Skip to main content
All Posts By


OpenChain Advent Calendar Day #16 – About Tooling Sub-Group of OpenChain Japan-WG (2020)

By News

This advent calendar has been created by our Japanese Work Group as part of their community outreach. We hope you enjoy their recap of compliance topics to end the year.

About me

Hello. I am Takashi Ninjouji.
I mainly participate in Tooling Sub-Group (Tooling-SG) of OpenChain Japan-WG, and I am this SG leader since April 2020.
This article introduces the activities of Tooling-SG.


The Tooling-SG group is to use OSS for OSS management operations to achieve the following in Open Source Compliance:

  • Build workflows according to your organization.
  • Automation
  • Quality improvement (on tools, workflows, and compliance)

Most of the participants are engineers. Many of them actually use the tools in their work, are developers of the tools, and even participate in the development community. On the other hand, because toolchain is also a means of handling open source compliance information, there will also be people from the compliance management departments such as legal and intellectual property, which are the relevant departments.

You may also want to read the article “About the activities of OpenChain Japan WG Tooling Sub-WG” by Kobayashi-san, the first leader at the time of its establishment in 2019, which was published in the 2019 Advent Calendar project. That article introduces why we wanted to create a place to exchange opinions about Open Source Compliance toolchain in Japanese and collaborate with global communities such as the OpenChain Reference Tooling Workgroup.


As in the previous year, the following activities and guiding principles have been established.

  • Compile/disseminate information about the tool (in collaboration with the global community)
  • Provide a place to study and discuss while using the tool (e.g., introducing the tool, holding seminars and hands-on sessions)
  • Information distribution and tool mapping (identify issues and collaborate to improve workflow implementation)
  • Promotion to expand membership (presentations at non-OpenChain meetings, use GitHub and other media)

We are welcome to feel free to participate and feel free to make a presentation (or talk).

At the meeting on 2020/11/24, we decided that we will have presentations in foreign languages. We would like to have a more active exchange of information.

You may arrange for your interpreter and translation of the materials in advance, or we would be happy to have volunteers to help you. If you are considering presenting in a foreign language, we would be glad to discuss this with you. Also, we may ask you to give your presentation at Tooling-SG.

How to participate

We use the following three means:

Mailing list


Virtual Meeting

Starting in April 2020, we are holding virtual meetings in conjunction with the Japan-WG meetings. Currently, we meet every other week for about an hour, alternating between the following meetings.

We are flexible in practice, so please feel free to join us if you have questions. If you have a topic to present, please contact us via the mailing list or Slack.

  • Monthly Meeting
    • about 1 or 2 presentations
    • Fourth Tuesday of every month 16:00-17:00 (JST)
  • Casual Meeting
    • anyone is welcome to talk about any topic.
    • Second Tuesday of each month 16:00-17:00 (JST)


We have had these meetings in FY 2020 so far.

Meeting Topics
10thFeature study: OSS Review Toolkit
11th“Sharing the challenges of field deployment (usage) of FOSSology“and “the results and impressions of the FOSSA OSS license management trial”
12thTern by VMware (ACT) (Article on Qiita)
13thSW360 v11 (Article on Qiita)
14thExchange of opinions on future initiatives

Upcoming events

As SW360, a component cataloging tool, becomes multilingual and a Japanese kit is provided, it is expected to spread to Japan in the future.

Tooling-SG is planning to hold a hands-on session for SW360 Chores, a version of SW360 available in containers, in early 2021. We discuss the content and timing on the mailing list and Slack, so please join us if you are interested.

What is the next article?

Morishita-san will introduce OSS toolchain for Open Source Compliance. With the OpenChain specification being ISO standard, there has been a lot of discussion about automation of compliance practices in various tool communities. Don’t miss it!


OpenChan Japan-WGでは主に Tooling Sub-Group (Tooling-SG) に参加し、2020年4月から同SGのリーダーを務めています。

Tooling SGとは

このTooling-SGは、OSS管理運用のためのOSS(ツール)を利用して、Open Source Compliance において次を実現することを目的とします。

  1. 組織に応じたワークフローの構築
  2. 省力化 (オートメーション)
  3. 質の向上 (ツール、ワークフロー、コンプライアンスについて)


なお、2019年のAdvent Calendar企画にあった、2019年設立時の初代リーダーの小林さんによる活動紹介記事「OpenChain Japan WG Tooling Sub-WGの活動について」もご一読頂けると幸いです。Japan-WGの活動趣旨に沿ってツールについて日本語で気軽に意見交換する場を設けたいとする経緯や、OpenChain Reference Tooling Workgroup などのグローバルコミュニティとの連携などを紹介しています。



