IF_MS_BUYS_GITHUB_IMMA_OUT icon indicating copy to clipboard operation
IF_MS_BUYS_GITHUB_IMMA_OUT copied to clipboard

As alternative, should give Sourceforge a chance again?

Open MarkoCen opened this issue 6 years ago • 17 comments

Here is today's Sourceforge main page with this GitHub importer Sourceforge website screenshot

MarkoCen avatar Jun 05 '18 17:06 MarkoCen

Hell no. Malware in installers? - tyvm.

Nepeta avatar Jun 05 '18 18:06 Nepeta

Sourceforge isn't even a free or open source, and it has a history of infrastructure problems, malware injections, and worse.

necrophcodr avatar Jun 05 '18 18:06 necrophcodr

It had a blackout in early 2018. Many projects landed on Github.

Atavic avatar Jun 05 '18 20:06 Atavic

Hi all, president of SourceForge here. Just in case people don’t know, a lot has changed at SourceForge since my company acquired them in 2016. We covered the improvements again here yesterday, but here is a summary since we took over.

The very first thing we did after acquiring SourceForge two years ago was remove bundled installers from projects, and vow that it'll never happen on SourceForge again. Since then, further improvements have included:

  • Implemented malware scans with a partnership with Bitdefender for every single project on SourceForge
  • Removed ads for developers (if you’re logged in, you’ll never see ads)
  • Added HTTPS support for project website hosting and all downloads
  • Completely redesigned SourceForge.net from the ground up

We'd love for people to give SourceForge another shot. We're committed to making SourceForge a solid, trustworthy place for FOSS hosting. If you're interested in giving us a shot, we have a GitHub to SourceForge importer here.

To address some of the above comments:

Sourceforge isn't even a free or open source, and it has a history of infrastructure problems, malware injections, and worse.

SourceForge is completely free, and is built with Apache Allura.

Hell no. Malware in installers? - tyvm.

Malware free since 2016. No adware in any installers, and every project on the SourceForge is scanned for malware by Bitdefender and another security service as well. Literally the first thing we did was eliminate the bundled installers as soon as we finished signing the acquisition agreement. We had nothing to do with those previous decisions and nobody who was involved with those decisions is at SourceForge anymore.

loganabbott avatar Jun 05 '18 22:06 loganabbott

Thanks for improving SourceForge. However, by comparison with GitLab's monthly (!) releases, these changes look like bringing a knife to a gunfight:

https://about.gitlab.com/2018/03/22/gitlab-10-6-released/ https://about.gitlab.com/2018/04/22/gitlab-10-7-released/ https://about.gitlab.com/2018/05/22/gitlab-10-8-released/

Bengt avatar Jun 05 '18 22:06 Bengt

Sourceforge is garbage. start a 501c3 to host a community developed alternative. You'll get bought just like GitHub did. It's the dream of sillyvalley

Revivify avatar Jun 05 '18 22:06 Revivify

@loganabbott It's nice to see the new direction SF is taking and the commitment you have for FOSS, however, I fear it's a bit late to recover from the damage that has been done over so many years :/

Furthermore, the solution you are up against has too many advantages and benefits over SF to even be a consideration:

  1. It's FOSS and thus maintained at a pace and scale you probably can't ever compete with

  2. It' installable on-premise, no fees or questions asked.

  3. It's pragmatically FOSS oriented, not business and marketing oriented. So there is no "Deals" section or advertising. Even if your new redesign is miles ahead of what it used to be, it's pretty much exactly what people fear Github will look like once Microsoft takes over and ruin it.

  4. It's already integrated with many FOSS tools or third-party SaaS solution as a first-class citizen just like Github because the integration is often very similar.

  5. The UX is reminiscent of the Github philosophy, so the learning curve is really really fast

  6. In its own right, Gitlab is already a good contender to replace Github, which I believe only latched on due to historical value and inherent developer laziness. Thanks to Microsoft, this is changing fast :)

My intention is not to trash SF, I don't think to have the right to criticise anyone trying to contribute to the FOSS universe, on the contrary, I can only applaud them.

However, I think you deserve to understand why your efforts will likely fail and why it's probably too late to surf the wave you are going for.

h3 avatar Jun 05 '18 23:06 h3

I don't look at it as a zero sum game where winner takes all. We have over a million daily users and 500,000 projects hosted with us, so we're just focused on improving their experience.

We're actually profitable at SourceForge already with no plans to sell. We're not located in Silicon Valley, and we have taken no outside funding. That's not the case with GitLab and others. They're great products too, but I'd imagine they'll end up being bought by a company like Microsoft eventually, or will have to drastically change their business model to be able to exist indefinitely. We've seen a huge influx of imports from GitHub in the past 3 days, so that's good.

At the end of the day, the more viable options out there for FOSS, the better. GitLab focuses on developers while SourceForge focuses not only on developers, but also on search and discovery for end-users where they can easily find, download, and install the software they need with the click of a button, whether or not they have any technical or coding ability. It's apples and oranges and I think we can both co-exist.

loganabbott avatar Jun 05 '18 23:06 loganabbott

@Bengt on the other hand, GitLab has the annoying "This site uses cookies" pop-up...

TwiN avatar Jun 05 '18 23:06 TwiN

@loganabbott the most important difference to me is that even if Gitlab gets bought or change philosophy significantly, its source code can always be forked and maintained openly. No closed source solution can offer that level of flexibility and long-term security.

Incidentally, Gitlab knows very well that if they take a shit in the punch bowl, someone else is likely to quickly roll-out an alternative solution based on their very own source code.

https://gitlab.com/gitlab-org/gitlab-ce/blob/master/LICENSE

h3 avatar Jun 06 '18 00:06 h3

@loganabbott: why don't you make the Source Code of sourceforge open source as well?

I think with 500,000 projects already hosted , your have nothing to lose.

rubo77 avatar Jun 07 '18 06:06 rubo77

@rubo77 SourceForge is built with Apache Allura, which is already open source.

loganabbott avatar Jun 07 '18 14:06 loganabbott

Are there many modifications from the standard Allura platform in sourceforge?

rubo77 avatar Jun 07 '18 17:06 rubo77

Yeah there are some, but when we make changes and improvements to the development tools on SourceForge, that code makes it's way back into Apache Allura, as our devs are the biggest contributors to the Allura project.

loganabbott avatar Jun 07 '18 17:06 loganabbott

I'm going to weight in here. I don't believe Github is going down the drain (in regards to MS acquiring them). However in the spirit of open source, collaborating with others, and knowledge sharing I'd be willing to try Source Forge a try again. @loganabbott I'm willing to give SF a try again. BTW got any PHP jobs open there? :smiley:

ghost avatar Jun 07 '18 19:06 ghost

Hey guys. I love the work you've been doing. Not everyone loves mine. Please read Issue 114.

vassudanagunta avatar Jun 07 '18 21:06 vassudanagunta

Hello,

The GitHub Evacuation Project has moved to GitLab (not an endorsement or even a final home). Your enthusiasm and contribution is still needed. Please check out the new project home, and read the project wiki for info to get restarted.

Thank you!

vas

vassudanagunta avatar Jun 16 '18 08:06 vassudanagunta