign keys to a different project_id when you delete a record.

I would also argue that the author was completely irresponsible, and made life difficult for everyone that used and supported the project. But that’s a separate issue and doesn’t make what the open collective decided right.

Re: Faker.js is now a community controlled project

#163
post #75
post #68

Why is this project so popular? I’ve built mini APIs to do this in several previous jobs - either for the purpose of fuzzing, anonymizing real user data for test environments, or readable testing. Each time it’s taken maybe two days of effort in total starting simple and growing for internal needs. How has this been funded so much, for something that’s as simple as dictionary.getRandom()? And why does it need eight c…

Because for some people, they don't want to spend the extra time to build and maintain a solution that they are now responsible for. `npm install --save faker` and boom you have access to a huge variety of random test data, across different locales. Doesn't stretch my imagination to see the appeal.

A lot of webdev is just pre-built stuff. When webdevs say "don't reinvent the wheel" it means "I'm too scared of doing it wrong to program it myself."

Re: Faker.js is now a community controlled project

#164
post #30

Earlier quoted context omitted.

It was a malicious act to the users of his project, sure. But how was it a malicious act to GitHub? I'm glad to hear that they reversed the suspension, but without understanding why it was suspended in the first place, it leaves open the question of what GitHub's motives were in the whole situation. If DHH decided that Rails was contributing more harm to the world then good, and tried to remove it from GitHub, would…

It was malicious act to Github's users. Github first responsibility comes to the community of users it supports, then to any individual user. Free speech/ personal choice / Freedom of expression come secondary to the welfare of its users. Is it a slippery slope ? Yes, but Github does not have a choice if it cared about the interest its community

I still keep failing to see how it's malicious to gh users and I've red all your comments.

Re: Faker.js is now a community controlled project

#165

You aren’t in control on a platform that isn’t yours. You don’t have rights. If you want to behave like a child, Microsoft may very well just take the keys away from you.

> You aren’t in control on a platform that isn’t yours

I wish everyone to read the above about 5 times and try to let it sink in.

Re: Faker.js is now a community controlled project

#166
post #59

Earlier quoted context omitted.

Freedom of speech doesn’t mean you can do whatever you want on someone else’s server. The project was hosted on GitHub, so GitHub can take significant action to protect the community. He can host his project elsewhere if he doesn’t agree with GitHub’s actions

What about somebody else's internet connection? If we apply the same logic to ISPs then the future of the internet would look quite bleak.

https://en.wikipedia.org/wiki/Net_neutrality

Re: Faker.js is now a community controlled project

#167
post #30

Earlier quoted context omitted.

It was malicious act to Github's users. Github first responsibility comes to the community of users it supports, then to any individual user. Free speech/ personal choice / Freedom of expression come secondary to the welfare of its users. Is it a slippery slope ? Yes, but Github does not have a choice if it cared about the interest its community

> It was malicious act to Github's users. I'm not sure why it matters they are Github users. The packages were hosted on npm through Cloudflare - does that allow Cloudflare to take over the packages too? And NS1 since they host the fakerjs domain?

Github owns npm.

Re: Faker.js is now a community controlled project

#168

It doesn't feel like there was enough criticism against GitHub for their decision to ban the developer of faker/colors. This was his own corner of the internet for him to publish his own personal projects. I understand the decision for npm to take ownership of his packages, because npm is a community package repository owned by, and for, the community. All community package repositories have some sort of policy for p…

I am completely baffled by folks defending Marak, or putting any sort of blame on GitHub. What Marak did was not "political speech". If he wanted to, he could have easily done any of the following: 1. Pulled down his repo, or replace his repo by whatever message he wanted to send. 2. Output his political message during the build. 3. Heck, all faker.js does is output fake data for things like names and addresses. I th…

General rule (at least for me) is to avoid people wanting to be a people-pleaser or politically correct without offering real tangible solutions at the problem on hand.

What he just did is intentionally mess with the society for the heck of it and naturally the society will find ways to fix it and restrict him as necessary, right.

Re: Faker.js is now a community controlled project

#169
post #78

Earlier quoted context omitted.

> By putting them on a social network, like Github, he is submitting to their whims. He doesn't have any legal right to stay on that site if they want to kick him off of it. Of course, legally speaking, Github can do whatever they want with their website, but we're not talking about the legal aspect. The developer community has put some trust on Github not to do whatever they want. It's an implicit, non-legal, non-en…

What you are going to get is people separating out into 2 camps, those that believe in individuality, and those that believe in more collectivism. This is a divide that extends well beyond programming and this topic. People that support GitHub actions believe in the concept of "greater good" and believe the actions of GitHub are ethical because it prevented harm to the community People that oppose GitHub actions reje…

I don't really see it that way -- GitHub is run by a company to (albeit somewhat nebulously) make money. They almost certainly made this call because distributing an obviously malicious package like this was damaging to their brand, not through some philosophical framework.

Expecting a company to have a moral framework is just setting yourself up for disappointment. They will always just do what they think will maximize their long term ROI. Possibilities lay between "enlightened self interest" and "barefaced self interest."

Post reply on HN