  1. ツールの情報をまとめる / 発信する (Globalコミュニティと連携)
  2. 実際に使いながら勉強や議論する場の提供 (ツール紹介、セミナーやハンズオンの開催など)
  3. 情報流通とツールのマッピング (ワークフロー実現のために課題を洗い出し、他と連携して改善)
  4. 活動に賛同するメンバ拡大のためのプロモーション (OpenChain以外の会合での発表、GitHubやその他メディアの活用)











  • 月例会
    • 発表は1または2件程度
    • 毎月第4火曜日 16:00-17:00 (JST)
  • カジュアル会
    • どんな話題でも、どなたでも、お話しください。
    • 毎月第2火曜日 16:00-17:00 (JST)



回 内容
第10回OSS Review Toolkit 機能調査
第12回VMware社による Tern について (Qiita投稿記事)
第13回SW360 v11 について (Qiita投稿記事)



Tooling-SGでは、SW360をコンテナで利用できる SW360 Chores を対象に起動や操作のハンズオンを、2021年早々に開催しようと計画中です。メーリングリストやSlackにて実施内容や時期を検討しているので、興味のある方はぜひご参加ください。


明日(2020/12/17) は森下さんが、Open Source Compliance のための OSS を紹介してくれます。OpenChain仕様がISO化されたことで、様々なツールコミュニティでコンプライアンス実務のオートメーションの議論が活発になってきています。お楽しみに!

OpenChain Advent Calendar Day #15 – Commentary of Spec v2.1 vol.4, §3.3 “Open source content review and approval”

By News

This advent calendar has been created by our Japanese Work Group as part of their community outreach. We hope you enjoy their recap of compliance topics to end the year.

About me

Hello. I am Takashi Ninjouji.
I mainly participate Tooling-SG of OpenChain Japan-WG.
This article is part 4 of introducing OpenChain Spec v2.1 (functionally identical to ISO/IEC 5280:2020).
(2020.12.14: “Status”is “Under development”, “Life cycle” is “60.00 International Standard under publication” at ISO/IEC)
(2020.12.15: “Status”is “Published”, “Life cycle” is “60.60 International Standard under published” at ISO/IEC!)

“OpenChain Self Certification” provides the Online Self-Certification. You can see the questionnaire in several languages in this repository: “OpenChain-Project/conformance-questionnaire”

OpenChain Spec v2.1 §3.3 “Open source content review and approval”

§3.3.1 Bill of Materials

§3.3.1 is about the Bill of Materials (BOM), which is a list of OSS that compose a software package, and an organization needs to have a process in place to create and manage that BOM.

Here is the questionnaire for Self-Certification:

Number Spec RefQuestion Text
3.a3.1, 3.1.1Do you have a documented procedure for identifying, tracking and archiving information about the open source components in a Supplied Software release?
3.b3.1, 3.1.2Do you have open source component records for the Supplied Software which demonstrate the documented procedure was properly followed?

§3.3.2 License compliance

§3.3.2 is about use cases. Internal processes need to be in place for each use case, such as distribution in binary form and distribution in source code form. Each organization can define use cases freely. In order to the efficiency of creation of BOMs and of open source license compliance using BOM, compliance tooling are needed and are discussed along with its development and its workflows as well.

Here is the questionnaire for Self-Certification:

Number Spec RefQuestion Text
3.c3.2, 3.2.1Do you have a documented procedure that covers these common open source license use cases for open source components in the Supplied Software?
3.c.i3.2, 3.2.1– Distribution in binary form;
3.c.ii3.2, 3.2.1– Distribution in source form;
3.c.iii3.2, 3.2.1– Integration with other open source that may trigger additional obligations;
3.c.iv3.2, 3.2.1– Containing modified open source;
3.c.v3.2, 3.2.1– Containing open source or other software under incompatible licenses for interaction with other components in the Supplied Software;
3.c.vi3.2, 3.2.1– Containing open source with attribution requirements.

What is the next?

Kobota-san will introduce part 5 on 12/18. Don’t miss it!

In tomorrow’s article (12/16), I will introduce the Tooling SG of Japan-WG. This subgroup aims to share information about the compliance tooling and the know-how to use them.


