Elektrine lite

← Feed

@mitchellh@hachyderm.io

Post #2493881

2026-02-07 21:43 UTC

AI eliminated the natural barrier to entry that let OSS projects trust by default. People told me to do something rather than just complain. So I did. Introducing Vouch: explicit trust management for open source. Trusted people vouch for others. https://github.com/mitchellh/vouch The idea is simple: Unvouched users can't contribute to your projects. Very bad users can be explicitly "denounced", effectively blocked. Users are vouched or denounced by contributors via GitHub issue or discussion comments or via the CLI. Integration into GitHub is as simple as adopting the published GitHub actions. Done. Additionally, the system itself is generic to forges and not tied to GitHub in any way. Who and how someone is vouched or denounced is up to the project. I'm not the value police for the world. Decide for yourself what works for your project and your community. All of the data is stored in a single flat text file in your own repository that can be easily parsed by standard POSIX tools or mainstream languages with zero dependencies. My hope is that eventually projects can form a web of trust so that projects with shared values can share their vouch lists with each other (automatically) so vouching or denouncing a person in one project has ripple effects through to other projects. The idea is based on the already successful system used by @badlogicgames in Pi. Thank you Mario. Ghostty will be integrating this imminently.

Replies (22)

  • @darkuncle@infosec.exchange 2026-02-07 21:45

    @mitchellh@hachyderm.io reminds me of early PGP Web of Trust days and keysigning parties

    Open ##2970268

  • @mitchellh@hachyderm.io sounds like the system for arxiv

    Open ##2970278

  • @rogueren@vt.social 2026-02-07 21:56

    @mitchellh@hachyderm.io my only concern is new and upcoming devs won't have anyone to vouch for them, thus cutting them out of open source entirely. Think there's a way to fix that?

    Open ##2970279

  • @johnefrancis@cosocial.ca 2026-02-07 22:05

    @mitchellh@hachyderm.io I like the explicit denouncement. Unclean! Unclean! Heretic! 👉

    Open ##2970281

  • @tobyjaffey@mastodon.me.uk 2026-02-07 22:12

    @mitchellh@hachyderm.io Reminds me of Advogato from c.1999, kind-of peer reviewed slashdot built on an attack-resistant trust metric. It built a huge trust network of people involved with opensource/freesoftware but ultimately failed, I think, because it only proved identity, rather than reputation. I like the generality you're suggesting about how to apply "trust" to a project.

    Open ##2970282

  • @sobek@social.linux.pizza 2026-02-07 22:19

    @mitchellh@hachyderm.io Mario is actually on mastodon. @badlogic@mastodon.gamedev.place

    Open ##2970285

  • @mitchellh@hachyderm.io @kevin@mastodon.km6g.us Does this do anything to help with the next/current Jia Tan (xz)?

    Open ##2970286

  • @Sassinake@mastodon.social 2026-02-08 01:30

    @mitchellh@hachyderm.io make sure to re-vet contributors to defend against liars and people later corrupted by 'interests'. Open source is still People.

    Open ##2970289

  • @qasimstatic@hachyderm.io 2026-02-08 02:16

    @mitchellh@hachyderm.io sending that to all my servers rn.

    Open ##2970290

  • @beemdvp@techhub.social 2026-02-08 02:21

    @mitchellh@hachyderm.io great idea, thanks for creating!

    Open ##2970291

  • @bpacia@androiddev.social 2026-02-08 02:29

    @mitchellh@hachyderm.io thanks for building this! i like the idea B) pessimist take: assuming this gains momentum (which i hope it does), i wonder how long it'll take until some more radical folks (on both sides of the political spectrum) will en masse block people on "the other side" from contributing to their projects. and then we'll have many blocklists of open-source developers. kind of like we have blocklists in adblock.

    Open ##2970292

  • @csolisr@hub.azkware.net 2026-02-08 03:01

    As a new contributor to most projects, what is the best way of gaining people's trust if I'm not allowed to submit code anywhere to do so?

    Open ##2970293

  • @mitchellh@hachyderm.io Hey @cstross@wandering.shop, look, accelerando's trust network is here!

    Open ##2970298

  • @LangerJan@chaos.social 2026-02-08 06:33

    @mitchellh@hachyderm.io That’s social scoring with extra steps.

    Open ##2970299

  • @wiersdorf@fosstodon.org 2026-02-08 07:05

    @mitchellh@hachyderm.io I don't know if you've read Neal Stephenson's Anathem—this reminds me of the reputation system the ITA (technologists in the society) have to access certain parts of their version of the internet.

    Open ##2970300

  • @mraiur@mamutut.space 2026-02-08 09:49

    @mitchellh@hachyderm.io well you can contact a trusted contributor and some tests can be done. I really like it, otherwise #slopocalipse will kill everything interesting.

    Open ##2970301

  • @mitchellh@hachyderm.io @RichiH@chaos.social but then we can't call it Open Source anymore, because it's not open to everybody by default anymore. So, how about we call it Vouch Source instead? :blobcatthinksmart:

    Open ##2970302

  • @mitchellh@hachyderm.io thank you!

    Open ##2970304

  • @jhaas@a2mi.social 2026-02-08 14:51

    @mitchellh@hachyderm.io I was waiting for some form of this to pop up. You're first on my radar. Things like this will eventually need to be something other than boolean. The clumsy n00b that is instantly denounced has no way to crawl out of that hole. "Karma" systems where one earns good credit for work also push these things to something other than boolean. This will always be able to be gamed, but it's at least a helpful speedbump. Thanks for the work.

    Open ##2970305

  • @uriel@keinpfusch.net 2026-02-08 17:01

    @mitchellh@hachyderm.io sure. a new sheriff. dictators, benevolent or not, weren't sufficient. Now we have black shirts, too, to decide if you are vouched enough. OSS is dead, man. And the reason is dead, is that it repels corporation logic, to embrace totalitarism logic.

    Open ##2970308

  • @Photo55@mastodon.social 2026-02-09 11:39

    @mitchellh@hachyderm.io In retrospect the PGP web of trust would now be useful, had we adopted it more enthusiastically back then. Perhaps this will be another node in the formation of such a web.

    Open ##2970313

  • @tris@chaos.social 2026-02-09 15:45

    @mitchellh@hachyderm.io Reminded of key signing party in @archlinux@fosstodon.org and @debian ;P

    Open ##2970314