More federal open source appreciated, if it behaves

Shutterstock / Pictofigo

Technology companies have welcomed the White House's recently unveiled policy that seeks to make software code used by federal agencies more open, sharable and reusable, but they're concerned about a few details.

Federal CIO Tony Scott announced a draft Federal Source Code policy on March 10 that would create a new set of rules for custom code developed by or for the federal government. The proposal is now open for comment on GitHub.

"Over the last two decades, we've seen open source bring more choice and flexibility to government IT," Gunnar Hellekson, director of product management at Red Hat, told FCW. "Many of the government's most innovative IT initiatives are built with open source. More open source is always a good thing."

The policy requires that custom code developed and paid for by the federal government be made available for reuse across federal agencies. Additionally, it would require a portion of that new custom code to be released to the public as open-source software.

"But not all open source is created equal," Hellekson said. "There's a significant difference between upstream or 'free' open-source software and what you'd consider 'enterprise-grade' or appropriate for government adoption in support of mission-critical systems."

Agencies must understand the difference because they might not have the resources to release the code or enough muscle to participate in the communities that support its development, he added.

Trey Hodgkins, senior vice president of the Information Technology Industry Council's IT Alliance for Public Sector, made a similar distinction.

"The dynamic has to be understood" as federal agencies move toward using more open-source code, he told FCW, adding that "it doesn't mean software is going to be free" for federal agencies. "It has to be licensed and managed."

He said ITI is talking to White House officials about making sure the policy remains technology-neutral and that business models for companies aren't endangered.

Some commenters on Github were also concerned about how open-source code would be maintained in the future.

Dave Taht, co-founder of the Bufferbloat Project and guest researcher at Karlstadt University who posts on GitHub as "dtaht," said making sure code is properly maintained and regularly updated is important in a world where bugs can be exploited worldwide in a matter of hours.

He attached a letter he and Internet pioneer and Google Vice President Vint Cerf sent to the Federal Communications Commission in October 2015. Signed by 260 cybersecurity and network experts, the letter asks the FCC to develop a new approach to improve Wi-Fi router security and manage open-source technology.

The letter recommends that the new approach mandate that to maintain FCC compliance, vendors of software-defined, wireless or Wi-Fi radios must make public the full and maintained source code for device drivers and firmware. In addition, the source code should be in a buildable, change-controlled repository on the Internet, available for review and improvement by all.

About the Author

Mark Rockwell is a senior staff writer at FCW, whose beat focuses on acquisition, the Department of Homeland Security and the Department of Energy.

Before joining FCW, Rockwell was Washington correspondent for Government Security News, where he covered all aspects of homeland security from IT to detection dogs and border security. Over the last 25 years in Washington as a reporter, editor and correspondent, he has covered an increasingly wide array of high-tech issues for publications like Communications Week, Internet Week, Fiber Optics News, magazine and Wireless Week.

Rockwell received a Jesse H. Neal Award for his work covering telecommunications issues, and is a graduate of James Madison University.

Click here for previous articles by Rockwell. Contact him at or follow him on Twitter at @MRockwell4.


  • Defense
    Ryan D. McCarthy being sworn in as Army Secretary Oct. 10, 2019. (Photo credit: Sgt. Dana Clarke/U.S. Army)

    Army wants to spend nearly $1B on cloud, data by 2025

    Army Secretary Ryan McCarthy said lack of funding or a potential delay in the JEDI cloud bid "strikes to the heart of our concern."

  • Congress
    Rep. Jim Langevin (D-R.I.) at the Hack the Capitol conference Sept. 20, 2018

    Jim Langevin's view from the Hill

    As chairman of of the Intelligence and Emerging Threats and Capabilities subcommittee of the House Armed Services Committe and a member of the House Homeland Security Committee, Rhode Island Democrat Jim Langevin is one of the most influential voices on cybersecurity in Congress.

Stay Connected


Sign up for our newsletter.

I agree to this site's Privacy Policy.