Skip to main content
THE LINUX FOUNDATION PROJECTS
All Posts By

Shane Coughlan

Shane Coughlan is an expert in communication, security and business development. His professional accomplishments include spearheading the licensing team that elevated Open Invention Network into the largest patent non-aggression community in history, establishing the leading professional network of Open Source legal experts and aligning stakeholders to launch both the first law journal and the first law book dedicated to Open Source. Shane has extensive knowledge of Open Source governance, internal process development, supply chain management and community building. His experience includes engagement with the enterprise, embedded, mobile and automotive industries.

Webinar: Containers and Compliance

By legal, licensing, News, security, Webinar

This was an exceptionally popular (over 50 attendees). Unfortunately, we had a recording mishap and are unable to bring you the full panel discussion. However, we are providing a summary below alongside the slides used.

Quick Recap

The meeting focused on discussing open-source containers, package managers, and compliance challenges, with panelists exploring issues around transparency, licensing information, and source code access. The group examined limitations in package manager information and binary scanning capabilities, discussing how incomplete or incorrect licensing data can hinder true compliance. The panel emphasized the importance of proper license declarations and developer awareness, while exploring potential solutions for addressing licensing issues in containerized environments and discussing the need for improved compliance automation tools.

Summary

Source Container Compliance Challenges:

The meeting focused on open-source containers, package managers, and compliance, with Chris chairing the discussion and introducing panelists including Karen from OSADL, Till, and others. Chris raised concerns about the transparency of package managers, noting that some widely used products lack sufficient licensing information and do not provide SBOMs or source code access, which may hinder true license compliance. The panelists were asked to share their thoughts on these issues.

Improving Open Source Compliance Tracking:

The panel discussed the limitations of package manager information for source compliance, with Caren, Heather, and Mary agreeing that package managers often provide incomplete, outdated, or incorrect licensing information. They emphasized the need to improve provenance tracking and source code analysis rather than relying solely on meta-information. Till explained that package managers can only use the information provided by open source projects, which is often insufficient. Mary noted a public database, ClearlyDefined, contains metadata for open source packages, including licenses discovered during scanning. It can be used as a reference during container content analysis. There is still some human curation for packages that have missing top-level license information, but at least it only needs to be completed once. The group also addressed the limitations of license scanners, noting that many only analyze the top-level license of binaries, which may not reflect the true complexity of the software’s licensing structure.

Binary Scanner Limitations and Potential:

The group discussed the limitations and potential of binary scanners in identifying licensing information. Caren emphasized the need for binary scanners to trace the origin and build information of binaries to extract licensing details, while Heather highlighted the evolution of scanning tools from line-by-line source code analysis to higher-level scans, noting a potential resurgence in detailed scanning due to AI coding tools. Mary mentioned ongoing experiments using AI to improve the detection of binary origins, and Till explained the convenience of binary scanning for large dependency trees but stressed the need for source code for comprehensive compliance. Florian raised concerns about relying solely on third-party binary scanning for compliance, and Stefan questioned the discrepancies in license declarations between Maven and GitHub, which Caren and Till acknowledged as a challenge due to incomplete or outdated meta-information.

Software Licensing Awareness and Management:

The panel discussed the importance of proper license declarations in software development, emphasizing the need for awareness training among developers to ensure accurate declarations. They highlighted the role of configuration management in preventing issues related to incorrect licensing, with Marcel explaining that the default Apache license in Maven requires explicit changes for different licensing. The group also addressed the limitations of binary scanning in identifying license information, with Till suggesting a theoretical approach using a database to link source code and binary information. Chris raised a question about remediation options for non-compatible licenses in containerized environments, which the panel acknowledged as an open issue.

Container Licensing Compliance Challenges:

The panel discussed challenges in container and package manager compliance, focusing on how to address licensing issues when using non-modified binary formats. Heather noted that license disclosures for pre-built containers have improved over time, and suggested working with upstream sources for remediation, while Caren emphasized engaging with source projects to resolve licensing problems. The group agreed that developer awareness of licensing requirements is crucial, particularly for containers, and Till highlighted the importance of using compliant and trusted base images. The panel expressed hope for improved tools to automate compliance processes in the future.

Read the Slides:

More About Our Webinars:

This event is part of the overarching OpenChain Project Webinar Series. Our series highlights knowledge from throughout the global OpenChain eco-system. Participants are discussing approaches, processes and activities from their experience, providing a free service to increase shared knowledge in the supply chain. Our goal, as always, is to increase trust and therefore efficiency. No registration or costs involved. This is user companies producing great informative content for their peers.

