Glossary
Plain-language definitions of the words that carry the most weight in FOSS arguments.
Glossary
The words that carry the most weight in open source arguments, defined plainly.
AGPL (Affero GPL) — GPL-3.0 plus a requirement to offer source to users who interact with the software over a network (§13). The standard "don't let cloud vendors resell this" licence that is still OSI-approved. See Licenses.
BDFL — Benevolent Dictator For Life: a single founder with final decision authority. Fast, coherent, and a succession risk. See Governance.
Bus factor — How many maintainers must be hit by a bus before the project stops. One is common and is the failure mode behind the xz backdoor.
CLA (Contributor License Agreement) — A signed agreement granting the project or foundation rights over a contribution, often enabling relicensing. Heavier than a DCO.
CNA (CVE Numbering Authority) — An organisation authorised to assign CVE IDs. Projects, vendors, foundations and GitHub can be CNAs.
Copyleft — The mechanism by which a licence requires modified or derivative works to stay under the same terms. Ranges from file-level (MPL) to whole-work (GPL) to network (AGPL).
CycloneDX — An OWASP-origin, security-first BOM standard now published as ECMA-424. Covers SBOM, HBOM, SaaSBOM, CBOM, ML-BOM, VEX and signed attestations. See CycloneDX.
DCO (Developer Certificate of Origin) — A one-line certification added by git commit -s that the
contributor has the right to submit under the project licence. No paperwork.
Derivative work — A work based on a copyrighted work. Whether linking, plugins or configuration create one is the central unresolved question in copyleft compliance.
DFSG (Debian Free Software Guidelines) — Debian's 1997 criteria for what may enter the distribution; the direct ancestor of the Open Source Definition.
Dual licensing — Offering the same software under two licences — typically copyleft for those who reciprocate, commercial for those who cannot.
FOSS / FLOSS — Free (and) Open Source Software; Free/Libre and Open Source Software. Umbrella terms that sidestep the free-vs-open argument.
Four freedoms — The FSF's definition: run, study and modify, redistribute, distribute modified versions.
Fork — An independent copy of a project under the same licence. The ultimate governance remedy and the reason single-vendor projects behave.
FSF (Free Software Foundation) — Founded 1985; publisher of the GPL family and the ethical wing of the movement. See Foundations.
Gratis vs libre — "Free as in beer" vs "free as in speech". FOSS is about libre; most of it also happens to be gratis.
InnerSource — Using open-source-style contribution practices inside a company: shared repos, PRs from any team, public-by-default.
LGPL — Lesser GPL: copyleft that stops at the library boundary, so proprietary programs may link against it.
Libre — Free in the sense of liberty. The origin of "libre software" as a disambiguation of "free".
Meritocracy — Governance where influence follows demonstrated contribution — write access and PMC seats earned over time. The Apache model.
NTIA minimum elements — The seven fields a US baseline SBOM must contain: supplier, component name, version, other unique identifiers, dependency relationship, SBOM author, timestamp. See Compliance.
Open core — An open base with proprietary enterprise features on top. The most common commercial compromise. See Business models.
Openwashing — Describing software as open source when its licence withholds a freedom — SSPL, BUSL, ELv2, Commons Clause.
OSAID — Open Source AI Definition, published by the OSI in October 2024 (version 1.0); extends the argument to training data, code and model parameters.
OSI (Open Source Initiative) — Founded 1998; maintains the Open Source Definition and the approved-licence list.
OSPO (Open Source Program Office) — The internal function that owns open source policy, contribution workflow and dependency risk at a company.
Permissive licence — A licence imposing almost nothing beyond attribution — MIT, BSD, ISC, Apache-2.0. Maximises adoption, permits closing derivatives.
Protestware — Software deliberately weaponised by its maintainer for a political cause; node-ipc and
colors.js in 2022.
Provenance (SLSA) — Machine-readable evidence of how an artifact was built — source repo, commit, builder, dependencies. Verified before you trust a binary.
REUSE — An FSFE specification for machine-readable copyright and licence information in every file,
checked by reuse lint.
SBOM (Software Bill of Materials) — A machine-readable inventory of the components in a piece of software. SPDX and CycloneDX are the two dominant formats.
SLSA — Supply-chain Levels for Software Artifacts: a maturity model (Levels 0–3) for build integrity and provenance.
Source-available — Source is published but one or more freedoms are withheld. Not open source.
SPDX — Software Package Data Exchange: a Linux Foundation standard (ISO/IEC 5962) for BOMs, and the home of the canonical licence identifier list. See SPDX.
Tivoisation — Shipping GPL software on hardware that refuses to run modified builds. GPLv3 requires the information needed to install your modifications.
TSC / TOC — Technical Steering Committee / Technical Oversight Committee: an elected body owning technical direction and often budget.
Upstream / downstream — Upstream is the project you depend on; downstream is everyone who consumes your work. "Upstream-first" means fixing things at the source.
VEX (Vulnerability Exploitability eXchange) — A machine-readable statement that a known vulnerability does or does not affect a given product — the cure for alert fatigue.
Vendor neutrality — A governance arrangement in which no single company controls the project, usually via a foundation holding the trademark and IP.
See also: Home · Licenses · Governance · Security & supply chain