Creating an OSS Policy: Considerations and Best Practices

What to Consider When Crafting Your OSS Policy

July 15, 2021
By Filipp Kofman

Free and open source software (OSS) continues to dominate the software development landscape, with an astounding 1.5 trillion component downloads in 2020.

With this growth, organizations are finding it more important than ever to ensure that they have documented policies to govern their use, distribution, and contribution of OSS.

This post offers an introduction to the topic and discusses some motivations for developing an OSS policy (open source policy) for your organization. It also describes best practices that companies should follow when implementing their own OSS policies.

What Is an OSS Policy and Why Should I Have One?

An OSS policy is a document developed and maintained by a company to govern how and when employees should use or contribute open source components. It sets out requirements that must be followed when:

Effective OSS policies are crafted collaboratively with all stakeholders, and will help ensure compliance with your software license obligations. Poor OSS hygiene can lead to the loss of proprietary rights.

What Are My License Obligations?

Despite being "free" and "open," OSS is subject to license terms with which your organization must comply. A single set of principles for internal developers helps ensure that your company does not inadvertently violate the terms of open licenses. These violations risk giving up exclusive rights to proprietary Intellectual Property (IP) and create exposure to infringement claims.

Your OSS policy can ensure that you keep track of your attributions and create a structured process to resolve issues.

Other Business Considerations

Beyond compliance with license terms, there are several reasons to implement an OSS policy:

This alignment reduces confusion about your organization's OSS goals and promotes compliance. A policy implementing an approval and documentation process that tracks usage from procurement to deprecation makes governing the whole system more efficient.

Best Practices to Include in Your OSS Policy

Matching your organization's needs and risk tolerances is key. For instance, software distributed to third parties will suffer substantially from a policy that only describes internal use. Some additional considerations for your OSS policy include:

You may even prohibit certain licenses altogether without an express, case-by-case approval from legal. Many organizations take this approach for code licensed under GNU Affero General Public License version 3 (AGPL-3.0).

However, it's important to make contributions in a structured manner and organization-wide. It should govern both code contributions to existing projects and the publication of company-owned code under OSS licenses.


Drafting assistance from Shannon McNeal.

Written by Filipp Kofman
Filipp Kofman is Counsel for Davis Wright Tremaine LLP and member of the firm's technology, privacy, and security group. He advises clients on a broad range of technology transactions matters, including software licensing and open source management.