https://github.com/dotnet-foundation/Home/discussions/39 Skip to content Sign up * Why GitHub? Features - + Mobile - + Actions - + Codespaces - + Packages - + Security - + Code review - + Issues - + Integrations - + GitHub Sponsors - + Customer stories- * Team * Enterprise * Explore + Explore GitHub - Learn and contribute + Topics - + Collections - + Trending - + Learning Lab - + Open source guides - Connect with others + The ReadME Project - + Events - + Community forum - + GitHub Education - + GitHub Stars program - * Marketplace * Pricing Plans - + Compare plans - + Contact Sales - + Education - [ ] * # In this repository All GitHub | Jump to | * No suggested jump to results * # In this repository All GitHub | Jump to | * # In this organization All GitHub | Jump to | * # In this repository All GitHub | Jump to | Sign in Sign up {{ message }} dotnet-foundation / Home Public * Notifications * Star 15 * Fork 0 * Code * Pull requests 0 * Discussions * Actions * Security * Insights More * Code * Pull requests * Discussions * Actions * Security * Insights I'm sorry #39 clairernovotny announced in Announcements I'm sorry #39 @clairernovotny clairernovotny Oct 6, 2021 * 2 comments * 17 replies Return to top edited @clairernovotny clairernovotny Oct 6, 2021 Maintainer I'm Claire Novotny, Executive Director for the .NET Foundation, and I made a mistake this last week when I made a PR and merged it to a project without discussion. While I'd been involved in this project as a founder and maintainer for many years - long before the foundation - I was not active recently and I overstepped. I failed to consider how the interaction would look through the lens of my current role. We often have many hats, like community member, early project contributor, foundation director, but that's a subtle distinction and doesn't change the fact this was a mistake. I sincerely apologize. Separate from this personal misstep, I want to note that the .NET Foundation exists to provide services and support to project maintainers and to encourage and enable the use of open source software by .NET developers. That's similar to the goals and approaches of other open source foundations. In the last week, there have been multiple cases where project maintainers were surprised and unhappy about the governance of .NET Foundation projects. In this post, I'll describe what happened and why. I'll start with the ReactiveUI project. I've been a ReactiveUI maintainer for many years, pre-dating my role at the .NET Foundation and with Microsoft. I've been personally focused on reproducible builds and maintain a project that enables that scenario. I created a PR in ReactiveUI's Splat project and merged it with my ReactiveUI maintainer permission. I shouldn't have merged this PR without explicit sign-off from the other maintainers, because it's disrespectful and rude not to follow the project's process. Also, as the executive director for the .NET Foundation I should have been able to manage the conversation and the disagreement with the other maintainers a lot better. I'm sorry. It's warranted for the ReactiveUI maintainers to review my maintainer permission. I'm happy with the outcome they decide. I love the ReactiveUI project and I only want what is best for it. This incident with the ReactiveUI project caused maintainers of .NET Foundation projects to discover that they are part of the .NET Foundation GitHub Enterprise account. The .NET Foundation uses GitHub Enterprise because it offers central billing and resource allotment (like GitHub Actions and Codespaces minutes). It sounds scary to "Move to GitHub enterprise" but it's done only for centralized billing and 2FA support. It puts projects on their own instance and gives them more control over their projects. That said, the fact that multiple people were surprised and upset means that the use of GitHub Enterprise as a tool to support projects was poorly communicated. We will post a document this week that explains that. The Foundation exists to make administration easier, not scarier. It is also clear that the .NET Foundation project governance model is not well understood. Project maintainers sign an agreement that either assigns or contributes their project to the .NET Foundation. That's the point at which project ownership changes. We'll post another document on that this week as well. There is a pattern that needs to be resolved. Projects might not fully understand what joining the .NET Foundation means. We share a checklist with project maintainers on project changes they accept as part of becoming part of the .NET Foundation. That's obviously not sufficient. We will post a new document that describes what you can expect when your project joins the .NET Foundation. This will include changes (observable or legal) and new benefits. It will also include changes that could occur later. We recently had .NET Foundation board elections. A new board started this week and has been meeting daily. These .NET Foundation project governance topics have become the top focus of the board. The board will hold a TMA (tell me anything) open call next week. The new board wants to hear what you have to say and to make changes to make the .NET Foundation a better home for project maintainers. To recap, I'm sorry about the PR I made and merged on the ReactiveUI Splat repo. That was a mistake. I joined the .NET Foundation as the Executive Director to help maintainers. I'm a maintainer. I know what it's like. On behalf of myself as the Executive Director, past and current boards, I'm sorry that we've created an environment where maintainers are surprised by their relationship with the .NET Foundation. It will be my and the new board's number one priority to fix that. Thank you for being part of the .NET Foundation. I ask for patience as we publish new documents, hold a listening tour/town hall/ something TMA, and work to help maintainers more. Please use this forum for future communications and "watch" the Announcements repo to be notified when we post the documents. 19 47 17 8 [?] 