The Linux Foundation Projects
Skip to main content
All Posts By

Shane Coughlan

Shane Coughlan is an expert in communication, security and business development. His professional accomplishments include spearheading the licensing team that elevated Open Invention Network into the largest patent non-aggression community in history, establishing the leading professional network of Open Source legal experts and aligning stakeholders to launch both the first law journal and the first law book dedicated to Open Source. Shane has extensive knowledge of Open Source governance, internal process development, supply chain management and community building. His experience includes engagement with the enterprise, embedded, mobile and automotive industries.

Ambassador – Help Adopt A Work Group

By unlisted

Adopt a Work Group!

Inspire people! Help our chairs! Help the next generation of our guides, education material and standards! Become famous! Get a free boat. *

(* you will not get a free boat)

Name
Choice of Work Group to Support:

Coming Soon: OpenChain @ OSS Security Technology Workshop (OWS) 2025

By News

The Event:

OSS Security Technology Workshop (OWS) aims to encourage interaction between the corporate OSS community and academia, thereby stimulating research on OSS security and movement toward its practical application. OWS 2025 will be a key event to share knowledge and experience.

The Speakers:

Kobota San and Namae San of Sony (and the OpenChain community) will be speaking in Okayama on the 28th of October at 15:50.

Title:

Improving SBOM Quality: Practitioner Challenges and Initiatives to Strengthen Software Supply Chain Trust

Abstract:

This presentation examines the critical role of high-quality SBOMs in regulatory compliance and software supply chain hardening. SBOM is essential for robust security management and compliance with OSS licenses. However, as things stand at present, many implementations are inadequate – for example, “Source SBOM” is often unable to capture real binaries or runtime components, while “Build SBOM” generated via CI/CD pipelines tends to rely on package metadata, resulting in incomplete or mismatched data. Sony is focusing its efforts on the OpenChain project, developing SBOM Document Quality Guides based on ISO/IEC 5230 and ISO/IEC 18974, implementing measures such as ESSTRA, software for embedding source code details of executable binaries released by Sony as OSS, and providing upstream OSS packages in collaboration with the Debian community.

Learn More:

OpenChain Newsletter #82

By Monthly Newsletter, News

Newsletter – Issue 82 – September 2025

The OpenChain Newsletter provides a monthly summary of our work. It contains an overview of what we are doing to build trust around license compliance and security in the open source supply chain. We accept suggestions and ideas. Feel free to mail us at any time.

Key Announcements and Updates

  • Seven Services Announces OpenChain ISO/IEC 5230 Conformant Program: Seven Services has announced a new program to help organizations conform to the OpenChain ISO/IEC 5230 standard for open source license compliance. You can learn more about this announcement here.
  • OpenChain ISO/IEC 18974 and the Cyber Resilience Act (CRA): The OpenChain security standard, ISO/IEC 18974, has been referenced in the EU Cyber Resilience Act (CRA) harmonized standards discussion. This is a significant development for the project and its role in the future of cybersecurity. Read the full update here.
  • Introducing the OpenChain Ambassador Program: A new Ambassador Program has been launched to recognize and support community members who are actively promoting OpenChain. Learn more about the program and how to get involved here.
  • SBOM Study Group Becomes a Work Group: The successful SBOM Study Group has now transitioned into a formal SBOM Work Group. This change reflects the group’s focus on producing tangible outputs, starting with a new guide to SBOM quality. You can find more information here.
  • Developing a New Guide to SBOM Quality: The SBOM Work Group is developing a new, cross-industry guide to SBOM quality. You can review the draft and contribute your feedback here.

Community Insights

  • OpenChain at Open Source Summit North America: A presentation at OSS NA by representatives from Sony Group Corporation highlighted the challenges and importance of managing a global community, with a focus on language and cognitive load. This is a must-read for anyone involved in international open source projects. You can find the details here.

