The argument
Why this exists
Almost no organisation can say what its software is built on, or who is behind it. Nobody has ever asked them to look.
On this page
The thing nobody does
In February 2024 a Microsoft engineer noticed that sshd logins on a Debian test
machine were taking about half a second longer than they should. He was investigating a
performance anomaly. What he found was a backdoor in xz utils, a compression
library present in effectively every Linux distribution on earth, placed there over roughly
two years by someone who had patiently worked their way into the trust of the project’s
single, exhausted, unpaid maintainer.
The interesting part is not the attack. It is that nobody was looking. Not one of the thousands of organisations depending on that library had any idea that a critical piece of their infrastructure rested on one tired volunteer, because none of them had ever had a reason to find out.
The same shape recurs without any attacker at all. Formik is an enormously popular React form library. It quietly stopped being actively maintained while thousands of teams kept building on it, and most of those teams did not notice for years. Before that: event-stream, left-pad, log4j. Each time the lesson is written down and each time nothing changes, because the lesson requires somebody to go and look, and looking is nobody’s job.
Most organisations genuinely cannot answer “what are we standing on?” Not will not. Cannot. There is no document, no owner, no process, and nobody has ever asked them for one.
So the purpose of this licence is not extraction. It is education. It makes an organisation understand, once a year, the chain its software comes to it through: the mechanics, the people, and how fragile the whole arrangement is. Whatever giving follows from that is a second-order effect, and a welcome one, but the looking is the product.
What SBOM answers, and what it leaves out
This is about to stop being voluntary. The EU Cyber Resilience Act has been in force since December 2024. From September 2026, vulnerability and incident reporting obligations apply, with a 24-hour early warning and a 72-hour full notification. From December 2027, full compliance arrives: machine-readable SBOM, conformity assessment, CE marking, secure by design, vulnerability handling, security updates across a declared support period.
The practical dependency matters more than either date. You cannot meet a 24-hour reporting obligation without already knowing what is in your software. So a very large number of organisations are, right now, being compelled to enumerate their dependencies for the first time.
They will end up holding a complete and accurate list of components, and no information whatsoever about the health of the people behind them.
| Question | Answered by SBOM? |
|---|---|
| What am I running? | Yes That is exactly what it is for. |
| What version, what licence, what known CVEs? | Yes |
| Who maintains this? | No |
| Are they paid? By whom? | No |
| How many of them are there? | No |
| Which of my dependencies has one exhausted maintainer? | No |
That missing column is the whole opportunity. It is the natural next layer on top of work that is becoming mandatory anyway, and as far as we can tell nobody has built it. Everyone builds payments platforms instead.
It also happens to be the version of this argument that gets funded. “Which of your dependencies has one exhausted maintainer?” is a business continuity question and it gets budget. “Are you giving back fairly?” is a moral question and it gets a nod. The ethics ride along free once the looking has happened.
Why the licences we have do not help
Permissive licences ask nothing
MIT, BSD and Apache 2.0 won on adoption, and deservedly so. But their entire posture toward the maintainer is a disclaimer of warranty. There is no point in the lifecycle of an MIT-licensed dependency at which anybody is prompted to consider who wrote it. That is a feature for adoption and a hole in everything else.
Copyleft compels the wrong act, to the wrong audience
AGPL-3.0 is the strongest instrument commonly available, and it has two properties that matter here.
First, its obligation runs only to users. If you run modified AGPL software as a service, you must offer the corresponding source to the people using that service. Not to the public. Which is why, in practice, almost nobody has ever seen anybody’s source. There is no audience, so there is no accountability, so the clause does almost no work in the world.
Second, it protects the code. That is what it is for. But for a platform whose value increasingly sits in a shared data layer rather than in the runtime, code copyleft defends the half that matters least, at the cost of the corporate adoption that would fund the rest. Grafana is AGPL and Amazon Managed Grafana exists anyway. Logseq is AGPL, has forty thousand stars, a fractured community and a paid sync tier its own users resent. The licence protected nothing that turned out to matter.
Copyleft compels you to share your changes. This compels you to know your suppliers. They are not competing answers to the same question. Nothing currently in wide use asks the second one at all.
Why “you should give back” fails in both directions
This has been tried. The Pay It Forward License exists. Its operative sentence says recipients should pay it forward, and its own FAQ confirms there is no actual obligation. So it is MIT plus a sentiment.
It has, as far as any search can establish, no adopters, no discussion and no criticism. And the diagnosis is worse than “it did not catch on”. It fails in both directions at once:
- It extracts nothing, because “should” is not an obligation and everyone involved knows it.
- It still costs something, because it is a non-standard licence, so every compliance scanner in every enterprise flags it for manual legal review.
All cost, no effect. And the underlying reason generalises well beyond that one licence:
Vagueness feels generous but lands as risk.
