Skip to content

Open Source software "under their responsibility" #151

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
oej opened this issue Feb 28, 2025 · 3 comments
Open

Open Source software "under their responsibility" #151

oej opened this issue Feb 28, 2025 · 3 comments
Assignees

Comments

@oej
Copy link

oej commented Feb 28, 2025

Recital 18 says:

"This Regulation does not apply to natural or legal persons who contribute with source code to products with digital elements qualifying as free and open-source software that are not under their responsibility."

What is the definition of "under their responsibility" ?

When does a person become responsible for open source code and products?

  • By owning a certain share of the copyright?
  • By not having commit rights?
@bukka
Copy link
Contributor

bukka commented Mar 17, 2025

I think this is somehow related to the control of the project that I mentioned here: #16 (comment) . I think this is something that would be good to get some clarification on.

@mrybczyn
Copy link
Contributor

I think that this is a very important question and it has a link with some other subjects. For example, an organization that supports an open source project (i.e. close to an open source steward) that could not enforce their decisions, are they "in" or not? This case actually applies to a number of organizations supporting open source projects that only handle administrative and as is today, they can't enforce a vulnerability reporting policy, for example.

@oej
Copy link
Author

oej commented Apr 7, 2025

If two persons from a company gets selected to a project steering group with three persons or an Open Source project - does the project end up in the company's control?

If there are ten developers with merge rights on a GitHub-based project and six are employed by the same company - does the project end up in the company's control?

We really need clarification of what this means and how a company needs to manage this.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
Status: Needs triaging
Development

No branches or pull requests

6 participants