licensingforkingrelicensingresearchcommunity-diversity

CHAOSS — What Happens to Relicensed OSS Projects and Their Forks?

Identifies relicensing as a critical health event that destroys contributor diversity and validates the superior organizational sustainability of foundation-led forks.

Summary

Relicensing popular open-source projects to more restrictive, non-OSI-approved licenses (e.g., SSPL, BSL, RSAL) frequently triggers hard forks and fundamental community disruption. CHAOSS case studies of Elasticsearch (forked to OpenSearch), Terraform (forked to OpenTofu), and Redis (forked to Valkey) reveal that relicensing typically results in a near-total flight of external organizational contributors within six months. For the Redis project, all major external contributors (including employees from Amazon, Alibaba, and Tencent) stopped committing immediately following the license shift. Conversely, forks led by neutral foundations have demonstrated rapid growth in organizational diversity, with the Valkey project recruiting 29 contributors from 10 different companies within its first six months—suggesting that foundation-led forks often achieve higher sustainability and security review capacity than the single-vendor projects they replace.

Related Checks

LICENSE_MODIFIED

Relicensing to restrictive, non-OSI-approved licenses (SSPL, BSL) is documented to cause a 100% loss of external organizational contributors within six months.

Adverse Outcome

unintentional legal exposure to restrictive commercial licenses that have replaced previously open versions

Because

detecting license changes is critical for identifying 'relicensing' events that trigger the collapse of a project's community oversight.

SOURCE_SINGLE_CONTRIBUTOR

The research finds that relicensed projects (like Elasticsearch and Terraform) functionally become single-company projects with 95%+ of code authored by employees.

Adverse Outcome

dependency on a project that has lost its independent review community and is now controlled by a single vendor's commercial interests

Because

maintainer concentration is the definitive outcome of relicensing, making it a reliable proxy for the loss of community-driven security review.

Gaps Analysis

Evidence

In the six months after the relicense, all of the external contributors... stopped contributing. Redis had strong organizational diversity before the relicense, but only Redis employees made significant contributions afterward.

Blind Spot

Risk Guard evaluates technical signals but does not explicitly flag 'License-Change Events' as a high-risk indicator for maintainer flight.

Actionable Capability

Risk Guard would be better if it integrated a 'License Change Alert' that specifically flagged recent shifts to non-OSI-approved or source-available licenses.

← Previous Next →