Tag Archives: chaoss

Part 2: Additional Sustainability Topics From the CHAOSS Practitioner Guides

This is the second post in a series, so I encourage you to go back to read the previous post about Building Healthy and Sustainable Projects Using CHAOSS Practitioner Guides if you haven’t already read it. The first post covered the introduction, contributor sustainability, responsiveness, and organizational participation, which were the original 4 guides in the series. 

Shortly after we launched the Practitioner Guide series, we followed up with three additional getting started guides on security, diverse leadership, and sunsetting a project. As I mentioned in the first post in this series, starting with the Practitioner Guide: Introduction – Things to Think about When Interpreting Metrics can help interpret metrics in light of your unique situation. Again, interpreting the metrics and figuring out what they are telling you is only useful if you take the additional step of driving appropriate actions to make decisions and improvements based on those metrics, and each guide provides recommended actions.

Security

Open source project security impacts the health and sustainability for our projects, which ripples out across the entire software ecosystem as dependency / supply chain components. Because security is a complex and critical topic, this Practitioner Guide: Getting Started with Security is designed only to get you started on your path toward improving the security of your project; it is not a comprehensive guide to everything you need to know about open source project security. The guide has suggested starter metrics that include OpenSSF Best Practices Badge, Libyears, and Release Frequency along with additional metrics that might also shed light on the security of a project. 

Recommendations for improvement from the security guide include:

  • Secure your code repository by managing access, implementing branch protection, managing contributions, and more.
  • Create a detailed security policy document (usually in a SECURITY.md file) with instructions for reporting security vulnerabilities along with documenting how the project will respond to those reports, including managing embargoes.
  • Keep your dependencies up to date and use tooling (e.g., Dependabot) to help identify and update your dependencies.
  • Make sure that your security fixes land in a release as soon as possible.
  • Working your way through the OpenSSF Best Practices badge criteria is also a good way to make security improvements.

Diverse Leadership

Without diverse leadership, underrepresented groups may face challenges in participating in and contributing to projects, losing valuable talent and ideas, so a huge thank you to Peculiar C. Umeh who drove the creation of the Practitioner Guide: Getting Started with Building Diverse Leadership! The guide focuses on three key metrics: Board/Council Diversity, Sponsorship (supporting people, not financial sponsorship), and Inclusive Leadership. The data collected can provide valuable insight, but storing, interpreting, and acting upon it requires careful thought to protect identities and be respectful of the people whose data has been collected.

Actions to take include to improve diverse leadership:

  • Start by creating and communicating clear pathways for contributors to grow into leadership roles, which may include creating sponsorship opportunities and transparent criteria for leadership positions.
  • Hold existing leaders accountable for promoting and improving inclusive leadership.
  • Implement programs that encourage diverse representation in leadership and promote diverse perspectives.
  • Regularly monitor and evaluate the diversity of all leadership roles by collecting and analyzing survey data and reporting progress to the community.

This was a challenging guide to write, and it can be a challenge to implement these recommendations. Open source communities are often global and encompass diverse people and backgrounds, so there is a need to avoid imposing a one-size-fits-all approach and be open to adapting strategies to fit the unique needs and values of different groups within your community. Each project should ensure that their practices are inclusive, making all members feel heard and valued, regardless of their background or identity.

Sunsetting (Winding Down and Archiving)

The Practitioner Guide: Getting Started with Sunsetting an Open Source Project is quite different from the other getting started guides because it’s not about making project health improvements or increasing sustainability, but instead about responsibly and proactively shutting a project down when it’s reached a natural end. It’s important to remember that not every open source project can or should exist forever: technologies evolve, corporate priorities change, and people’s interests change. Part of the beauty of open source is that we work in the open as we innovate, and some of those innovative projects will stand the test of time, while others should be responsibly deprecated via a sunset process. The guide looks at several metrics to determine whether a project is still active, Change Requests, Issues New, and Technical Forks, but the guide also covers other reasons for sunsetting a project. 

