# Give Up GitHub - Software Freedom Conservancy

**URL:** https://discuss.privacyguides.net/t/give-up-github-software-freedom-conservancy/21473
**Category:** General
**Tags:** article
**Created:** 2024-10-13T11:18:11Z
**Posts:** 35

## Post 1 by @anon48875053 — 2024-10-13T11:18:11Z

> **[Give Up GitHub - Software Freedom Conservancy](https://sfconservancy.org/GiveUpGitHub/)**
>
> The Software Freedom Conservancy provides a non-profit home and services to Free, Libre and Open Source Software (FLOSS) projects.

---

## Post 2 by @ph00lt0 — 2024-10-13T12:01:37Z

the alternatives are simply put quite bad imho.

Codeberg has a lot of downtime and seems to not really care about QoS and continuity.

Gitlab has their own controversies and a relatively bad security reputation.

The other alternatives are immature when it comes to UX.

Let alone that I would want to use GenAI as a developer, and gh copilot is really good. You would be wasting your time without it really and just be replaced by companies and people who do.

There can be set a lot about ethics and making the right settings etc and I think that that is relevant, but simply the: ‘avoid using it’ is no longer going to cut it.

---

## Post 3 by @anon41112412 — 2024-10-13T12:03:39Z

Not everything owned by a big tech is worth leaving. What will a developer do on a platform where there is no other developer to collaborate? Github have millions of developers that you can connect and collaborate with, who’s on codeberg or gitlab? Just a niche developers who care too much about foss? Like being on extreme side?

The organisation (SFC) you mentioned have accounts on X, Facebook and Youtube. I wonder what they are doing on those proprietary platforms. They can just stay on fediverse, as it’s open. Well because there’s no one there lol. Same is the case with github and all these other platforms like codeberg and gitlab.

I love open source, and all but with all due respect, these alternatives are just bad and not upto the mark. Not Everything that is FOSS is better.

---

## Post 4 by @anon41112412 — 2024-10-13T12:06:48Z

Exactly my sentiments!

---

## Post 5 by @anon48875053 — 2024-10-13T14:40:50Z

> [@anon41112412](#):
>
> Github have millions of developers that you can connect and collaborate with, who’s on codeberg or gitlab? Just a niche developers who care too much about foss? Like being on extreme side?

Tor Project, FUTO, F-Droid, GNOME, etc. Wouldn’t call these projects or their developers “niche.”

---

## Post 6 by @anon41112412 — 2024-10-13T15:10:00Z

How many internet users use Tor project, F-droid or Gnome? Probably 3% ? Does average user use it? Does average user care for this? Nope. These are ofcourse “niche” in vast digital world.

---

## Post 7 by @anon48875053 — 2024-10-13T15:12:48Z

> [@anon41112412](#):
>
> Does average user use it? Does average user care for this? Nope.

Is the average user properly educated when it comes to digital security, privacy, and freedom? No.

Do people who are properly educated on these things use something that Tor Project, GNOME, or F-Droid provide? Very likely.

---

## Post 8 by @bigdzi — 2024-10-13T16:45:29Z

@incrementor well, thats main problem withn GitHub: its so popular that most of well-known projects are there and some 90% of daily dev-qork happens there.

CB, SH are all too inmature to even be considered ready for serious work.  
GL is all another story that I will not be explaining here for obvious reasons.

> [@incrementor](#):
>
> How many internet users use Tor project

Im using Tor almost everyday.

---

## Post 9 by @ph00lt0 — 2024-10-13T16:48:16Z

they are far more niche than you think.

---

## Post 10 by @anon41112412 — 2024-10-14T10:44:28Z

Then educate millions of developers on github to leave github then. I guess most developers are tech savvy and do know about alternatives like gitlab, bitbucket, codeberg etc.

Are they well educated? Most developers are: Yes. Do they care of alternatives like these ? No; cuz there’s no need when a better product exists.

Point is that these alternatives are just extra hassle and alternatives for most people no matter how good their intentions are.

You can recommend Protonmail as an alternative to Gmail as proton is now popular, it’s private and best part is the proton users can interact with Gmail users.

I think privacy guides should insure that only those alternatives should be recommended that are on par or very equal to the mainstream option in any way.

Also Tor project, F-droid isn’t used by everyone (regularly) even in the niche privacy community.

---

## Post 11 by @anon41112412 — 2024-10-14T10:46:34Z

Yes, these options are not as viable as we think to many mainstream options. It’s not that they aren’t technically capable, it’s just all other factors (popularity included), makes these options unusable for vast majority of developers.

> Im using Tor almost everyday.

More power to you brother. It’s awesome that you are able to use tor regularly. I would encourage more users to use Tor if their threat model allows for it.

---

## Post 14 by @hakavlad — 2024-10-14T11:25:11Z

First of all, GitHub is a social network. Projects not hosted on GitHub automatically receive less attention. Interacting with most developers who choose GitHub will be difficult.

---

## Post 15 by @hakavlad — 2024-10-14T11:33:09Z

> [@anon41112412](#):
>
> proton users can interact with Gmail users

But proton users cannot interact with [mail.ru](http://mail.ru) users: [mail.ru](http://mail.ru) ignores letter from proton (gmail has no such problem).

