Recently I am not a supplier | Musings about software made it rounds through FOSS circles.
In the context of the XZ discussions, it was used to highlight that we can not demand delivering security ratings from hobbyist projects, the way how orgs like OpenSSF attempted to put it.
FOSS maintainers do not owe you a security-aware pipeline, government certifications, scorecards or anything like that, we say. Bullying maintainers to give up the maintainers rights because they don’t perform up to your expectations and do not provide a clear SLA on CVE fixes is not a solution.
But then, is the situation with the Code of Conduct and communities not the same?
Writing and maintaining a Code of Conduct, or generally maintaining a healthy community in your project, if you really mean it, and are not just putting a badge on your github repo, is a lot of work. It is important, it is needed, it is a growing pain and a huge risk. Exactly like the security work.
It requires high trust levels and careful navigation through non-disclosure topics.
It goes for years unnoticed until vulnerability (a certain conflict) is discovered and then the whole world goes crazy about it.
Should we demand every FOSS enthusiast to be able to deal with it? Can we demand it?
There are a lot of open conflicts and pain points in the world right now. We are all struggling with the questions how do we make society better, do we do enough ourselves, how can we convince or force others to do their part…
And in FOSS communities we often try to compensate for things which we can not fix in the bigger world: I can not convince my government to enforce mask mandate so I go and push the local event organizer into it.
But we can not hold local volunteer accountable for everything which is wrong in the world. The organizer of a 20 people meetup in a local neighborhood can not magically solve the problem of the systemic sexism in the industry and give you a lineup of 5 professional women speakers. They also can not be your bouncer and law enforcement officer. All of their resources, as a fellow volunteer, already went into overcoming their own autistic issues and announcing the date and topic of the event.
I am worried that the ever-growing list of criteria on how to be a “proper volunteer” and a “proper community” while means well, is damaging our grass roots. Rather than setting a direction to grow into, it creates a barrier for people to enter.
And the only people who pass that barrier, are those who are ignorant to it from the start and are the least interested in growing.