Once you’ve decided to sunset a project, there are several recommended steps:

  • Communication should start with any existing contributors, since there may be contributors who would like to continue the project. When you decide to sunset the project, this needs to be communicated to existing users in a transparent manner and being clear about the reasons for sunsetting it.
  • Do a code and security review to get it into the best possible shape before archival.
  • Review and resolve open issues and change requests (PRs / Merge Requests), including marking some as ‘won’t fix’.
  • Use the checklists and tools linked from the guide to help with this work.
  • Officially archive the repositories and consider adding the code to Software Heritage for preservation over time.
  • There are also recommendations for handling the special case of sunsetting an active project, which can happen when a company changes strategy or when an individual needs to step away. 

Sunsetting a project is not an indication of failure and should not be positioned as such. Projects have life cycles; they endure for as long as they are needed and then they should be responsibly deprecated when they are no longer needed. Consider providing transition details, and if possible, tooling that helps your existing users transition to an alternative solution if a reasonable one is available. I’d also like to express my thanks to Stefka Dimitrova whose work drove much of the content in the guide and to the team from the US Centers for Medicare & Medicaid Services OSPO who made significant contributions and improvements to the sunsetting guide.

Summary

Improving open source project security and increasing diverse leadership can help a project become more sustainable over time, but when a project has reached the end, it can be responsibly sunsetted, instead of being abandoned. The CHAOSS Practitioner Guide series can help with all of these activities. Come back next week for the next post in this series, ‘Determining Value and Viability Using CHAOSS Practitioner Guides’.

As always, if you want feedback or help with open source strategy, sustainability, governance, or related open source topics, I’m available for consulting engagements.

Additional Resources:

As with everything I write, this was written by a human without the use of LLMs or other AI assistance.

Part 1: Building Healthy and Sustainable Projects Using CHAOSS Practitioner Guides

Metrics can provide deep insights into our open source projects, but they can also be overwhelming, and because every open source project and every situation is a bit different, metrics require interpretation. And that’s only the first step. Interpreting the metrics and figuring out what they are telling you is only useful if you take the additional step of driving appropriate actions to make decisions and improvements based on those metrics. I’ve been working in open source and using metrics for decades, but for me the metrics have never been what’s important. They are simply the means to an end, a way to make improvements or demonstrate whether we are accomplishing our goals. 

This is why I focused on creating the CHAOSS Practitioner Guide series during my three years as CHAOSS Director of Data Science, and I’m proud of what we, as a community, accomplished with these guides. I’ve written quite a few blog posts about the individual guides, but I wanted to take some time here to reflect on the guides and talk about how they can be used together as a cohesive whole. The guides roughly break into two categories, which I’ll address in a series of four blog posts. The first category focuses on health and sustainability of open source projects. This post is about the first category, ‘Building Healthy and Sustainable Open Source Projects’, with part 2 coming next week to cover ‘Additional Sustainability Topics From the CHAOSS Practitioner Guides’. The second category of guides are the more advanced ones dealing with complex topics, like value, viability, and impact, that span multiple projects. Part 3 in the series focuses on value and viability while part 4 will cover determining impact.

Overview

We launched the Practitioner Guide series with a few getting started topics that apply to almost every open source project: contributor sustainability, responsiveness, and organizational participation.

The guides are paired with as ‘Introduction – Things to Think about When Interpreting Metrics’ as a starting guide with more details about how to interpret metrics in light of your unique situation. The introduction has general suggestions about how you should spend time understanding the goals of the project and talking to the people working within the project as key inputs into interpreting metrics. When it comes time to look at the metrics, focusing on trends over time for just a few metrics can help cut through the noise before drilling down into the details where there might be a potential issue. This is why each getting started guide focuses on just a few metrics to get started with tips for expanding to additional metrics as needed.