OpenChan Japan-WGでは、主にTooling-SGなどに参加しています。
本稿は国際規格 ISO/IEC 5230:2020 に相当する OpenChain Spec v2.1 を紹介するシリーズの第4回となります。
(2020.12.14: ISO/IEC にて、進捗(Status)は “Under development”, “Life cycle” は “60.00 International Standard under publication” です。)
(2020.12.15: ISO/IEC にて、進捗(Status)は “Published”, “Life cycle” は “60.60 International Standard published” です! )

なお、自己認証の手続は“OpenChain Self Certification” でできます。 また、確認項目はGitHubの “OpenChain-Project/conformance-questionnaire”で確認できます。英文和文などで用意されています。

OpenChain Spec v2.1 §3.3 “Open source content review and approval”

§3.3.1 Bill of Materials

§3.3.1 は、BOM (Bill of Materials) に関する章です。BOMは各ソフトウエアを構成するOSSのリストを指します。OpenChain適合を果たす組織は、このBOMの作成および管理するためのプロセスを整備する必要があります。


Number Spec RefQuestion Text
3.a3.1, 3.1.1Do you have a documented procedure for identifying, tracking and archiving information about the open source components in a Supplied Software release?

3.b3.1, 3.1.2Do you have open source component records for the Supplied Software which demonstrate the documented procedure was properly followed?


§3.3.2 License compliance

§3.3.2は、ライセンスコンプライアンスの実務におけるユースケースに関する章です。バイナリ形式での頒布、ソースコード形式での頒布等の各ユースケースに対応できるよう社内プロセスを整備する必要があります。ユースケースの定義については各組織が自由に設定することができます。BOMの作成やBOMを利用してのオープンソース ライセンス コンプライアンス業務については、ツールによる効率化が検討されています。


Number Spec RefQuestion Text
3.c3.2, 3.2.1Do you have a documented procedure that covers these common open source license use cases for open source components in the Supplied Software?

3.c.i3.2, 3.2.1– Distribution in binary form;

3.c.ii3.2, 3.2.1– Distribution in source form;

3.c.iii3.2, 3.2.1– Integration with other open source that may trigger additional obligations;

3.c.iv3.2, 3.2.1– Containing modified open source;

3.c.v3.2, 3.2.1– Containing open source or other software under incompatible licenses for interaction with other components in the Supplied Software;

3.c.vi3.2, 3.2.1– Containing open source with attribution requirements.



次回仕様紹介となる第5回の記事は、小保田さんから 12/18 に公開予定です。お楽しみに!
明日(12/16)は、再び僕の投稿になりますが、ツールに関する情報共有を行っているTooling SGの活動を紹介します。

NCSOFT Is The Second Company To Announce Adoption Of ISO/IEC 5230, The International Standard For Open Source Compliance

By Featured

NCSOFT is the first global game company to formally announce conformance with ISO/IEC 5230:2020, the International Standard for open source license compliance. It is the second company in Korea to announce conformance to a version of the OpenChain specification after LG Electronics. This historic development underlines the global reach and value of the standard.

ISO/IEC 5230 is maintained by the OpenChain Project as OpenChain 2.1 and edited for ISO via the Joint Development Foundation OpenChain Working Group. ISO/IEC 5230 is supported by Arm, BMW CarIT, Bosch, Cisco, Comcast, Facebook, Fujitsu, Google, Hitachi, Microsoft, MOXA, OPPO, Panasonic, Qualcomm, Siemens, Sony, Toshiba, Toyota, Uber and Western Digital as governing board members, and a wide community of companies across three continents.

“The OpenChain Project has a long history in Korea and our local work group has provided great support to the project as we have grown,” says Shane Coughlan, OpenChain General Manager. “The announcement by NCSOFT today is a superb example of how companies can improve their processes to align with other companies across the market. It makes open source license compliance faster, more effective and more efficient.”


NCSOFT is a premiere digital entertainment company and global publisher with worldwide locations and more than 4,000 employees focused on bringing extraordinary games to life for millions of fans around the world. Established in 1997 and headquartered in Seoul, South Korea, we quickly became a key leader in online games. Best known for critically acclaimed franchises including Lineage, Aion, Guild Wars, and Blade & Soul, NCSOFT is also one of the world’s top mobile developers with Lineage 2M occupying the #1 grossing revenue slot on Google Play. Our core goal is making people in this world happier by delivering games that entertain a globally connected audience has remained the same. Our culture is innovative, creative, collaborative and impactful, and we are passionate about creating the best gaming experiences for our players.

About the OpenChain Project

OpenChain began when a group of open source compliance professionals met in a conference lounge and chatted about how so much duplicative, redundant open source license compliance work was being done inefficiently in the software supply chain simply. They realized that while each company did the same work behind the scenes in a different manner the output for downstream recipients could not realistically be relied on because there was no visibility into the process that generated the output.

The answer the early principles of this discussion arrived at was to standardize open source compliance, make it transparent and build trust across the ecosystem. The project began as outreach to the community with the idea of a new standard for open source license compliance with slides titled, “When Conformity is Innovative.” A growing community quickly recognized the value of this approach and contributed to the nascent collaboration soon named The OpenChain Project.