Check Out The Rest Of Our Webinars

This OpenChain Webinar was broadcast on 2025-10-29.

OpenChain @ Open Source India

By News

OpenChain will be represented at the Open Source India conference on the 6th of November by Biju K Nair, OpenChain India Work Group Chair, OpenChain Ambassador. See him on stage at 15:30!

Title: Open Source in the Age of Generative AI: Collaboration, Compliance, and Control

Date: 6th November 2025

Time: 15:30-16:15

Panelists:

  • Srivathsa NS, Senior Engineering Director, Office Of The CTO, Unisys (Chair)
  • Biju K Nair, OpenChain India Work Group Chair, OpenChain Ambassador
  • Karrtik Iyer, Principal AI Researcher, Thoughtworks
  • Heena Juneja, Industry Principal, Frost & Sullivan
  • Janardan Revuru JavaScript Evangelist
  • Sukarn Singh Maini, Founding Partner, LegaliTech

OpenChain @ Open Source Summit Korea

By News

The OpenChain Project has a significant presence at Open Source Summit Korea.

You can catch our Chair, Jimmy Ahlberg, and two of our key local contributors and OpenChain Ambassadors – Seoyeon Lee and Haksung Jang, during the talk schedule today:

and

As always if you see one of us in the hallways, just say hi. We would be delighted to tell you more about what we are doing in the project, and how we are personally contributing to the open source community.

Hancom Announces an OpenChain ISO/IEC 5230 Conformant Program

By Featured, News

Hancom has announced an OpenChain ISO/IEC 5230 conformant program.

“We are delighted to welcome Hancom to the OpenChain community of conformance,” says Shane Coughlan, OpenChain General Manager. “Korea has a vibrant technology ecosystem, and the companies in the local area have an exceptional commitment to process excellent. Hancom is a great example of this, and we look forward to working with them to inspire other companies to adopt and use the international standard for open source license compliance.”

About Hancom:

Hancom Inc. (KOSDAQ: 030520) is software development company based in South Korea. It was founded in 1990 and is well-known for Hangul, a word processer for the Korean language. They maintain a broad portfolio of products, including in the field of AI.

About the OpenChain Project:

The OpenChain Project has an extensive global community of over 1,000 companies collaborating to make the supply chain quicker, more effective and more efficient. It maintains OpenChain ISO/IEC 5230, the international standard for open source license compliance programs and OpenChain ISO/IEC 18974, the industry standard for open source security assurance programs.

About The Linux Foundation:

The Linux Foundation is the world’s leading home for collaboration on open source software, hardware, standards, and data. Linux Foundation projects are critical to the world’s infrastructure, including Linux, Kubernetes, Node.js, ONAP, PyTorch, RISC-V, SPDX, OpenChain, and more. The Linux Foundation focuses on leveraging best practices and addressing the needs of contributors, users, and solution providers to create sustainable models for open collaboration. For more information, please visit us at linuxfoundation.org.

Check Out The Publicly Announced Community of Conformance:

RECORDING: OpenChain Meridian 22 Work Group Call – CRA, AI Act, DMA, DSA, PLD – Requirements and Meeting Them

By News

First Meeting, Big Discussion:

The OpenChain Meridian 22 Work Group met with Ciaran O’Riordan of Eclipse Foundation as a special guest. The core topic was EU regulation and how it impacts countries along the Meridian 22 area. This was a lot of ground to cover, and provided a great example of the type of in-depth discussion OpenChain communities can engage in.

Watch the Meeting:

Read the Slides:

Be Part of Future Meetings:

We will arrange future meetings and hold online discussions via the official mailing list, and everyone is invited to join: https://lists.openchainproject.org/g/meridian22-wg

RECORDING: OpenChain Monthly Specification and Education Call (Europe – Asia) – 2025-10-15

By News

We Discussed:

  • OpenChain Project News
  • Specification Work Group – CRA, other regulations and our standards
  • Education Work Group – Update on Status and Community Work Items
  • Any Other Business?

