> Well, what else does that mean? Is this really something to worry about, or is this really just a misunderstanding - or both?
It means microsoft has hijacked the repo. I don't think their intentions or anything else matters. This is imo crossing a huge line.
I was always kind of wary of github, ever since MS acquired it, and I have always made sure to not get trapped by using any lock in features. But I never assumed their lock-in includes going full SourceForge and hijacking people's repos.
Honestly, if GitHub/MS don't come out with a very good statement on how and why this will never happen again, I'll need to figure something out and make sure people use a different URL instead of pointing to my github.
It's absolutely something to worry about. If someone breaks into your house, you should be worried irregardless of if they stole something, or not.
I’m not sure how this is related to Microsoft’s control of GitHub. This was the .NET Foundation using application-level permissions that it was granted on each repo. It wouldn’t matter what platform was used, if it supported re-organizing project hierarchy, this could have happened.
Just to reiterate: the observable consequences of that "hijacking" is apparently an almost imperceptible icon most people don't even see. That cannot be worth getting this worried about; the worry needs to be something else, probably something that hasn't happened yet but the maintainers feel like it (whatever it is) is something terrible they believe the foundation now has the capability for, and do not entirely trust the foundation to refrain from exercising this unknown power in some future circumstance.
If that sounds absurdly vague, it's because the concrete accusations are that vague.
On the one hand: it's possible this tiny UI change does signify some deeper permissions change, but it's not exactly obvious what that would be (especially given the already admin nature of the dnfadmin account). Nor is it clear both the foundation and maintainer really understood what that permission might mean, if it even exists. It's not clear the maintainers have any specific reason to object in the first place!
The one thing that seems clear is that the github UI wasn't clear, allowing the maintainers and dnf to read very different things into a superficially trivial change, and that there's some level of miscommunication at the very least. But it's still not at all clear whether the actual change made warranted the fears expressed, not at all.
Personally, while the dnf clearly and objectively failed in its task of keeping maintainers on board, I can't help but also feel that these maintainers deserve a bit of opprobrium. They essentially started a major social media freak out, and cannot even express exactly what it is they're afraid of, let alone point to any evidence that whatever mistakes the foundation made weren't fixable by measures with less collateral damage.
It's all very nice to blame some scary sounding not-entirely-defined shadowy corporate conspiracy between github, microsoft and dnf, but at the end of the day meltdowns like this do harm, and it's just not clear that was at all warranted.
It might not be clear to you but as a maintainer and member of the Foundation it's very clear to me. The DNF used temporarily assigned permissions (assigned under the premise that they needed authority to fix a CLA bot) to move several repositories to their own organization. This is unacceptable by any measure.
Technically no, they used their permissions to include the organization in the enterprise. But the more relevant question is why that matters. As I tried to point out above, this has essentially 0 impact so far; so people must be worried about some future impact. Which specific one? How does this move cause problems that otherwise would not exist?
It means microsoft has hijacked the repo. I don't think their intentions or anything else matters. This is imo crossing a huge line.
I was always kind of wary of github, ever since MS acquired it, and I have always made sure to not get trapped by using any lock in features. But I never assumed their lock-in includes going full SourceForge and hijacking people's repos.
Honestly, if GitHub/MS don't come out with a very good statement on how and why this will never happen again, I'll need to figure something out and make sure people use a different URL instead of pointing to my github.
It's absolutely something to worry about. If someone breaks into your house, you should be worried irregardless of if they stole something, or not.