Projects with bigger problems
Projects with bigger problems
Posted Apr 24, 2026 17:32 UTC (Fri) by farnz (subscriber, #17727)In reply to: Projects with bigger problems by marcH
Parent article: Dependency-cooldown discussions warm up
Right, but the high level approach we're discussing is "put a delay between maintainer publishing a new release and it being generally used, rely on the maintainer to take action if a release is bad to protect the users".
For group maintained projects, this is fine - one or more of the maintainers will be around to handle the notification that the release is bad, and will take action, But for sole maintainers, this runs into the "what if the maintainer is absent at no notice" problem; given that the maintainer can log off forever, a solution based on "maintainer takes action" is not enough.
One answer is social change - we accept that BigCorps will effectively take over sole maintainer projects by adding more maintainers, and if the sole maintainer doesn't want that, BigCorp will fork it and group maintain their fork, trying to stay in sync. This requires us to all accept that BigCorp will fork a lot of interesting projects, and that we have to consider "hostile forks" by big companies as "normal" - it's just BigCorp taking on responsibility for things they depend upon.
The LWN site is currently under high scraper load, so comment display has been suppressed for anonymous users. If you are a human, you may read the comments by clicking the button below:
Note: you can avoid this step in the future by logging into your LWN account.
