Live data from Hacker News

I gave commit rights to someone I didn't know

jakewins.com

71–80 of 106 posts

Re: I gave commit rights to someone I didn't know

#71
post #8

I did something similar with a project I lost interest in several years ago ( https://github.com/dbfit/dbfit - table-oriented database unit testing). Just gave over commit rights, and there's a whole bunch of people writing code for it and maintaining it now, still going strong. I occasionally look at the github repo, and always end up amazed how much it's moved on.

We use DbFit every day at our shop. It's really changed how we work (as DB developers). Was funny that I thought of this project right after reading this article, and how I should probably try and contribute, then I see this in the comments. :) Thanks!

nice :) I built DbFit at a time when I was getting a lot of work helping companies with a huge investment in oracle pl-sql, but my interests moved on, and for a while it just felt I was holding the project back.

People wanted to implement new things, support new databases, I felt overprotective of the design, but didn't have enough time to bring new contributors onboard. So I just kind of gave up, and that allowed me to think about it from a completely different perspective. If I just deleted it, then I wouldn't care too much about it any more. Giving away the keys was kind of the same, but without preventing others from contributing. And it worked out great.

Re: I gave commit rights to someone I didn't know

#72

Let me tell you the story of how I got involved in the Perl 6 community. I was trying to find out how Perl 6 was progressing, and found a broken link on a related website (pugscode.org, now defunct). So I went into the #perl6 IRC channel to report it. Within three minutes, Audrey Tang (to become minister without portfolio in Taiwan in October) had committed a fix, somehow found an email address of mine, and sent me a…

Sure, sounds fun, my username is Dorian :)

Re: I gave commit rights to someone I didn't know

#73
post #61

Earlier quoted context omitted.

I think the most interesting part of your story is that Taiwan now has a minister "placed in charge of helping government agencies communicate policy goals and managing information published by the government, both via digital means" who actually knows about computers! Something that seems as if it would never happen here. [1] https://en.wikipedia.org/wiki/Audrey_Tang#Political_career

Yeah, I'd be very surprised if anyone in congress could even spell IRC, let alone be an active contributing member of a programming community. It's a shame that the people who are making the biggest decisions about the legality and future of all this stuff largely have no idea what they're dealing with or have any clue how any of it works.

But that's true for literally every industry. Congress passes laws about healthcare even though very few of them are doctors. They pass laws about oil drilling and I doubt many of them have training in that. Etc, etc.

Congress is incompetent at everything. Its just that you only notice when they are talking about something you know about.

Re: I gave commit rights to someone I didn't know

#74
post #32

Earlier quoted context omitted.

Wouldn't it have made sense to revert the first subpar commit, pulled aside the contributors and explained to them what is acceptable? Disowning the project seems like a lose/lose situation.

It was a project that I didn't give a lot of love, and hence just gave them commit rights. It was about a year later before I looked again, by which time they had done far too much work on top of their non-cross-platform bits for me to revert. I still didn't use the project myself; and didn't care enough to fix it, so I just removed myself.

Yeah, that's one of the dangers. Did you start a conversation with them about it, or just move on silently?

I'm trying to think of a good way to start such a conversation... but it sounds tricky. Probably would depend on the personality of the person. ;)

Re: I gave commit rights to someone I didn't know

#75

I was introduced to open source software in 1996 and have been a huge advocate since. About five years ago, I decided to quit my job and, shortly thereafter, went out in search of a project I could contribute to in my spare time (which was now much more abundant). I quickly discovered that a particular piece of software I used daily wasn't really being maintained all that well, despite the fact that there were severa…

Ugh, that kind of dev behaviour is extremely lousy, and not at all the norm for Open Source projects.

Hopefully you've found places/projects more receptive to your time/effort since then. :)

Re: I gave commit rights to someone I didn't know

#76
Whilst this is an interesting story and shows how open source software can work it leaves me wondering how large corp's handle their increasing use of open source software.

Traditional corporate development is very controlled with everyone getting background checks on hiring and code reviews and change control and a load of other stuff around managing what software runs their business.

Into that mix corps are adding loads of software that's developed by people who they have no control over and no knowledge of their motivations, affiliations or skill level. Even if they did a one-time check of all the developers who had contributed to libriaries they use (which would be a huge task) there's nothing to stop any of the maintainers from handing over to someone else the next day.

It's even a change from using things like RHEL where there's at least a contract with another company that you could point at if things go wrong...

It seems a very odd match up....

Re: I gave commit rights to someone I didn't know

#77

Earlier quoted context omitted.

Yeah, I'd be very surprised if anyone in congress could even spell IRC, let alone be an active contributing member of a programming community. It's a shame that the people who are making the biggest decisions about the legality and future of all this stuff largely have no idea what they're dealing with or have any clue how any of it works.

But that's true for literally every industry. Congress passes laws about healthcare even though very few of them are doctors. They pass laws about oil drilling and I doubt many of them have training in that. Etc, etc. Congress is incompetent at everything. Its just that you only notice when they are talking about something you know about.

When Bill Frist was Senate majority leader, despite his training as a medical doctor he didn't exactly use that competence in the Terri Schiavo case.

Congress is inevitably political, the problem is how to provide unbiased expert advice to it.

Re: I gave commit rights to someone I didn't know

#79
post #14

Ha, Same thing happened to me with the SAME contributor!! Benjamin Bach is an awesome dude. He helped me maintain django-dbbackup for quite some time then we found a third contributor, Anthony Monthe, who is also very interested in the project and I would say owns it now. It's been maintained by those two for quite some time now. I wish there was a way for me to buy them both a bunch of rounds of beer. :D

Use Bitcoin or Venmo. Sounds like they've been great stewards.

Stop using Venmo

http://gizmodo.com/stop-using-venmo-1759867212

Re: I gave commit rights to someone I didn't know

#80
post #67
post #65

Earlier quoted context omitted.

I don't want to sound too negative but doesn't this look like they were in need of volunteers even by risking the repo's integrity by allowing total strangers commit access from lack of commitment from the real core team? It almost sounds like perl6 is a publically writeable repo.

What do you think the risk is? That some sociopath gains access to the perl6 repo and replaces all the code with a shellscript that "sudo rm -rf /"'s? Sure, that's possible, but good contributors will vastly outnumber bad contributors, and such a person's commit access would be revoked instantly. There's still code review for everything, and such a change would not go unnoticed. Just look at Wikipedia. That's the equ…

> That some sociopath gains access to the perl6 repo and replaces all the code with a shellscript that "sudo rm -rf /"'s?

No, that some sociopath gains access to the perl6 repo and introduces subtle, plausibly deniable backdoors.

I have looked at Wikipedia. I saw that obvious vandalism, like inserting "HAHA PENIS" in the middle of an article about — I don't know — US presidential candidates, is detected quickly; sometimes it is even caught by filters before it can be saved. Fabricating citations about a fictitious Bhutanese author[1] or Aboriginal deity[2], on the other hand, can go unnoticed for months. This is exacerbated by the fact that your typical "counter-vandalism patrol" usually looks only for the former; even though most hoaxes aren't even especially sophisticated and fall apart after 15 minutes of research. But who can blame those people? It's the easiest way to score virtue points.

I don't know why some people are so okay with the most popular reference work of today being developed by a process basically equivalent to Twitch Plays Pokémon. It doesn't even work for the latter... and yet here we are.

[1] http://wikipediocracy.com/2015/04/05/bhutanese-passport-what...

[2] https://en.wikipedia.org/wiki/Jar%27Edo_Wens_hoax (embrace the irony!)

Post reply on HN