While it's easy to see how this sounds scary; the flip-side of this is that it's not clear if there's more to it than misperception/miscommunication.
To take the example from the blogpost; the author was particularly scared by the move into github enterprise. I don't want to dismiss that worry; but on the other hand - the only consequence of that move seems to have been that logged in members of the project have a very slight UI change. Obviously that's not what people are worried about; they're worried about... well, what else does that mean?
Well, what else does that mean? Is this really something to worry about, or is this really just a misunderstanding - or both?
> Well, what else does that mean? Is this really something to worry about, or is this really just a misunderstanding - or both?
It means microsoft has hijacked the repo. I don't think their intentions or anything else matters. This is imo crossing a huge line.
I was always kind of wary of github, ever since MS acquired it, and I have always made sure to not get trapped by using any lock in features. But I never assumed their lock-in includes going full SourceForge and hijacking people's repos.
Honestly, if GitHub/MS don't come out with a very good statement on how and why this will never happen again, I'll need to figure something out and make sure people use a different URL instead of pointing to my github.
It's absolutely something to worry about. If someone breaks into your house, you should be worried irregardless of if they stole something, or not.
I’m not sure how this is related to Microsoft’s control of GitHub. This was the .NET Foundation using application-level permissions that it was granted on each repo. It wouldn’t matter what platform was used, if it supported re-organizing project hierarchy, this could have happened.
Just to reiterate: the observable consequences of that "hijacking" is apparently an almost imperceptible icon most people don't even see. That cannot be worth getting this worried about; the worry needs to be something else, probably something that hasn't happened yet but the maintainers feel like it (whatever it is) is something terrible they believe the foundation now has the capability for, and do not entirely trust the foundation to refrain from exercising this unknown power in some future circumstance.
If that sounds absurdly vague, it's because the concrete accusations are that vague.
On the one hand: it's possible this tiny UI change does signify some deeper permissions change, but it's not exactly obvious what that would be (especially given the already admin nature of the dnfadmin account). Nor is it clear both the foundation and maintainer really understood what that permission might mean, if it even exists. It's not clear the maintainers have any specific reason to object in the first place!
The one thing that seems clear is that the github UI wasn't clear, allowing the maintainers and dnf to read very different things into a superficially trivial change, and that there's some level of miscommunication at the very least. But it's still not at all clear whether the actual change made warranted the fears expressed, not at all.
Personally, while the dnf clearly and objectively failed in its task of keeping maintainers on board, I can't help but also feel that these maintainers deserve a bit of opprobrium. They essentially started a major social media freak out, and cannot even express exactly what it is they're afraid of, let alone point to any evidence that whatever mistakes the foundation made weren't fixable by measures with less collateral damage.
It's all very nice to blame some scary sounding not-entirely-defined shadowy corporate conspiracy between github, microsoft and dnf, but at the end of the day meltdowns like this do harm, and it's just not clear that was at all warranted.
It might not be clear to you but as a maintainer and member of the Foundation it's very clear to me. The DNF used temporarily assigned permissions (assigned under the premise that they needed authority to fix a CLA bot) to move several repositories to their own organization. This is unacceptable by any measure.
Technically no, they used their permissions to include the organization in the enterprise. But the more relevant question is why that matters. As I tried to point out above, this has essentially 0 impact so far; so people must be worried about some future impact. Which specific one? How does this move cause problems that otherwise would not exist?
I think it depends on whether or not you are operating in good faith and you think he foundation is too. It sounds to me like people are attributing bad faith to this whole misunderstanding.
It’s unfortunate that this has become our mode of conflict resolution: blog posts, public apologies that don’t grovel enough and a trivial issue that people have turned into a political football so they can run that shit into the end zone and spike the hell out of it.
Grievance culture is weak, and frankly, dishonorable.
I might agree with parts of what you are saying but when the channel to communicate back to the "powers that be" is broken and you face (what feels like) an existential threat, the public forum is an enticing, sometimes effective but very messy option.
To take the example from the blogpost; the author was particularly scared by the move into github enterprise. I don't want to dismiss that worry; but on the other hand - the only consequence of that move seems to have been that logged in members of the project have a very slight UI change. Obviously that's not what people are worried about; they're worried about... well, what else does that mean?
Well, what else does that mean? Is this really something to worry about, or is this really just a misunderstanding - or both?