Every project is a little different, so it’s essential to interpret the metrics in light of a project’s individual needs and ways of operating. It’s also important to remember that metrics are more than just data, they represent actual human beings, so it’s important to be careful about comparing people against each other in ways that might result in the punishment of individuals. The non-human data (e.g., bots, automation, AI) should also be carefully taken into account in your interpretation of metrics. The Introduction – Things to Think about When Interpreting Metrics guide has more details about how to think about metrics and use what you’ve learned productively and ethically.

Contributor Sustainability

The Practitioner Guide: Getting Started with Contributor Sustainability focuses not just on determining whether you have enough contributors to sustain a project over the long-term, it also has tips for increasing contributor sustainability while keeping in mind that new contributors can also create additional burdens on the time of already overloaded maintainers. The guide includes Contributor Absence Factor, Contributors, and Types of Contributions as the key metrics to start investigating contributor sustainability.

To improve contributor sustainability, here are just a few of the recommendations from the guide:

  • Start by looking at your existing contributor base to determine whether you have people who are ready to step into a maintainer role, even if they start by maintaining just a sub-project. If there are people who are almost ready, some mentoring or reviewer roles might be a good first step. 
  • Before starting to recruit new contributors, it might help to review and update existing contributor guides and other onboarding documentation to help people get up to speed quickly while requiring less help from existing maintainers.  
  • Good first issues and help wanted labels can help new contributors get started on something productive, especially if those issues are created with the information that a new contributor needs to know to accomplish the task.
  • Be proactive about asking people for help with specific tasks. Knowing that we’re wanted and appreciated makes us feel good, which can be a strong motivator to contribute to an open source project or to continue contributing.
  • Defining the roles and responsibilities for contributors, reviewers, and maintainers as a contributor ladder where contributors can climb up to become reviewers and those reviewers can become maintainers can help with recruiting new people into these roles. 
  • Think about how people can move into leadership positions to be responsible for documentation, community management, marketing and other important roles.

Responsiveness

Responsiveness is one of the most important factors in attracting newcomers and retaining existing contributors for a project. The Practitioner Guide: Getting Started with Responsiveness uses Time to First Response, Time to Close, and Change Request Closure Ratio as the key metrics to help determine whether a project is responding to requests in a timely manner. It can be tempting to attempt to solve issues with responsiveness by putting more pressure on existing maintainers by asking them to respond more quickly and resolve more contributions, but this rarely solves the long-term problem. It might result in short-term gains, but it could be damaging to the community and the project over time if you are burning out your maintainers by not resolving the underlying problems that are causing the lack of responsiveness in the first place.

Some suggestions for improving responsiveness from the guide include:

  • As suggested in the contributor sustainability guide, start by looking at whether you can promote some existing contributors into reviewer or maintainer roles.
  • Use the project’s contributing documentation to set expectations about when to expect a response to a contribution.
  • Use issue and change request templates to help contributors make good contributions that require less work from maintainers.
  • Talk to your maintainers and find out where they are spending too much of their time and focus documentation or recruitment in those targeted areas.

Note that responsiveness is hard to diagnose because many things can impact responsiveness, so don’t be discouraged if your first attempt doesn’t result in improvement.

Organizational Participation

Organizations can have a significant impact on the health and sustainability of an open source project. On the one hand, organizations can help sustain projects over time by employing people to work on projects, but they also introduce risk (e.g., from relicensing, strategy shifts, acquisitions) when one organization is too dominant. From a contribution standpoint, it can be difficult if one organization has all of the influence and other people don’t feel like they are participating as equals.

The Practitioner Guide: Getting Started with Organizational Participation uses three primary metrics, Organizational Influence, Organizational Diversity, and Elephant Factor, to understand organizational participation. 

The recommendations for improving organizational participation depend on whether the improvement is coming from the dominant organization. From the dominant organization:

  • Contribution documents should be clear about whether contributions are accepted from people outside of the organization and whether those people can move into leadership positions. Transparency and setting expectations can reduce frustration from other contributors.
  • Spend some time thinking about why the project isn’t getting contributions from other organizations. Is all of the work happening in the open, and can others easily find decisions and discussions in public channels? If not, some work might be required to redirect private conversations into the public channels.
  • Promote opportunities to contribute via social media, conferences, and other channels.
  • Use your existing connections to other organizations who are using the project to encourage specific people to contribute.

