FOSS Wiki StationFOSS Wiki Station

Welcome to FOSS Wiki

What "free and open source software" actually means — the licence spectrum, the four freedoms, the OSD, and why it matters.

Free & Open Source Software — Home

What "free and open source" means

Two definitions, two origins, largely the same set of licences.

Free software (Free Software Foundation, 1985) is an ethical position. Software is free if it grants users the four freedoms: to run it for any purpose; to study and change it (which requires source code); to redistribute copies; and to distribute modified versions. "Free" means freedom, not price — libre, not gratis.

Open source (Open Source Initiative, 1998) describes the same territory as a development methodology and a marketing argument. The Open Source Definition has ten criteria: free redistribution, source availability, derived works allowed, integrity of the author's source, no discrimination against people or groups, no discrimination against fields of use, licence travels with the distribution, licence not tied to a specific product, licence must not restrict other software, and technology neutrality.

In practice the two accept almost identical licences. The difference is emphasis: the FSF argues from user freedom; the OSI argues from engineering outcomes. "FOSS" and "FLOSS" are the neutral umbrellas.

Three words that get confused. Free = the four freedoms. Open source = meets the OSD. Source-available = you can read the code but a freedom is withheld. Source-available licences (SSPL, BUSL, Elastic License 2.0, Commons Clause) are not open source, however they are described in marketing.

The licence spectrum

PositionTypical licencesObligations on youBest for
Public domainCC0-1.0, Unlicense, 0BSDNoneData, snippets, maximal reuse
PermissiveMIT, ISC, BSD-2/3-Clause, Apache-2.0Preserve notice; Apache-2.0 covers patentsLibraries, maximum adoption
Weak / file copyleftMPL-2.0, EPL-2.0, LGPL, CDDLShare changes to covered files; linking allowedCommercial-friendly reciprocity
Strong copyleftGPL-2.0/3.0Distribute complete corresponding source of derivativesKeeping improvements open
Network copyleftAGPL-3.0Same as GPL-3.0, plus source offer to network usersServer software
Source-availableSSPL-1.0, BUSL-1.1, Elastic-2.0, FSL-1.1Field-of-use or service restrictionsVendors restricting cloud competitors

Quick facts

Value
Free software4 freedoms (FSF, 1985)
Open source10 criteria (OSD, 1998)
OSI-approved licences100+
SPDX License List3.29.0 · 2026-09-16
SPDX standardISO/IEC 5962 · current 3.0.1
CycloneDX standardECMA-424 2nd ed. · current 1.7.2

Short timeline

DateWhatNote
1983-09-27GNU Project announcedStallman posts to net.unix-wizards; FSF follows in 1985
1989GPL v1Copyleft enters the world; GPLv2 June 1991
1991-09-17Linux 0.01Relicensed to GPLv2 with 0.12 in early 1992
1993-08-16Debian foundedIan Murdock; the DFSG becomes the seed of the OSD
1997-05The Cathedral and the BazaarRaymond makes the engineering case
1998-02"Open source" coinedChristine Peterson's term; OSI founded the same month
2005-04GitCreated after BitKeeper's free licence was withdrawn
2007-06-29GPLv3Patent and anti-tivoisation clauses; AGPLv3 in November
2008-04GitHub launchesPull requests turn contribution into a social act
2015-07Kubernetes 1.0 & CNCFFoundation-scale, corporate-funded infrastructure
2021-12-10Log4ShellCVE-2021-44228; dependency risk becomes a board topic
2024-03-29xz backdoorCVE-2024-3094; a multi-year campaign against a volunteer maintainer
2024-10-28OSAID 1.0The OSI extends the definition to AI
2027-12-11EU CRA main obligationsRegulation (EU) 2024/2847 becomes generally applicable

Why it matters

If you use open source

  • You have licence obligations — attribution at minimum, source disclosure under copyleft.
  • You carry the security risk of dependencies you did not write and do not fund.
  • Regulation increasingly requires you to enumerate those dependencies.
  • You can influence outcomes: report issues, fund maintainers, contribute back.

If you publish open source

  • Your licence choice is close to irreversible — inbound contributions assume it.
  • Missing a LICENSE file means nobody can legally use your code.
  • Bus factor and funding decide whether the project survives contact with success.
  • Governance documents are what turn a repo into a project people can trust.

Compiled September 2026. Licence and policy facts are dated — verify against opensource.org and gnu.org before relying on them. Nothing here is legal advice.

See also: History · Licenses · Governance · Business models · Security & supply chain · OEM & supplier playbook · Assurance framework

On this page