42 3 Replies 2 comments * 17 replies Oldest Newest Top @Aaronontheweb Aaronontheweb Oct 6, 2021 While I appreciate that this must have been hard to write, this is a total non-apology and just about meets the incredibly low expectations I and others had for the .NET Foundation's public statement. Let's start with this: The .NET Foundation uses GitHub Enterprise because it offers central billing and resource allotment (like GitHub Actions and Codespaces minutes). It sounds scary to "Move to GitHub enterprise" but it's done only for centralized billing and 2FA support. Many of the projects that were moved into the .NET Foundation Github Enterprise account, such as @robmen 's WIX project, cost exactly $0 in Github consumption each month. There's no reason "central billing" would be an issue in that case. How many other projects that were moved that don't actually consume anything from a billing perspective that were moved? Why did you not feel it necessary to explain the reasoning behind this move in the first place? It would have been a 5 minute bulk email to the project leaders' mailing list that would have probably been met with few objections. Project maintainers sign an agreement that either assigns or contributes their project to the .NET Foundation. That's the point at which project ownership changes. We'll post another document on that this week as well. Absolutely not what we were told by @jongalloway, Martin Woodward, et al when we joined. In fact, our Contribution License Agreement we signed explicitly refutes this: image Myself and my fellow contributors own and manage the project, not the .NET Foundation, as is plainly stated in our agreement. On what basis can you make this claim? There is a pattern that needs to be resolved. Projects might not fully understand what joining the .NET Foundation means. We share a checklist with project maintainers on project changes they accept as part of becoming part of the .NET Foundation. That's obviously not sufficient. We will post a new document that describes what you can expect when your project joins the .NET Foundation. This will include changes (observable or legal) and new benefits. It will also include changes that could occur later. I think you have this exactly backwards - the expectation that was set with us that we were to be left alone to our own devices, that the .NET Foundation would support our efforts to build a bigger and better .NET, but that ultimately we were to be in charge of how we did that. It seems to me that your vision for how the .NET Foundation will execute that is what's changed - a top-down, command and control approach rather than a collaborative approach with us and our projects. I have no confidence in your leadership or this foundation's ability to work with its members and projects. 18 21 1 [?] 7 5 16 replies Show 11 previous replies @Aaronontheweb Aaronontheweb Oct 6, 2021 @gortok that's covered by: d. Other Rights Reserved. Each party reserves all rights not expressly granted in this Agreement. No additional licenses or rights whatsoever (including, without limitation, any implied licenses) are granted by implication, exhaustion, estoppel or otherwise @dustinmoris dustinmoris Oct 6, 2021 There is a lot of nuance in all of the jargon in these contracts. Licenses, copyrights, ownership, etc., I would advise each project "owner" to ask yourself and the .NET Foundation the following questions: * If a company was to approach you tomorrow, let's say someone like Infragistics or JetBrains (just making it up here), and they were to offer you X $ to buy your work off you in order to advance their own product offerings, would you be in the legal position to a) accept and authorize such a transaction and b) be the legal entity who would receive the renumeration? * Can you make autonomous decisions in regards to the fate of your project after joining the .NET Foundation? For example, can you singlehandedly revoke access to the DNF, leave the DNF if you wish, join another foundation or exercise other control over your project which clearly demonstrate legal ownership? If any of these two questions cannot be answered with a clear YES then regardless of what jargon is being used, you have essentially lost ownership of your project in the sense that most people understand it. If this is not what you thought was the case then either you have not asked the right questions when you signed up to the DNF or you have been grossly mislead. My advice for the future is, if you cannot afford your own lawyer then ask concrete questions like the ones above to the lawyers or representatives of the other side and record their answers. You can also request that extra documents, with such questions and answers can be attached as an addendum to the legal contract, so that in case of a dispute there is extra information which can be used by other lawyers to interpret the text and resolve any issues. 4 @dustinmoris edited dustinmoris Oct 6, 2021 One more thing from me... The .NET Foundation, was just like everything else that comes out of Microsoft massively advertised by DevDiv machinery to the .NET OSS community. The fact that they ask project owners/maintainers to sign a legal complex document like the one pictured by @Aaronontheweb and nobody has gone through the effort of talking project maintainers through each paragraph of it before asking them to sign shows exactly how much Microsoft really cares about you. In my opinion that should have been the least that the .NET Foundation should have done before they groomed many OSS kids into signing projects away. @barnson barnson Oct 6, 2021 Whether the Foundation had the contractual authority to do any of the things they did isn't a very interesting question -- most maintainers are asking what it ought to have done, instead of whether they "could." @to11mtm edited to11mtm Oct 6, 2021 (Edited to not have Aaron's full quoted reply) @Aaronontheweb Soooo I was looking into this because I was curious for broader context... This change to the website documentation is of note. I want to assume good faith but this feels just a little 'submarined' to those who may have already been assigned to the Contributor model. Were projects notified of this change in legal verbiage? @dansiegel dansiegel Oct 6, 2021 @clairernovotny I have known you for years, and as you know I have a tremendous respect for you and all that you have done for the .NET Community, for Prism and for me personally as an Open Source maintainer. When you stepped into the role as Executive Director of the .NET Foundation I had high hopes for what the Foundation could do under your leadership. It's with a heavy