Laurie Voss, who was one of the founder of NPM, the Javascript package repository that is now run by Microsoft, has written a longer post about an idea about how to fund Free Software that I found interesting. It’s worth reading if you have some time and makes good points even though I will critique it a bit. But financing Free Software is an unsolved problem right now and any meaningful contribution can help us move this forward.
So, let’s dive in Laurie’s idea is quite simple:
We need a way to force companies to pay for Free Software and the package repositories (NPM, PyPI, etc) are the ideal chokepoint to enforce that payment. The package repositories should force companies to pay for access and distribute the money among the packages that were being used:
Second, a fixed slice of that revenue is a royalty, and it goes to the packages. Not to the registry, not to a foundation, not to a grants committee with an application form. Pro rata, to every package that shows up in the paying customer’s dependency trees, weighted by how many paying customers depend on it, automatically, every month
Laurie Voss, https://seldo.com/posts/nobody-pays-for-open-source-we-can-force-them-to/
Now I do think that a few things in the post are smart: Turning charity towards a forced expense for companies makes sense, companies already know how to pay bills and licenses. Also: Understanding package repositories as chokepoints is a clever idea. I also appreciated how he directly addressed the “but people will cheat to game it” argument basically with a “yeah, might happen to a degree, but not doing something cause someone might cheat is not a good strategy” which I think we need to apply a whole lot more when it comes to support systems. Means testing is shit and we shouldn’t do it.
But you know how sometimes you read and argument by someone and it is built well but doesn’t click with you until you realize that their concept of the problem space is very different from yours? This is one of those cases. After I read through the article and thought a bit about it, I had this sort of intrusive thought: “I bet Laurie uses a Mac.”
This is not some FSF-style purity argument or me hating Macs (I do but that’s only cause I have to use one at work and not the matter here). This realization explained to me, why Laurie’s solution didn’t do what I think matters most.
I think Laurie – who as I mentioned in the beginning was one of the founders of NPM – has a very narrow view of Free Software (I keep writing Free Software where Laurie writes Open Source and maybe that is also part of the difference in understanding): To him, Free Software are all the libraries that you (or your “agent” given the hellscape we live in today) can pull into your software project through a package manager such as NPM. And I’d disagree.
Not just cause a lot of those package managers (for example NPM) are run by for-profit companies, though I do think that creates a non-ideal incentive structure. Because what he describes is basically the Spotify sales pitch – at least how many users think about it. Spotify gets money, takes a cut and distributes it among the artists that their users listen to (let’s ignore for a second that that’s not how it works for bullshit reasons and a lot of the money just goes to Taylor Swift). But then Spotify realized that they would have to pay out a lot less money if they created their own music and got that into the playlists. Having that much money flow through a business just to distribute is a recipe for triggering ideas. Like the ones MBAs have. Horrible ideas.
I disagree because that sees Free Software as this backend stack that companies (and if they want to also individuals) build upon. He tries to solve the problem that if you maintain some library in the middle of the JS dependency tree you are basically working for Amazon or Microsoft without a paycheck. And that would do some good, would support a few people who I’d love to have a stable income.
But it also ignores a lot of Free Software that aims (I’d argue) even more at human beings and their needs. You do not install GNOME through NPM or PyPI. It comes with your distribution who put in a lot work into packaging, potentially patching and curating a whole environment for you to be able to use your computer in a more liberating way. It ignores all the infrastructure projects that work outside of the package registry pipeline. Think of all the core C libraries that a modern Linux system is build around. None of them come from any of those package repositories.
Laurie’s idea implicitly frames Free Software as “the underpaid supply chain for startups and big tech” which is partially true, but that’s not the core of it, I’d argue. Some Open Source communities might disagree of course, especially the JavaScript community feels (from the outside) a lot less political than other parts of the Free Software ecosystem. But I think what Laurie’s suggestion really brings forward is the question of what kind of software are important.
All software is important of course. Our data flows through these systems, our infrastructure is built on those countless libraries that are thanklessly being maintained in people’s free time at the expense of sleep. Laurie’s analysis is on point with that. But I am a bit old maybe so when I think about computers I do think about the device people have in front of them. Not just “the services on the Internet that accumulate your data and rent compute back to you” but the thing you start up where your files are. Where you start the tools you want to use to solve a problem at hand, to do a task, to play and have fun.
Obviously he push towards web-based solutions has reshaped computing. “A website with a mobile app and a chrome wrapper for Mac, Windows and maybe Linux” has been turned into the default. everything has a server now that does … something. Often useful things, store your data in a hopefully safe way or provide resources you can’t afford to buy or that wouldn’t be worth buying for the one time you need them. In my impression Laurie thinks about how to fund a world of Chromebooks, of dumb terminals attached to Internet services built on Free Software stacks.
But is that the path that we are 100% happy with? I spent the day on trains from Zurich to Berlin and the wireless fucking sucked. And so much shit just didn’t work. What worked was what I had downloaded before to have available for applications on my machine.
Of course one can argue that cell service and wireless will just get better and that the future is “the Internet + terminal”. But why do we have to subscribe to this understanding of computing that has been defined dominated and pushed by Google, Amazon and Microsoft?
When thinking about how to fund software we quickly end up at the question of what kind of software we want to fund. Not just which single libraries or developers to support but what kinds of structures and systems we want to see in the world.
I think Laurie’s idea is a clever hack to siphon money out of big corporations. I am a big fan. And it would fund a few people who today don’t get funding or who have to have a day job on the side to be able to eat. That is fantastic.
But it is also built around the idea that the kind of computing that big tech has pushed in order to establish chokepoints. Build around the processes that big tech corporations use to build software. And maybe that’s my main irritation.
Package repositories are useful to individual developers. I find a library I could use for something and I can quickly install it. Great. But here’s the question: Am I the target audience of those registries or am I just … kinda there? I think that repositories such as NPM or PyPI are build especially for corporate software development processes. For contractors and developers who have to think about SBOMs and dependency trees to be able to deploy their software to hundreds if not thousands of machines based on a git commit and a successful CI run. DevOps engineers have polished those pipelines to be almost frictionless. They re so polished, that you can even have stochastic parrots use them.
But that is infrastructure for big corporations and their needs. And I am not saying that package repositories are inherently bad, I just wonder if just following those corporate logics is the way. Because setting it up that way does create an implicit pressure towards being a proper cog in the machine that keeps Google’s software supply chain running. They are – after all – directly paying you to use your code.
I think we need to find better solutions to make developing Free Software humane. That does include giving people the resources to be able to learn how to do it and to do it. And the two core resources here are time and money – with time often coming from giving people money so they don’t have to have another job. And that is how we should think about building systems to support and fund the creation and maintenance of Free Software. Not as a way to keep the people Microsoft or some Startup doesn’t want to hire but whose work they’d like to use kinda fed. But as a way to actually create space for human beings to come in and be able to contribute. Regardless of whether your library fits into Big Tech’s supply chain.





