Why use Github, why not use Savannah, others, or self-host?

What you’re missing is that they’re not just making a choice for themselves, but for anyone who might want to post or comment on an issue, etc. As @Licaon_Kter put it a few comments back;

Developers can do that just as effectively on a code forge that doesn’t lock-in and DataFarm anyone using it, nor misuse their contributions to “train” MOLEs.

Because it doesn’t affect the user’s in any way.

F-Droid takes the source code and compiles it to make sure that nothing is added or removed from the source code and that this can be verified through reproducible builds.

… unless they want to participate in any way in the project that forges the software, instead of just being a disengaged consumer. Sometimes even then, they’re still affected. If that project uses GritHub, and hosts their homepage on GritHub Pages and their releases on their GritHub project, they may need to run proprietary JavaScript just to read about the app, and download a copy to install.

In most cases now, they have to run proprietary JavaScript from GritHub to browse or search Issues, or even just to read Issue discussion. If they want to open an Issue or comment on an existing one, or submit a merge request, this definitely requires running nonfree JS. For that they also need a GritHub account, which forces 2FA, and applies all sorts of Dark Patterns to try to DataFarm the person in the process of setting it up.

If the project uses other GritHub components like docs, roadmap, forum, kanban board or components post, they may need to run nonfree JS to browse any of those, and to login with an account to post in the community forum or add a tile to a kanban board (eg for feature requests).

In the discussion on GitLab about whether to re-add the Amethyst Nostr app to the F-Droid repo, @Licaon_Kter mentioned that an anti-feature flag was added to Amethyst simply because a person installing it was required to read the ToS hosted on GritHub before using it. In hindsight I agree with the logic of this. Although as I’ve written elsewhere, some of the anti-feature flags are a bit broad brush, and need to be split into a number of more nuanced and descriptive flags.

need a GritHub account, which forces 2FA

I just logged in to Github literally a minute ago and it does NOT require 2FA unless you set up that option in your settings. Just the usual ugly javascript.

I don’t know what do tell you. That doesn’t match my experience, either on desktop or mobile. Maybe it varies depending on factors like what browser you’re using, what country you’re in, what ISP provides your net connection?

Being forced to run nonfree JS to use a code forge ought to be enough to convince any developer who cares about software freedom to move their project elsewhere.

As a normal user without organisations and stuff, you might not.

Once you start doing more advanced stuff… you’ll be asked

That’s interesting. Explains why it’s never asked me. But I’m not a coder, don’t own any repos, only thing I do on GH is read and post issues and comments and occasionally search through source code looking for things that are easy to find.

As for Gitlab, I hate them because they will not display one single pixel to you unless you enable javascript. (See screenshot, that was trying only to view the F-droid page.) I disable JS entirely by default, only enable on sites I need to view which won’t work without it. (EDIT: I spelled f-droid “f-droid” which is why I got the 100% blank page. When I re-spelled it “fdroid” I got an ALMOST blank page with an F-droid icon and could not do anything else.)

Nice thing about Github is that if I just want to quickly check the homepage, issue or release page for a repo, I can do all of that without JS.

Bad thing about Github: Microsoft and minor UI annoyances.

I think that we have much bigger issues than that we should focus on.

What is the problem with 2FA?

You can do 2FA with fully Libre Apps like Aegis

This is a different issue, because they force you to open the website to run the software.

It also very easy to avoid by just keeping a local copy of the ToS

I get the concern, but as someone building an open-source project that will also be on F-Droid, the boring answer for me was the discovery.

GitHub is still where a lot of users, contributors, bug reporters, packagers, and security people already look. For newer or smaller open-source projects, being on GitHub can make the difference between getting feedback and being basically invisible.

That doesn’t mean GitHub is good or ideal. Codeberg, Forgejo, GitLab, Savannah, etc. are better aligned with free software values in many ways. But I’m not sure “developed on GitHub” should be an anti-feature for the app itself, especially if the app is still free software, builds on F-Droid, and doesn’t depend on GitHub at runtime.

I’d rather see projects encouraged to mirror elsewhere and keep contribution paths open than punish them for using the one place where people are most likely to find and help them.

This whole GirHub, GitLab, and other repository talk is really intriguing. Are there other repositiory sites? Maybe there’s some still likely lurking in the shadows of the Internet just waiting to be uncovered.

(Also, I finally added my own PFP, so it helps me stand out from the numerous users who lack a PFP)

That’s all I’ve ever done. Most of the projects I’ve contributed to using GH weren’t even developing code, but policy (eg NZGOAL-SE), reference works (Awesome Lists), stuff like that. The only projects I’ve had commit access to have been on other code forges.

As above, I’m normal, and I always get asked now. Maybe something to do with my use of NoScript and other anti-tracking filters? Although I have to turn on JS from 2 GritHub-owned domains if I want to see issue comments, commit dates on items in repos, and a whole bunch of the other stuff a visitor might use when trying to file issues, or evaluate the dev activity level of a codebase.

Could also be the OS/ browser combo I use, or some other variable.

This is the F-Droid forum. Helping people avoid having proprietary code forced on us, is why we’re here. When it’s run without the user’s knowledge or consent, by quietly loading it from 3rd-party domains and stuffing it into their browser, it’s even more dodgy and worth avoiding.

We can avoid it by using NoScript (or LibreJS), but that means we need to use Free Code forges for forging Free Code, which work properly without proprietary JS. Choosing to host your code on GritHub - or any proprietary platform - forces people to choose between being exposed to proprietary JS, OR, not contributing to your project. That’s an unkind choice to force on members of the software freedom community who just want to give back to a project we’re benefiting from.

The problem is not making 2FA an option. The problem is making it compulsory. There’s no good reason to require 2FA for accounts that are only used for filing issues and commenting on them, or occasionally for making a merge request that committers can accept or not. The way it’s done on GritHub is clearly using 2FA to extract more personal data from people using the platform.

GritHub forces you to open their website to run their software. If you’re not using it from a command line Git client, that is. Like most of the newbies or casual users trying to tip you off about bugs or make suggestions, and if this isn’t valuable to you (it isn’t always), why use a forge with a web interface at all? Just use a static Git host like Fossil.

OT but …

No, it’s not. Read the linked issue discussion.

I absolutely agree with the sentiment of this; the goal here is to make GritHub optional, not to punish anyone for their choice of compromises. Which will get less necessary if and when federation between independent forges makes collaborating across them as simple as doing it within one proprietary platform.

I’d reverse your suggestion though; hosting the project on a forge that fully respects software freedom, and mirroring it on GritHub for discovery (this is the same principle I hope we all apply to having a presence on FarceBook, etc).

Many. This list is heavily in need of an update, but;

https://wiki.p2pfoundation.net/List_of_Community-Hosted_Code_Forge_Instances