AGPL and Government Contracting

By Brandon Graves, Partner

Open source software is widely used both by the government and by government contractors. Open source libraries are frequently integrated into software delivered to the government, and most developers understand how to integrate open source code properly.

However, relatively new open source licenses are designed to reduce the availability of these tried and true development models. Government contractors, especially software developers, need to be aware of these licenses and the potential impact on how they deliver software.

What is Open Source Software and Why Does it Matter?

Open Source Software is software governed by a license that meets the criteria defined by the open source initiative. The full criteria are beyond the scope of this post, but the first two are worth mentioning: the license “shall not restrict any party from selling or giving away the software . . .” and the “program must include source code, and must allow distribution in source code as well as compiled form.”

Open source licenses are typically defined as permissive or copyleft, which is often broken down into weak and strong copyleft licenses. Permissive licenses create minimal restrictions and focus on proper attribution to the original authors. Copyleft licenses typically require that derivative works remain open source.

The requirement that derivative works remain open source can cause some concern. Some commentators go so far as to label such licenses as “viral licenses.” This takes concerns too far, but concerns do remain.

Most responsible software developers have development practices that address these concerns. One prominent method is to deliver software that includes open source components through a software as a service (SaaS) model. Because SaaS does not distribute the software, it does not trigger any of the traditional requirements in open source software licenses.

AGPL and New Concerns

The open source community has consistently updated licenses to address new technology. In response to the ubiquity of SaaS, the GNU organization introduced the Aggero General Public License (AGPL). The AGPL “is a modified version of the ordinary GNU GPL version 3. It has one added requirement: if you run a modified program on a server and let other users communicate with it there, your server must allow them to download the source code corresponding to the modified version running there.” Due to these changes, some large companies such as Google prohibit the use of any code subject to AGPL.

This change in the language creates new concerns that government contractors should be aware of. Some of these include that the integration of AGPL licensed software components may require distribution of source code, even in a SaaS application, and even to nongovernmental entities. Second, the government may be entitled to demand source code that was not included in the deliverables. Third, the inclusion of such components may directly violate the contract because of the nature of the license.

This does not mean that AGPL is incompatible with government work. In fact, the government has released certain software under an AGPL license. It is important to understand the issues that AGPL can raise in government contracting and mitigate those issues through proper design choices.

If you don’t understand open source licenses generally, or AGPL in particular, don’t use code subject to those licenses without talking to someone who does. If you have concerns about how to mitigate the risks of open source licenses, reach out to the author of this post at bgraves@centrelawgroup.com.

Share
LinkedIn
X
Facebook