> The author history was harder to understand. An earlier package file listed Pierre-Louis Favreau, Jean-Pierre Lo, and Nicolas Dehandschoewercker. The version that replaced it removed all three names and substituted another author. The only change to the files was the author list. GitHub’s activity record shows that the replacement happened through a force push in August, before our investigation this September.
Wow, this looks pretty damning. I can't imagine Google seeing this as worth the risks. Is an innocent explanation possible here?
If there is an innocent explanation, I'd love to hear it, because it kind of reads like the force push was done to move the commit with the attribution change out of the public eye so it wasnt clear what they had done.
Given the replacement author and email seem like a random person rather than an employee, I wonder if whomever did this thought they had found the "real" author and that somehow the others were incorrect? It's confusing, I don't know.
For over a decade at least, Google has been a hostile entity hoarding trillion dollar's worth of wealth at the expense of everyone else's freedom and well-being. We don't need to embolden them any further by hunting for excuses.
This is normal (specific to pyproject.toml overwriting authors). I am not sure about pyproject.toml conventions but I would have done the same. This is the equivalent of telling you who the maintainers of the project are.
Usually what you see in the code is the retention of Copyright statements on source code and LICENSE with some reference on README.
That's not "trying to cover it up", that's a link to them adding credits that were missing, which is the main corrective action to get into compliance with the source project's license.
Hahaha adding credit… after that credit had already existed, then been removed and the history of its removal spirited away?
Yeah, they’re totally being forthright. /s
For the amount of money Google’s engineers are paid, I expect you guys to be able to tell your manager when you’ve used OSS code, since you already have a proven worth to the software engineering ecosystem as a whole… that’s why you’re a googler. If you’re too afraid to make sure attribution is properly documented, perhaps due to your only engineering knowledge centering around basic understanding of VCSs, then perhaps you’re not yet ready for the high-stakes lifestyle of a Fortune 50 Engineer.
Well I am shocked, who would have thought, an advertising company who prides themselves on not being evil, used code that wasn't credited.
I mean, if that's the case, we better start a revolution.
Regardless of whether or not Google is liable, what would be interesting to me is how this happened, the role(s) at Google that were involved, when each knew of the problem, and what each did.
20 comments
[ 11.9 ms ] story [ 506 ms ] threadWow, this looks pretty damning. I can't imagine Google seeing this as worth the risks. Is an innocent explanation possible here?
This is normal (specific to pyproject.toml overwriting authors). I am not sure about pyproject.toml conventions but I would have done the same. This is the equivalent of telling you who the maintainers of the project are.
Usually what you see in the code is the retention of Copyright statements on source code and LICENSE with some reference on README.
They're trying to cover it up now
Yeah, they’re totally being forthright. /s
For the amount of money Google’s engineers are paid, I expect you guys to be able to tell your manager when you’ve used OSS code, since you already have a proven worth to the software engineering ecosystem as a whole… that’s why you’re a googler. If you’re too afraid to make sure attribution is properly documented, perhaps due to your only engineering knowledge centering around basic understanding of VCSs, then perhaps you’re not yet ready for the high-stakes lifestyle of a Fortune 50 Engineer.
I was going to comment on the title's perpetuation of big IPs stealing/theft meme but it turns out that TFA did not use those words.
https://github.com/google/artemis/compare/14e02c4c27bc5b3c0d...
Seems legitCredit should be assigned tho.