Skip to content
Documentation menu

Open-source verification

Public repositories under an OSI-approved licence get the full reviewer, free forever. This page is how a repository earns that, and what can un-earn it.
LiveFree for every qualifying repository, on every plan tier.

What qualifies

  • The repository is public, and stays public. Going private pauses the free tier at the next review.
  • The licence is OSI-approved — matched against the OSI's published list, not a hand-picked subset. MIT, Apache-2.0, BSD, MPL-2.0, GPL family: all fine.
  • The repository has real review traffic. This is a reviewer's plan, not a parking spot: zero-activity repositories age out of verification after 90 days and can re-verify in one click.

How the check runs

Verification happens at review time, not at install time. When a pull request opens on a repository, the reviewer resolves the licence file against the OSI list, records the match (licence, commit, timestamp) with the review, and applies the Open source entitlements from that point on.

There is no form, no waiting list, and no manual approval step for the common cases. The first pull request after install is the verification event.

What the free tier includes

  • All review depths — quiet, balanced, and thorough.
  • Up to 12 reviews per hour, 400 changed files per pull request.
  • Secret scanning and deterministic checks in the review, team learnings, and suppression memory — the same machinery paid private-repo teams get.
  • About 600 reviews a month included at the org level; reviews pause when they run out — never billed by surprise.
  • Outside contributors never count against anything. Maintainers do not pay for other people's pull requests.

What is not included

Nothing is feature-gated below the paid tiers except scale: the Open source plan does not include private repositories, and enterprise controls (SSO, audit export, self-hosting) belong to the Enterprise tier.

If verification is lost

A repository that goes private, swaps to a non-OSI licence, or goes dormant drops back to the Free plan's limits at the next review. Nothing is deleted: findings, learnings, and suppression memory stay, and re-verification restores the free entitlements in one review cycle.

The licence data comes from the repository itself at review time; if the licence file moved or is unusual, @superdiffs config shows what the reviewer resolved and where.