An independent network for people who build public services with Drupal

  • Open source

Checking who contributes: open source and public procurement

Two recent pieces, one from Drupal’s founder and one from LocalGov Drupal, make the same point from different sides: public money spent on open source should be easy to trace back to the project.

A speaker at a lectern on a stage, in front of large letters spelling DrupalCon.
Photo: Illek Petr, CC BY-SA 4.0, via Flickr

When a public body buys Drupal work, it is usually told that the supplier is “active in the community”. Two recent articles are useful if you want to test that claim, or write a brief that gets more from it.

The 60-second procurement test

In a post on 9 September, Drupal’s founder Dries Buytaert argues that open source projects with a commercial ecosystem should publish an official record of who contributes. His test for a good record is that a buyer can answer three questions in about a minute:

does this vendor contribute at all, how much do they contribute compared to other vendors, and do they work on the parts of the project I care about?

Drupal already has most of this. The post explains that Drupal has tracked contribution credits since 2015, that the system is now governed by the Drupal Association, and that it credits the organisations and customers who fund work as well as the individuals who do it. Those credits feed the Drupal.org marketplace, where buyers can look up and compare agencies.

He is careful about the limits. Contribution, he writes, “does not prove that a vendor can deliver”. It is one factor alongside delivery capability, expertise and price. His advice to buyers is to decide at the start how contribution should count in the decision, and then check what bidders say against the project’s record.

Why sharing code makes sense for councils

LocalGov Drupal made the case from the buyer’s side in an article on 18 August. Its argument is that councils keep paying to solve the same problems separately, and that sharing code lets commissioned work create value beyond a single contract.

The article points to existing government guidance. The Technology Code of Practice asks teams to be open and use open source, and to share, reuse and collaborate. The GOV.UK Service Manual’s guidance on making source code open and reusable says new code should be published in an open repository, and that this includes code developed for you by a third party such as a development agency.

It ends with one question to ask at the start of every project:

Could another council reuse this work?

What to put in your next brief

Taken together, the two pieces suggest a short list for anyone commissioning Drupal work:

  • Ask bidders how they contribute to Drupal, and check the answer on Drupal.org before you score it.
  • Say in the brief that reusable work should be contributed back, and ask where the code will live and who will maintain it.
  • Ask for your organisation to be credited on the work you fund. Drupal’s credit system has a place for the customer.
  • Review code before it is published. The Service Manual says you must make sure you do not release information that should remain closed.

Procurement was also on the programme at the Government Summit at DrupalCon Rotterdam, where one session was listed on how buying decisions could fund accessibility work in open source.