Hi

As we all know the XZ-Backdoor showed how open source can help to find out how and when things happened. You can look back into the source code, commits and comments to see what happened. Many started to talk about what it means regarding open source, and also showed that security is a very important part of computers and software.

But the XZ-Incident showed again one of the biggest problems of FOSS (and OSS), the lack of support the maintainers and contributors get. The maintainer of XZ (before he got replaced by Jia Tan via a social engineer attack), talked about mental issues and overall many things to look after. He was the only maintainer for a library that is used in many big Linux distributions but no one thought maybe to help him or support him.

We all use FOSS projects either knowingly or unknowingly (the XKDC comic comes to mind with the Nebraska maintainer project) and we all love and fight for open and free (libre) software. Simply using and pushing it is not enough we need to support the people that code, test and maintain the projects, libraries, programs that we use. If we don’t, it will crash down on us sometime in the future.

When a friend does something for you, you say thank you and maybe buy him/her a beer. Why not do that too for a converter you used or some cool little terminal addition you found and now can’t live without it?

As an experiment, make a list of all FOSS/OSS things you use in your daily life that you know of, and then look them up to see if they need funding or in general how they stand. Maybe you can donate to a few of them.

Make FOSS not only a philosophy but also a community that looks after each other.

  • astraeus@programming.dev
    link
    fedilink
    arrow-up
    6
    ·
    8 months ago

    Kind of goes against the underlying principles of FOSS to hire a team to work on a project. Not that all FOSS work is volunteer based, but once something becomes an incentivized project the FOSS part starts to become a bit ambiguous.

    • averyminya@beehaw.org
      link
      fedilink
      arrow-up
      5
      ·
      8 months ago

      I also just don’t see donations ever funding a long term development team. $20 an hour? For how many people? (X) to doubt. Idk it’s a rough circumstance

    • anlumo@beehaw.org
      link
      fedilink
      English
      arrow-up
      1
      ·
      8 months ago

      Works pretty well for the Linux kernel, and that’s arguably the most successful FOSS project ever.

      • astraeus@programming.dev
        link
        fedilink
        arrow-up
        5
        ·
        8 months ago

        The Linux Foundation isn’t doing most of that legwork though, multiple corporations with their own interests are. Microsoft, Valve, and Red Hat are some of the biggest contributors to the kernel, but they aren’t paying teams specifically to keep up Linux as much as they are paying teams to develop for them things which must be contributed back to the kernel.