Recent Meeting Recordings

For those who missed recent meetings, recordings are available:

  • OpenChain Monthly Specification and Education Call (Europe / Asia) – 2025-09-17: Recording
  • OpenChain Monthly Specification and Education Call (North America – Europe) – 2025-09-10: Recording
  • OpenChain SBOM Work Group – Monthly Meeting – 2025-09-24: Recording
  • OpenChain AI Work Group – Asia Sync – 2025-09-11: Recording
  • OpenChain Telco Work Group – September – 2025-09-04: Recording
  • OpenChain AI Work Group – Monthly Workshop for North America and Europe – 2025-09-02: Recording

Recent Webinars

  • Webinar: Introduction to the Cyber Resilience Act (CRA): An overview of the new EU law covering “products with digital elements.” You can watch the webinar here.
  • Webinar: Compliant containers with the OSADL Base Image: Learn how to manage FOSS license obligations for containers using the OSADL Base Image. The webinar recording is available here.

Potential Further Actions

  • Get Involved with the SBOM Work Group: With the SBOM Study Group now a Work Group, this is an excellent opportunity to contribute to the development of a crucial industry guide.
  • Attend Future Meetings: The best way to stay informed and contribute is to attend the various work group and specification calls. The schedule and connection details for all meetings can be found on the OpenChain participation page.
  • Watch Past Recordings: If you are new to a topic or a working group, watching the past recordings is a great way to get up to speed.

To participate further in the OpenChain Project, including joining mailing lists and attending meetings, please visit: https://openchainproject.org/participate

Note: This newsletter usually only contains primary meetings. Some community meetings are not recorded or are released through other channels.

Read Previous Newsletters:

AI Usage:

This newsletter is created by using a template, curating links from a month of OpenChain news posted on the blog and using these prompts on Google Gemini to fill out the central news:

  • “Summarize the following newsletter for folks interested in the open source compliance to learn the latest changes in the space and find possible items that can act on. Include the links in this newsletter. Add notes on potential further actions by readers, particularly around attending future meetings. Direct people to this link to participate further: https://openchainproject.org/participate”

The newsletter is then subject to an edit cycle. If you spot any errors we missed, please contact us.

Seven Services Announces an OpenChain ISO/IEC 5230 Conformant Program

By Featured, News

Seven Services is the latest company to announce an OpenChain ISO/IEC 5230 conformant program. Based in Saudi Arabia, they are the first organization to enter the OpenChain Community of Conformance from that region.

Seven Services is a multi-industry company, delivering advanced services and solutions tailored to meet the evolving demands of multiple industries. With a strong commitment to innovation, reliability, and excellence, we specialize in providing comprehensive solutions across key sectors, including:

  • Information Technology
  • Security
  • Oil & Gas
  • Industrial Support
  • Facility Management
  • General Trading
  • Logistics

Committed to innovation and customer success, Seven Services empowers businesses with secure, efficient, and scalable solutions.

You Will Find Their Listing In The Community of Conformance Here:

Learn More About The Organization:

OpenChain Newsletter #81

By Monthly Newsletter, News

Newsletter – Issue 81 – August 2025

The OpenChain Newsletter provides a monthly summary of our work. It contains an overview of what we are doing to build trust around license compliance and security in the open source supply chain. We accept suggestions and ideas. Feel free to mail us at any time.

