Every government GitHub organization on the official governments.yml list, counted: what they publish, what is still maintained, and how much of it anyone outside government has actually contributed to.
The list at government.github.com is the closest thing that exists to an official register of government open source. It is maintained by GitHub, and governments add themselves to it. This analysis enumerates all 1,079 organization handles on it, then every public repository each one owns, then the merge history of every repository that is still alive.
Two facts about the list shape everything that follows. First, it is opt-in. No government appears on it that did not choose to. Whatever these numbers show is therefore a best case, not a representative sample of government technology. Second, it is well maintained: only 2 of the 1,079 handles no longer resolve, so the picture below is not an artifact of link rot.
Between them these organizations hold 75,638 public repositories. The distribution is extremely uneven: the median organization has 15 repos, while the largest single one, Norway's labour and welfare agency navikt, has 3,098. Fifty-five listed organizations have none at all.
The United Kingdom, with 212 organizations, publishes more public code than the United States does with 332.
| Bloc | Orgs | Public repos | Active | Active rate | Repos w/ outside PR |
|---|---|---|---|---|---|
| United States | 332 | 17,114 | 3,419 | 20.0% | 615 |
| United Kingdom | 212 | 24,314 | 8,484 | 34.9% | 1,726 |
| Other national | 509 | 30,497 | 9,235 | 30.3% | 1,482 |
| Multilateral (UN, EU, other) | 26 | 3,713 | 1,199 | 32.3% | 142 |
| Total | 1,079 | 75,638 | 22,337 | 29.5% | 3,965 |
Publishing a repository and maintaining one are different acts. Filtering the 75,638 repos down to those a person could actually work on removes roughly four out of five.
Forks account for 8,670. A further 875 are empty. The largest single deduction is archiving: 22,082 repositories, 29.2% of everything on the list, are already archived, which on GitHub means read-only by explicit choice. What remains after requiring a push inside 12 months is 22,337 repos, and requiring that issues are open and a license is present leaves 15,577.
Only 20.6% of government public repositories are simultaneously alive, accepting issues, and carrying a license. A repository without a license is not open source in any legal sense: default copyright applies, and a contributor has no clear right to use or modify the code they are being invited to improve.
The sharpest test is not whether a repository is public but whether anyone outside the organization has successfully changed it. For all 22,337 living repositories this study read the 15 most recently updated merged pull requests and classified each author by their relationship to the organization.
Most living government repos do merge pull requests: 70.8% merged at least one in the last 12 months. But the overwhelming majority of that traffic is internal.
GitHub organization membership can be private. When it is, a staff engineer's pull request is reported with exactly the same author association as a stranger's. Spot checking confirmed this: on alphagov/govuk-frontend, several of the accounts labelled as outside contributors are GOV.UK Design System developers.
So the raw 53.6% figure is an upper bound, not an estimate. To get a floor, this study excluded any "outside" author who had merged pull requests into three or more separate repositories belonging to the same organization, a pattern that describes staff rather than a passing contributor. That cuts the figure to 17.8% of living repos, or 5.2% of all government public repositories.
Because the threshold is a judgement call, here is the full sensitivity range rather than a single number.
| Staff filter | Repos | % of all repos | % of active repos | Distinct contributors |
|---|---|---|---|---|
| No filter (raw) | 11,982 | 15.8% | 53.6% | 7,715 |
| Author in 8+ org repos | 7,562 | 10.0% | 33.9% | 6,832 |
| Author in 5+ org repos | 5,859 | 7.7% | 26.2% | 6,172 |
| Author in 4+ org repos | 4,992 | 6.6% | 22.3% | 5,725 |
| Author in 3+ org repos | 3,965 | 5.2% | 17.8% | 5,093 |
| Author in 2+ org repos | 2,574 | 3.4% | 11.5% | 3,868 |
Inside the United States the pattern runs against intuition. Federal agencies, which are furthest from the public, publish the most code by a wide margin and are the most open to outside contribution. The layers of government closest to residents, cities and counties, are the least active on both measures.
All 53 U.S. state-level organizations combined publish 1,256 public repositories. The United Kingdom's tax agency alone publishes 1,792.
| U.S. category | Orgs | Public repos | Active | Active rate | Repos w/ outside PR |
|---|---|---|---|---|---|
| Federal | 164 | 10,833 | 2,278 | 21.0% | 480 |
| Special District | 10 | 884 | 243 | 27.5% | 7 |
| States | 53 | 1,256 | 293 | 23.3% | 36 |
| Military and Intelligence | 17 | 869 | 175 | 20.1% | 26 |
| City | 66 | 2,773 | 371 | 13.4% | 57 |
| County | 18 | 484 | 56 | 11.6% | 8 |
| Tribal Nations | 3 | 10 | 2 | 20.0% | 0 |
| Local Law Enforcement | 1 | 5 | 1 | 20.0% | 1 |
| U.S. total | 332 | 17,114 | 3,419 | 20.0% | 615 |
Outside contribution is not evenly spread. It concentrates in a small number of organizations that have built the habit deliberately, and they are disproportionately British and Nordic. The U.K. Ministry of Justice alone attracted more distinct outside contributors in a year than every U.S. state, city and county organization combined.
