Wiki Map
The full table of contents at a glance — pages, SBOM hub and sector deep-dive.
Free & Open Source Software Wiki
A working knowledge base on free and open source software — what it is, where it came from, how it is licensed, governed, funded, contributed to, attacked, and regulated.
Each page exists twice: as HTML in the site root and as Markdown in docs/.
Pages
| Page | What's in it |
|---|---|
| Home | What FOSS means, the licence spectrum, why it matters |
| History of FOSS | Sharing → property → GNU → BSD → Linux → 1998 rebrand → cloud → licence wars → supply chain |
| Licenses | Anatomy, families, compatibility, SPDX identifiers, how to choose and apply, enforcement |
| Governance | Models, roles, governance documents, CLA vs DCO, releases, security policy, forks |
| Foundations | FSF, OSI, ASF, LF, CNCF, Eclipse, PSF, OpenSSF and others; what they actually do |
| Contributing | First issue to merged PR, non-code contributions, the maintainer's side |
| Business models | Open core, SaaS, support, dual licensing; funding, sustainability, relicensing |
| Security & supply chain | Threat model, attack techniques, incidents, defences, SBOM |
SBOM hub
The supply-chain section, in depth:
| Page | What's in it |
|---|---|
| SPDX | Governance, version history, the 3.x graph model, profiles, serialization, License List, security/VEX, trade-offs |
| CycloneDX | Governance, ECMA-424, version history, document anatomy, BOM flavours, what's new in 1.7, VEX, CDXA, trade-offs |
| SPDX vs CycloneDX | Side-by-side comparison, how to choose, conversion caveats, NTIA minimum-element mapping |
| Tooling | Generators, language libraries, converters/validators, consumers, a sane pipeline |
| Compliance | US EO 14028 / NTIA, EU Cyber Resilience Act, post-quantum & CBOM, sector rules |
| Check process | Seven phases, four blocking gates, entry requirements, activities, 17 step-by-step check tasks, work products |
| Assurance framework | Five layers, cross-cutting evidence and feedback, the one audit question, maturity ladder |
Sector deep-dive
| Page | What's in it |
|---|---|
| Automotive OEM FOSS | Sector regimes, OEM policy anatomy, licence matrix, supplier requirements, OpenChain |
| OEM & supplier playbook | The obligation/fact asymmetry, the milestone deliverable, four gates, what each side builds, verification, contract schedule |
Reference
| Page | What's in it |
|---|---|
| Glossary | Plain-language definitions of the terms that carry the arguments |
The site is the same content rendered as HTML: open ../index.html to read it, or any of
index.html, history.html, licenses.html,
governance.html, foundations.html,
contributing.html, business.html,
security.html, automotive.html,
oem-supplier.html, framework.html and
glossary.html.
Compiled September 2026 from the specification repositories and primary sources linked on each page. Version, licence and policy facts are dated — verify before relying on them. Nothing here is legal advice.