heart that I find myself having to write this. This "I'm Sorry" letter is very much as @Aaronontheweb described it, a total Non-Apology. This reads more as a damage control, PR stunt to get people to stop blasting the Foundation publicly. The one thing that this does not read as is a heartfelt apology. Following the incident that you referenced on the Splat repository you found that I soon after blasted your behavior there. I then spent most of the last week traveling. To my surprise in all of that time you could not find the time to respond. You did not need a board of directors to tell you that an apology was owed specifically to the maintainers of that repo and that org, or that such an apology should have been available for all to see. Nor did you need someone to help draft something that should have been very easy for you do a week ago. You and I both know that you know better. Instead of doing what was right, you waited. You allowed the community to erupt into an uproar, and one by one maintainers of member projects began voicing their frustrations with the Foundation. This caused many maintainers to discover actions that were taken behind their back and in at least one case in direct violation of conversations that had been had. The .NET Foundation uses GitHub Enterprise because it offers central billing and resource allotment (like GitHub Actions and Codespaces minutes). It sounds scary to "Move to GitHub enterprise" but it's done only for centralized billing and 2FA support. Most member projects had NO GitHub bill. In other words what exactly are you spending $7,510 / year to support? Also for reference my non-paying orgs support 2FA just fine thanks. Next Steps If the new Board is serious about rectifying the situation at hand here I believe that several actions need to be taken within the next 24 hours. 1. The Foundation needs a new leader that has not eroded the trust of the member projects. While I am sure that we may not have a new person for the role in 24 hours, @clairernovotny I am asking you to please tender your resignation as Executive Director. 2. The Foundation needs to make it clear that any member project that wants to be removed from the Foundation's Enterprise account can and will be removed immediately without question or interference. 3. The Foundation needs to make it clear that all projects who wish to leave the foundation following this incident will be allowed to without any interference or burdens of requiring members to hire legal representation to bring anything to court. This would include the restoration of their GitHub organization & NuGet packages. If the Board would like to take a step above and beyond to show that they are serious about supporting Community based Open Source, then you might consider asking how you can help those members that wish to leave. Could you help them to set up their own Code Signing server? Could you help them to draft their own CLA and setup their own CLA Bot for PR's? Such actions would help to show some good will and restore some degree of faith in the Foundation. Moving Forward As we move past this as a community and move beyond the next 24 hours, I believe that it will be important for the Board to understand that it is really non-negotiable that when the Board makes decisions affecting projects, the Board needs to have a dialog with the maintainers of those projects. What's more is that the Board needs to recognize that sometimes they are wrong. This is where some organizational restructuring is really needed to allow member projects to block bad decisions by the board. Think of it as a check and balance. Something that this so-called apology misses entirely is that the Foundation exists for the benefit of the Member Projects, and not the other way around. IMO it would be a very good idea to start thinking about what would a Maintainers Bill of Rights look like? We cannot continue a tradition of the Board meeting, making some decisions that affect member projects without even considering whether or not the member projects agree that it is a good direction. The Foundation has dealt serious blows to the health of the .NET Community specifically in advocating Sustainable Open Source. This is something that the Board needs to be a Champion of. Before Commenting - Please Read As this is a public forum here I do want to be clear. For those wishing to follow up with bashing comments, please don't. While there have been some actions that require serious conversations, we all owe @clairernovotny a debt of gratitude for all that she has done for us over the years. While I may believe that it is in the Foundation's best interest to appoint a new Executive Director, I do believe wholeheartedly that as we move past this @clairernovotny will continue providing value for the .NET Community both as a Microsoft Employee within the .NET Organization (outside of the Foundation) and at large as someone who like many of us just love to code! 13 3 [?] 10 1 reply @FiniteReality edited FiniteReality Oct 6, 2021 This is where some organizational restructuring is really needed to allow member projects to block bad decisions by the board. I completely agree - Until these recent events, I have had multiple projects I would like to have asked for support with via the .NET Foundation. However, I legitimately feel that I would be signing away almost all of my autonomy for the sole gain of having a dotnet/ my-cool-project URL under the current structure and/or leadership. Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment Insert Link Link Text [ ] URL [ ] Add Translated from {{ originalLanguageInEnglish }} Beta Was this translation helpful? Give Feedback Beta i beonyeogi doumi doesyeossnayo? pideubaeg jegong Beta Esta traducao foi util? De sua opiniao An error occurred while translating this comment. Try again 1 1 1 1 1 [?] 1 1 1 Category Announcements Labels None yet 11 participants @clairernovotny @hhariri @Aaronontheweb @gortok @brianlagunas @barnson @dansiegel @dustinmoris @svengeance @to11mtm @FiniteReality * (c) 2021 GitHub, Inc. * Terms * Privacy * Security * Status * Docs * Contact GitHub * Pricing * API * Training * Blog * About You can't perform that action at this time. You signed in with another tab or window. Reload to refresh your session. You signed out in another tab or window. Reload to refresh your session.