From outside of the dominant organization: 

  • Engage in the project to determine whether contributions are really welcome.
  • If so, encourage your employees to contribute to the project as part of their time at work. Don’t expect employees to contribute to work projects in their free time.

Being transparent is critical. Saying one thing in the documentation and doing another can damage your organization’s reputation more than just being honest and transparent about how people can (or cannot) contribute to a project. If you are considering using an open source project as a key component of your organization’s products or infrastructure, you should think very carefully about that decision when that project is controlled by a single organization.

Summary

Increasing contributor sustainability, improving responsiveness, and garnering participation from a variety of organizations can all help improve the health and sustainability for an open source project. Check back next week for the second blog post in this series about security, diverse leadership, and sunsetting an open source project.

As always, if you want feedback or help with open source strategy, sustainability, governance, or related open source topics, I’m available for consulting engagements.

Additional Resources:

As with everything I write, this was written by a human without the use of LLMs or other AI assistance.

A Strategic Approach to Demonstrating the Value of OSS Efforts

OSPOs and other open source teams often struggle to demonstrate the value of their work in a way that resonates with the people in leadership positions within their organization. The topic of demonstrating open source value is one that I’ve been blogging about and giving presentations about frequently over the past year, so this blog post is a way for me to collect all of that work in one place to make it easier for people to find.

In the CHAOSS OSPO Working Group, which I co-chair, the topic of how to demonstrate the value of our work in open source has been a popular topic since we started the group many years ago. However, given the current financial climate and the number of OSPOs that have been the targets of cutbacks and layoffs, this feels like a particularly important topic right now.  This is why we created a CHAOSS Practitioner Guide all about Demonstrating Organizational Value, which I blogged about when the guide was launched.  In a second blog post on the topic, More about Demonstrating Organizational Value, I talked about the episode of CHAOSScast where Bob Killen and I joined Harmony Elendu to share our thoughts about how organizations can more effectively demonstrate the value of their open source efforts.

I expanded on this topic in another blog post, OSPO Contribution Strategies to Demonstrate Value. This post highlights how to articulate the importance of your contributions to upstream projects as part of a broader open source strategy, which often has 2 components: 1) identifying which projects are most strategic / critical for your organization and 2) creating contribution strategies for individual projects. The blog post has examples of how I did this when I worked at VMware and Pivotal.

I’ve also presented on this topic several times recently, but I wanted to highlight the two most recent talks, since they are the most comprehensive examples of these presentations. I blogged about my talk for the folks from CURIOSS (Community for University and Research Institution OSPOs) where I expanded on the content in the guide to also include more about how to demonstrate value in a university context. I further expanded it beyond corporate and university contexts to include how government / public sector organizations can demonstrate the value of their work in my talk at the Open Source Summit in Minneapolis a few weeks ago. Here’s the video and slides for this most recent version of the talk.

If you want feedback or help with your open source strategy and how to demonstrate value for your organization, I’m available for consulting engagements.

Related blog posts:

How OSPOs can Measure the Impact of OSS Funding

So much of the critical infrastructure that we all rely on contains open source projects that are under-resourced and struggling. One (of many) ways to help these projects is by funding development and maintenance so that contributors can focus on this work, but times are tough. Organizations and OSPOs are feeling the pinch, and it can be hard to justify continuing to fund open source projects. Measuring the impact of open source funding is something that I’m passionate about because the best way to continue to get leadership to give you money to fund open source is by showing them the impact of that funding. 

