91
Why GitHub? (lemm.ee)
submitted 1 year ago* (last edited 1 year ago) by james@lemm.ee to c/nostupidquestions@lemmy.world

I can't help but notice most (all I've seen anyway) of the federated projects are hosted on GitHub. GitLab is also not federated, but can be self hosted and has at least discussed it.

I am fully aware of my bias for GitLab over GitHub, but I still wonder why is those things? Is there a federated source hosting project?

top 50 comments
sorted by: hot top controversial new old
[-] marsara9@lemmy.world 52 points 1 year ago

IMHO federation doesn't bring any real benefits to git and introduces a lot of risks.

The git protocol, if you will, already allows developers to backup and move their repositories as needed. And the primary concern with source control is having a stable and secure place to host it. GitHub already provides that, free of charge.

Introducing federation, how do you control who can and cannot make changes to your codebase? How do you ensure you maintain access if a server goes down?

So while it's nice that you can self host and federate git with GitLab, what value does that provide over the status quo? And how do those benefits outweigh the risks outlined above?

[-] james@lemm.ee 5 points 1 year ago* (last edited 1 year ago)

You bring up some good points. I agree on the risk, even though I'm a fan I find federated tools harder to get started with.

I agree git is decentralized, but services like GitHub are not. They're more than just hosting code. They're issues, wiki's, CI/CD, peer reviews, etc.

how do you control who can and cannot make changes to your codebase?

I'd image it's the same as now. Except now you could say @everyone@that-server is cool and can contribute, or @those-guys@over-there shouldn't even be allowed to see this code.

How do you ensure you maintain access if a server goes down?

How do you do this on GitHub?

what value does that provide over the status quo?

I feel like this is the root of fediverse problems. It's easy to send your first tweet, but that first toot takes some effort (I just learned they're called toots).

[-] marsara9@lemmy.world 3 points 1 year ago

Btw I appreciate the fediverse and decentralization as much as the next guy, heck I'm even writing software for the fediverse. But I feel like there's a handful of people out there that want to try and apply the fediverse concept to everything. Similar to what happened with Blockchain. Everyone and everything had to be implemented via Blockchain even if it didn't make sense in the end.

IMO though, GitHub is just one "instance" in an already decentralized system. Sure it may be the largest but it's already incredibly simple for me to move and host my code anywhere else. GitHub's instance just happens to provide the best set of tools and features available to me.

But back to my original concerns. Let's assume you have an ActivityPub based git hosting system. For the sake of argument let's assume that there's two instances in this federation today. Let's just call them Hub and Lab....

Say I create an account on Hub and upload my repository there. I then clone it and start working... It gets federated to Lab... But the admin on Lab just decides to push a commit to it directly because reasons... Hub can now do a few things:

  1. They could just de-federate but who knows what will happen to that repo now.
  2. Hub could reject the commit, but now we're in a similar boat, effectively the repo has been forked and you can't really reconcile the histories between the two. Anyone on Lab can't use that repo anymore.
  3. Accept the change. But now I'm stuck with a repo with unauthorized edits.

Similarly if Hub was to go down for whatever reason. Let's assume we have a system in place that effectively prevents the above scenario from happening... If I didn't create an account on Lab prior to Hub going down I now no longer have the authorization to make changes to that repository. I'm now forced to fork my own repository and continue my work from the fork. But all of my users may still be looking for updates to the original repository. Telling everyone about the new location becomes a headache.

There's also issues of how do you handle private repositories? This is something that the fediverse can't solve. So all repos in the fediverse would HAVE to be public.

And yes, if GitHub went down today, I'd have similar issues, but that's why you have backups. And git already has a solution for that outside the fediverse. Long story short, the solutions that the fediverse provides aren't problems that exist for git and it raises additional problems that now have to be solved. Trying to apply the fediverse to git is akin to "a solution in search of a problem", IMHO.

[-] Mubelotix@jlai.lu 1 points 1 year ago

I would like to add that git is a pretty good example of data people have backups for. I don't care if Github blows up tomorrow because I have repos on my disk. Even if my disk also dies, my friends have my repos cloned so I wouldn't lose much

[-] Obsession@sh.itjust.works 34 points 1 year ago

Git is already decentralized - every contributor has a copy of the repo on their own machine.

At that point, it's just about using what's most popular. I have a slight preference toward gitlab myself, but the prevalence of github means I still push most of my projects to there, just because I'm already visiting the website so often.

[-] kobra@lemm.ee 20 points 1 year ago

Once you move off the free tier, GitLab is quite expensive in comparison. That might be part of it.

