69
submitted 1 week ago by [email protected] to c/[email protected]

I’m looking for a way to keep an eye on open source software I’m using, especially if there are detrimental changes. Like for example when there’s an acquisition (Raivo Authenticator) or the project has not been updated in a long time (potentially posing a security risk).

But I don’t want to have to read about every project, just the ones I’m using.

Anyone got any ideas?

all 11 comments
sorted by: hot top controversial new old
[-] [email protected] 18 points 1 week ago

I think participating in communities which are centered around discussion of open source software is the ideal solution. That could be on Lemmy, Mastodon, GitHub, Reddit, Discord, wherever devs and users congregate (and, whatever platforms you find tolerable). I think the information you are seeking is too varied and in some cases subjective to be captured and parsed by an automated tool. And it would be great if you could help others by posting in those communities about changes that you are unhappy with, so others can make informed decisions.

[-] [email protected] 3 points 1 week ago

Just here to comment on your PFP.

Shimarin FTW.

[-] [email protected] 15 points 1 week ago

I don't think one currently exists, but it would be an interesting project. There are plenty of trackers for CVEs but in terms of project ethics, acquisitions, etc., there's a space for it.

The two main problems I can see are:

  1. How do you define 'negative'? An open source application being acquired is often a bad thing, but not always. An acquisition by FUTO is more likely to be viewed positively than an acquisition by Microsoft, but either can be interpreted positively or negatively depending on the person.

  2. Community involvement is absolutely critical. If I were running a service like this (for example), I would only really be keeping up on the services I use and care about. I would need others to submit info and then verify it.

[-] [email protected] 13 points 1 week ago* (last edited 1 week ago)

I can't imagine any way this is possible without crowdsourced information, and at that point you're just interacting with a community (likely the same one as you already are) through a different interface.

But if such an interface existed, it could be a cool project.

[-] [email protected] 7 points 1 week ago

I can't remember what it was called but, I seem to remember there was on you could monitor change of ownership on Github-repo's.

[-] [email protected] 4 points 1 week ago

Subscribe to #open-source #enshitification

[-] [email protected] 4 points 1 week ago

I think it's mostly related to LICENSE file. For example Redis and now Valkey. Otherwise some eye-catching issue drama on repo. As long as the license is truely FOSS like GPL v3 then in 99% cases you should be fine.

[-] [email protected] -5 points 1 week ago

Define "negative way"... GNOME changes in negative ways in a weekly basis so... Notification DDoS? :P

[-] [email protected] 9 points 1 week ago* (last edited 1 week ago)

Bruh I think they're talking about serious stuff like adding spyware, deprecation, suspicious change of owner etc. But your question is valid

[-] [email protected] 1 points 1 week ago

I was thinking that the license is no longer open

this post was submitted on 05 Jul 2024
69 points (94.8% liked)

Open Source

29114 readers
335 users here now

All about open source! Feel free to ask questions, and share news, and interesting stuff!

Useful Links

Rules

Related Communities

Community icon from opensource.org, but we are not affiliated with them.

founded 4 years ago
MODERATORS