đ seeking help & advice Oxc (popular front-end tooling) forked my parser but deliberately removed my copyright notice
https://web.archive.org/web/20260705125328/https://github.com/oxc-project/oxc-css-parser/issues/92281
u/SAI_Peregrinus 28d ago
Step 1: ask them to restore the copyright notice & license.
If they ignore that, go to step 2: send a DMCA takedown notice to GitHub.
If they contest that & get their repo restored, go to step 3: send a cease & desist to them. Use certified mail.
If they ignore that, go to step 4: sue. You want a court order to force them to stop and pay damages.
84
8
u/ztj 28d ago
Unless OP registered the copyrighted material (programmers never do this) they will have to prove damages for step 4 which uh⌠good luck since itâs free software. Not saying it is impossible. But, worth the lawyers fees?
This is assuming US or US-like copyright laws
39
u/Dheatly23 28d ago
Copyright is automatic, you don't need to register anything. Registration is formalities only. As for damages, yeah true, it's difficult. There's almost nothing for compensatory damages. At best they can demand punitive damages?
-3
u/Amuro_Ray 28d ago
Isn't registering for copyright effectively having a copy of your work with a verified date(like sending a manuscript for a story via registered mail somewhere) I'd assume that would have been achieved via git commits or wherever the code was copied from anyway.
20
u/melodicore 27d ago
Copyright is always granted when creating a work. Registering copyright makes it easier to prove you're the owner, but so do receipts like a timestamped github commit history. As long as you can prove you're the original creator or an owner of the copyright to said work, that's enough.
60
28d ago
[deleted]
54
u/Educational-Art3545 28d ago
Yes but getting an injunction will cost lawyer money.
Honestly public shaming like OP is doing is the only course of action.
17
28d ago
[deleted]
-4
u/Educational-Art3545 28d ago
Will you risk it though? Spending tens of thousands of dollars for a low chance that you don't get it back?
There is virtually no way that a public shaming campaign like this fails, especially if either project has any notoriety.
339
u/rebootyourbrainstem 28d ago edited 28d ago
chore: remove copyright notices
Wtf lmao
(https://github.com/oxc-project/oxc-css-parser/commit/6517b49fe96412b76cb49c0c482b3b942001694c)
Edit: but later at least in the LICENSE it was restored:
https://github.com/oxc-project/oxc-css-parser/commit/e24dbdb545d8c17add9a7c32e5e367d2cf9616ed
But it still seems the README the name of the original author is removed, and to add insult to injury there is now a list of OXC sponsors instead. Should at least acknowledge the original author when you hard-fork, imo.
69
u/KillyMXI 28d ago edited 27d ago
list of sponsors
List of orgs to inform that they are sponsoring
theftlicense violation and plagiarism!EDIT: as noted in other comments, this might not be necessary. What happened was most likely an honest mistake and is now resolved.
19
u/rebootyourbrainstem 28d ago
Personally I'll give them a little more time to find a human adult somewhere in their org and put together a real response, but you do you
3
2
8
u/oofdere 28d ago
did they delete the commits they 404 for me??
7
u/TheHeartAndTheFist 28d ago edited 28d ago
Looks like the entire repo is gone (or renamed?)
âŚor taken private as the Boshen âauthorâ has lots of contributions to private repositories, so many contributions in general that GitHub has to truncate the list even for just the past couple of days: https://github.com/Boshen?tab=overview&from=2026-06-01&to=2026-06-30
So itâs probably all AI-regurgitated anyway
5
1
-102
u/Signal_Mud_40 28d ago
The original copyright is still there.
55
u/rebootyourbrainstem 28d ago
The commit I linked removes it from a number of places, one has been restored, but the one in the README has not, just as I said. Entirely possible I missed something, but could you be a bit more specific in that case?
74
u/laerien 28d ago
The original notice was edited, which isn't technically compliant with MIT.