OpenChain Advent Calendar Day #14 – OpenChain Japan Working – Leaflet SubGroup

By News

This advent calendar has been created by our Japanese Work Group as part of their community outreach. We hope you enjoy their recap of compliance topics to end the year.

Leaflet SubGroupの活動紹介 / Introduction of Leaflet SubGroup acts.

今年も残すところ後半月となりました。今日は、ネットワーク・セキュリティ系のエンジニアの経験を活かし、今は自社でオープンソースプログラムオフィスの一員として、OpenChain Projectの活動に参加させていただいている小保田が、OpenChain Project 日本グループのleafletグループの活動について、少しご紹介させていただきます。

Today, I would like to tell you about the activities of the leaflet group of the OpenChain Project Japan working group. I’m Norio Kobota who is now participating in the OpenChain Project activities as a member of the open source program office of my company, making use of my experience as an engineer in the network security field.

リーフレットって何? / What is the leaflet?

リーフレットは、OpenChain ProjectのReference Materialから取得可能な、オープンソースソフトウェアを取り扱う際の注意事項について記述された簡単なガイドブックです。日本語版は、こちらのgithubより取得できます。
OpenChain Projectにおいては当初より、そのソフトウェアサプライチェーンにおけるOSSライセンスコンプライアンスの難しさが重要視されており、それを解決する一つの手段として、企業における様々な立場の方々にとって、分かり易い簡単なガイドブックが必要だと、Japan Working Groupのメンバは考えました。
その後、グループメンバーの協力の元、2019/04 日本語版、2019/05 英語版をJapan Working Groupより提供することが出来ました。また素晴らしいことに、このリーフレットは世界中で必要とされることとなり、各国のサブグループの協力の元、今では、中国語(繁体字、簡体字)、ベトナム語への翻訳も済んでいます

The leaflet is a simple guide book which describes useful information when dealing with open source software, available from Reference Material of OpenChain Project. You can obtain the Japanese version from github here.
In the OpenChain Project, the difficulty of OSS license compliance in the software supply chain has been emphasized from the beginning, and the members of the Japan Working Group thought that as a means to solve this problem, a simple guidebook that is easy to understand for people in various positions in the enterprise was necessary.
After that, with the cooperation of the group members, we were able to provide the Japanese version 2019/04 and the English version 2019/05The great thing about this leaflet is that it has become global, and thanks to the cooperation of various subgroups, Chinese(Traditional and Simplified) and Vietnamese versions are now available here.

リーフレットサブグループって何してるの? / What are the activities of the leaflet subgroups.

例えば、Linux Foundationが開催するOpen Source Summit/Embedded Linux Conferenceや、電子機器の祭典である、CES、果ては日本のほぼ裏側で開催されたDebConf 2019など、それぞれが主業務などで参加する様々なイベントにこのリーフレットを持ち込み、紹介すると共にリーフレットの配布を行っています。

Because the creation of leaflets was settled last year, there are not many activities such as creating documents rececntly. For this reason, I would like to introduce the activities of (2019) last year.
The fact that we were able to create a leaflet that is easy to understand is a great achievement. However, what we think is really important is to increase the number of people with that knowledge, and to have many people use the guidebook when they need it. For this reason, we print leaflets for various lectures and introduce their purpose and necessity.
For example, the Open Source Summit/Embedded Linux Conference held by the Linux Foundation, CES which is a festival for electronic devices, and DebConf 2019, which was held in almost the other side of Japan, have introduced and distributed leaflets at various events attended by members of the Japan Working Group.

これから / Future

明日は、忍頂寺さんによる、OpenChain Spec2.1の内容紹介 第4弾です。お楽しみに!

Due to the effects of the COVID-19, this subgroup activity itself is currently stagnating. However, I would like to invite you to join us. We will do some writing and public relations activities with other subgroups.
Tomorrow is OpenChain Spec2.1, 4th introduction by Ninjoji-san. Look forward to it!

OpenChain Advent Calendar Day #13 – Opensource for ALL

By News

This advent calendar has been created by our Japanese Work Group as part of their community outreach. We hope you enjoy their recap of compliance topics to end the year.

1. Introduction

Hello. I’m Masato ENDO.
Today, I would like to introduce the topics related to Promotion SG of OpenChain Japan WG.

As you can see in the article on December 6, we found that although awareness of the importance of OSS compliance is gradually increasing, each company is struggling to secure resources.
In order to secure resources, it is essential to promote the understanding of executives.
Therefore, the Japan Patent Office and the Cabinet Office created “Open source for ALL” as a tool to educate management about the importance of OSS itself, and released it in June.
I also participated as a member in the Expert Committee for the preparation of this material.
So, I would like to introduce it.