NASA is the strongest performer in the United States by a wide margin, with more than twice the outside contributors of the next American organization.
| Country | Orgs | Public repos | Active | Active rate | Repos w/ outside PR |
|---|---|---|---|---|---|
| United Kingdom | 212 | 24,314 | 8,484 | 34.9% | 1,726 |
| Canada | 58 | 5,352 | 1,723 | 32.2% | 282 |
| Norway | 31 | 5,255 | 2,172 | 41.3% | 363 |
| France | 45 | 3,255 | 963 | 29.6% | 197 |
| Sweden | 44 | 2,156 | 655 | 30.4% | 51 |
| Australia | 44 | 1,962 | 361 | 18.4% | 62 |
| Finland | 16 | 1,763 | 585 | 33.2% | 104 |
| Netherlands | 19 | 1,533 | 474 | 30.9% | 72 |
| Brazil | 37 | 1,401 | 318 | 22.7% | 60 |
| Germany | 26 | 1,235 | 518 | 41.9% | 86 |
| Spain | 20 | 968 | 252 | 26.0% | 9 |
| Switzerland | 21 | 527 | 167 | 31.7% | 30 |
| Italy | 7 | 445 | 130 | 29.2% | 11 |
| New Zealand | 12 | 414 | 95 | 22.9% | 23 |
| Japan | 4 | 128 | 6 | 4.7% | 0 |
Everything above answers a question about the estate. None of it helps the person deciding whether to spend a weekend on one repository. That is a different question, and it has a cheaper answer: read the last 80 merged pull requests and look at who wrote them.
GitHub stamps every pull request with an author_association, the author's standing in that repository at the time it was opened. OWNER, MEMBER and COLLABORATOR are inside the organization. CONTRIBUTOR has had a pull request merged before but is not a member. NONE and FIRST_TIME_CONTRIBUTOR have no merged work there yet.
The instinct is to count the last group, on the theory that newcomers getting work merged is what openness looks like. That reading fails in both directions, and the ways it fails are the useful part.
On ckan/ckan, 17 of the last 80 merged pull requests carried NONE. Read literally, that is a fifth of all merges going to people with no prior standing, which would make it one of the most welcoming repositories in this study. Every one of those 17 was ckanbot, the project's own release automation.
The distortion runs the other way too. On GSA/notifications-admin, 61 of the last 80 merges are Dependabot. The repository looks busy. Nineteen of those merges were written by a human.
Any count that includes bots is measuring continuous integration, not community.
Organization membership on GitHub can be private, and when it is, a staff engineer's pull request carries exactly the same association as a stranger's. On alphagov/govuk-frontend, the CONTRIBUTOR bucket is led by NickColley, seaemsi and 36degrees, who are GOV.UK Design System developers. Nothing in the API says so.
So CONTRIBUTOR cannot be read as "outsider". It is the bucket where a contractor roster and a real community both live.
Not the label. The number of distinct people behind it, and how concentrated their work is. A contractor roster is a handful of names doing nearly everything. A community is a longer tail, each name appearing once or twice.
| Repository | Bot merges | Human merges | Inside | CONTRIBUTOR merges | Behind them | Top 3 share | Newcomers |
|---|---|---|---|---|---|---|---|
| GSA/notifications-admin | 61 | 19 | 0 | 19 | 2 | 100% | 0 |
| cds-snc/platform-forms-client | 5 | 75 | 48 | 27 | 5 | 85% | 0 |
| alphagov/govuk-frontend | 42 | 38 | 8 | 30 | 7 | 80% | 0 |
| ckan/ckan | 29 | 51 | 20 | 31 | 11 | 68% | 0 |
Last 80 merged pull requests per repository, read on 13 August 2026. "Behind them" counts the distinct people in the CONTRIBUTOR bucket. ckan is not a government project and is included as a control, because it is the kind of civic-adjacent open source that governments actually deploy, and it shows what the same measurement looks like when a project does have a contributor community.
The gradient is legible. GSA/notifications-admin has two non-member humans merging anything at all, and they account for every non-bot merge in the window. cds-snc and alphagov sit in the middle, with small teams that include private members. ckan has eleven distinct non-member names and the flattest distribution of the four.
Across all four repositories, in 320 merged pull requests, the count of merges by someone with no prior standing in the repository was zero.
Not low. Zero.
Whatever these projects are doing, none of them merged a first pull request from a newcomer in the window measured. That is the census finding restated at a scale a person can check in a minute, and it is the part worth sitting with.
The window is recent merges, so a repository that was open two years ago and has since closed looks closed, correctly, and one that just opened up looks closed, incorrectly. It says nothing about whether maintainers respond, only about what they merge. A project with a genuine community that has simply been quiet for three months will read as a roster.
It is a cheap filter, not a verdict. It is worth running before the weekend rather than after. The script is scripts/openness_probe.py in the repository behind this piece. These four figures are a point-in-time API read rather than part of the crawl, so unlike every other number here they are not covered by verify_all.py.