open-source

v2026.09.24

Open source readiness best practices. Covers licensing, documentation, community health, CI/CD, compliance, legal, and packaging. USE WHEN: user mentions "open source", "license", "LICENSE", "CONTRIBUTING", "CODE_OF_CONDUCT", "CHANGELOG", "open source readiness", "community health", "OSS compliance", "SPDX", "CLA", "DCO", "OpenSSF", "SBOM", "release automation", "npm publish", "make project open source", "prepare for open source" DO NOT USE FOR: Git workflow and branching - use git-workflow skill, Code quality and linting - use qa-expert agent, CI/CD pipeline design - use devops-expert agent

GitHub
Install command
npx skhub add claude-dev-suite/open-source
Markdown
SKILL.md

Open Source Readiness - Core Knowledge

Deep Knowledge: Use mcp__documentation__fetch_docs with technology: git-workflow for Git-specific documentation.

When NOT to Use This Skill

This skill focuses on open source project setup and compliance. Do NOT use for:

  • Git commands and branching - Use git-workflow skill
  • Code quality and static analysis - Use qa-expert agent
  • CI/CD pipeline architecture - Use devops-expert agent
  • Package development (library code) - Use language-specific skills

Essential Files Checklist

FilePurposePriority
LICENSELegal terms for use and distributionRequired
README.mdProject overview, install, usage, badgesRequired
CONTRIBUTING.mdHow to contribute (setup, PR process, style)Required
CODE_OF_CONDUCT.mdCommunity behavior expectationsRequired
SECURITY.mdResponsible disclosure processRequired
CHANGELOG.mdVersion history (Keep a Changelog)Recommended
GOVERNANCE.mdDecision-making processRecommended
.github/CODEOWNERSAuto-assign reviewers by pathRecommended
.github/FUNDING.ymlSponsorship linksOptional
CITATION.cffAcademic citation metadataOptional
NOTICEThird-party attributions (Apache 2.0)Conditional

Quick Reference Guides

TopicGuideCovers
Licensinglicensing.mdLicense selection, SPDX, CLA/DCO, compatibility
Documentationdocumentation.mdREADME, CONTRIBUTING, CHANGELOG, ADR templates
Community and Governancecommunity-governance.mdGovernance models, maintainer path, communication
Repository Setuprepository-setup.md.github/, templates, CODEOWNERS, branch rules
CI/CD and Automationci-cd-automation.mdGitHub Actions, releases, dependency updates
Compliancesecurity-compliance.mdOpenSSF Scorecard, SBOM, supply chain
Legal and Packaginglegal-packaging.mdLicense headers, NOTICE, publishing, signing
Metrics and Inclusivitymetrics-inclusivity.mdCHAOSS metrics, inclusive language, badges

Decision Flowchart

Project needs open source setup?
 - Just starting? -> Run full Tier 1 setup
     - Choose license -> licensing.md
     - Create docs -> documentation.md
     - Setup repo -> repository-setup.md
     - Add CI -> ci-cd-automation.md
 - Already has basics? -> Run audit, fill gaps
     - Missing compliance files? -> security-compliance.md
     - No community docs? -> community-governance.md
     - No release process? -> ci-cd-automation.md
 - Publishing a package? -> legal-packaging.md
 - Growing community? -> community-governance.md + metrics-inclusivity.md
 - Compliance audit? -> security-compliance.md + legal-packaging.md

License Quick Decision

If you want...Choose
Maximum freedom, simpleMIT
Patent protection includedApache 2.0
Copyleft (derivatives must be open)GPL v3
Copyleft for libraries onlyLGPL v3
File-level copyleft (compromise)MPL 2.0
Network copyleft (SaaS must share)AGPL v3
Public domain equivalentUnlicense or 0BSD

Common Anti-Patterns

Anti-PatternWhy It Is BadBest Practice
No LICENSE fileCode is NOT open source without oneAlways include LICENSE
LICENSE in README onlyNot legally clearSeparate LICENSE file
No CONTRIBUTING.mdContributors do not know how to helpClear contribution guide
No CODE_OF_CONDUCTUnwelcoming community signalAdopt Contributor Covenant
Hardcoded secretsCredential exposure riskUse environment variables
No .gitignoreAccidental binary commitsComprehensive .gitignore
No CI pipelineUntested contributionsGitHub Actions CI
No issue templatesLow-quality bug reportsStructured YAML templates
Manual releasesError-prone, inconsistentAutomated release pipeline
No SECURITY.mdIssues reported publiclyPrivate disclosure process
Discovery
Tags

No tags published for this skill.

Version
Latest version metadata

Version

v2026.09.24

Published

Sep 24, 2026

Category

Uncategorized

License

MIT

Source path

skills/best-practices/open-source

Default branch

main

Latest commit

9496306

Tree SHA

fe4e2f1