---

## Post 16 by @anon41112412 — 2024-10-14T11:36:39Z

Exactly, and this guy @anon48875053 , shared an article and guess what, those people (writing articles) have an account on Facebook and Youtube. I wonder why that is. These people never understand that something may be more private but is useless (better word unviable), when considering for masses, when that service is not comparable with mainstream options.

---

## Post 17 by @anon41112412 — 2024-10-14T11:38:54Z

> But proton users cannot interact with [mail.ru](http://mail.ru/) users: [mail.ru](http://mail.ru/) ignores letter from proton (gmail has no such problem).

I didn’t know about that. Thanks for educating me. This might be probably due to them not complying with the russian government. In such a case, a throwaway gmail account with PGP encryption using an email client would be way better. Still Email was/is never a secure way of communicating. Signal (hope this works in russia) are better.

But yeah thanks for telling me that it doesn’t work with [mail.ru](http://mail.ru).

---

## Post 18 by @hakavlad — 2024-10-14T11:39:49Z

> [@anon41112412](#):
>
> hope this works in russia

By default - no.

---

## Post 19 by @anon41112412 — 2024-10-14T11:41:15Z

By censorship circumvention mode? I hope or with an VPN. There are other solutions like session, simplex chat etc as well.

---

## Post 20 by @hakavlad — 2024-10-14T11:42:57Z

> [@anon41112412](#):
>
> By censorship circumvention mode?

This stopped working. Full functionality - only with VPN.

---

## Post 21 by @hakavlad — 2024-10-14T11:43:29Z

> [@anon41112412](#):
>
> session, simplex

also was banned.

---

## Post 22 by @overdrawn98901 — 2024-10-14T17:02:22Z

As end users, how does where the code being hosted affect our security and privacy? I understand the sentiment as an author of code not wanting it to be ingested by AI without compensation, but I’m not sure how this has huge impact for us. Other than screw M$.

---

## Post 23 by @ph00lt0 — 2024-10-14T17:45:46Z

That seems like an advantage to me. I defintely also drop all messages coming from such mail providers.

---

## Post 25 by @gregandcin — 2024-10-14T18:17:03Z

I use Codeberg for some projects. The community around Forjeo is doing really good on both improving the platform’s current features and adding new ones, though I think GitHub’s PR system is still better when it comes to reviews.

I will say, I find tools like GH Codepilot, Codeium, etc. to be very limited in functionality. I find myself either writing code faster before the autocompletes pop up or I just want it to generate boilerplate that I end up rewriting half the time anyways because I know parts of it are wrong.

I don’t want to use GitHub, but everyone and their metaphorical mother uses it, so if I want to contribute to a project or _download user facing binaries_ (Please make a website with a direct download link for non-Linux users I pray to the FOSS devs) I am stuck using it.

---

## Post 26 by @anon48875053 — 2024-10-14T18:22:38Z

> [@gregandcin](#):
>
> I don’t want to use GitHub, but everyone and their metaphorical mother uses it, so if I want to contribute to a project or _download user facing binaries_ (Please make a website with a direct download link for non-Linux users I pray to the FOSS devs) I am stuck using it.

And this is a massive issue, if you’re someone new and want to contribute, then you’re forced to use GitHub no matter if you want it or not.

---

## Post 27 by @overdrawn98901 — 2024-10-14T21:35:55Z

> [@Anon47486929](#):
>
> GitHub could replace app binaries, could change app signatures presented in Readme used for verification, could compromise the code used, could deliver malicious payloads, could change GitHub actions maliciously, etc.

Do you really think GitHub would replace binaries in releases? Like if they deliver such an attack, it would case a mass exodus from their platform, why would they do that? This just seems far fetched.

A meteor can fall from the sky and kill me when I walk out my door, but I don’t really plan my days around that.

---

## Post 29 by @overdrawn98901 — 2024-10-15T01:46:38Z

I’m sorry, I didn’t mean to offended you. It just seems that if these are the things of concern, then I’d suspect moving hosting providers just shift liability from GitHub to some other party. Maybe some general gains for specific jurisdictions, and maybe less telemetry from others.

---

## Post 30 by @hakavlad — 2024-10-15T11:14:17Z

> [@Anon47486929](#):
>
> could replace app binaries, could change app signatures presented in Readme used for verification, could compromise the code used, could deliver malicious payloads

Codeberg cannot do this?

---

## Post 31 by @hakavlad — 2024-10-15T11:32:19Z

> [@Anon47486929](#):
>
> could deliver malicious payloads

If you are a target of the state, they can do it through any other site. Refusing GitHub will not help here.

---

## Post 33 by @hakavlad — 2024-10-15T12:28:32Z

> [@Anon47486929](#):
>
> Can you point where I implied that?

This implied by the OP: If you criticize GitHub, you should expect that its alternatives do not have the undesirable properties.

---

## Post 35 by @anon41112412 — 2024-10-15T13:32:33Z

Well, this discussion is seriously going in a weird place. I think one should use the software that fits best for their needs be it github or codeberg. That’s all I wanna say and I’m out.
