Score
Designs, builds, and maintains software or other artifacts intended for public distribution under open-source licenses, including repository structure, licensing and contribution policies, packaging and release workflows, CI/CD automation, documentation, and community contribution processes. Evaluates and manages project health, license compliance, dependency and security risks, and contribution metrics to sustain and grow an open-source ecosystem.
License compliance for open-source components is critical in software development, yet developers frequently face legal and reputational risks due to challenges in license identification, unclear understanding of downstream obligations, and inadequate tooling support. This study presents the first interdisciplinary empirical investigation jointly conducted by software engineering and legal experts. Through 58 surveys and 7 in-depth interviews with practitioners, it systematically characterizes developers’ compliance practices, core challenges, and current tool usage. The analysis yields 15 key findings—including frequent license misclassification, breakdowns in cross-role collaboration workflows, and poor comprehensibility of legal terminology—highlighting critical gaps between legal requirements and developer cognition. Based on these insights, the study proposes empirically grounded design principles for developer-centric compliance tools and actionable policy recommendations. It thus provides a foundational evidence base for building human-centered, automated, and legally integrated compliance support systems.
This study addresses the challenges of open-source software governance, where ambiguously defined roles and permissions often lead to unclear accountability and excessive burdens on core maintainers. For the first time, it systematically analyzes governance documents such as GOVERNANCE.md in GitHub projects, applying institutional grammar to structurally dissect roles in terms of their scope, authority, obligations, and lifecycle. The research uncovers a phenomenon termed “role drift” and identifies the “maintainer paradox”: while core contributors foster community engagement, they frequently become bottlenecks in governance. Empirical findings reveal substantial variation in responsibilities among identically named roles across projects and demonstrate that a small number of individuals often concentrate technical, managerial, and community-facing functions. These insights provide critical foundations for improving role design and enhancing the sustainability of open-source communities.
The accountability, sustainability, and robustness of open-source projects remain poorly understood as they transition from founder-led governance to community-driven models. Method: Leveraging GOVERNANCE.md files from 637 GitHub repositories, we develop a scalable semantic parsing pipeline that systematically traces governance evolution—integrating version-control analysis, extraction of institutional roles/behaviors/permissions, and clustering-based modeling. Contribution/Results: We find governance maturation does not stem from discursive shifts but from progressive responsibility layering and refinement: persistent role and behavioral differentiation, increasing clarity of oversight functions, strengthened ecosystem-level collaboration, and growing regulatory balance. This work establishes the first large-scale empirical framework and reusable methodology for studying governance evolution in open-source digital public infrastructure.
This study addresses the widespread practice of directly copying open-source code to bypass dependency management, which obscures license compliance risks. Leveraging the World of Code dataset, the authors construct a code reuse network through large-scale clone detection and quantify, for the first time at the scale of the entire open-source ecosystem, the compliance risks arising from such copy-paste reuse. Their analysis reveals that 39.4% of project compositions entail potential license conflicts, yet conventional dependency analysis tools capture only 2.43% of these instances, indicating severe under-detection. Integrating network modeling and regression analysis, the study further finds that code under permissive licenses such as MIT and Apache is reused across programming languages more frequently, whereas public-domain-licensed code exhibits comparatively lower reuse rates.
Open-source license variants—ranging from minimally modified standard licenses to fully custom terms—are pervasive yet poorly understood across ecosystems like PyPI; existing tools fail to reliably detect them, leading to compliance risks and flawed license analysis. This paper presents the first large-scale empirical study characterizing such variants, revealing widespread textual divergence but rare substantive modifications—many of which nonetheless introduce critical license incompatibilities. To address this, we propose LV-Parser, a lightweight license parser leveraging differential analysis and LLM-assisted validation, achieving 0.936 accuracy with 30% lower computational overhead; and LV-Compat, a dependency-aware compatibility checker that improves detection rate by 5.2× and attains 0.98 precision. Together, they form an end-to-end automated pipeline that significantly enhances license identification accuracy and compliance assessment efficacy.
This study addresses the unclear distribution of software licenses in open-source projects and their impact on code reuse and project activity. Leveraging a dataset of over 100 million open-source repositories, this work presents the first large-scale analysis of license adoption trends across programming language ecosystems and examines how license changes influence project activity over time. Through data mining and time-series comparisons, the authors find that most projects lack an explicit license, while permissive licenses have steadily increased in prevalence. Notably, the C ecosystem exhibits a preference for restrictive licenses, and transitioning from restrictive to permissive licensing correlates with decreased activity in C projects—contrasting sharply with Python projects, which show significantly enhanced activity following such transitions. These findings demonstrate that the effects of licensing strategies are highly dependent on the language ecosystem, challenging assumptions of universal applicability.
研究分析了200多个开源网络安全项目,识别许可类型和语言,发现宽松许可项目中存在限制性许可污染问题,并提出改进措施。
Existing open-source licenses lack a systematic, large-scale methodology for comparing permissiveness. This work proposes the first approach leveraging large language models to conduct pairwise comparisons among mainstream licenses, constructing a partial order based on license permissiveness and mapping it onto established classification schemes. By doing so, it elucidates interpretable legal constraint dimensions underlying combinations of license terms. The method not only effectively recovers key attributes associated with more restrictive licenses but also provides an extensible framework for license compliance analysis and selection, supporting platforms such as GitHub and Hugging Face.
本文通过分析开源软件项目中关于AI贡献的政策,提出AI贡献治理框架,旨在解决AI对代码生产、文档编写等影响下维护者评估贡献者的问题。
This study addresses the sustainability challenges faced by open-source software projects due to the attrition of core contributors, a problem exacerbated by the lack of effective mechanisms for accurately assessing the technical capabilities of potential successors. To bridge this gap, we propose the first code-metric-based framework for contributor competency evaluation and task matching. By analyzing source code contribution metrics and integrating machine learning techniques, our approach establishes a reproducible, quantitative model of developer capability. This model not only identifies developers with high potential to assume critical roles but also predicts the competency level required to successfully complete specific tasks. The resulting data-driven insights offer actionable support for talent selection and development, thereby significantly enhancing the resilience and continuity of open-source projects.