-
step in and help review a few PRs
-
help the project triage/reproduce bugs
-
if code in the PR looks complicated or is hard to understand, ask for an explanation
-
express your gratitude to the maintainers
-
make your company sponsor projects they depend on
https://mastodon.social/@bagder/112194895793007918
Daniel is the creator of cURL : https://daniel.haxx.se/blog/2021/03/30/howto-backdoor-curl/
I personally think you should move the fourth bullet (express your gratitude to the maintainers) to the first position in your list. But a great, simple list none-the-less.
Make your company sponsor projects they depend on
Definitely worth trying to do, but making my employer do anything isn’t likely!
is “step in and help review a few PRs” really that helpful? like… oh great, now this one person that i don’t trust is telling me that the other person that i don’t trust made some code that i should merge
How does one become trusted? If they regularly review and provide feedback that you agree with it can really speed up the process, even if you’re still double checking.
Exactly. At first it means nothing. Over time they can begin to trust you.
@twei Well of course as an outsider you can’t call the “All clear”. But you can raise concerns and ask questions about binary files, obfuscated parts, you can checkout the branch and run it, … if you find something, say it, it’s easy to verify your claim. Saying “I didn’t find any problem” is not so helpful, as that is also not so easy to verify, and doesn’t prove the absence of problems. But pointing to a problem proves the existence of problems.
I’d love to help out on Open Source projects but have often just not really known where to start. I guess the challenge is to become a experienced enough user of a specific project first.
That one is maybe the easiest to do :
express your gratitude to the maintainers
Besides that there is the possibility to donate. And since the xz backdoor incident I would say it makes sense to keep an eye on end users trying to bully or overload developers. If I remember well I read that the developer of uMatrix stopped with that project because of annoying users filing bug reports with unfriendly and demanding discourse, which can be exhausting for a sole developer.
Yeah agree this is the easiest… I would like to help carry the load somehow. Perhaps filtering /dealing with comments could be a start.
If the project has a community forum or chat, be active and help answer questions. That takes a lot of pressure off the dev team. I did that for 4-5 years on the Handbrake project before family commitments ate up my free time.
I myself am a maintainer/main developer of a project and the people that help out in the group chat are a god sent. Takes a lot of pressure out of my day.
Cool. Good suggestion.
Sometimes an open source project is too niche for anyone to take notice. I myself am developing a networking reliability layer ported from C to modern C++ and I’ve yet to see a person use it except yours truly. Sad truth.
😐 Care to share the project web link ?
👍
Your project shows 6 stars and 1 watching. 6 open and 6 closed issues. Not bad.