You can access the materials from the links below.(Sorry, Japanese only)

・ Executive Summary of enlightenment tools (presentation materials)
・ Detailed report

2. Background of realization

The beginning of the story was that in May 2019, I made a presentation at the Intellectual Property Headquarters Verification, Evaluation, and Planning Committee, which is a policy meeting of Japanese government.
At this time, Mr. Nakauchi of the current Imabari City officer, who was at the Intellectual Property Headquarters at that time, was interested in it, and a committee of experts was formed.
Therefore, we decided to create OSS enlightenment materials for managers, and we asked Mr. Shinozaki of PwC, who was selected as the secretariat based on discussions at the committee, to compile the materials.
It is assumed that this material will be used as it is or arranged for use in internal executives and symposiums in which executives participate.
This material is supported not only by Japanese companies but also by foreign companies such as Google, Microsoft, Qualcomm, and Siemens.
I introduced these companies to the Committee through OpenChain connection.

3. Interesting information

Here, I will pick up and introduce the topics that I found interesting from the report.
In this survey, we conducted a questionnaire to the executives of the system development and software development departments of large companies, mainly non-IT companies, and added analysis from various angles.
Among them, what I am paying attention to is the figure below that summarizes the answers to the question “Will the expansion of OSS utilization expand in the future?”
As the result, we can confirm that executives in almost all industries responded that they would “expand in the future.”
On the other hand, in this report “It became clear that the approach to OSS was individual-dependent and that activity was sluggish overall.”
From the perspective of promoting DX, it is thought that the issue for Japanese companies will be how to systematically handle OSS in the future.
Overseas, it is becoming a trend to establish OSPO (Open Source Compliance Office), which is a specialized organization that formulates OSS utilization strategies and rules regardless of the type of industry.
At OpenChain, we have accumulated the know-how of leading companies overseas and in Japan, so if you have a need to deepen understanding within the company, please let us know! The project will support you free of charge.
(I also explained the importance of OSS community activities to the CTO of a IT company in such a context.)

4. Tomorrow’s theme is …

Tomorrow, Kobota-san will introduce the activities of Leaflet SG, which is creating an enlightenment leaflet for OSS compliance.
This leaflet has been distributed free of charge at events around the world such as CES2020 and has been very well received.
Stay tuned!

1. はじめに

本日はOpenChain Japan WGのPromotion SG関連のトピックを紹介します。

そこで、経営層にOSSそのものの重要性も含めた啓発を行うためのツールとして「Opensource for ALL」を特許庁・内閣府が作成し、6月にリリースされました。


・啓発ツール(プレゼン資料)のExective Summary

2. 実現の経緯



3. 興味深い情報




海外では業種問わずOSSの利活用戦略策定やルール作りを行う専門組織であるOSPO(Open Source Compliance Office)を設置することがトレンドになってきてます。

4. 明日のテーマは・・・


OpenChain Advent Calendar Day #12 – Commentary of spec v2.1 vol.3, §3.2

By News

This advent calendar has been created by our Japanese Work Group as part of their community outreach. We hope you enjoy their recap of compliance topics to end the year.

OpenChain Specification v2.1, Clause 2.

Today I am writing about the third part of the OpenChain Specification v2.1 Chap 3.2 (that is under the ISO/IEC pending). If you want to know the OpenChain Spec
correctly, please read the original documents from the linke at the end of this page.

Chapter 3.2.1 is about dealing with external inquiries, and requires that a third party has a reasonable path to contact the organization for OSS license compliance, and that the organization is prepared to respond to such inquiries.

Chapter 3.2.2 is about resources. Adequate staffing and resources should be allocated to compliance program-related roles, legal experts should be assigned, and a process for resolving concerns should be maintained.

OSS license compliance will continue to become more important, but it is necessary to make executives aware of its importance in order to ensure resources are available.

Tomorrow, Mr. Endo of Promotion SG will share with us some examples of such educational activities conducted for the public and private entities.

Resources (Links) / 関連リンク

OpenChain Specification v2.1 の紹介 §3.2

本日は、ISO/IECに申請中のOpenChain Specification v2.1の中身の紹介第3弾(2章)です。著者の適当な和訳ですので、本格的にOpenChain Specを知りたい方は巻末のリンクより原文をお読みください。

また、このページから見た方は OpenChain Japan Advent Calendar 2020 より他の記事もご覧ください。他の章や関連する情報が書かれています。

§3.2 Relevant Tasks Defined and Supported

2章では、OSS に関連する業務の定義とそれを実行するための支援に関する内容が書かれています。大きくは2つです。

§3.2.1 Access


  1. 外部からOSSに関する問合せるための方法(たとえば専用のメールアドレスとか)が公開されている。
  2. 問い合わせがあったときにどう回答するかの手続きを規定した文章が組織内部にある。