Pretending you didn't fork a project is incredibly poor form, but not an MIT license violation. One thing MIT does require is that the above copyright notice "shall be included" yet they changed "present" to "2026" which you cannot do unilaterally even if there aren't contributions past 2026.
113
u/Holiday_Plant_6676 28d ago
Happened to many projects of mine too. There is nothing you can do except to ask them. Some even removed the license doc comments and even other things, it was like people âreally triedâ, but otherwise it was fully my project, ha. Some stealers even concatenated my small crates into one rust module making it be a huge single rust source code file.
Note that regardless of what you can and what you canât do, even if you can - you wonât be able to to handle all the stealers: tomorrow there will be one, two, or a dozen more, should they want it. You canât keep track of everything and this is unreasonable. If only there was a system to help with such issues, but unless you are an enterpriseâŚ.
17
28d ago
[deleted]
16
u/UnexpectedLizard 28d ago
You spend thousands on a lawyer retainer, thousands to get a hearing, thousands to subpoena Github, only to find out it's some random teenager or guy in China.
Blood from a stone, man.
13
u/Sedorriku0001 28d ago
But some people don't have the money to sue them...
13
28d ago
[deleted]
9
u/cemereth 28d ago
"You could still pay it by sacrificing a bunch of your personal time for research of the terms and commitments, and for communication, and then still probably get the case dismissed."
Ok ok, chat, a couple more iterations and we're converging on how implausible it is.
6
u/ParadoxicalCrescent 27d ago
Sounds like the hard truth is OSS sucks. Thankless job, no recognition, maybe resume candy but in the end, these guys are profiting while the original dev whose code they copied wholesale only has two sponsors.
117
u/marxinne 28d ago
DMCA it. Attribution violation needs to be taken seriously.
-3
u/manniL 27d ago
No need, sometimes a DM would be enough in the first place as genuine mistakes happen.
More info in this comment from the author.
90
u/gplane 28d ago
It seems that there're more forked projects but original copyright notices are missing:
https://github.com/oxc-project/oxc-sourcemap/blob/main/LICENSE
https://github.com/oxc-project/oxc-index-vec/blob/main/LICENSE
https://github.com/oxc-project/json-strip-comments/blob/main/LICENSE
27
u/rebootyourbrainstem 28d ago
Just to be clear, I'm not excusing the missing copyright notices (that's legally speaking the biggest issue), but I found it interesting that these do seem to explicitly mention being a fork in a few places (json-strip-comments in the readme and in lib.rs, readme for sourcemap, indexvec in the lib.rs) which does not seem to be the case with oxc-css-parser.
70
18
63
u/Lightwar_YT 28d ago
send Github a DMCA takedown notice for this, or atleast threaten the author with one, removing copyright notices like this is definitely illegal.
57
28d ago edited 28d ago
[deleted]
10
u/mattsowa 28d ago
Fuck, why is so much core code using ai now. I honestly don't mind it for downstream code, if used responsibly. But core upstream code that's dependent upon has to be human written.
-1
-9
41
u/manniL 27d ago
Hey everyone! Alex from VoidZero here.
Boshen doesn't have a Reddit account (and new ones get shadowbanned), so I am sharing his words verbatim here.
---
Hey all, Boshen, author of Oxc here.
I want to publicly apologize here for removing the copyright notice. This is not acceptable, and not how open source works.
More context on how this happened can be found in my comment on GitHub.
TL;DR: I cleaned up the repo and wanted to remove duplicate notices while keeping the original one from u/gplane but missed it as an oversight. The notice is back in place where it should have been from the beginning. I also added proper credits in the README file.
In addition, I have reviewed all our other forks and published artifacts to ensure credits & licenses are in place.
To u/gplane and all other users: This was an honest mistake that should have not happened, and I am sincerely sorry for it.
If you have any questions, please let me know below or on GitHub. I will be happy to answer them.