However, measuring the impact of funding isn’t easy, and there is no one approach, since the goals and objectives for funding vary widely for different types of funding organizations and different open source projects. It’s also important to consider that not all funding provides positive outcomes, since money can introduce tension within projects. In 2024 to help organizations navigate these challenges, I collaborated with several people to write an academic paper on this topic: A Toolkit for Measuring the Impacts of Public Funding on Open Source Software Development. We recently turned this paper into the CHAOSS Practitioner Guide: Funding Impact Measurement, which is much shorter and focused on practical steps that organizations can take to justify the impact of funding provided to open source projects and maintainers. 

The guide talks about the challenges of funding and the lessons we’ve learned along the way in addition to a section to help you navigate the actions that you can take to measure the impact. The “How to Take Action” section of the guide has three sections. 

  • First, start by understanding the context. This includes understanding the funding objectives and how the funding is structured for the projects being funded, considering project life stages and social structures, and accounting for salary structures and cost factors for different types of contributors across multiple regions.
  • Second, look at economic, social, and technological impacts across multiple dimensions. The potential social, economic, and technological impacts can be both positive and negative, direct and indirect, internal (i.e. within a project) and external (i.e. ecosystem), and manifest over different time horizons. The guide contains examples of how to think about each of these areas.
  • Third, using various methods to combine scalable quantitative measures along with contextual depth from qualitative data to better understand the funding impact. Mixed-methods approaches offer the best of both words: scalability and contextual depth. The guide and the paper have more details about how to do this.

This post doesn’t tell you how to justify getting new funding for open source efforts, so if you want to start funding open source projects, you need to demonstrate the value of that work to your leadership. There is a Demonstrating Organizational Value practitioner guide, and I’ve talked about demonstrating organizational value in several posts on this blog, which are linked in the “Related Resources” section below to provide a starting point. However, even if you haven’t yet started funding projects, you can still put together a plan for how you’ll measure the impact of that funding as part of demonstrating the value and making a case to your leadership along with the funding request.

I’ll conclude with a short quote from the guide:

“Funders need to be able to understand the impacts of past funding in order to secure buy-in for future funding as well as to adapting and/or innovating funding approaches whilst mitigating ineffective or even harmful approaches. We all benefit from more public institutions, philanthropic organizations, and companies giving money to open source; when done in a way that positive impact is the ultimate goal and objective. We hope that this guide helps organizations measure the impact of their funding initiatives so that we can increase the funding to open source projects to drive future improvements and allow these projects, and the people working on them, to become healthier and more sustainable over time.”

If you want help with measuring the impact of your funding or with other OSPO strategy topics, I’m available for consulting engagements.

Related Resources:

CURIOSS: Demonstrating Open Source Value

The lovely folks from CURIOSS (Community for University and Research Institution OSPOs) invited me to join them in March as part of their Deep Dive series of talks. I gave a quick overview of CHAOSS before diving into one of my favorite topics: demonstrating the value of open source efforts. This is the first time I’ve given this talk with some additional content about how to demonstrate value in a university / academic context, which is a bit different from how we think about value in corporate environments.

The slides and video are available for you to enjoy!

Related resources:

Transitions

TL;DR version: As planned, my time as the CHAOSS Director of Data Science has come to an end, but I’ll still be around the CHAOSS community as a board member and Working Group (WG) lead. I’ll be taking April and most of May off before transitioning into open source strategy consulting starting in June.

The CHAOSS Director of Data Science role was funded by an Alfred P. Sloan Foundation grant for 3 years, so the plan was always to move on to something else when it ended in March 2026. I’m very proud of what we’ve accomplished in 3 years, so a huge thank you to the folks at the Sloan Foundation for the funding that allowed me to focus on this over the past few years. When I started this work, one of the first steps was to create the CHAOSS Data Science WG, which has allowed us to grow the data science community. We started the Practitioner Guide series within the WG and have published almost a dozen guides on a wide variety of topics! We also launched several research projects in addition to the Relicensing and Forks project that I’ve been focused on over the past few years. You can learn more about what we’ve accomplished by reading our updates from January 2025, June 2025, and November 2025. I feel confident that the CHAOSS data science community and the WG are in good hands as I step down and leave the work in the very capable hands of the other 2 co-chairs, Cali Dolfi and Sal Kimmich, and maintainer, Ernest Owojori.