[-] ryannathans@lemmy.fmhy.ml 3 points 1 year ago

Open source projects enjoy free gitlab ultimate or whatever it's called

[-] james@lemm.ee 2 points 1 year ago

I've never moved off the free tier, even when self hosting. Although I did get to use a paid version at a previous job and I admit some of those features were nice.

Are they paying on GitHub?

[-] Vlyn@lemmy.ml 17 points 1 year ago

From the view of a small team that actually paid for GitLab Bronze: Their pricing is a mess and they keep changing things. We went with GitLab at first, Bronze tier, everything was great.

Then they removed Bronze tier (which was $4 per user per month) and only offered a premium tier from then on, $20 per user per month. Which is insane if you look at GitHub pricing.

So instead of paying that much we went with the free tier afterwards. Then GitLab limited free tier repos to 5 users max. Which was yet again annoying and we had to act on that.

In the end the company moved to GitHub, all we wanted was a stable solution we pay for and be left in peace. GitLab kept messing with things and wasting developer hours (Damn meetings with management). GitHub still has a $4 per user per month tier, GitLab.. wtf.. just raised the price again to $29 per user per month. Are they insane?

[-] agressivelyPassive@feddit.de 6 points 1 year ago

As a user, I have to say gitlab isn't exactly top tier, either.

We use a selfhosted instance at my company and it a) eats resources like a badly configured Bitcoin miner and b) keeps not only changing it's UI, but also puts 8000 different things in it.

[-] Vlyn@lemmy.ml 3 points 1 year ago

Yeah, I have no clue how they make software that's so damn inefficient.

Don't even get me started, for example I bought a personal license from Jira (Atlassian) to run on my Linux server. Tiny university project, 5 users (with no one using it most of the time) and the thing ate up all my memory and used half my CPU cores just by idling. That server also hosted Minecraft, which used less resources than that..

[-] agressivelyPassive@feddit.de 4 points 1 year ago

Jira suffers from the problem that you can configure almost everything. Pouring that into an efficient data structure (in memory and in SQL) is almost impossible, so it always has to do tons of overhead.

I feel like ironically this freedom to adapt it to you needs makes it not only slow, but also unusable, because every bullshit business requirement gets some artefact in Jira. Even though 95% of the workflows look exactly the same in practice.

[-] james@lemm.ee 1 points 1 year ago

Yeah, I have no clue how they make software that’s so damn inefficient.

Software is a gas.

[-] james@lemm.ee 1 points 1 year ago

I haven't run into the resource issue (running in docker), but yeah I wish I could turn off some UI features. We never need to upload designs so why do I have to look at it on every issue?

[-] twistypencil@lemmy.world 1 points 1 year ago

You can turn off features by default! Check your gitlab.rb and you will find even more stuff they have bundled in there that is off, like a matter most server 😀

[-] james@lemm.ee 1 points 1 year ago* (last edited 1 year ago)

When I looked some could be disabled and some couldn't 🤷
I'm not a devops engineer I only play one when no one else is willing.

[-] james@lemm.ee 4 points 1 year ago

I'm forced to agree, GitLab's pricing could be easier to understand and more competitive.

I haven't ran into the 5 user limit; I suspect that's not a limit of the self-hosted version. I will say it's a pain to get a clear understanding of what is available and what's not on the free edition when self hosting... also there are 2 free editions (community and unlicensed enterprise) now which adds to the confusion.

[-] xtremeownage@lemmyonline.com 13 points 1 year ago

I use github for public projects. Easily discoverable and it works extremely well.

It's also free for FOSS.

For private/internal, inuse gitea. Very small, lightweight, but works perfectly

[-] sol@lemm.ee 7 points 1 year ago

UI and pricing aside (I don't have much direct experience of either on GitLab), GitHub is, AFAIK, by far the most popular and therefore it's easier to get your project discovered and get other developers to contribute.

I do kind of think that by centralising so much stuff on a website owned by Microsoft we are running the risk of another Reddit-like situation where GitHub turns sharply anti-user in an attempt to monetise in the future. But for the moment, the network effects are real and significant.

[-] james@lemm.ee 4 points 1 year ago

I don't think I've ever discovered projects by perusing GitHub. It's always the "fork this" link on a project page or a link from an article.