A corporate lawyer cannot approve “do something kind”. It is an unbounded liability with no way to know when it has been discharged, and their job is to say no to exactly that. They can approve “publish an annual statement”, because the cost is knowable, the work is finite, and completion is provable. Counterintuitively, a defined $10-a-seat fee is easier to get through legal than an undefined moral duty.
So the design rule is: be specific about the obligation and silent about the substance. Tighten the fields, loosen the content.
The precedent: food labelling
Nobody legislated that people should care about how chickens are kept. They legislated that the label must say. Caring followed, and then producer behaviour followed the caring, and none of it was ever compelled.
This is a better precedent than carbon disclosure for four reasons. Everyone understands it instantly. It was fought hard at the time and is now completely uncontroversial. It mandates disclosure rather than behaviour. And it changed producer behaviour anyway, without ever telling a producer what to do.
That is this design exactly. The floor is zero. You must publish. Nobody is told what to do about what they find.
Food labelling is statutory. This does by private licence what the state did by law, which fairly invites the question “who made you the regulator?” The honest answer is that this is not regulation, it is an industry norm: a sector adopting a labelling practice voluntarily, ahead of regulation it can see coming. If it turns out to be a good idea, the right end state is that a standards body owns it and this site becomes a footnote.
The codified version already exists
The closest thing to this design that is already law is section 54 of the UK Modern Slavery Act 2015, and the Australian equivalent. In-scope companies must publish an annual statement about slavery and human trafficking in their supply chain, on their own website, signed at board level.
Read the mechanics of it and it is startlingly familiar:
| Modern Slavery Act s.54 | This licence |
|---|---|
| Annual statement | Annual declaration |
| Published on your own website | Published at your own .well-known path |
| No certifying body | No certifying body |
| No minimum performance bar; “we took no steps” is a valid statement | Floor is zero |
| Enforcement is essentially reputational | Enforcement of content is entirely reputational |
| Failure to publish is the breach | Failure to publish is the breach |
Companies comply. Not perfectly, and the statements are often thin, but the regime is workable and it is real law in two countries. This matters because the most common objection to a zero-floor disclosure obligation is that it is toothless and therefore pointless. Legislatures have already decided otherwise, in a domain with much higher stakes.
Why the floor is zero
The obvious improvement, every time this is described to someone, is: make them give something. Even a token. Surely a floor of one dollar is better than a floor of nothing.
It is not, and the reasons compound.
- Any amount is a fee. The moment the licence names a number it is a commercial licence with a royalty, and everything about how it is received changes.
- A fee needs a payee. Someone has to receive it, account for it and distribute it, honestly, forever.
- A payee is an institution, and institutions die. An obligation owed to a body that no longer exists is impossible to discharge, which makes every licensee an infringer through no fault of their own. This is not hypothetical. It is precisely how the previous attempt at this licence failed, and it is why the domain this site sits on is named after something abandoned.
- A fee has to be variable, and a variable fee is unapprovable. Inflation alone forces it. A schedule that one party can change unilaterally is a hard no at any corporate legal review, correctly.
So the licence contains no numbers at all. Suggested amounts, percentages of spend, recommended splits: these are real and useful things and they belong in the standard, which is non-binding, revisable, and where being wrong costs nothing.
What you get in exchange for giving up the teeth is the thing nobody else has: a licence a lawyer will approve and a public record of who is freeloading. Permissive gives you the first. Copyleft attempts the second and fails for want of an audience.
Objections worth taking seriously
“Everyone will publish a two-line nothing.”
Many will, and that is compliant. But two things follow anyway. The organisation had to walk its tree to write even the thin version, so the looking happened. And the thin version is public and permanent and sits next to a competitor’s better one. Modern slavery statements went the same way and got slowly better under exactly that pressure.
“Nobody will read these.”
Probably true of any individual declaration. It does not need to be read by humans to work. It needs to be machine-readable and aggregated, which is what registries are for, and the interesting artefact is the aggregate: which projects everything depends on, and which of those have nobody behind them.
“This is unenforceable in practice.”
In the sense that nobody will sue: correct, and true of nearly every open licence ever written. Enforcement is not the mechanism. Compliance scanning is. Once a licence is in your dependency tree, its obligations turn up in an automated report, and organisations comply with things that turn up in automated reports.
“You have made yourself the regulator.”
Addressed above, and taken seriously enough that separability is a hard requirement rather than an aspiration. The licence works for anyone. The format works with no licence at all. Governance should end up somewhere that is not a sole developer in New Zealand. See the open questions.
“The privacy exposure is unacceptable.”
It would be, if the declaration listed everything. It does not. Only components in a public registry are ever counted, proprietary internal work never appears, and there is no field for how much you withheld, because “we have 43 proprietary components” is competitive intelligence. The privacy rules are part of the format.