Dries Buytaert Proposes License-only and Stewarded Open Source Terms

Licence Terms Do Not Measure Maintenance, Security, or Operational Support
Vertical TDT card about open-source stewardship. Title: “Open Licences Do Not Guarantee Stewardship.” Deck: “Dries Buytaert’s proposed labels separate source-code rights from ongoing maintenance, security response, governance, and infrastructure support.”

Software released under the same open-source licence can differ sharply in how it is maintained and supported. Dries Buytaert, founder of Drupal, proposed “License-only Open Source” and “Stewarded Open Source” in a blog post published 9 July 2026. The terms distinguish legal permission to use, modify, and redistribute code from the maintenance, security response, release management, governance, and infrastructure surrounding a project.

The proposal is not a new licensing standard or formal open-source classification. The Open Source Initiative defines open source through the licensing criteria in its Open Source Definition, while the Open Source Project Security Baseline provides maturity-based controls for project security practices. The European Union’s Cyber Resilience Act separately defines an “open-source software steward” as a legal person providing sustained support for certain free and open-source products intended for commercial activities. That legal category carries regulatory obligations and is not equivalent to Dries’s proposed descriptive terms.

In Dries’s framing, License-only Open Source covers code shared without a commitment to updates, fixes, vulnerability response, or long-term support. Stewarded Open Source describes projects where maintainers and supporting organisations review contributions, manage releases, handle vulnerabilities, operate infrastructure, and provide continuing care. He cites Drupal as an example of stewardship whose infrastructure and maintenance cost millions of dollars each year, arguing that organisations benefiting from that work should recognise the responsibilities and funding behind it. The proposal offers vocabulary for discussing dependency risk and sustainability, but it does not itself certify a project’s maintenance or security posture.

Disclosure: This content is produced with the assistance of AI.

Note: The vision of this web portal is to help promote news and stories around the Drupal community and promote and celebrate the people and organizations in the community. We strive to create and distribute our content based on these content policy. If you see any omission/variation on this please reach out to us at #thedroptimes channel on Drupal Slack and we will try to address the issue as best we can.

Related Organizations

Related People

Upcoming Events