I've learned I don't use most of the internet the way everyone else does, so my anecdotal evidence is nothing to go by. 🤣

[-] twistypencil@lemmy.world 2 points 1 year ago

Drive by contributions are just as frequent in gitlab as github. I've been involved in moving multiple large free software projects from github to gitlab and there was zero difference seen in discoverability, in fact contributions grew on gitlab, although there is no data to suggest it was because of gitlab, as it could have been because projects aged and grew

[-] ryannathans@lemmy.fmhy.ml 6 points 1 year ago

As a large repo maintainer I use gitlab because they are much friendlier to open source devs

[-] atocci@kbin.social 5 points 1 year ago
[-] DarkThoughts@kbin.social 4 points 1 year ago
[-] FaceDeer@kbin.social 2 points 1 year ago

Either you're a really big fan of Codeberg or you typoed a bit there.

[-] DarkThoughts@kbin.social 3 points 1 year ago

Or, I might have done it on purpose to do a silly internet joke.

[-] BURN@lemmy.world 5 points 1 year ago* (last edited 1 year ago)

GitHub is (mostly) free and central, as well as being the default for the majority of developers. Gitlab handles some things differently, scales less well (from what I can tell) and is honestly just different (change is bad /s).

I think the fact it isn’t federated is a point in favor of GitHub. If something goes wrong in a federation protocol then there’s no impact to the code bases.

[-] Zeth0s@lemmy.world 5 points 1 year ago

Legacy I would say. Github used to be the first and the best.

Now they are literally selling out work of open source developers with copilot, but their service is honestly good

[-] james@lemm.ee 2 points 1 year ago

Legacy I would say. Github used to be the first and the best.

I know this is the answer, but I'm sad when the answer is "because we've always done it that way".

[-] twistypencil@lemmy.world 4 points 1 year ago

Wait what? I'm running three different self hosted gitlab, and they aren't resource hogs at all. One has thousands of active users. Maybe if you are trying to run on a rpi or something you are going to have issues... But come on, Bitcoin miner? That is hyperbole

[-] hot_milky@lemmy.ml 2 points 1 year ago

Let's not forget the EULA difference. GitHub will own your code to a greater degree than the alternatives, in order to feed their AI. I don't think you can opt out?

load more comments
view more: next ›
this post was submitted on 12 Jul 2023
91 points (97.9% liked)

No Stupid Questions

35729 readers
987 users here now

No such thing. Ask away!

!nostupidquestions is a community dedicated to being helpful and answering each others' questions on various topics.

The rules for posting and commenting, besides the rules defined here for lemmy.world, are as follows:

Rules (interactive)


Rule 1- All posts must be legitimate questions. All post titles must include a question.

All posts must be legitimate questions, and all post titles must include a question. Questions that are joke or trolling questions, memes, song lyrics as title, etc. are not allowed here. See Rule 6 for all exceptions.



Rule 2- Your question subject cannot be illegal or NSFW material.

Your question subject cannot be illegal or NSFW material. You will be warned first, banned second.



Rule 3- Do not seek mental, medical and professional help here.

Do not seek mental, medical and professional help here. Breaking this rule will not get you or your post removed, but it will put you at risk, and possibly in danger.



Rule 4- No self promotion or upvote-farming of any kind.

That's it.



Rule 5- No baiting or sealioning or promoting an agenda.

Questions which, instead of being of an innocuous nature, are specifically intended (based on reports and in the opinion of our crack moderation team) to bait users into ideological wars on charged political topics will be removed and the authors warned - or banned - depending on severity.



Rule 6- Regarding META posts and joke questions.

Provided it is about the community itself, you may post non-question posts using the [META] tag on your post title.

On fridays, you are allowed to post meme and troll questions, on the condition that it's in text format only, and conforms with our other rules. These posts MUST include the [NSQ Friday] tag in their title.

If you post a serious question on friday and are looking only for legitimate answers, then please include the [Serious] tag on your post. Irrelevant replies will then be removed by moderators.



Rule 7- You can't intentionally annoy, mock, or harass other members.

If you intentionally annoy, mock, harass, or discriminate against any individual member, you will be removed.

Likewise, if you are a member, sympathiser or a resemblant of a movement that is known to largely hate, mock, discriminate against, and/or want to take lives of a group of people, and you were provably vocal about your hate, then you will be banned on sight.



Rule 8- All comments should try to stay relevant to their parent content.



Rule 9- Reposts from other platforms are not allowed.

Let everyone have their own content.



Rule 10- Majority of bots aren't allowed to participate here.



Credits

Our breathtaking icon was bestowed upon us by @Cevilia!

The greatest banner of all time: by @TheOneWithTheHair!

founded 1 year ago
MODERATORS