Live data from Hacker News

Faker.js is now a community controlled project

fakerjs.dev

351–357 of 357 posts

Re: Faker.js is now a community controlled project

#351

Earlier quoted context omitted.

I am completely baffled by folks defending Marak, or putting any sort of blame on GitHub. What Marak did was not "political speech". If he wanted to, he could have easily done any of the following: 1. Pulled down his repo, or replace his repo by whatever message he wanted to send. 2. Output his political message during the build. 3. Heck, all faker.js does is output fake data for things like names and addresses. I th…

What he did was utterly unprofessional, hazardous, and outright dangerous to those who trusted and used his library. By putting it on Github, he surrendered a portion of his right to distribute to Microsoft, and Microsoft did the best course of action to protect their reputation and the interest of their stakeholders. I see nothing wrong with this.

How was it hazardous or "outright dangerous"?

You see a build fail, you pin the previous version of that dependency, run the build again and go on with your life.

Asshole move? Sure. Hazardous and dangerous? Don't be dramatic.

Re: Faker.js is now a community controlled project

#352

Earlier quoted context omitted.

I see only one of those alleged "nutso's", and that was GitHub. Everyone else should have been responsibly consuming the dependency. You don't get to call foul when you knowingly use something for something important and don't check to make sure it is okay.

Now that’s just plain victim blaming

As an engineer, part of your responsibility is to foresee this type of thing. Software that does exactly what it should, and is free of defects for it's immediate use case, has no need to be continually updated. As each line is adding more functionality you do not need.

Even if you're trying to keep things rolling forward and buy into taking in updates anyway; you don't do it in such a way as to cause it to leak to production until you are good and certain there is no potential for breakage. If you haven't learned this yet, give a monorepo a try. I assure you, you will be divested of any naivete in this regard.

Re: Faker.js is now a community controlled project

#353

Earlier quoted context omitted.

> or any other nonsense you're trying to extrapolate. Sorry you were complaining about straw man arguments?

Yes he was, and you were making them.

Are you sure you understood my point?

>> It's a "the needs of the many outweigh the needs of the few" situation.

> It's a bit mind-boggling that FOSS authors who give their work away for free are the selfish baddies, and Microsoft of all people, are the communistic heroes in your telling.

The discussion is about Github - microsoft - undoing the author's changes, the guy I replied to saying that this was good because he felt the author was "doing harm". So he definitely is saying that microsoft are the heroes there defeating "harm". And since he is supposed to be "doing harm" for his own benefit, the FOSS author being overridden by microsoft is the "selfish baddie".

For my edification, if you have a moment you can you help me understand where my comment failed to hew to a valid analysis of that part of the discussion and became some nasty straw manning activity?

Re: Faker.js is now a community controlled project

#354

It doesn't feel like there was enough criticism against GitHub for their decision to ban the developer of faker/colors. This was his own corner of the internet for him to publish his own personal projects. I understand the decision for npm to take ownership of his packages, because npm is a community package repository owned by, and for, the community. All community package repositories have some sort of policy for p…

I am completely baffled by folks defending Marak, or putting any sort of blame on GitHub. What Marak did was not "political speech". If he wanted to, he could have easily done any of the following: 1. Pulled down his repo, or replace his repo by whatever message he wanted to send. 2. Output his political message during the build. 3. Heck, all faker.js does is output fake data for things like names and addresses. I th…

> I am completely baffled by folks defending Marak... > I think he would have been well within his rights to...

I think this is the crux of it all. I (and many others it seems) disagree with the actions he took and think they're shitty, but also think he has a right to do this with his code that he provides and publishes for free.

Re: Faker.js is now a community controlled project

#355

Earlier quoted context omitted.

> malicious act to Github's users Usually if I modify my car in my own backyard (aka my property) it is nobody's business to intervene, as long as it's on my property. Legally speaking, fakerjs was Marak's property and GitHub has no right to intervene with a legitimate user action. I can see that they "tried their best" but we also have to uphold the law here. If GitHub, say, called him on his phone whether or not hi…

This code has never belonged to Marak. This code is ported from other existing projects which had been acknowledged by Marak. I see it like this. I can't buy a Harry Potter book, translate it to a different language, maybe change some of the character names and then claim ownership while not acknowledging the original work even if I publish it for free. It's like you and your friends building a Mustang in your backya…

> This code has never belonged to Marak. This code is ported from other existing projects which had been acknowledged by Marak.

Completely irrelevant to the issue at hand, though. The copied code was copied in accordance with an open source license. By this same token, the affected users/companies are free to start their own fork, but they didn't. The developer shouldn't be under any obligation to maintain anything, and GitHub shouldn't be intervening in these kinds of situations as that will simply serve to dull the positive effects these scenarios could have on the dependency landscape (people actually figuring out their shit). This is the package equivalent of a bail-out. At the end of the day it hurts more than it helps.

Re: Faker.js is now a community controlled project

#356

Earlier quoted context omitted.

This code has never belonged to Marak. This code is ported from other existing projects which had been acknowledged by Marak. I see it like this. I can't buy a Harry Potter book, translate it to a different language, maybe change some of the character names and then claim ownership while not acknowledging the original work even if I publish it for free. It's like you and your friends building a Mustang in your backya…

The ToS of GitHub state that it's not their property, they only claim the license for redistribution. If it would be their property, legal cases (e.g. DMCA) would be against GitHub, not the owners of the repositories. So from their point of view they do not want to be legally responsible for the code they're hosting. So I'd argue that it wasn't GitHubs backyard. They might be the landlord but they can't take ownershi…

In fact, this action could set a precedent that allows RIAA/MPAA/etc to sue GitHub because it demonstrates they curate and editorialize everyone's code, effectively.

Re: Faker.js is now a community controlled project

#357
post #256

Earlier quoted context omitted.

> malicious act to Github's users Usually if I modify my car in my own backyard (aka my property) it is nobody's business to intervene, as long as it's on my property. Legally speaking, fakerjs was Marak's property and GitHub has no right to intervene with a legitimate user action. I can see that they "tried their best" but we also have to uphold the law here. If GitHub, say, called him on his phone whether or not hi…

If you modify your car in your backyard sure, but it wasn't his backyard, it was the public roads, and it wasn't (just) his car, it was his car that he shared with his neighbours. And then he decided to tamper with the brakes as a "prank", knowing full well that others would then use the car.

No. Imagine if all traffic lights were 3D-printed, and that entire infrastructure depended, as an active dependency each time a new traffic light is printed, on some random guy's 3D model that he decided to post on his personal blog years ago. Guy decides to take down the model, now all of a sudden his hosting provider takes control of his site and forces him to put the model back. That is the lens through which you should view this situation.

The people building infrastructure that depends on one guy's 3D model existing on his blog at all times were the ones who made a mistake. If one of your thousands of dependencies breaks, shame on you, make a fork. The dependency owner owes you nothing, and he can change his creation or remove it any time he likes. If you weren't fortunate enough to fork it while it was still up, then too bad.

Instead we as a corporate community are encouraging coddling and ensuring that if you make this mistake, GitHub, NPM, et al will take care of it for you. The downstream effects of this are much worse than the temporary damage of making people actually figure out their dependency chains.

Post reply on HN