open-source.sgit.ai / what's next

What's next

The build order is published with its open questions visible, because a position that hides what it has not yet settled is advertising. This page is what is built, what is next in order, and the open questions — seven still open and one decided — several of which are decisions for the project rather than research tasks for the site.

What is built

SectionStateNote
/views/ — the argumentshippedThe position, sovereignty, open core, the villagers. Each with its counter-case attached.
/survivability/shippedThe argument, the stress test as a working tool, and the self-audit, run on the estate itself.
/history/shippedSix corrections leading, timeline behind them, six success stories, and the numbers with the unpublishable ones named.
/practice/partialThe three licences and Apache-vs-MIT are written. Q5, the licence alignment, is decided: CC BY.
/agents/partialThe argument ships. Four theses are named and next to be written — the most original writing still available.
/funding/shippedThree proposals compared for the first time, a position taken, and cURL.
/owasp/partialSummit history ships from the public record. The first-person account is the author's to write, and is planned.
/founders/shippedOwning the code, or opening it — the guidance from a strategy session with another founder, released CC BY.
/about/shippedThe author, the companies the strategy runs on, and interests declared.
Agent surfaceshippedMarkdown twin at every URL, self-sufficient llms.txt, llms-full.txt — all three enforced in CI.

What is next, in order

  1. An SBOM of the estate, and a licence audit in CI. The single highest-value item on the list: it is roughly a day's work and it converts the labelling argument from a proposal into a demonstration. The site asks companies to declare their supply chain; this is the estate's own declaration. One manual licence review exists (February 2026 — 17 transitive dependencies, an SPDX table, a clean verdict); the automated, continuous version is the item.
  2. The four agent-era theseslicence compliance at machine speed, provenance of AI-generated code, training-data licensing, and what CC BY means for machine reuse. Each follows obviously from material that exists; none is written.
  3. A licence taxonomy. Copyleft versus permissive as a position, compatibility, where AGPL fits, and how to treat source-available. The history research supplies the ground; the position is next.
  4. The first-person OWASP account, and six project retrospectivesthirteen questions, already published, that only the author can answer. O2 Platform, MGraph-DB, OSBot, memory_fs, sgit-ai, Issues-FS: why each was open-sourced, and what happened next.
  5. A trademark policy. The clearest quick win from the self-audit: publishing one costs almost nothing and removes the worst of the ambiguity even while the holder stays the same.
  6. Separately licensing the schemas. The cheapest of the self-audit fixes, and there is no good argument against it.
  7. Visual assets. A timeline, a licence-family diagram, a map of the estate. The timeline and the four-leg test both want a picture.

The open questions — seven open, one decided

#QuestionWhere it stands
Q1Is the customer subset open core or packaging?The test is proposed: does the customer build contain anything the public repo does not? The June and July positions are both published, and the July document names the tension itself. Needs a decision, not more analysis.
Q2Which funding model?A position is now taken — they address three different failures and were never competitors. Still: none costed, none piloted, and the value-contribution calculation unsolved.
Q3Does the junior pipeline restructure, or break?March and July say opposite things, four months apart. What would settle it is a cohort measurement nobody appears to be making. The villagers argument depends on the July answer.
Q4Would the estate change to pass its own stress test?Leg by leg, with what each fix requires. The honest answer on leg one may be "no, and here is why that is an accepted risk" — still publishable, and better than silence.
Q5Was CC0 on the articles deliberate?Decided, 6 September 2026: no — CC BY. The CC0 in the published-articles repository was drift, not a third layer; the documents layer is CC BY 4.0 throughout and the repository's licence file follows. Recorded on the practice page.
Q6Do agents help or harm open-source sustainability?Current evidence says harm — cURL's bounty closed 31 Jan 2026, vulnerabilities reported up 107%. Is that a transition cost or the steady state? Nobody knows, and this site declines to claim the optimistic answer.
Q7Is "open source AI" coherent without training data?The OSI's definition exists and drew heavy criticism; almost no model marketed as open source meets it. The author's 2025 position, and a browser vendor now betting on the open-weight side of the line.
Q8What does this site owe a community it does not have?The position that open source is right even with zero contributions is coherent — and it means governance, review and codes of conduct are not yet written about here, despite the survivability argument turning on DCO-versus-CLA in practice. The next contributor relationship is where that page gets written.

Where this site stops

Several arguments here sit on a boundary with a sibling site, and the rule is one canonical copy, cross-linked rather than a duplicate on each.

SiteOwnsThe shared edge
wardley-maps.sgit.aiMapping technique; Explorer/Villager/Town Planner as a pattern"Somebody has to be the villagers" — they own the pattern, this site owns the NFR market argument.
standards.sgit.aiInstruments, provisions, crosswalks, the SPDX machineryLicence compliance at machine speed — they own the machinery, this site owns the argument.
graphs.sgit.aiGraph theory, meaning through connectivitySemantic OWASP and the PBOM. This site owns the why; graphs owns the how.
pki.sgit.aiKeys, signatures, the registry designProvenance of AI-generated code — they hold the signing machinery, the licensing argument belongs here.
sgit.aiThe parent project and the vault layerShould link here for the licence and sovereignty argument.