FOSS Wiki StationFOSS Wiki Station
Overview

Wiki Map

The full table of contents at a glance — pages, SBOM hub and sector deep-dive.

Free & Open Source Software Wiki

A working knowledge base on free and open source software — what it is, where it came from, how it is licensed, governed, funded, contributed to, attacked, and regulated.

Each page exists twice: as HTML in the site root and as Markdown in docs/.

Pages

PageWhat's in it
HomeWhat FOSS means, the licence spectrum, why it matters
History of FOSSSharing → property → GNU → BSD → Linux → 1998 rebrand → cloud → licence wars → supply chain
LicensesAnatomy, families, compatibility, SPDX identifiers, how to choose and apply, enforcement
GovernanceModels, roles, governance documents, CLA vs DCO, releases, security policy, forks
FoundationsFSF, OSI, ASF, LF, CNCF, Eclipse, PSF, OpenSSF and others; what they actually do
ContributingFirst issue to merged PR, non-code contributions, the maintainer's side
Business modelsOpen core, SaaS, support, dual licensing; funding, sustainability, relicensing
Security & supply chainThreat model, attack techniques, incidents, defences, SBOM

SBOM hub

The supply-chain section, in depth:

PageWhat's in it
SPDXGovernance, version history, the 3.x graph model, profiles, serialization, License List, security/VEX, trade-offs
CycloneDXGovernance, ECMA-424, version history, document anatomy, BOM flavours, what's new in 1.7, VEX, CDXA, trade-offs
SPDX vs CycloneDXSide-by-side comparison, how to choose, conversion caveats, NTIA minimum-element mapping
ToolingGenerators, language libraries, converters/validators, consumers, a sane pipeline
ComplianceUS EO 14028 / NTIA, EU Cyber Resilience Act, post-quantum & CBOM, sector rules
Check processSeven phases, four blocking gates, entry requirements, activities, 17 step-by-step check tasks, work products
Assurance frameworkFive layers, cross-cutting evidence and feedback, the one audit question, maturity ladder

Sector deep-dive

PageWhat's in it
Automotive OEM FOSSSector regimes, OEM policy anatomy, licence matrix, supplier requirements, OpenChain
OEM & supplier playbookThe obligation/fact asymmetry, the milestone deliverable, four gates, what each side builds, verification, contract schedule

Reference

PageWhat's in it
GlossaryPlain-language definitions of the terms that carry the arguments


The site is the same content rendered as HTML: open ../index.html to read it, or any of index.html, history.html, licenses.html, governance.html, foundations.html, contributing.html, business.html, security.html, automotive.html, oem-supplier.html, framework.html and glossary.html.

Compiled September 2026 from the specification repositories and primary sources linked on each page. Version, licence and policy facts are dated — verify before relying on them. Nothing here is legal advice.

On this page