This one starts as a correction and doesn’t stay one.
Last episode, talking about auth, Matt said that after the IdentityServer licence change Microsoft “closed ranks” and stopped taking third-party dependencies in their templates. A re-listen flagged it as something worth revisiting. Then, working on something unrelated, he hit the example that settles it outright — and once you’ve seen one, they’re everywhere.
So that’s the correction. It takes about ten minutes.
The rest of the episode is what the correction opened up.
Microsoft put IdentityServer into the ASP.NET Core templates. Overnight, two blokes became responsible for the support and maintenance of millions of developers and an unknown number of commercial products.
Did anyone ask them if they wanted that?
We get into:
- What the real pattern is, once you stop assuming and go and look
- Where a vendor puts a wrapper around a dependency, where it doesn’t, and whether that distinction is protection or something else
- Liam’s argument that the protocol matters more than the package
- How other ecosystems handle the same problem, and which one refuses to play
- The same question asked of a much smaller template, with a very different answer
- Whether putting something in a default carries a duty, and what that duty would even look like
Then, live on the recording and for entirely unrelated reasons, Matt opens a repo and finds an announcement neither of us had seen.
That sends the back half somewhere we didn’t plan: whether an honesty system can fund open source when auditing your own dependency tree is this painful, what the streaming wars taught us about convenience beating enforcement, and one very specific thing we noticed about a file in the Aspire repo that we couldn’t explain on the night.
This is the third time we’ve revisited this topic, after one and two years for prior episodes, so we’re right on schedule — once from the community’s side, once from the maintainer’s, and once with Jimmy. And it’s still a big ball of open questions. We’re closer than we were. We’re not there.
🍻 Tonight’s Drinks
Waters all round
Links from the episode
- Polly on GitHub
- The Polly Project
- Polly’s Open Source Maintenance Fee announcement
- The Open Source Maintenance Fee
- OSMF registered projects
- Microsoft FOSS Fund
- Aspire service defaults
- OpenTelemetry for .NET
- Jason Taylor’s Clean Architecture template
- Cisco’s OpenH264 (Internet Archive page, original announcement no longer listed)
- OSI licence list — homework for a future episode
Previously on BDD
- Open Source, Closed Wallet, Questionable Ethics — October 2024
- Jimmy Bogard: Sustainability and Community from an OSS Veteran — September 2025
- Auth and Other Things We Forgot How To Do — the episode being corrected
Any Likes 👍, Shares 📣, Subscriptions 🔔, and Love ❤️ go a long way to helping us keep doing this for fun.
Cheers! 🍻