However, I’m not leaving the CHAOSS community. I’ll still be on the CHAOSS Governing Board and will continue co-chairing the OSPO WG, Funding Impact Measurement WG, and the Education WG. All of these WGs have co-chairs, so WG meetings will continue and nothing should change while I’m enjoying some time off to rest and recharge in April and May. The only exception to my time off is to attend the Open Source Summit in Minneapolis in May, since I didn’t want to miss it. I’m disappointed to need to say this, but I also wanted to make sure people know that this transition and the time off has been planned for over a year and has nothing to do with the current drama unfolding in the CHAOSS project this week.

What’s next? While I’ve enjoyed being able to focus on data and metrics over the past few years, I’ve found that I missed working on open source strategy, which has been my focus over the past two decades. The data science work was a fun diversion, but now I’m ready to get back to my roots. Starting in June, I’ll be shifting into open source strategy consulting. This is NOT a temporary solution while I figure out what to do next. My plan is to continue consulting on a part-time basis while I free up some time for my other hobbies (reading, working out / running, designing 3D prints, traveling), and to continue to do this for as long as I remain able to work. 

You can learn more about my consulting business on my consulting website, but here are a few focus areas:

  • Open Source Strategy: Crafting strategies for your OSPO, open source teams, or product teams that help employees focus their open source work in areas with the most impact along with demonstrating the value of your open source efforts to your executive team.
  • Contributor and Community Strategy: Strategies and techniques for growing your contributor base and improving sustainability for the open source projects driven by your organization and when working upstream.
  • Governance: Documenting and improving project governance processes for open source projects along with providing advice when there are governance issues or concerns.
  • Research and Data Analysis: Open to a variety of research and data projects to answer questions you have about open source projects from understanding an existing contributor base to doing audits of your GitHub organizations to understand the status of your repositories.

If you’d like my help in any of these areas, please reach out to me in June!

Funding Open Source Sustainability at CHAOSScon and FOSDEM

Open source sustainability impacts all of us, and unfortunately, we know that many open source projects are struggling. Maintainers are experiencing burnout, lack of funding, and a general lack of resources to sustain their projects over the long term. This is something that was top of mind for me while I was in Brussels for CHAOSScon EU, the Open Forum Europe (OFE) Summit, and FOSDEM.

At CHAOSScon, during the opening session, I talked about demonstrating the value of open source efforts with a focus on how to articulate the value within organizations so that the open source work can continue over time (slides), which is one aspect of sustainability that I’ve already talked about here on this blog. 

We also had a fishbowl panel all about funding for open source projects to wrap up the day at CHAOSScon. The funding panel covered a wide variety of topics, so here are just a few topics mentioned by the panelists:

  • Past vulnerabilities can be used to make the case for future funding (e.g., Germany’s Sovereign Tech Fund)
  • Money isn’t something that all open source maintainers want to spend time thinking about, and it can be a problem for communities to decide who gets funding?
  • We need more recognition by policy makers about the value of open source and need to revamp procurement to make it easier to use public money to fund open source. 
  • Funders need to understand the impact of their funding, but many corporate FOSS funders programs don’t have a focus on understanding and measuring impact.
  • Funding can be exploited when it’s not well-defined, and this can happen when people who aren’t particularly familiar with open source (e.g., policy, regulators, legal folks) are defining these programs.
  • Open Source Wishlist is an effort that Emma Irwin has been working on to bridge the gap between maintainers, funders, and practitioners.

