FOSS Wiki StationFOSS Wiki Station
Overview

Glossary

Plain-language definitions of the words that carry the most weight in FOSS arguments.

Glossary

The words that carry the most weight in open source arguments, defined plainly.

AGPL (Affero GPL) — GPL-3.0 plus a requirement to offer source to users who interact with the software over a network (§13). The standard "don't let cloud vendors resell this" licence that is still OSI-approved. See Licenses.

BDFL — Benevolent Dictator For Life: a single founder with final decision authority. Fast, coherent, and a succession risk. See Governance.

Bus factor — How many maintainers must be hit by a bus before the project stops. One is common and is the failure mode behind the xz backdoor.

CLA (Contributor License Agreement) — A signed agreement granting the project or foundation rights over a contribution, often enabling relicensing. Heavier than a DCO.

CNA (CVE Numbering Authority) — An organisation authorised to assign CVE IDs. Projects, vendors, foundations and GitHub can be CNAs.

Copyleft — The mechanism by which a licence requires modified or derivative works to stay under the same terms. Ranges from file-level (MPL) to whole-work (GPL) to network (AGPL).

CycloneDX — An OWASP-origin, security-first BOM standard now published as ECMA-424. Covers SBOM, HBOM, SaaSBOM, CBOM, ML-BOM, VEX and signed attestations. See CycloneDX.

DCO (Developer Certificate of Origin) — A one-line certification added by git commit -s that the contributor has the right to submit under the project licence. No paperwork.

Derivative work — A work based on a copyrighted work. Whether linking, plugins or configuration create one is the central unresolved question in copyleft compliance.

DFSG (Debian Free Software Guidelines) — Debian's 1997 criteria for what may enter the distribution; the direct ancestor of the Open Source Definition.

Dual licensing — Offering the same software under two licences — typically copyleft for those who reciprocate, commercial for those who cannot.

FOSS / FLOSS — Free (and) Open Source Software; Free/Libre and Open Source Software. Umbrella terms that sidestep the free-vs-open argument.

Four freedoms — The FSF's definition: run, study and modify, redistribute, distribute modified versions.

Fork — An independent copy of a project under the same licence. The ultimate governance remedy and the reason single-vendor projects behave.

FSF (Free Software Foundation) — Founded 1985; publisher of the GPL family and the ethical wing of the movement. See Foundations.

Gratis vs libre — "Free as in beer" vs "free as in speech". FOSS is about libre; most of it also happens to be gratis.

InnerSource — Using open-source-style contribution practices inside a company: shared repos, PRs from any team, public-by-default.

LGPL — Lesser GPL: copyleft that stops at the library boundary, so proprietary programs may link against it.

Libre — Free in the sense of liberty. The origin of "libre software" as a disambiguation of "free".

Meritocracy — Governance where influence follows demonstrated contribution — write access and PMC seats earned over time. The Apache model.

NTIA minimum elements — The seven fields a US baseline SBOM must contain: supplier, component name, version, other unique identifiers, dependency relationship, SBOM author, timestamp. See Compliance.

Open core — An open base with proprietary enterprise features on top. The most common commercial compromise. See Business models.

Openwashing — Describing software as open source when its licence withholds a freedom — SSPL, BUSL, ELv2, Commons Clause.

OSAID — Open Source AI Definition, published by the OSI in October 2024 (version 1.0); extends the argument to training data, code and model parameters.

OSI (Open Source Initiative) — Founded 1998; maintains the Open Source Definition and the approved-licence list.

OSPO (Open Source Program Office) — The internal function that owns open source policy, contribution workflow and dependency risk at a company.

Permissive licence — A licence imposing almost nothing beyond attribution — MIT, BSD, ISC, Apache-2.0. Maximises adoption, permits closing derivatives.

Protestware — Software deliberately weaponised by its maintainer for a political cause; node-ipc and colors.js in 2022.

Provenance (SLSA) — Machine-readable evidence of how an artifact was built — source repo, commit, builder, dependencies. Verified before you trust a binary.

REUSE — An FSFE specification for machine-readable copyright and licence information in every file, checked by reuse lint.

SBOM (Software Bill of Materials) — A machine-readable inventory of the components in a piece of software. SPDX and CycloneDX are the two dominant formats.

SLSA — Supply-chain Levels for Software Artifacts: a maturity model (Levels 0–3) for build integrity and provenance.

Source-available — Source is published but one or more freedoms are withheld. Not open source.

SPDX — Software Package Data Exchange: a Linux Foundation standard (ISO/IEC 5962) for BOMs, and the home of the canonical licence identifier list. See SPDX.

Tivoisation — Shipping GPL software on hardware that refuses to run modified builds. GPLv3 requires the information needed to install your modifications.

TSC / TOC — Technical Steering Committee / Technical Oversight Committee: an elected body owning technical direction and often budget.

Upstream / downstream — Upstream is the project you depend on; downstream is everyone who consumes your work. "Upstream-first" means fixing things at the source.

VEX (Vulnerability Exploitability eXchange) — A machine-readable statement that a known vulnerability does or does not affect a given product — the cure for alert fatigue.

Vendor neutrality — A governance arrangement in which no single company controls the project, usually via a foundation holding the trademark and IP.


See also: Home · Licenses · Governance · Security & supply chain

On this page