open-source.sgit.ai / what's next
What's next
The build order is published with its open questions visible, because a position that hides what it has not yet settled is advertising. This page is what is built, what is next in order, and the open questions — seven still open and one decided — several of which are decisions for the project rather than research tasks for the site.
What is built
| Section | State | Note |
|---|---|---|
| /views/ — the argument | shipped | The position, sovereignty, open core, the villagers. Each with its counter-case attached. |
| /survivability/ | shipped | The argument, the stress test as a working tool, and the self-audit, run on the estate itself. |
| /history/ | shipped | Six corrections leading, timeline behind them, six success stories, and the numbers with the unpublishable ones named. |
| /practice/ | partial | The three licences and Apache-vs-MIT are written. Q5, the licence alignment, is decided: CC BY. |
| /agents/ | partial | The argument ships. Four theses are named and next to be written — the most original writing still available. |
| /funding/ | shipped | Three proposals compared for the first time, a position taken, and cURL. |
| /owasp/ | partial | Summit history ships from the public record. The first-person account is the author's to write, and is planned. |
| /founders/ | shipped | Owning the code, or opening it — the guidance from a strategy session with another founder, released CC BY. |
| /about/ | shipped | The author, the companies the strategy runs on, and interests declared. |
| Agent surface | shipped | Markdown twin at every URL, self-sufficient llms.txt, llms-full.txt — all three enforced in CI. |
What is next, in order
- An SBOM of the estate, and a licence audit in CI. The single highest-value item on the list: it is roughly a day's work and it converts the labelling argument from a proposal into a demonstration. The site asks companies to declare their supply chain; this is the estate's own declaration. One manual licence review exists (February 2026 — 17 transitive dependencies, an SPDX table, a clean verdict); the automated, continuous version is the item.
- The four agent-era theses — licence compliance at machine speed, provenance of AI-generated code, training-data licensing, and what CC BY means for machine reuse. Each follows obviously from material that exists; none is written.
- A licence taxonomy. Copyleft versus permissive as a position, compatibility, where AGPL fits, and how to treat source-available. The history research supplies the ground; the position is next.
- The first-person OWASP account, and six project retrospectives — thirteen questions, already published, that only the author can answer. O2 Platform, MGraph-DB, OSBot, memory_fs, sgit-ai, Issues-FS: why each was open-sourced, and what happened next.
- A trademark policy. The clearest quick win from the self-audit: publishing one costs almost nothing and removes the worst of the ambiguity even while the holder stays the same.
- Separately licensing the schemas. The cheapest of the self-audit fixes, and there is no good argument against it.
- Visual assets. A timeline, a licence-family diagram, a map of the estate. The timeline and the four-leg test both want a picture.
The open questions — seven open, one decided
| # | Question | Where it stands |
|---|---|---|
| Q1 | Is the customer subset open core or packaging? | The test is proposed: does the customer build contain anything the public repo does not? The June and July positions are both published, and the July document names the tension itself. Needs a decision, not more analysis. |
| Q2 | Which funding model? | A position is now taken — they address three different failures and were never competitors. Still: none costed, none piloted, and the value-contribution calculation unsolved. |
| Q3 | Does the junior pipeline restructure, or break? | March and July say opposite things, four months apart. What would settle it is a cohort measurement nobody appears to be making. The villagers argument depends on the July answer. |
| Q4 | Would the estate change to pass its own stress test? | Leg by leg, with what each fix requires. The honest answer on leg one may be "no, and here is why that is an accepted risk" — still publishable, and better than silence. |
| Q5 | Was CC0 on the articles deliberate? | Decided, 6 September 2026: no — CC BY. The CC0 in the published-articles repository was drift, not a third layer; the documents layer is CC BY 4.0 throughout and the repository's licence file follows. Recorded on the practice page. |
| Q6 | Do agents help or harm open-source sustainability? | Current evidence says harm — cURL's bounty closed 31 Jan 2026, vulnerabilities reported up 107%. Is that a transition cost or the steady state? Nobody knows, and this site declines to claim the optimistic answer. |
| Q7 | Is "open source AI" coherent without training data? | The OSI's definition exists and drew heavy criticism; almost no model marketed as open source meets it. The author's 2025 position, and a browser vendor now betting on the open-weight side of the line. |
| Q8 | What does this site owe a community it does not have? | The position that open source is right even with zero contributions is coherent — and it means governance, review and codes of conduct are not yet written about here, despite the survivability argument turning on DCO-versus-CLA in practice. The next contributor relationship is where that page gets written. |
Where this site stops
Several arguments here sit on a boundary with a sibling site, and the rule is one canonical copy, cross-linked rather than a duplicate on each.
| Site | Owns | The shared edge |
|---|---|---|
| wardley-maps.sgit.ai | Mapping technique; Explorer/Villager/Town Planner as a pattern | "Somebody has to be the villagers" — they own the pattern, this site owns the NFR market argument. |
| standards.sgit.ai | Instruments, provisions, crosswalks, the SPDX machinery | Licence compliance at machine speed — they own the machinery, this site owns the argument. |
| graphs.sgit.ai | Graph theory, meaning through connectivity | Semantic OWASP and the PBOM. This site owns the why; graphs owns the how. |
| pki.sgit.ai | Keys, signatures, the registry design | Provenance of AI-generated code — they hold the signing machinery, the licensing argument belongs here. |
| sgit.ai | The parent project and the vault layer | Should link here for the licence and sovereignty argument. |