Melpa: To remove packages that guide users to non-free software or wrap around proprietary software

Created on 16 Oct 2020  路  11Comments  路  Source: melpa/melpa

I have noticed that some packages like lastpass or helm-lastpass guide users to non-free or proprietary software, thousands of such packages have been downloaded thus putting MELPA users at greater risks. I am proposing for MELPA authors and contributors to make a policy not to include the software that is exclusively made to use proprietary software, such as helm-lastpass or lastpass, chatwork and similar, I have not made a full review how many there are.

Most helpful comment

Thanks for getting in touch.

The MELPA maintainers already take some care to host only Emacs Lisp packages with GPL or GPL-compatible licences. We are not aware of any packages which are in legal violation of this compatibility, including the packages you mention.

Beyond that, we respectfully decline to institute a policy as proposed, and wish you all the best.

All 11 comments

To be clear, it seems that @gnusupport is "Jean Louis," a frequent, strongly opinionated poster on the Emacs mailing list, who just linked to this issue in this message of his: https://lists.gnu.org/archive/html/emacs-devel/2020-10/msg01050.html It almost seems like trolling to post here under a pseudonym, trying to pressure MELPA to change long-held policies (which have surely been discussed and settled in the past), without mentioning that context.

I did not know that my nickname is any issue here. The subject of the issue is explaining the issue. Even you use nicknames or usernames, I see for example alphapapa, I do not mind what is your real name, and there was absolutely no evil intention to post "under pseudonym" how you call it. Please assume good faith.

I am interested to see those policies, if you could kindly give me a reference, thank you. Where is it that I can read it?

Sorry, did not know that my nickname which I was required to choose, is an issue here. The subject of the issue is telling you what is the issue.

It's merely my opinion that, when, shall we say, cross-pollinating a discussion from one forum to another, and that being unsolicited, one ought to be fully transparent about the context.

I am interested to see those policies, if you could kindly give me a reference, thank you.

Have you looked at the wealth of information found in MELPA's readme and linked documentation?

Aside: It's disappointing to see so many messages on emacs-devel from people who seem to think that MELPA hosts non-free software (not that Jean Louis is one of those people, but it is an idea frequently claimed there to be the case). MELPA explicitly only hosts Free Software.

Regarding the policy: MELPA does not prohibit software it hosts from interoperating with non-free software or installing it at the user's request, especially when that is the package's purpose, to provide interoperation between that software and Emacs.

I understand the position of those who would prefer that no one provide any aid to users who wish to use non-free software with Emacs. However, by that logic, it would seem that GNU Emacs's Windows and Mac OS support should be removed. To allow it to run on proprietary platforms may encourage users to remain on them instead of committing fully to FOSS platforms.

Of course, in reality, such support provides a bridge which allows users to "taste" FOSS and gradually convert to it as their requirements permit. I see no reason that FOSS Emacs packages which interoperate with non-free software should be treated otherwise. It's not as if these FOSS packages that interoperate with non-free software do so secretly, behind a user's back--were that ever the case, that would certainly be objectionable.

It will be easy to show me policies, I have seen website, and I have downloaded melpa, and CONTRIBUTING.org,

It is asking for reasonably innovative packages licensed under GNU GPL, which is somehow good, and yet contradictory for those packages that are made solely to interact with proprietary software, like lastpass for example. There is no title that it is a policy, if you have some policy that you can reference, let me know.

How about removing lastpass packages as they were obviously made only to support the proprietary software.

If you don't take my word for it, you can search this issue tracker, where the topic has come up over the years, usually when such packages are proposed to be added.

Regardless, there need not be an explicit you may do this policy. As long as the software is freely licensed, it meets this requirement from CONTRIBUTING.org:

GPL compatible license
The package is released under a GPL-Compatible Free Software License, preferably the GNU General Public License (GPL) version 3. The license boilerplate should be applied above the ;;; Commentary of each source file. The repository should contain a LICENSE or COPYING file, formatted so that it can be detected by common tooling.

I can't speak for the MELPA maintainers, but I think it would be appreciated if you didn't try to coerce them into changing their longstanding policies or demand that they provide written lists of explicitly allowed characteristics which may otherwise be assumed to be allowed unless explicitly prohibited. They are busy actually maintaining MELPA, a very valuable community resource.

Logic is not quite, as let us say GNU Emacs is not made to be used exclusively in interaction with proprietary software or to install such, neither installation of free software like GNU Emacs make user controllable by programmers, while packages made exclusively for proprietary software steer users into direction to be controlled by the company who promotes proprietary software. This raises security and freedom issues.

For example lastpass, it does nothing innovative, interacts with already made lastpass software. Then every small detail could be considered "innovative".

Coerce is strong word, I have proposed to remove packages that wrap proprietary or steer users to non-free software, as by the speed how MELPA is maintained, it can hardly be said, that me, under pseudonym can coerce any manager of this project into anything. It is issue just as any other.

You simply ignore my argument and then make a vague claim of not being logical. That isn't a fair way to argue.

GNU Emacs is not made to be used exclusively in interaction with proprietary software or to install such

That is true. And so what? Who said that MELPA shouldn't host software whose purpose is to interact with non-free software?

packages made exclusively for proprietary software steer users into direction to be controlled by the company who promotes proprietary software

"Steering" is your characterization. From another perspective, users are not "steered" toward non-free software--users who already use such non-free software can now interoperate with it from Emacs, which encourages them to use Emacs and FOSS for more things.

This raises security and freedom issues.

If there are security issues in the FOSS code hosted on MELPA, you may raise them. If there is non-free code hosted on MELPA, you may point to it. But you may not fairly make vague accusations of security and freedom problems.

Emacs and MELPA exist to allow users to meet their needs. It is not for us to decide whether a user needs to interoperate with non-free software, and it is not for us to artificially make such interoperation more difficult. To do so would treat users paternalistically, with great disrespect.

Coerce is strong word, I have proposed to remove packages that wrap proprietary or steer users to non-free software, as by the speed how MELPA is maintained, it can hardly be said, that me, under pseudonym can coerce any manager of this project into anything. It is issue just as any other.

You haven't come here asking, "Why is this the policy?" You've come here saying, "How about removing lastpass packages." You've come here trying to push your agenda, unsolicited. There are users of those packages, and authors, and maintainers who have accepted them. You would take those packages off the archive, as if you know what's best for those users, like Apple removing apps from its App Store. "Coerce" seems like a fair word to me.

Reading further into the thread on emacs-devel, and seeing this comment from you, now I understand your position even better:

It is "proprietary thought police" and there is nothing wrong with
it. Even the thought police will not say there is anything wrong with
thought police. :-p

So when we distribute free software, we tend to speak out against
proprietary software being distributed or promoted together with free
software.

In that sense we are policing various free software repositories and
speaking out publicly against, or denouncing, the inclusion, usage,
and dangers of proprietary software.

So, next time somebody thinks of proprietary software, just remember,
we are watching... slap on fingers.

Good grief. M-x uninstall-thought-police-overlord RET?

Thanks for getting in touch.

The MELPA maintainers already take some care to host only Emacs Lisp packages with GPL or GPL-compatible licences. We are not aware of any packages which are in legal violation of this compatibility, including the packages you mention.

Beyond that, we respectfully decline to institute a policy as proposed, and wish you all the best.

Was this page helpful?
0 / 5 - 0 ratings