A reminder for those in North America – while this edition of the monthly call happens in the darkest hours of the night for you, we also have a monthly North America / Europe call that works better for Western time zones. Check out the schedule for this and all our other meetings here:
https://openchainproject.org/participate

Watch the Recording:

Coming Next:

  • Expect a new edit cycle for the specifications, and for enhancement of OpenChain training material

Join Our Work:

Everyone is welcome to be part of the Specification Work Group. You can join their mailing list here:
https://lists.openchainproject.org/g/specification/

You can find and be part of all OpenChain calls through our participation page here:
https://openchainproject.org/participate

OSPO Now is the latest OpenChain Partner

By News
“OSPO Now is delighted to announce our acceptance as an official OpenChain partner,” says Raphael Sonabend-Friend, Co-Founder, OSPO Now. “This recognition underscores our commitment to helping organisations build, manage, and mature their open source programs with confidence. Through our services, OSPO Now enables teams to outsource Open Source Program Office (OSPO) requirements, from community engagement to compliance management. Partnering with OpenChain further validates the expertise of our team in guiding organizations along their open source compliance journey, ensuring they can adopt and develop open-source software in a safe, secure, and responsible way.”
“An extensive community of service providers is key to enabling choice across the market,” says Shane Coughlan, OpenChain General Manager. “One reason we are delighted to work with OSPO Now is to enable such choice. Another is that the emergence of OSPOs has provided a pivotal opportunity for companies to improve their process management around open source, and direct expertise in this domain is a vital part of ensuring health.”
 
About OSPO Now
OSPO Now’s mission is to empower organizations through the strategic use of open source, fostering sustainability and maximising impact. Through training, working groups, hands-on development, and consulting, OSPO Now supports the creation, consumption, and deployment of open source software, as well as the wider practice of open science.
Learn more: osponow.com

OpenChain Webinar: Containers and Compliance @ 09:00 PDT / 16:00 UTC / 17:00 CET / 21:30 IST

By News

About This Webinar:

A special panel on Containers and Compliance from the OpenChain Project hosted by Chris Wood, Chair of Specification. This panel will feature Caren Kresse, Heather Meeker, Mary Hardy and Till Jaeger.

More Details:

Join Chris and a panel of experts for an informal chat exploring the key challenges in achieving comprehensive license compliance within containerised environments. This discussion will cover three critical areas:

(1) Package Manager Transparency: The current products of several key package managers do not contain sufficient information to achieve true license compliance as many only reveal the top-level license. More often than not they fail to provide the necessary information (source code and SBOMs) for a comprehensive license assessment. Increased transparency and standardization in this area are crucial.

(2) Another cause lies with the design limitations of License Scanners: While license scanners are improving, many still lack the capability to deeply analyze binaries, resulting in incomplete and therefore inaccurate license compliance reports. The development of more robust and sophisticated scanning technologies is essential to address this gap.

(3) A need for improved developer awareness of container license and copyright information to help the community to achieve a comprehensive container license compliance process is necessary to achieve a shift in developer practices. A greater understanding of open source licensing and the importance of proper metadata Management is essential, as we are already doing through the OpenChain education and specifications work groups.

RECORDING: OpenChain SBOM Work Group – Monthly Meeting – 2025-10-22

By News

As always, we focused on the question of “how do we use SBOMs in production, large-scale and complex supply chains?”

This Meeting Discussed:

  1. The content and release date of the Guide to SBOM Quality
  2. Any Other Business

Watch the Meeting:

Learn More About This Study Group:

Our SBOM Study Group brings all our various SBOM-related activities together and helps answer the question of “how do we use SBOMs in production, large-scale and complex supply chains?” Our original kick-off call has all the details.

 

Get Involved:

 

Everyone is welcome to be part of this study group! OpenChain has free, open access to all its work groups and study groups. Just turn up, and listen in, and contribute comments, ideas and suggestions.

 

✉️ We have a dedicated mailing list: https://lists.openchainproject.org/g/sbom

 

💻 We have a dedicated GitHub Repo: https://github.com/OpenChain-Project/SBOM-sg

Attend Future Meetings:

You can find and get the dial-in details for all future meetings from our participate page here: https://www.openchainproject.org/participate

RECORDING: OpenChain AI Work Group – Asia Sync – 2025-10-09

By News

We had a straightforward agenda, building on the earlier North America / Europe workshop:

Item #1: We have completed the AI SBOM Compliance Management Guide
Item #2: We are going live on 20th October – your help with promotion is requested
Item #3: We have started coordination with Lord Clement-Jones in the UK, UK working group, Spec Group, LF legal conference and PyTorch conference
Item #4: Early market feedback can be used to update the guide for solution/market fit – Your help is requested
Item #5: FINOS working group
Item #6: Any Other Business

Watch the Recording:

Get Involved:

Everyone is welcome to be part of this activity! OpenChain has free, open access to all its work groups and study groups. Just turn up, and listen in, and contribute comments, ideas and suggestions.

✉️ We have a dedicated mailing list for the AI Work Group: https://lists.openchainproject.org/g/ai

Attend Future Meetings:

You can find and get the dial-in details for all future meetings from our participate page here: https://www.openchainproject.org/participate