Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

High-profile projects actually can't stop. If you attempt to stop using Sourceforge, they will consider your account "abandoned" and continue mirroring the new site and serving downloads with their malware dropper included. So if you want to keep the malware out of your releases, you need to maintain control of your project by keeping SourceForge up to date.

The GIMP project learned this the hard way: http://www.gimp.org/news/2015/05/27/gimp-projects-official-s...

Since they used to be the official source, their repository tend to have very high PageRank and they're essentially cashing in on it. Since the content they host is open-source, this is technically legal, but it's scummy as all hell.



When I had a project that I started on sf and later moved off, I kept the sf project technically alive, but removed all downloads. I updated with links to the project site.

This was a BlackBerry project, though, and it wasn't something you could install on a desktop - that may have been a contributing factor, but I never had any problems with them continuing to host the content after I deleted it.


"Since the content they host is open-source, this is technically legal, but it's scummy as all hell."

If the project is licensed under GPLv3 (or any other strong copyleft license), wouldn't they be illegally hosting it because they are bundling their malware dropper with software that isn't compatible with the license?


Simple bundling is not a GPL violation, only linking.


Is there any license that prohibits this then? If not, should one be created?


If there was, it wouldn't be open source. The Open Source Definition explicitly prohibits any license that restricts simple bundling [0]:

> The license shall not restrict any party from selling or giving away the software as a component of an aggregate software distribution containing programs from several different sources.

Same with the Debian Free Software Guidelines [1]:

> The license of a Debian component may not restrict any party from selling or giving away the software as a component of an aggregate software distribution containing programs from several different sources.

[0] https://opensource.org/osd-annotated

[1] http://www.debian.org/social_contract#guidelines


Yeah I still can't believe how scummy sourceforge is. I wonder how new oss projects can protect themselves against this type of behavior. Anyone know if any oss licenses include a restriction against this kind of repackaging or any kind of malicious use clause?


That would be contradiction of terms. Anything with such restrictions is, by definition (look it up!), not Open Source.


Sure if you want to be pedantic about it...

In reality though there's a reason there are many different OSS licenses - many devs want options around attribution and yes, around use in limited ways. A please don't use this for abject evil clause may not meet the no true open source dictionary definition, but pragmatically speaking it's not necessarily a terrible idea.


Then we should all probably point our collective fingers at google. Let's not pretend they couldn't blacklist sourceforge links for pulling this kind of BS.




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: