Skip to content
Open {re}Source
Glossary

Open Source Glossary

The words the guide uses without stopping to explain them, defined once, in a sentence or two each, alphabetically. Every term links to the chapter that covers it, and every term has its own address: add #copyleft to this page’s URL and you land on its definition.

A#

AGPL
The GNU Affero General Public License: the GPL plus one rule, that users who talk to the program over a network can ask for its source. It closes the gap that lets a company run modified GPL code as a service and share nothing. Read more

B#

BDFL
Benevolent Dictator For Life: a governance model where one person has the final say. Python worked that way until Guido van Rossum stepped down in July 2018. Read more
Bounty
A payment promised for one defined piece of work. A bug bounty pays for a valid vulnerability report; an issue bounty pays whoever fixes a given issue. Read more
Breaking change
A change after which code that worked with the previous version stops working: a removed function, a renamed option, a new default. Under semantic versioning it needs a new major version. Read more
Burnout
The exhaustion of someone who maintains a project for too long without enough help or thanks. In maintainers it often shows as dread of opening the issue tracker, not as tiredness. Read more
Bus factor
The number of people who would have to disappear, hit by a bus or just gone quiet, before a project stalls. A project with one person holding the release keys has a bus factor of one. Read more

C#

CC0
A Creative Commons tool that waives every right the author can waive, as close to the public domain as the law of the country allows. Use it for data or text that anyone may reuse with no condition, not even credit. Read more
Changelog
A file, usually CHANGELOG.md, that lists what changed in each version, written for the people upgrading rather than the people who wrote the code. It is where a breaking change gets announced. Read more
CI
Continuous integration: a server builds the project and runs its tests on every push and pull request. A red check on your pull request is CI telling you what to fix. Read more
CLA
Contributor License Agreement: a contract in which a contributor grants the project owner a license to their contributions, often a wider one than the project license. The owner can then relicense the code, which is the point and the risk. Read more
Code of conduct
A file that says how people behave in the project, what happens when they don’t, and whom to write to. It protects contributors first, and it only works if someone answers the mail. Read more
Codeberg
A non-profit code hosting platform run by Codeberg e.V. in Germany, built on Forgejo. Zig moved its repository there from GitHub in November 2025. Read more
CODEOWNERS
A file that maps paths to the people or teams who review them. GitHub then requests their review automatically on any pull request that touches those paths. Read more
Committer
Someone who can write to the project’s main branch, a role named in Apache and PostgreSQL. A project with 31 committers has 31 people who can merge. Read more
Community health files
The files GitHub looks for to treat a project as welcoming to strangers: README, LICENSE, code of conduct, contributing guide, security policy, issue forms. A .github repository can hold defaults for every repository of an account. Read more
Contributor Covenant
The most widely copied code of conduct template, written by Coraline Ada Ehmke in 2014. You paste it, add a contact address and enforcement steps, and it is yours. Read more
Contributor ladder
A written list of the roles in a project, from contributor to maintainer, with what each role may do and what it takes to reach the next one. It answers “how do I become a maintainer?” before anyone has to ask. Read more
Copyleft
A license condition: if you distribute a modified version, you must share it under the same terms. Strong copyleft (GPL) reaches the whole combined work, weak copyleft (LGPL, MPL-2.0) only the library or the files you changed. Read more
Core team
The small group of maintainers who make a project’s main decisions and hold its keys. PostgreSQL’s core team has seven members. Read more
CRA
The EU Cyber Resilience Act: a regulation that sets security and vulnerability-handling duties for products with digital elements sold in the EU. It entered into force on 10 December 2024, with the duties phasing in until December 2027, and treats open-source stewards more lightly than manufacturers. Read more
Creative Commons
A family of licenses for content that is not code: text, images, music, data. CC BY lets anyone reuse your work if they credit you; the NC and ND variants restrict use and are not open licenses. Read more
CVE
Common Vulnerabilities and Exposures: a public identifier for one vulnerability, such as CVE-2024-3094 for the xz backdoor. A CVE gives scanners and users the same name to search for. Read more

D#

DCO
Developer Certificate of Origin: a contributor states, with a Signed-off-by line in each commit, that they have the right to submit the code under the project license. The Linux kernel has used it since 2004, and it costs a contributor one flag. Read more
Dependabot
GitHub’s bot that opens pull requests to update your dependencies and to fix the ones with a security advisory. Renovate does the same job with more settings. Read more
Dependency
A package your project needs in order to build or run. A direct dependency is the one you list in your manifest; a transitive one is pulled in by your dependencies, and you still ship it. Read more
Deprecation
Marking a feature as scheduled for removal while it still works. A good one names the replacement and the version that removes the old feature. Read more
Dual licensing
Offering the same code under two licenses: a copyleft one for everyone and a paid commercial one for companies that cannot comply with it. It only works for an owner who holds every contributor’s rights, usually through a CLA. Read more

F#

Fiscal host
An organization that holds a project’s money and handles its taxes and contracts, so the project does not have to incorporate. Software Freedom Conservancy and Open Collective’s hosts are examples. Read more
Forgejo
Free software for hosting repositories, issues and pull requests on your own server, forked from Gitea in 2022. Codeberg runs on it, and it is developed there. Read more
Fork
A copy of a repository. It is the personal copy you push branches to before a pull request, a long-lived variant that tracks the original and adds patches, or a hard fork that goes its own way under a new name, as OpenTofu did from Terraform in 2023. Read more
Foundation
A non-profit that holds a project’s trademark, money or infrastructure so that no single company owns it. The Apache Software Foundation, the Linux Foundation and the CNCF, which hosts Kubernetes, are three. Read more
Free software
Software that gives its users four freedoms: to run it, study and change it, share it and share the changed version. It is the Free Software Foundation’s term and mostly describes the same licenses as open source, with an ethical argument instead of a practical one. Read more
FSF
The Free Software Foundation, founded in 1985 by Richard Stallman. It wrote the GNU General Public License and keeps the definition of free software. Read more

G#

GitHub Actions
GitHub’s built-in CI/CD service: workflows written in YAML under .github/workflows/ run on pushes, pull requests or a schedule. It is free on public repositories with the standard runners. Read more
Good first issue
A label that maintainers put on issues a newcomer can take without knowing the whole codebase. GitHub lists them on each repository’s Contribute page and in search. Read more
Google Summer of Code
A Google-funded program, running since 2005, that pays contributors a stipend to work on an open-source project over the summer with a mentor. Organizations apply, publish project ideas, and choose their contributors. Read more
Governance
Who decides what in a project, and how: who can merge, who can add a maintainer, what happens when two of them disagree. Every project has a model; the useful ones write it down in GOVERNANCE.md. Read more
GPL
The GNU General Public License, the best-known strong copyleft license, written by the Free Software Foundation. Anyone who distributes a modified version must share its source under the GPL; version 3 came out in 2007. Read more
Grant
A one-off sum from an institution for defined work, such as a security audit or a rewrite. The Sovereign Tech Agency and NLnet fund open-source work this way. Read more

H#

Hacktoberfest
A month-long event in October, run by DigitalOcean, that encourages first pull requests to open-source projects. Maintainers opt in by adding a topic to their repository. Read more
Help wanted
A label meaning the maintainers would welcome an outside contributor on this issue. It does not mean the issue is easy: that is what good first issue is for. Read more

I#

Inbound = outbound
The rule that contributions come in under the same license the project goes out under. Without a CLA or a DCO it is the default: a contributor who opens a pull request to an MIT project licenses the code as MIT. Read more
Issue
A tracked item in a repository: a bug report, a feature request or a question, with a discussion thread under it. Search closed issues before you open one. Read more

L#

Lazy consensus
A way to decide without a meeting: someone proposes a change, and if nobody objects within a stated time, it is approved. Silence counts as yes, so the time to object has to be long enough for people to see it. Read more
License compatibility
Whether code under one license can be combined with code under another in one work and still satisfy both. Apache-2.0 code can go into a GPL-3.0 project, but not into one that is GPL-2.0-only. Read more
Lockfile
A file that records the exact version of every dependency your last install resolved, such as package-lock.json or Cargo.lock. Commit it for an application, so every build uses the same versions. Read more

M#

Maintainer
A person who can merge changes and who answers for the project: triaging issues, reviewing pull requests, publishing releases. Being a maintainer is a role, not a skill level. Read more

N#

Nit
A review comment about something small the author can fix or ignore, usually style, prefixed with nit:. Labelling it tells the author it does not block the merge. Read more

O#

Open Collective
A platform that collects donations and sponsorships for a project and publishes every expense. A project either joins a fiscal host on it or holds its own account. Read more
Open core
A business model with an open-source core and paid proprietary extras. GitLab’s Community Edition and Enterprise Edition are the standard example. Read more
Open Source Definition
The ten criteria an OSI-approved license must meet, among them free redistribution, source code access and no discrimination against fields of endeavor. A license that forbids commercial use fails the last one. Read more
Open weights
A model released with its trained weights for anyone to download, but not always with its training data, its training code or a license that allows every use. “Open weights” says what you can download, not what you may do with it. Read more
OpenSSF
The Open Source Security Foundation, a Linux Foundation project started in 2020. It publishes Scorecard, the best-practices badge and guides for maintainers. Read more
OSI
The Open Source Initiative, a non-profit founded in February 1998. It maintains the Open Source Definition and decides which licenses it approves. Read more
Outreachy
Paid, remote internships on open-source projects for people who are underrepresented in tech, run by the Software Freedom Conservancy. Mentors and projects apply, and interns apply to them. Read more

P#

Permissive license
A license that lets anyone do almost anything with the code, closed products included, as long as they keep the notice. MIT, BSD and Apache-2.0 are the common ones. Read more
Pull request
A proposal to merge one branch into another, with a diff, a discussion and the checks. GitLab calls it a merge request, and sourcehut replaces it with patches sent by email. Read more

R#

README
The file shown on a repository’s front page, and the one most visitors read before anything else. It should say what the project is, how to install it and where to get help on the first screen. Read more
Rebase
Replaying your commits on top of a newer base, so your branch looks as if you started from today’s main. After a rebase you push with --force-with-lease, because the commits have new hashes. Read more
Review
Reading a change before it merges, and approving it, asking for changes or commenting. A good review says what blocks the merge and what does not. Read more
RFC
Request for Comments: a written proposal for a significant change, discussed in public before anyone writes the code. Rust’s RFCs are a well-known example. Read more

S#

Scorecard
OpenSSF Scorecard: a tool that runs automated checks on a repository’s security practices, such as branch protection, pinned dependencies and a security policy, and gives each a score from 0 to 10. Read more
Security advisory (GHSA)
GitHub’s record of a vulnerability, identified as GHSA-xxxx-xxxx-xxxx: affected versions, patched versions, severity, credits. A maintainer drafts it privately in the repository, and GitHub can request a CVE for it. Read more
Sign-off
The Signed-off-by: Name <email> line at the end of a commit message, added with git commit -s. It is how a contributor accepts the DCO. Read more
Source-available
Code you can read, with a license that restricts what you may do with it, such as running it as a service or competing with its maker. It is not open source: the Open Source Definition rules out those restrictions. Read more
SPDX
The Software Package Data Exchange: among other things, a list of short license identifiers, such as MIT or Apache-2.0, that tools and manifests agree on. A file header SPDX-License-Identifier: MIT says the license in one line. Read more
A person or company that pays a project on a recurring basis, through GitHub Sponsors, Open Collective or an invoice. Projects publish tiers, so a sponsor knows what a given amount buys. Read more
Squash
Combining several commits into one. “Squash and merge” turns a whole pull request into a single commit on main, which keeps the history short and hides the review back-and-forth. Read more
SSPL
The Server Side Public License, written by MongoDB in 2018: the GPL plus a rule that whoever offers the program as a service must release the source of the whole service. The OSI does not consider it open source. Read more
Stale bot
A bot that labels issues and pull requests with no activity after a set time and then closes them. Some projects use it to keep the tracker small; others find it closes real problems. Read more
Star
A GitHub button that bookmarks a repository and adds one to its count. Stars measure attention, not maintenance: a project can have 50,000 and no one reading its issues. Read more
Steering committee
A small group elected or appointed to set a project’s direction and settle disputes, often replacing a single leader. Kubernetes has one, and Python has a five-person steering council. Read more
Sublicense
To grant a license to others on rights you were licensed, not owned. A CLA that includes the right to sublicense lets the project owner change the license later. Read more
Supply chain
Everything your software is built from and delivered through: dependencies, build tools, CI workflows, registries. A supply chain attack hides in one of them, as the xz backdoor did in March 2024. Read more

T#

Tag
A fixed name for one commit, such as v1.4.2, used to mark a release. Unlike a branch, a tag does not move. Read more
Trademark
A legal right over a name or logo, separate from the copyright and license on the code. Anyone can fork your MIT code; nobody may call the fork by your name without your leave. Read more
Triage
Sorting incoming issues and pull requests: labelling them, asking for a reproduction, closing duplicates, routing them to someone who can fix them. It is the contribution maintainers are shortest of. Read more

U#

Upstream and downstream
Upstream is the project you forked from or depend on, and downstream is whoever builds on you. A fix made in your fork should go upstream, and your upstream remote is where you fetch from. Read more