Providing kickbacks to the repos being scraped would be a good way to help fund open source projects and pay creators like streaming services do. Seems like they're headed in this direction - it would be a massive product differentiator over GH
My first reaction was that I really like this idea.
If we had a system where people who access projects pay and popular FOSS developers get paid for it we'd have much better alignment.
My second thought was that bots would immediately try to circumvent such a plan. They'd probably spam Gitlab with fake repos to try to harvest those payouts.
I think the main issue here is that the access point for many OSS projects most of the time is package managers.
People often aren’t hitting up GitHub directly to get or install open source projects: they’re going via homebrew, npm, or whatever, so the registry becomes the source. Of course you can install directly from GitHub even with package managers but most times you don’t and it’s increasingly seen as a security issue.
On your second point, ugh, yes, you’re absolutely right. I don’t think it would work exactly the way you describe but, if there’s some automated revenue sharing/distribution, you can bet that people will find ways to exploit it via some form of spamming.
You're right. Blanket rate limits probably aren't a good way to handle the traffic profile of places git services.
Package managers tend to only need a small portion of what's in any given repo; some metadata to figure out what's going on and a single binary package is generally enough. The obvious answer is to separate those out and serve them differently from developers, who are actually monkeying around with the source code.
cush · · focus · HN ↗
aprentic · · focus · HN ↗
If we had a system where people who access projects pay and popular FOSS developers get paid for it we'd have much better alignment.
My second thought was that bots would immediately try to circumvent such a plan. They'd probably spam Gitlab with fake repos to try to harvest those payouts.
bartread · · focus · HN ↗
People often aren’t hitting up GitHub directly to get or install open source projects: they’re going via homebrew, npm, or whatever, so the registry becomes the source. Of course you can install directly from GitHub even with package managers but most times you don’t and it’s increasingly seen as a security issue.
On your second point, ugh, yes, you’re absolutely right. I don’t think it would work exactly the way you describe but, if there’s some automated revenue sharing/distribution, you can bet that people will find ways to exploit it via some form of spamming.
aprentic · · focus · HN ↗
Package managers tend to only need a small portion of what's in any given repo; some metadata to figure out what's going on and a single binary package is generally enough. The obvious answer is to separate those out and serve them differently from developers, who are actually monkeying around with the source code.