Key Updates and Announcements

  • AI System Bill of Materials Guide: The public comment period for the “Artificial Intelligence System Bill of Materials – Compliance Management Guide for the Supply Chain” has now closed. The AI Work Group, Governing Board, and Steering Committee are reviewing the feedback received. You can follow the progress and view the draft guide here.
  • OpenChain at Open Source Summit Europe: The OpenChain Project had a strong presence at the recent Open Source Summit Europe, with talks and panels from board members and work group chairs. A mini-summit was also held to share knowledge on license, security, and regulatory compliance. You can learn more about the event here.
  • Call for Translation Collaboration: The OpenChain Project is seeking community assistance in translating the self-certification materials for ISO/IEC 5230 (Open Source License Compliance) and ISO/IEC 18974 (Open Source Security Assurance) into German, Japanese, Korean, and Chinese (Simplified and Traditional). If you are fluent in these languages, you can contribute to this important effort. Draft machine translations are available on GitHub to get you started. Find out more here.
  • Improved Self-Certification: The online self-certification process for both OpenChain ISO/IEC 5230 and OpenChain ISO/IEC 18974 has been updated and improved, making it easier for organizations to assess and declare their conformance. Check out the updates here.
  • OpenChain in China: A successful mini-summit on “Open Source Software Supply Chain Security Compliance in the AI Era” was held at the 2025CCF China Open Source Conference in Shanghai. The event was led by the OpenChain China Work Group and covered both legal and technical aspects of compliance. Read more about it here.
  • Understanding the CHAOSS Project: A recent webinar explored the CHAOSS (Community Health Analytics for Open Source Software) project, a Linux Foundation initiative focused on developing metrics and software to better understand the health of open source communities. You can find more information about this informative session here.

Recent Meeting Recordings

For those who missed them, recordings of recent OpenChain meetings are now available:

  • Monthly Specification and Education Call (North America – Europe) – August 13, 2025: This call covered the latest project news, a call for papers for the Open Compliance Summit, and updates from the Specification and Education Work Groups. You can watch the recording here.
  • OpenChain Japan Community Day #34 at Mitsubishi Electric: Recordings from this two-day event, featuring discussions on OSPO activities, preventing common licensing mistakes, and an introduction to OSS compliance for beginners, are now online. Access the recordings here.

Potential Further Actions for Readers

  • Attend Future Meetings: The best way to stay informed and contribute is to participate in the various OpenChain work group calls. The monthly Specification and Education calls, along with other topical and regional meetings, are open to everyone. You can find the full schedule of upcoming meetings and information on how to join on the OpenChain participation page.
  • Contribute to Translations: If you have language skills, your contribution to the translation of self-certification materials would be highly valuable. This is a practical way to help the global community adopt OpenChain standards.
  • Engage with Work Groups: Consider joining the mailing lists of the work groups that align with your interests, such as the AI Work Group, Specification Work Group, or Education Work Group. This will allow you to follow discussions and contribute your expertise.

To get more involved in any of these activities and to help build a more trusted open source supply chain, please visit: https://openchainproject.org/participate

Note: This newsletter usually only contains primary meetings. Some community meetings are not recorded or are released through other channels.

Read Previous Newsletters:

AI Usage:

This newsletter is created by using a template, curating links from a month of OpenChain news posted on the blog and using these prompts on Google Gemini to fill out the central news:

  • “Summarize the following newsletter for folks interested in the open source compliance to learn the latest changes in the space and find possible items that can act on. Include the links in this newsletter. Add notes on potential further actions by readers, particularly around attending future meetings. Direct people to this link to participate further: https://openchainproject.org/participate”

The newsletter is then subject to an edit cycle. If you spot any errors we missed, please contact us.

RECORDING: OpenChain SBOM Work Group – Monthly Meeting – 2025-09-24

By News

As always, we focused on the question of “how do we use SBOMs in production, large-scale and complex supply chains?”

This Meeting Discussed:

  1. The next steps for the SBOM Work Group and its Guide to SBOM Quality
  2. Any Other Business

Watch the Meeting:

Learn More About This Study Group:

Our SBOM Study Group brings all our various SBOM-related activities together and helps answer the question of “how do we use SBOMs in production, large-scale and complex supply chains?” Our original kick-off call has all the details.

Get Involved:

Everyone is welcome to be part of this study group! OpenChain has free, open access to all its work groups and study groups. Just turn up, and listen in, and contribute comments, ideas and suggestions.