I also attended several sessions in the FOSDEM Funding Devroom. Luckily, all of the devroom talks are recorded, since I wasn’t available to watch every talk, but I did pick up a few interesting tidbits from the talks that I did attend:

  • When measuring funding impact, quantitative data can help support credibility claims, but you also need qualitative data with narratives that carry meaning. 
  • Human sustainability is harder to measure than infrastructure impact, but maintainer health is a critical blind spot that should also be considered when making funding decisions.
  • Short term deliverables dominate impact measurement while long-term sustainability is undervalued because success often looks like nothing happened. 
  • Funding impact isn’t neutral. Funders’ visions shape everything: what / who gets funded, how impact is measured, and how work is valued. Funding from companies can bias development toward corporate interests. 
  • Funders often use a trust model where they fund people, projects, and organizations they trust, but that’s fragile because it’s personal, and people change roles. This is also hard to scale and creates bottlenecks. 
  • Funders often struggle to provide funding to individuals, since it’s often easier to fund projects or organizations.
  • Funding can be a time consuming and ongoing process for maintainers and projects to continue to find more funding when one wave of funding ends. 
  • It can also be hard for funders to work together to align processes and goals to create joint funding efforts.

Seeing more people talking about funding was great, and I really appreciated the thoughtful approach from several of the speakers about how funding isn’t a panacea. Funding doesn’t solve all of our sustainability issues, but it is one important tool that can help projects improve sustainability. If you are interested in learning more, we have a CHAOSS Funding Impact Measurement Working Group that meets every other Wednesday, and I am also available for consulting on this topic.

Related Resources:

Photo by micheile henderson on Unsplash

Sustainable Open Source Leadership

Sustainable leadership for open source projects is something that we all know is important, but it’s also one of those topics that can be neglected for far too long within a project. We’ve all seen projects where the same people sit in the same leadership positions year after year without providing opportunities for other contributors to move up within the project. Contributors can become disillusioned and disengage if they don’t feel like there are enough opportunities within a project, and since there are so many open source projects that need help, those contributors might just move on from your project to another one where they have more opportunities to participate and lead in a more meaningful way.

Sustainable open source projects and sustainable leadership is something that I’m deeply passionate about. I’ve had discussions about sustainability with more projects than I can count as part of my past role as co-chair of the CNCF Contributor Strategy Technical Advisory Group (TAG) and the Governance Working Group that was part of the TAG, and as part of my previous corporate open source roles when I worked at companies like VMware, Pivotal, and Intel. 

A few months ago, I published a 5-part blog post series about governance, and while all of the posts touch on sustainable leadership, Part 3: New Contributors and Pathways to Leadership is particularly relevant. But I’ve been thinking more about sustainable leadership lately, in part, because we recently recorded a CHAOSScast episode on diverse leadership to go along with the CHAOSS Practitioner Guide: Getting Started with Building Diverse Leadership, but also because we’ve been having discussions within the CHAOSS Governing Board about making the process for joining the board more inclusive. 

The CHAOSS Inclusive Leadership metric has several best practices that leadership bodies can reflect on as they work toward becoming more inclusive. This includes whether there are terms for leaders and regular opportunities for community members to get involved and have a voice in the project. 

Those of us who are established in our careers and in open source projects can use our influence and reputation in a project to help others gain visibility and opportunities that eventually result in other people moving into leadership positions. We call this sponsorship, which is more than just mentoring, and can include things like inviting someone to co-present or join a panel at an event, providing opportunities to collaborate together on some aspect of a project, or other activities that give people new opportunities to learn and lead. For me, it was Danese Cooper who encouraged me to blog and gave me opportunities for some of my first conference talks as part of panels and lightning talks that she was organizing. This gave my career in open source a huge boost back in the mid-2000s and helped me move from doing mostly internal corporate open source strategy roles into more publicly facing open source community roles that provided even more opportunities for me to lead.

As we move into the new year, I’d like to take this time to encourage everyone in a leadership position in an open source project to reflect on your governance processes and whether those processes provide ample opportunities for up and coming contributors to move into leadership roles. You could also be thinking about ways that you can personally provide more opportunities (aka sponsorship) for someone newer in their career or new to open source who is showing promise, but who could use your support to move to the next level.