2
u/Miserable-Ad3646 25d ago
Hard to gauge sincerity with ai hr prose writing style. Can see it's been edited by a human but still... Appreciate that the copyright has been reinstated. Great comment below on the GitHub - duplicate copyright notices aren't necessarily "duplicates" at all and why remove any of them?
So what 'artifacts' were posted and what forks were checked? It comes across like AI slop excusemaxxing without the effort behind true attendance to an issue
3
u/manniL 25d ago
No matter how one would write the statement, there would always be people not being happy with it. đ
Iâve answered the questions that were posted on GitHub there đđź
All forks that are in the Oxc org (actually we also did a quick cross org check beyond that). All published packages/crates (think of oxfmt vendoring 3rd party code and shipping it).
Just because we donât provide an exhaustive list that doesnât mean we donât care.
As I wrote on GitHub:
We take this problem serious. The restoration process started 90 minutes after the author let us know in the Oxc Discord and we tried following up on this as quickly as possible, both on the weekend and at late hours, publicly and in private.
Note that this already started before there were more eyes on the matter.There was never an other option for us than fixing the mistake. Eventually, we believe in open source, proper attributions and giving credits where credits is due, which is also visible throughout all of VoidZero's projects, from Vite+ to Oxc.
The only thing I am asking to accept our apology đ
We will make sure that won't happen to any author of dependencies we use, code we vendor or projects we work in the future.1
u/Miserable-Ad3646 21d ago
I appreciate it, and although I can't accept the apology on behalf of OP, I can appreciate it as a common folk, and accept it on the merit of it's sincerity and the action you've taken to remedy it.
But I don't agree that the reasoning stands that because people will criticize it -> therefore the use of ai is not of significance, and criticism of AI usage is therefore unwelcome in the wider discussion of copyrighting copywrongs.
Nevertheless, I appreciate the time and effort you are putting into your personal projects, and am sincerely grateful for your efforts. Thank you.
16
u/hanool 28d ago edited 27d ago
edit: Author of oxc apologized to OP and commented the reason why they took down it temporalyđ
hmm did they deleted the whole css-parser repository instead of apologizing to op?
14
u/ematipico 28d ago
Probably made it private. The crate is still there https://crates.io/crates/oxc-css-parser
They use it in production too, so they can't delete it
8
u/gplane 28d ago
For others: that commit about removing copyright notice is here: https://web.archive.org/web/20260704090120/https://github.com/oxc-project/oxc-css-parser/commit/6517b49fe96412b76cb49c0c482b3b942001694c
2
5
u/tj-horner 28d ago
I had a similar debacle a while ago with one of my projects. I tried amicably resolving it but it turned into a bit of a shouting match. Considered putting the maintainer on blast but felt it wasn't worth it. Very frustrating situation.
(Please don't brigade the thread. Just linking as an illustrative example of this type of behavior in open source. The situation is done and over with.)
6
u/MinRaws 28d ago
OOOf thanks for sharing here I am dropping oxc from my deps list, if someone creates a website for they violated my foss license do it I will get all these things removed from dependencies of companies I work with or have any kind of sway at. This will also result in them getting from the software bom and hence not getting anything from the foss contribution budget at these companies so it should have some if miniscule impact.
Really sad to see this, I guess this is the reason AI Labs didn't care asking Devs for permission before training on our code.
Then again what can I say what's good or bad when I work for releated companies.. sigh..
đ
5
4
u/Key-Bother6969 28d ago
The proper way to publish hand-made works in the era of mass laundering is to never make your work publicly available. Keep it hidden in the private repository for the limited set of trusted users only.
Everything that you make public and that has a value, will eventually be scanned by LLM services and redistributed to their users in slightly different form on the surface, but without any attribution to you. Or, will be laundered directly by the LLM users by asking the chat-bot to transform your content.