✉️ We have a dedicated mailing list: https://lists.openchainproject.org/g/sbom

💻 We have a dedicated GitHub Repo: https://github.com/OpenChain-Project/SBOM-sg

Attend Future Meetings:

You can find and get the dial-in details for all future meetings from our participate page here: https://www.openchainproject.org/participate

OpenChain @ Balkan Computer Congress (BalCCon2k25)

By News

OpenChain was represented by Vladimir Slavov at the Balkan Computer Congress (BalCCon2k25) on the 21st of September with a talk entitled ‘OpenChain: Towards a More Secure and Compliant Software Supply Chain.’

The talk was split into three parts of roughly the same length.

Part 1 made the case for implementing a program to manage OSS in your organization. It focused on both the positive effects of establishing such a program, as well as the risks assumed by not having one.

Part 2 focused on the OpenChain ISO Standards and how they can be used as simple reference documents for upgrading your operations for a secure and compliant software supply chain.

Part 3 was about the OpenChain community, what it has to offer, and how you can get involved and contribute. Special focus was placed on the OpenChain Eastern European chapter we are currently in the process of establishing, with an open invitation to anyone who would like to participate.

Learn more:

RECORDING: OpenChain Monthly Specification and Education Call (Europe / Asia) – 2025-09-17

By News

We Discussed:

Lead by Martin Yagi (Chair Education Work Group), the call covered the following agenda:

  • OpenChain Project News
  • Open Compliance Summit – Call for Papers
  • Specification Work Group – Some Questions for the Community
  • Education Work Group – Update on Status and Community Work Items
  • Any Other Business?

A reminder for those in Asia – while this edition of the monthly call is happening in the darkest hours of the night (01:30 in Japan!), we also have a monthly Europe / Asia call that works better for those in Eastern time zones. Check out the schedule for this and all our other meetings here:
https://openchainproject.org/participate

Watch the Recording:

Coming Next:

  • A ton of work pending on education, and a survey to be released for the spec. Expect a strong focus on looking at what we have accomplished, looking at feedback, and making it better.

Join Our Work:

Everyone is welcome to be part of the Specification Work Group. You can join their mailing list here:
https://lists.openchainproject.org/g/specification/

You can find and be part of all OpenChain calls through our participation page here:
https://openchainproject.org/participate

Update on OpenChain ISO/IEC 18974 and the CRA

By News

Thanks in no small part to the advocacy of SZ Lin, OpenChain ISO/IEC 18974 has been officially referenced in the EU Cyber Resilience Act (CRA) harmonized standards discussion.

You will find OpenChain ISO/IEC 18974 cited in Slide 67 of the “CRA Standards Unlocked: Unlocking CRA Security Controls: preparation for UNE Event” from CEN CENELEC:

We are referenced alongside:
• ISO/IEC TR 5895:2022 – Cybersecurity – Multi-party coordinated vulnerability disclosure and handling
• ISO/IEC 30111:2019 – Information technology – Security techniques – Vulnerability handling processes
• ISO/IEC 29147:2018 – Information technology – Security techniques – Vulnerability disclosure

What this means:

The value of our security standard has been positively recognized by the parties bringing together the official CRA standards / requirements portfolio.

It provides a door to both continue and expand our collaboration in this space. The precise next steps will be determined in collaboration with our community and the governing board.

Welcoming the OpenChain Ambassador Program

By Featured, News

OpenChain Ambassadors are official advocates within the OpenChain Project helping build a more trusted supply chain. They are a point of contact for new participants, and can help connect the community with knowledge and solutions. They provide support, training, mentorship and guidance to help:

  • With OpenChain community through local meetups, events, and content
  • Foster strong community collaboration and relationships
  • Attract and welcome new community participants
  • Provide feedback to the OpenChain Governing Board about community programs and initiatives
  • Advocate OpenChain best practices and OpenChain initiatives around the world

We are delighted to welcome 21 initial ambassadors from around the world, and to provide an even greater community of support for everyone working on a more trusted supply chain.

To learn more about who is in the program, and how to contact them, via our official Ambassadors page.