Open Source Ideals Clash with Corporate Export Policies on GitHub
Description
This is a screenshot of a GitHub pull request discussion, displaying a conflict between open source principles and corporate policy. The top of the image shows a closed pull request titled "Add Flux.unfold #3897". The first comment is from a user named 'mminella', who states that as a project stewarded by Broadcom, they cannot accept contributions from 'Russian sources' due to the company's export policy. Below this, another user, 'LashaDev', expresses confusion and challenges the decision. They question if the rejection is based on the contributor's nationality, which would contradict the project's 'Contributor Covenant Code of Conduct'. LashaDev quotes a section of the code of conduct emphasizing a harassment-free experience for everyone, regardless of nationality, and then asks 'mminella' to clarify the policy and the term 'Russian sources'. The image captures a real-world dilemma where the global, collaborative nature of open-source software development collides with legal and geopolitical restrictions imposed by corporate stewards, in this case, Broadcom, likely in response to international sanctions
Comments
7Comment deleted
I guess 'permissionless innovation' has a new gatekeeper: the corporate legal department. Your PR is not merged pending a full OFAC review
CI summary: Build ✅ Tests ✅ CodeQL ✅ Contributor Covenant ✅ OFAC Compliance ❌ - turns out the hardest part of distributed systems is distributing patches across embargo lines
When your open source project's inclusivity statement collides with export control laws, and suddenly you're explaining why your code accepts everyone except those whose commits might violate ITAR regulations
When your pull request gets rejected not because of failing tests, merge conflicts, or code quality issues, but because of your passport. Turns out 'works on my machine' has evolved into 'works in my jurisdiction.' Who knew that after decades of open source preaching borderless collaboration, the biggest blocker wouldn't be technical debt but export compliance? At least now we know what 'enterprise-grade' really means: geopolitically-aware CI/CD pipelines that check your IP address before your code quality
Flux PR meets ultimate backpressure: not from publishers, but Broadcom's export controls
Open source in 2025: CI stages are lint, tests, license scan, and OFAC - green code, red passport; turns out the hardest dependency to upgrade is your jurisdiction
Modern PR pipeline: lint ✅, tests ✅, SAST ✅, CLA/DCO ✅, OFAC ❌ - merge blocked with a polite “Thanks for your continued use,” a.k.a. HTTP 403 for humans