§3.2.1 Effectively resourced

2.2章は、”Effectively resourced”という章題で、リソースに関する章です。


  1. コンプライアンスプログラムの業務が明確で確実に実行するために役割/担当/組織が決まっている
  2. 業務を実行する時間と十分な予算が配分されている
  3. ポリシーと支援業務に関して、レビューして更新するプロセスがある
  4. 必要なときにオープンソースのコンプライアンスについて法的な内容を話し合える専門家がいる(すぐ話せる相手がいる)
  5. オープンソースのコンプライアンス問題が発生した際に、それを解決するためのプロセスが規定されている



明日は、そのような啓発活動を官民で行った例について、Promotion SGの遠藤さんから紹介いただきます。

OpenChain Advent Calendar Day #11 – OpenChain Japan WG – FAQサブグループの紹介

By News

This advent calendar has been created by our Japanese Work Group as part of their community outreach. We hope you enjoy their recap of compliance topics to end the year.

Introduction of FAQ subgroup

Today, I would like to introduce the FAQ subgroup of the OpenChain Japan WG.

FAQ Subgroup Activities

The FAQ subgroup creates and publishes “common misunderstanding FAQs related to OSS licenses“, which is mainly targeted at beginners of OSS licenses.

The members of the FAQ subgroup are consist of those who are in charge of OSS license consultation and license compliance support at each company / organization, those who are not in charge but are volunteer-based, and those who are about to start studying OSS licenses or those who are just starting (<-this is important).

There are various QA candidates, such as those that the members actually consulted, those that the members wondered, and those that are generally misunderstood.

How to make QA

To create a QA, first create a base for Questions and Answers using Slack and give your opinion. After that, the QA will be finalized by making corrections at a meeting (which used to be actually gathered, but recently it is online in view of recent circumstances). (<- This is actually the most fun because we have a lot of opinions and discussions.) Then, after confirming with the attorney attorney, we will publish it.

In this way, each QA is verified and nurtured from the perspectives of various companies, organizations, and roles, so I think that the QA collection is relatively homogeneous and has few mistakes.

It’s been about 10 years since I was involved in OSS licensing, but I’m still studying through this FAQ subgroup every time. In particular, I often get noticed from the perspectives and opinions of companies whose business types are different from those of my company.
People who participated for the purpose of studying also commented, “I am studying because I am trying to convey it in an easy-to-understand manner.” and “I will be able to understand by listening to the discussion.” and so on.


It’s been about 10 years since I was engaged in OSS license compliance, but I still study through this FAQ subgroup every time. In particular, I often get noticed from the perspectives and opinions of companies whose business types are different from those of my company.
People who participated for the purpose of studying also commented, “I am studying because I am trying to convey it in an easy-to-understand manner.” and “I will be able to understand by listening to the discussion.” and so on.

If you are interested in the activities of the FAQ subgroup, please join us at any time. Those who want to participate by trial rather than immediately, and those who can not contribute much to the creation of FAQ but want to participate for study purposes are also welcome.
For details, please contact


本日は、OpenChain Japan WGのFAQサブグループについてご紹介します。






QAの作り方は、まずSlack上でQuestionとAnswerのたたき台を作成、意見出しをします。その後、会合(以前は実際に集まっていましたが 最近は昨今の事情を鑑みオンラインです)で再度揉みなおしてFIXします。(←喧々諤々議論をかわすので実はここが一番楽しい)そして仕上げに弁護士の先生にご確認いただいたものを公開するという流れで行っています。




詳しくは まで。

OpenChain Advent Calendar Day #10 – Commentary of spec v2.1 vol.2, §3.1.4-3.1.5

By News

This advent calendar has been created by our Japanese Work Group as part of their community outreach. We hope you enjoy their recap of compliance topics to end the year.

Today, we will introduce the contents of the OpenChain spec v2.1 (Chapter 1.4-1.5).

Chapter 1.4 is about the scope of the OSS Compliance Program. Th e OSS compliance program gives you the freedom to choose whether it covers your entire organization or just some product lines.

Chapter 1.5 is a chapter on reviewing each OSS license within your organization. Organizations should establish a process for reviewing and documenting OSS license obligations, restrictions, and rights for each use case.
Reviewing OSS licenses in Chapter 1.5 is a very important task for an organization, but a difficult task for an unfamiliar organization.
Therefore, the FAQ subgroup of the Japan WG is working to publish “common misunderstanding FAQs related to OSS licenses” together.

Tomorrow we will introduce the activities of this FAQ subgroup.

