Live data from Hacker News

Cal.diy: open-source community edition of cal.com

github.com

51–60 of 75 posts

Re: Cal.diy: open-source community edition of cal.com

#51
post #45

Earlier quoted context omitted.

But the OSS license already absolves them of responsibility. This might just be to set the tone that security fixes won't be prioritized to the standard that they used to be.

You seem really confident that an OSS license would protect them from liability… what is that confidence based on?

It's a straightforward MIT license: https://github.com/calcom/cal.diy/blob/main/LICENSE

> IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.

Re: Cal.diy: open-source community edition of cal.com

#52
The irony of labeling this 'not recommended for production' while it's a fork of your own previously production-grade OSS is hard to miss. Feels less like a community edition and more like a liability shield. Curious how long before an actual community fork ends up being the thing people self-host.

Re: Cal.diy: open-source community edition of cal.com

#53
post #51

Earlier quoted context omitted.

You seem really confident that an OSS license would protect them from liability… what is that confidence based on?

It's a straightforward MIT license: https://github.com/calcom/cal.diy/blob/main/LICENSE > IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.

This is good , switching from viral license to more corporate friendly licensig

Re: Cal.diy: open-source community edition of cal.com

#54
post #18

I just installed calrs, a recent alternative to cal.diy. It absolutely rocks! The only downside is that it requires me to activate STARTTLS as force-TLS-SMTP isn't supported (I had to check the source code). It’s young, very promising, and honestly, I don't know what I could ask for more. I also replaced Radical with rustical, and I gained free push updates. https://cal.rs/ and https://github.com/lennart-k/rustical A…

sadly it's one of the strictly viral license AGPL , i prefer the more permisive one

Re: Cal.diy: open-source community edition of cal.com

#55
post #11

Earlier quoted context omitted.

https://cal.com/blog/cal-com-goes-closed-source-why

I'm unpersuaded by the assertion that closing the source is an effective security bulwark. From that page: > Today, AI can be pointed at an open source codebase and systematically scan it for vulnerabilities. Yeah, and AI can also be pointed at closed source as soon as that source leaks. The threat has increased for both open and closed source in roughly the same amount. In fact, open source benefits from white hat s…

A much better argument would be "if you can point the AI to scan it for vulnerabilities, why not do that yourself and fix the vulnerabilities"?

Re: Cal.diy: open-source community edition of cal.com

#56
post #11

Earlier quoted context omitted.

I'm unpersuaded by the assertion that closing the source is an effective security bulwark. From that page: > Today, AI can be pointed at an open source codebase and systematically scan it for vulnerabilities. Yeah, and AI can also be pointed at closed source as soon as that source leaks. The threat has increased for both open and closed source in roughly the same amount. In fact, open source benefits from white hat s…

The HN discussion on the announcement is just 90% posts of the theme "if a student can brute force your FOSS for $100, they can do you proprietary code for $200" and "if it's that cheap to find exploits, why don't you just do it yourself before pushing the code to prod?" I believe that the reason the chose to close the source is just security theater to demonstrate to investors and clients. "Look at all these FOSS pr…

I think it's more prosaic, OSS is great for building a userbase but not great at generating revenue. So just wave the OSS flag while you build a userbase, then pull out whichever flimsy excuse seems workable at the time when you want to start step two of your enshittification plan.

The only thing new here is the excuse.

Re: Cal.diy: open-source community edition of cal.com

#57
post #33

Earlier quoted context omitted.

Seems to be mostly vibe coded.

Who gives a shit. Cal.com is written by hand and the code is absolute garbage. Of all people that should be luddites I never imagined software engineers would be the most pointlessly staunch advocates of that philosophy.

LLM-assisted is different from vibe-coded. Weird how you're so defensive about it, though

Re: Cal.diy: open-source community edition of cal.com

#58

Tempted to buy cal.zone or cal.sucks just to add the paid features to cal.diy. They even made a list! Teams, Organizations, Insights, Workflows, SSO/SAML, and other EE-only features have been removed cal.ws is $630 on Namecheap... the tokens required to build this are cheaper than the domain.

Bonus: if you pick cal.zone you can have fun with pizza puns.

Perfect recipe to launch a cheesy saas.

Re: Cal.diy: open-source community edition of cal.com

#60
post #33

Earlier quoted context omitted.

Seems to be mostly vibe coded.

Who gives a shit. Cal.com is written by hand and the code is absolute garbage. Of all people that should be luddites I never imagined software engineers would be the most pointlessly staunch advocates of that philosophy.

You might want to look up what Luddism was all about. Hint: it's not about being anti-technology, but about fairness.
Post reply on HN