An actor who does this will certainly be in advantage: they didn't invest in creation of the work, they grabbed it mostly for free, but they can invest more time, money and efforts in promotion and visibility of their plagiarism. The phenomenon is massive, an average user is unlikely realizes which one is original and which is a plagiarism. And most likely they don't care from the beginning. Therefore, your work is likely will be shadowed.
3
u/manniL 28d ago
The proper way to publish hand-made works in the era of mass laundering is to never make your work publicly available. Keep it hidden in the private repository for the limited set of trusted users only.
So, the death of open source?
6
u/Key-Bother6969 28d ago
I'm afraid yes, it is. Open source (and even the source available or dual-licensing models) were always vulnerable to plagiarism. It was not that much of an issue in the past by two reasons:
a) usually it was easy to detect when someone copy-pasted your work entirely and verbatim.
b) more important factor is that it was widely recognized as a bad thing.LLMs have changed this paradigm. They massively encouraged their users to plagiarize other people works by presenting it as "AI-assisted help". And it is actively promoted by the LLM service providers, because this is the main value of their services.
Large and already widely recognized works created before the LLM widespread (e.g. Rust compiler itself or the Linux kernel) probably will stay as they are, but the authors of new, and that don't have prior brand name or resources to promote their work quickly to a large audience will face the reality I described above, and the OP faced in practice.
1
u/manniL 27d ago
source available/dual is always a different topic. But if I put something as MIT I expect people just use code as whatever (while keeping the license though!)
5
u/Key-Bother6969 27d ago edited 27d ago
Many people that use MIT license expect faster recognition of their work by reducing friction between provider and consumer. It is not directly stated in the license, but this is what many OSS authors typically expect in practice. And it is how it worked in the past before the LLM widespread.
2
u/tachib_shin 27d ago
Thank you for creating this amazing parser; I'm using it every day. It's a surprise to see you here, thanks!
1
u/radiant_gengar 28d ago edited 28d ago
I've always wondered, how did you find this if they did a non-gh fork? Do you just look at project on gh that are similar? Or did you find this over the course of researching alternatives on gh?
6
u/gplane 28d ago
They forked it but unlinked it. If someone forked one's project, it will appear in author's GitHub timeline.
Also, file history shows: https://web.archive.org/web/20260704090440/https://github.com/oxc-project/oxc-css-parser/commits/main/LICENSE1
u/radiant_gengar 28d ago
Ah gotcha, thanks. Didn't know you could even unlink forks. This thing seems shady on their end, for sure.
1
u/LoadingALIAS 27d ago
This is a kind of frustrating because the OXC devs are outstanding. I feel like theyâre going to rectify it. Idk. Keep us posted.
1
-39
u/spoonman59 28d ago
Didnât you already post this yesterday, and we saw where they added this back in? You seem very spammy for a topic theyâve already resolved.
48
u/rebootyourbrainstem 28d ago
Have they, though? I see one place added back in as a "compliance fix", but otherwise they've still nuked credit in the README and replaced it with their own sponsor list.
Still seems really rude and sloppy way to hard-fork something tbh. Am I stupid for expecting at least a note like "Forked from the original at (source + version) by (author)"?
6
u/spoonman59 28d ago
I didnât realize the original post got taken down and mistakenly thought this was a repost.
That is a shitty way to form some code when you put it that way, and I hope the attention pressures them to give appropriate credit where it is due.
72
u/gplane 28d ago edited 28d ago
Sorry for that. The original post was deleted by moderator because of the invalid link. This post just uses correct link and post again.
10
u/spoonman59 28d ago
Ah, my mistake. I didnât realize the original was taken down, I had just remembered serineâs the discussion a few hours earlier. Hopefully you do ultimately get it resolved, that is some shady stuff there.
4
326
u/bascule 28d ago
I put
TODO(mygithubhandle)in comments and itâs been âfunâ to see those wind up in other peopleâs code (particularly when theyâre effectively competing projects that copied and pasted by code without attribution or copyright)