档案库 · 开发与企业工具 · 战略决策 · 2024
Bitwarden 反转限制性 SDK 许可,因开源社区反弹
免费增值密码管理器 Bitwarden 将使用受限的内部 SDK 打包进桌面版;GitHub 和 Hacker News 的反弹使它称这是打包错误。
Bitwarden
做的是什么生意
Bitwarden runs a freemium password-management service built around an encrypted vault and clients for many platforms; it has long published code as open source so users and self-hosters can audit what they run.
起因
Bitwarden founder and CTO Kyle Spearrin built the service on a freemium model, publishing code as open source as part of its trust story. In October 2024, pull request #10974 made the desktop client depend on @bitwarden/sdk-internal, whose license stated: 'You may not use this SDK to develop applications for use with software other than Bitwarden (including non-compatible implementations of Bitwarden) or to develop another SDK.'
经过
A user filed issue #11611, 'Desktop version 2024.10.0 is no longer free software', arguing that the dependency and its clause 'violates freedom 0' and that the desktop client could not be built without it; other users echoed the concern. Spearrin replied that the SDK and the client are separate programs in separate repositories communicating over standard protocols, so GPLv3 compatibility held, and that the build blocker was 'merely a bug' they planned to resolve; the ticket was then locked to collaborators. Phoronix reported the dispute on 2024-10-20 as 'Concerns Raised Over Bitwarden Moving Further Away From Open-Source', and it reached the HN front page the next day, where commenters debated whether Bitwarden was quietly leaving open source behind.
结果
That evening Bitwarden posted on X that the dependency was a 'packaging bug' and that 'Bitwarden remains committed to the open source licensing model'; a linked Phoronix follow-up reported 'Bitwarden Makes Change To Address Recent Open-Source Concerns'. The company walked the restriction back and reaffirmed the open-source positioning the episode had put at risk.
背景
Bitwarden 是一个免费增值的密码管理器,围绕加密保险库构建,在多个平台上有客户端,代码作为开源发布。其创始人和 CTO Kyle Spearrin 的信任故事建立在那种透明度上。2024年10月,拉取请求 #10974 使桌面客户端依赖于 @bitwarden/sdk-internal,一个内部 SDK,其许可证禁止用于 Bitwarden 以外的软件或开发另一个 SDK。
用户立即将该条款解读为 Bitwarden 放弃自由软件。一个 GitHub 问题标题为“桌面版 2024.10.0 不再是自由软件”认为该依赖“侵犯了自由0”;Spearrin 回答说 SDK 和客户端是分离的 GPLv3 程序,并且障碍“只是一个错误”,然后该工单被锁定给协作者。Phoronix 于2024-10-20报道了这场争议,故事在第二天登上了 Hacker News 首页(102 分,60 条评论),社区在那里辩论该限制是失误还是战略。
Bitwarden 当晚在 X 上回应称该依赖是一个“打包错误”,并且它“仍然致力于开源许可模式”,一篇 Phoronix 后续报道称 Bitwarden 做出了改变以回应担忧。这一事件表明,构建依赖中的许可变化能多快考验——并且,通过公开逆转,恢复——免费增值品牌所依赖的开源信任。
这件事要成立,得有什么
- Bitwarden 发布的源代码是其免费增值宣传所指的证据,因此任何使用限制都被解读为背叛而非打包。
- 该依赖进入了桌面构建,而桌面构建是由打包者和自托管者自己编译的,所以社区立即遇到了该条款,而不是逐渐遇到。
- GitHub 问题给批评者提供了一个编号的、可引用的工件,Phoronix 和 Hacker News 在48小时内将其变成了头版故事。
- 锁定工单使交流看起来像是回避,直到 Bitwarden 公开的“打包错误”声明和后续改变恢复了其立场。
可借鉴之处
对于开源品牌,许可是产品:构建依赖中的使用限制读起来像撤稿的第一步,只有明显的反转才能恢复信任。
后续进展
一天之内,Bitwarden 公开称该依赖是打包错误,重申它仍然致力于开源许可模式,Phoronix 后续报道称它做出了改变以回应担忧。截至2026-09-06审查,GitHub 问题页面仍然公开,Bitwarden GitHub 组织——‘为个人、团队和企业组织提供的开源安全解决方案’——仍在积极维护,客户端仓库在2026-09-05有活动;在审查的来源中,没有记录到该事件对收入、用户或产品的影响。
资料来源
- Concerns raised over Bitwarden moving further away from open source
- Desktop version 2024.10.0 is no longer free software · Issue #11611 · bitwarden/clients
发现哪里写错了?告诉我们。
轮到你了
你刚读完一家。说说你在做什么,看看谁在赌同一件事。
免费账号 · 3 次免费提问 · 不用绑卡