本日は、OpenChain spec v2.1 の中身の紹介第2弾(1.4~1.5章)です。


そこで、Japan WGのFAQサブグループでは「OSSライセンス関連でよくある誤解FAQ」を纏めて公開する活動を行っています。

明日はこのFAQ SGの活動を紹介します。

OpenChain Advent Calendar Day #9 – The Need for Skills Standards on OSS Compliance

By News

This advent calendar has been created by our Japanese Work Group as part of their community outreach. We hope you enjoy their recap of compliance topics to end the year.

The research team in OpenChain Japan WG about OSS compliance made academic presentations at two conferences, “Intellectual Property Association of Japan” and “Japan Society for Research Policy and Innovation Management” in 2020.

Today, I would like to introduce the “Framework for Skill Standards on OSS Compliance” presented at “Intellectual Property Association of Japan”.

Necessity of skill standards for OSS compliance

Work related to OSS compliance is complex and needs to be carried out in cooperation with various departments in the company, such as development and intellectual property departments.

On the other hand, OSS-related tasks are often relatively new to the people in each department, and therefore, in order to promote human resource development, we have developed a systematic index to clarify and systematize the skills required to perform these tasks. In other words, we thought a “skill standard” was necessary.

The skill standard framework for OSS compliance

The table below shows the framework of skill standards about OSS compliance. On the left side, tasks related to OSS compliance are extracted for each of planning, development, and maintenance (operation) of the system, and on the right side, tasks to be handled by each department are organized.

In this presentation, we have only presented the overall picture above. In the future, we will further subdivide each task, and organize the skills required to perform each task and the evaluation method.


The OpenChain Specification 2.0, which was adopted by the ISO, also defines the roles, responsibilities, and suitability of personnel to achieve OSS compliance in Chapter 1.2, and specifies that the results of the suitability assessment must be retained. (Article link.)

However, OpenChain does not mention the specific items and indices of what roles each department should play and how to evaluate each person in charge, and it is left to each company to decide. We hope to create a tool that can be used to facilitate compliance work.

Tomorrow, Mr. Shima of FAQ SG will introduce the contents of chapter 1.4 to 1.5 in OpenChain.

Advent Calendar、2回目の登場となる山田です。今回は、先日紹介した12/6に遠藤さんが投稿したOSSコンプライアンスの調査に関連する話題を投稿します。

OpenChain Japan WG Promotion SGの有志メンバーを中心に立ち上げたOSSコンプライアンスについての研究チームでは、2020年に「日本知財学会」と「研究・イノベーション学会」の2つの学会で学術発表を行いました。今日は、その中から日本知財学会で発表した「OSSコンプライアンスに関するスキル標準のフレームワーク(全体マップ)」について紹介しようと思います。(研究・イノベーション学会で行った発表に関しては、12/21の記事で土手さんから紹介いただく予定です)

*Please scroll down for the English version.




既存のスキル標準としては、ITスキル標準 、知財人材スキル標準、標準化人材スキル標準などがありますが、OSSコンプライアンス業務のスキル標準を策定するに当たり、社内の関係者が部署の枠を超え連携し、さらに他社や業界団体等と共に実施するという共通点を持つ「標準化人材スキル標準」を参考に、OSSコンプライアンス業務に関するスキル標準策定の第一歩として、業務遂行に必要となる細分化された業務フェーズを明確化し、スキル標準フレームワークを作成し、その内容を発表しました。






今回ISOに採択された「OpenChain Specification 2.0」においても、1.2章でOSSコンプライアンスを実現する人員の役割と責任および適性を定義し、その適性評価の結果を保管する必要があると規定しています。(記事リンクを貼る)


明日はOpenChainの中身(Specification)紹介第2弾として、FAQ SGの島さんから1.4~1.5章の内容について紹介いただきます。明日以降もぜひOpenChain Japan Advent Calendar 2020をご覧ください!

OpenChain Advent Calendar Day #8 – SWG活動紹介(Education)

By News

This advent calendar has been created by our Japanese Work Group as part of their community outreach. We hope you enjoy their recap of compliance topics to end the year.

Yoshitaka Iwata of Hitachi, Ltd. will be on duty for the Advent calendar on December 8th. I am the leader of the “Educational Materials for Role” SWG of the Open Chain Japan WG. Thank you in advance.
By the way, what are you careful about when using OSS? Also, what kind of structure and content will you use when conducting education for using OSS within the company or team? What should software developers know to use OSS need? In order to answer these questions, I decided to think about what kind of educational materials would be good for each role related to OSS. The following content is, of course, based on the Open Chain specifications and curriculum.

