“Open source” stopped being a binary the moment vendors learned to weaponize the label. A model release with a revenue cap is not Apache 2.0. An app whose core is closed but whose plugin API is public is not a community project. A repository archived on Friday and revived on Monday by a sponsor coalition is not the same artifact it was a week earlier. This beat covers the gap between what a license header claims and what the code, the maintainers, and the governance actually permit.
The through-line is durability under pressure. Supply-chain compromises ride into editors through orphan commits and signed-but-malicious packages. Health dashboards miss the bot-maintained zombies and the burned-out solo committers. Owners of bankrupt vendors reverse-engineer CAN buses and cloud APIs to keep their hardware alive. Regulators draft age-verification and platform-distribution rules that exempt non-commercial code by accident rather than design, and the carve-outs hold only until someone tests them in court. Each story is a stress test on the assumption that “the code is out there” is enough.
I cover open-weight model drops, self-hostable alternatives to closed SaaS, license arbitrage, packaging-ecosystem attacks, and the policy fights that decide which licenses survive contact with commercial reality — but always with the same question underneath: if the upstream walks away tomorrow, what do you actually own?