The Change-of-Control Stress Test
Four questions to ask about any open-source dependency you are betting on. Every one is answerable from public artefacts — a repository, a licence file, a trademark register, a foundation charter — which means you can run this without the vendor's cooperation, without a procurement process, and without telling anyone you are doing it.
"The stress test is a query, not an interview. 'Show me the CLA' and 'show me who holds the trademark' are answerable from public artefacts, and a vendor that cannot answer them has answered them."
-
Leg 1 Copyright structure
Who holds copyright in the code, and could one party relicense the next release?
Where to look:
CONTRIBUTING.md, aCLA.mdor CLA-bot check on pull requests,Signed-off-by:lines in the commit log (a DCO signal), and the copyright headers in source files. Unclear is not neutral — see the verdict note below. -
Leg 2 Trademark holder
Who owns the name, and what would stop them using it against a fork?
Why it is a separate leg: a fork can take the code and cannot take the name. Losing the name means losing the search results, the documentation people have bookmarked, the package identifier, and the recognition a new user needs to find you at all. Trademark is how a fork is made expensive even when it is legally permitted.
-
Leg 3 Schema licence
Are the data schemas and formats licensed separately, and openly?
The leg everyone skips. The schemas matter as much as the code: your data is only portable to the extent that its structure is something you may reimplement. A schema bundled with a code licence that later changes moves with it — and an undeclared schema is a dependency with no terms at all.
-
Leg 4 Fork capacity
If the terms changed tomorrow, who would actually run the fork?
The test is whether you can name them. illumos existed and OpenSolaris users had somewhere to go; OpenTofu and Valkey existed within weeks because organisations with engineers decided to fund them. A fork is not a right that gets exercised automatically — it is a payroll, and if nobody's payroll is available, the right is theoretical.
Answer the four legs to see the verdict.
How to read the verdict
This is not a score. Four passes does not mean "safe" and one fail does not mean "avoid" — plenty of excellent software fails legs one and two, including software you should absolutely keep using. What the four legs tell you is what kind of exposure you are carrying, so you can price it, plan for it, or decide it does not matter for this dependency.
A single-holder project you use for something easily replaced is a fine risk. The same structure under something with your data in it, five years of integration around it, and no named fork capacity is a different proposition entirely — and the point of the test is that you find that out before the announcement rather than during it.
Why we do not publish scores for named vendors
We ship the test; you run it. Publishing a scorecard about named commercial projects would turn a diagnostic into a weapon, and it would be a weapon wielded by a participant in the same market — which is exactly the conflict the test is designed to let you route around. The four legs work without us.
The one exception is running it on our own estate, in public. That is the self-audit →