  1. Collection and analysis of education cases
    It seems that some companies have been educating on OSS even before the establishment of Open Chain. Therefore, we investigated the system, target member, form (lectures, group training, e-learning, material browsing, etc.), timing, and the existence of the English version of four companies. We analyzed the table of contents of each education and the outline of chapters / sections, and summarized the structure for software developers. The structure example is as follows.
    (1) What is OSS?
    (2) Intellectual property rights
    (3) OSS license
    (4) OSS compliance program
    (5) Examination when introducing OSS
    (6) OSS review
    (7) OSS distribution
    (8) Summary
    (9) Contact information
    (10) References / organizations
    First of all, we targeted software developers because we thought that software developers would be the first to use OSS internally or within a team.
  2. Development of examples of specific educational materials
    Actually specific examples of educational materials for software developers were examined by the “Educational materials for Role” SWG.
    (1) What is OSS?
    Considering software developers who have never used OSS, how about telling them about general OSS definitions, usage examples of OSS in the target business (different for each business targeted by the company or team), the advantages and disadvantages of using OSS, and others?
    (2) Intellectual property rights
    In particular, intellectual property rights related to OSS include copyrights and patent rights. Since OSS is software, each OSS is copyrighted. Copyright means the right to modify, distribute, and copy. I hope you can explain these things in an easy-to-understand manner.
    (3) OSS license
    Why don’t you explain copyright rights obtained by the OSS license compliance(in other words, it is necessary to protect the OSS license in order to modify, distribute), examples of OSS licenses, permissive OSS licenses, copyleft and reciprocal OSS licenses, etc?
    (4) OSS compliance program
    The Open Chain specification recommends creating an OSS compliance program consisting of policies, processes, training, tools, etc. First, let’s share the policy for using OSS within the company and within the team. (The policy may differ depending on the use cases of target businesses.) Next, let’s show the organization related to OSS and the role of each member related to OSS. Then explain how OSS-related processes (OSS listing, OSS review, OSS distribution review) are incorporated into our software development process.
    (5) Examination at the time of introduction
    Let’s explain the points to be noted in the characteristics of the license and the points to be noted regarding intellectual property rights (patent rights, etc.).
    (6) OSS review
    Let’s explain the information collected in the OSS review, the content of the review, the available tools, and others.
    (7) OSS distribution
    Let’s explain what precess will be applied to distribute OSS in the target business form, including examples. Also, explain the implications of improper use of OSS and lack of license information in the software supply chain.
    (8) Summary
    (9) Contact information
    (10) References / organizations
    I think that (9) to (10) are effective for deepening the understanding of OSS within the company and the team.

Then, especially if (2) and (3) are explained to software by using analogy to legal terms that are common within the company and within the team, software developers will understand more easily. Also, in (4) to (7), if you explain by applying it to the system within the company or team and the software development process actually used, I think that you can deepen the understanding of software developers. Please devise.

An example of actual educational materials is shown in the markdown format at the following URL. Please refer to.

Tomorrow, tech_nomad_ will talk by the title “Framework for Skill Standards on OSS Compliance”. Among the roles related to the use of OSS, what kind of skills each person in each role should have is a difficult theme, isn’t it? I am also very interested in this theme and am looking forward to it.

12月8日のアドベントカレンダを担当するのは、株式会社 日立製作所の岩田です。Open Chain Japan WGの「役割ごとの教育資料」SWGのリーダを担当しています。宜しくお願いします。
 さて、皆さんはOSSを利用する上で、一体何に気を付けていますか。又、社内やチーム内でOSSを利用するための教育を行う場合、どんな構成、内容にするでしょう。OSSを利用するソフトウェア開発者は、どんな事を知っておけば良いのでしょう。こんな疑問に答えるために、OSSに関係する役割ごとにどんな教育資料が良いかを、考えてみる事にしました。下記内容は、もちろんOpen Chainの仕様やカリキュラムを参考にしています。

 Open Chainの設立前から、OSSに関する教育を実施している会社もある様です。そこで4社から、教育の体系、対象者、形態(講演会、集合研修、e-learning、資料閲覧、他)、タイミング、英語版有無、等を調べました。各教育の目次、章/節の概要を分析し、ソフトウェア開発者向けの構成を纏めました。その構成例は下記の通りです。

  Open Chainの仕様では、ポリシー、プロセス、トレーニングやツール等から成るOSSコンプライアンスプログラムを作る事を推奨しています。先ずは、社内やチーム内でOSSを利用する上でのポリシーを共有しましょう。(ポリシーは、対象とするビジネスのユースケース毎に異なるかもしれません。)次に、OSSに関係する体制、それぞれのメンバーがOSSに関係する役割を示してあげましょう。それから、自分たちのソフトウェア開発プロセスの中で、OSSに関係するプロセス(OSSリスト作成、OSSレビュー、OSS配布物確認)がどの様に組み込まれているかを説明しましょう。
