1---2name: open-source3description: Open source readiness best practices. Covers licensing, documentation, community health, CI/CD, compliance, legal, and packaging. USE WHEN: user mentions "open source", "license", "LICENSE", "CONTRIBUTING", "CODE_OF_CONDUCT", "CHANGELOG", "open source readiness", "community health", "OSS compliance", "SPDX", "CLA", "DCO", "OpenSSF", "SBOM", "release automation", "npm publish", "make project open source", "prepare for open source" DO NOT USE FOR: Git workflow and branching - use git-workflow skill, Code quality and linting - use qa-expert agent, CI/CD pipeline design - use devops-expert agent4---56# Open Source Readiness - Core Knowledge78> **Deep Knowledge**: Use `mcp__documentation__fetch_docs` with technology: `git-workflow` for Git-specific documentation.910## When NOT to Use This Skill1112This skill focuses on open source project setup and compliance. Do NOT use for:1314- **Git commands and branching** - Use `git-workflow` skill15- **Code quality and static analysis** - Use `qa-expert` agent16- **CI/CD pipeline architecture** - Use `devops-expert` agent17- **Package development (library code)** - Use language-specific skills1819## Essential Files Checklist2021| File | Purpose | Priority |22|------|---------|----------|23| `LICENSE` | Legal terms for use and distribution | Required |24| `README.md` | Project overview, install, usage, badges | Required |25| `CONTRIBUTING.md` | How to contribute (setup, PR process, style) | Required |26| `CODE_OF_CONDUCT.md` | Community behavior expectations | Required |27| `SECURITY.md` | Responsible disclosure process | Required |28| `CHANGELOG.md` | Version history (Keep a Changelog) | Recommended |29| `GOVERNANCE.md` | Decision-making process | Recommended |30| `.github/CODEOWNERS` | Auto-assign reviewers by path | Recommended |31| `.github/FUNDING.yml` | Sponsorship links | Optional |32| `CITATION.cff` | Academic citation metadata | Optional |33| `NOTICE` | Third-party attributions (Apache 2.0) | Conditional |3435## Quick Reference Guides3637| Topic | Guide | Covers |38|-------|-------|--------|39| Licensing | [licensing.md](quick-ref/licensing.md) | License selection, SPDX, CLA/DCO, compatibility |40| Documentation | [documentation.md](quick-ref/documentation.md) | README, CONTRIBUTING, CHANGELOG, ADR templates |41| Community and Governance | [community-governance.md](quick-ref/community-governance.md) | Governance models, maintainer path, communication |42| Repository Setup | [repository-setup.md](quick-ref/repository-setup.md) | .github/, templates, CODEOWNERS, branch rules |43| CI/CD and Automation | [ci-cd-automation.md](quick-ref/ci-cd-automation.md) | GitHub Actions, releases, dependency updates |44| Compliance | [security-compliance.md](quick-ref/security-compliance.md) | OpenSSF Scorecard, SBOM, supply chain |45| Legal and Packaging | [legal-packaging.md](quick-ref/legal-packaging.md) | License headers, NOTICE, publishing, signing |46| Metrics and Inclusivity | [metrics-inclusivity.md](quick-ref/metrics-inclusivity.md) | CHAOSS metrics, inclusive language, badges |4748## Decision Flowchart4950```51Project needs open source setup?52 - Just starting? -> Run full Tier 1 setup53 - Choose license -> licensing.md54 - Create docs -> documentation.md55 - Setup repo -> repository-setup.md56 - Add CI -> ci-cd-automation.md57 - Already has basics? -> Run audit, fill gaps58 - Missing compliance files? -> security-compliance.md59 - No community docs? -> community-governance.md60 - No release process? -> ci-cd-automation.md61 - Publishing a package? -> legal-packaging.md62 - Growing community? -> community-governance.md + metrics-inclusivity.md63 - Compliance audit? -> security-compliance.md + legal-packaging.md64```6566## License Quick Decision6768| If you want... | Choose |69|-----------------|--------|70| Maximum freedom, simple | MIT |71| Patent protection included | Apache 2.0 |72| Copyleft (derivatives must be open) | GPL v3 |73| Copyleft for libraries only | LGPL v3 |74| File-level copyleft (compromise) | MPL 2.0 |75| Network copyleft (SaaS must share) | AGPL v3 |76| Public domain equivalent | Unlicense or 0BSD |7778## Common Anti-Patterns7980| Anti-Pattern | Why It Is Bad | Best Practice |81|--------------|---------------|---------------|82| No LICENSE file | Code is NOT open source without one | Always include LICENSE |83| LICENSE in README only | Not legally clear | Separate LICENSE file |84| No CONTRIBUTING.md | Contributors do not know how to help | Clear contribution guide |85| No CODE_OF_CONDUCT | Unwelcoming community signal | Adopt Contributor Covenant |86| Hardcoded secrets | Credential exposure risk | Use environment variables |87| No .gitignore | Accidental binary commits | Comprehensive .gitignore |88| No CI pipeline | Untested contributions | GitHub Actions CI |89| No issue templates | Low-quality bug reports | Structured YAML templates |90| Manual releases | Error-prone, inconsistent | Automated release pipeline |91| No SECURITY.md | Issues reported publicly | Private disclosure process |