A New Look at How Governments Treat Open Source

Government policies are increasingly shaping the software landscape, and GitHub Policy is backing an effort to track those policies more closely. The company is supporting a refresh of the Center for Strategic and International Studies (CSIS) dataset on government policies related to open source software—a resource that has been updated periodically since its original release.

The dataset catalogs public policies from around the world that reference open source, with entries dating back to 1999. CSIS maintained the dataset through seven editions, with the last one published in 2010. Over the years, it has served as a reference for developers and researchers; a previous version, for instance, was used in a study linking GitHub activity to startup formation across different countries.

Why This Update Matters Now

The renewed attention comes at a time when governments are increasingly recognizing that contributing upstream to open source projects offers security and influence over the software they depend on. One example is the German Sovereign Tech Fund, which supports maintainers of critical open source infrastructure. Additionally, proposed regulations such as the EU's Cyber Resilience Act and AI Act highlight how much open source is intertwined with broader tech policy discussions.

This makes it essential to have accurate, current data on how governments are approaching open source—both for researchers and for policymakers shaping future regulation. The updated dataset is intended to fill that gap.

Launch and Community Input

GitHub's Chief Legal Officer Shelley McKinley joined a CSIS panel to mark the dataset's release, alongside Laura Cunningham of the Open Technology Fund, Allan Friedman of the U.S. Cybersecurity and Infrastructure Security Agency, Frank Nagle of Harvard Business School, and dataset co-author Eugenia Lostri. Their conversation centered on the growing role of open source in cybersecurity, how to measure its impact, and the need to support the communities that maintain and depend on it.

With the dataset now public, those behind it are inviting contributions. Anyone who spots a policy mentioning open source that isn't in the catalog, has ideas for expanding the dataset beyond initial findings, or wants to cross-reference it with other data can open an issue or submit a pull request on the GitHub repository for the project.