Additional Resources:

If you want feedback or help with sustainable leadership, governance, or related open source topics, I’m available for consulting engagements.

Photo by Markus Winkler on Unsplash

Responsibly Sunsetting OSS Projects: A Guide for OSPOs

Not every open source software project can or should live on forever: priorities change, technologies evolve, and interests shift over time. From a corporate perspective, you don’t want to have neglected or abandoned open source projects with security vulnerabilities owned by your organization. However, responsibly sunsetting an open source project is more than just clicking the archive button on your repository. You should also be thinking about how you communicate the change and give any existing users time to transition. 

Your organization’s customers and the users of your open source projects might trust the projects found in your repositories because of their relationship with your organization. This is why it’s particularly important for companies to monitor the open source projects owned by the organization and responsibly sunset them when they will no longer be updated. One of the benefits of having an OSPO is that they can help the rest of the organization with processes and best practices for responsibly sunsetting projects. 

When I worked in VMware’s OSPO, we had a process for monitoring and sunsetting projects that we’ve documented in the CHAOSS Practitioner Guide: Getting Started with Sunsetting an Open Source Project. This guide uses change requests, new issues, and forks as metrics that can help you identify abandoned or neglected projects along with people who might still be using those projects. The guide also has communication steps for what to do before you archive the project, and there is even a section with special considerations for sunsetting active projects, which can happen when a company is making a shift in strategy and no longer plans to work on a project.

All of these details can be found in the guide, and you can also listen to the CHAOSScast podcast episode where Stefka Dimitrova and I recently discussed the guide and the process we used at VMware. Here’s a short quote from the guide:

“Many open source projects, even widely used ones, become abandoned for a variety of reasons (e.g., evolving interests, family situations, employment changes), but abandonment can be done in a responsible way by proactively sunsetting the project (Miller et al. 2025). Sunsetting is an important consideration for corporate environments where it can be easy to lose track of projects that were created by employees who later walked away from the project and left if abandoned. You don’t want abandoned open source projects with security vulnerabilities sitting in your organization’s source code repositories where someone might trust that project simply because they trust your organization. Finding inactive projects and responsibly sunsetting them is a good business decision and something that many open source teams / Open Source Program Offices (OSPOs) do on a regular basis.”

– The CHAOSS Practitioner Guide: Getting Started with Sunsetting an Open Source Project

If you want feedback or help with your sunsetting process or related OSPO topics, I’m available for consulting engagements.

Additional Reading:

More about Demonstrating Organizational Value

OSPOs and other open source teams often struggle to demonstrate the value of their work in a way that resonates with the people in leadership positions within their organization. This is why we created a CHAOSS Practitioner Guide all about Demonstrating Organizational Value, which I blogged about in July when the guide was launched. Since then, it’s still been something I’ve continued to spend quite a bit of time thinking about!

Bob Killen and I recently joined Harmony Elendu for an episode of CHAOSScast to share our thoughts about how organizations can more effectively demonstrate the value of their open source efforts. We talked about the guide and shared some of our own stories about what we’ve done at past companies to demonstrate the value of our teams’ open source work. It’s only 23 minutes long, so I hope you enjoy listening to our conversation!

I’ll also be at OSPOlogy Lyon on November 5 & 6 where I’ll be giving a 20 minute talk about Demonstrating the Value of Open Source Efforts, which is based partly on the content from the guide along with my own experience working within organizations to demonstrate open source value. It’s in person, but free to attend, so I hope to see some of you in Lyon!

OSPOlogy hosted by LF Energy and Réseau de Transport d’Electricité (RTE) on 5-6 November 2025 in Lyon, France on a purple-blue background. Profile picture of Dawn Foster with text underneath reading, Speaker Dawn Foster with the CHAOSS logo.

If you want feedback or help with your open source strategy and how to demonstrate value for your organization, I’m available for consulting engagements.

Related blog posts: