Skip to main content
All Posts By

Shane Coughlan

Shane Coughlan is an expert in communication, security and business development. His professional accomplishments include spearheading the licensing team that elevated Open Invention Network into the largest patent non-aggression community in history, establishing the leading professional network of Open Source legal experts and aligning stakeholders to launch both the first law journal and the first law book dedicated to Open Source. Shane has extensive knowledge of Open Source governance, internal process development, supply chain management and community building. His experience includes engagement with the enterprise, embedded, mobile and automotive industries.

OpenChain Telco Work Group Meetings – 2024-12-06 – Full Recording

By News

Watch the European Morning Recording:

Watch the European Afternoon Recording:

Be part of this:

You can get involved with the OpenChain Telco Work Group through their dedicated mailing list. At this link, you will also find connections to other working groups around the world:

Please note: you do not have to be an expert in telecommunications or work for a telecommunications company to join the group. Work on subjects like the Telco SBOM Quality Guide is intended to also help other market sectors.

Webinar: CHAOSS Practitioner Guides for Healthy & Sustainable OSS Projects

By automation, community, legal, licensing, News, security, Webinar

We had an insightful session with Dawn Foster on sustaining OSS projects and communities over the long-term. The CHAOSS project has been creating a series of MIT-licensed Practitioner Guides focused on improving the sustainability of our software and communities. The guides are designed to make it easier for people to draw meaningful and actionable insights using community metrics, even when those people do not necessarily have a deep background in data analysis or much experience working within OSS communities.

This talk identified several categories of metrics from the Practitioner Guide Series, including responsiveness, contributor sustainability, organizational participation, and security. It covered not just how to interpret the metrics, but also on providing ideas for improving in areas identified using the metrics. The audience walks away with a better understanding of how to use metrics to proactively improve the long-term sustainability of their OSS projects and communities.

Watch The Recording

About Our Speaker

Dawn leads the data science initiative for the CHAOSS project where she is also a Governing Board member / maintainer. Dawn is an OpenUK board member and co-chair of the CNCF Contributor Strategy Technical Advisory Group.

Dawn has 20+ years of experience working in open source positions at companies like VMware, Intel and Puppet with expertise in managing people, open source strategy, building new communities, and managing existing communities with a particular emphasis on developer and open source communities. She has held a wide range of roles over the years, including UNIX system administrator, researcher, consultant, strategist, director / manager, and more.

Dawn holds a PhD from the University of Greenwich, an MBA from Ashland University, and a BS in Computer Science from Kent State University. Dawn blogs about online communities as the author of the Fast Wonder Blog, and she’s blogged for The New Stack, Linux.com, GigaOM’s WebWorkerDaily, and in various other places.

She has done over a hundred talks at industry events, including many Linux Foundation events, KubeCon, OSCON, SXSW, FOSDEM and more. In her spare time she enjoys reading science fiction, running, and traveling.

More About Our Webinars:

This event is part of the overarching OpenChain Project Webinar Series. Our series highlights knowledge from throughout the global OpenChain eco-system. Participants are discussing approaches, processes and activities from their experience, providing a free service to increase shared knowledge in the supply chain. Our goal, as always, is to increase trust and therefore efficiency. No registration or costs involved. This is user companies producing great informative content for their peers.

Check Out The Rest Of Our Webinars

This OpenChain Webinar was broadcast on 2024-12-05.

UnionTech Software Announces An ISO/IEC 18974 Conformant Program

By Featured, News

UnionTech Software – known for Deepin Linux – has announced an ISO/IEC 18974 conformant program.

About UnionTech Software

UnionTech Software is a research and development leader in the operating system
industry in China, ranking among the top tier in terms of market share and
ecological maturity. It has a focus on technical accumulation in research and development,
internationalization, industry customization, migration and adaptation, and
interactive design. UnionTech Software has established a diverse range of operating system product lines, including desktops, servers, intelligent terminals, and more. Over 6 million installations of UOS operating systems have been deployed in key sectors across 40,000 customers.

Learn More About UnionTech Software

Webinar: Enabling SBOMs Across The Linux Foundation

By automation, legal, licensing, News, standards, Webinar

We have been doing source level license scans for Linux Foundation (LF) projects for a long time including generating SPDX formatted files, but what about SBOMs that can meet (and exceed) the government minimum specification? Here at the LF, we are now leveraging our existing scanning capabilities to generate SBOMs for these same critical open source projects.

In the LF spirit, we are using existing open source tools to scan project dependencies to produce an SBOM that meets the minimum spec. We are also producing dependency level license data to complement our source level scans. In the near future we will be combining these to produce a grand unified SBOM that will meet a newly defined LF minimum specification for SBOMs.

We will talk about our process to generate these SBOMs, the challenges we faced, our future plans, and share more about how you can make use of these for the projects you care about most.

Watch The Recording

About Our Speakers

Gary O’Neall

Gary is a contributor to the Software Package Data Exchange® (SPDX™) – an open standard for communicating software bill of material information, including components, licenses, copyrights, and security references. Gary has contributed several open source tools. Gary O’Neall is responsible for product development and technology for Source Auditor Inc., a software and service company helping software companies manage the technical and legal risks of open-source software.

Jeff Shapiro

Jeff Shapiro is the Director of License Scanning for The Linux Foundation. He has over 30 years of experience in the software industry, including 10 years in software auditing, open source scanning, and training developers in OSS license compliance.

More About Our Webinars:

This event is part of the overarching OpenChain Project Webinar Series. Our series highlights knowledge from throughout the global OpenChain eco-system. Participants are discussing approaches, processes and activities from their experience, providing a free service to increase shared knowledge in the supply chain. Our goal, as always, is to increase trust and therefore efficiency. No registration or costs involved. This is user companies producing great informative content for their peers.

Check Out The Rest Of Our Webinars

This OpenChain Webinar was broadcast on 2024-12-04.

Full Recording: OpenChain SBOM Study Group – 2024-11-27

By News

In this SBOM Study Group meeting, Okada San from OWASP Japan lead an overview of ”Vulnerabilities and the Future – Multilayered Software Vulnerabilities and Response Tactics.” This discussion built on a talk he recently delivered at the first Japan SBOM Summit on a similar topic.

Watch The Recording:

Learn More About This Study Group:

Our new SBOM Study Group brings all our various activities together and helps answer the question of “how do we use SBOMs in production, large-scale and complex supply chains?” Our original kick-off call has all the details.

Get Involved Through Our Mailing List:

Full Recording: OpenChain AI Work Group – Monthly Workshop for North America and Europe – 2024-12-03

By News

With its new structure as an official OpenChain Work Group, and a clear mandate to work on an Guide to AI Compliance BOM, this is the first call in a new series to pull thoughts together into a practical guide.

The document they are working from is here:
https://docs.google.com/document/d/1g1kdmx1bDlQ0feSeW-ZY5JRFAF-HC30a/edit

Watch The Recording:

Track This Work:

You can follow and contribute to the work of the OpenChain AI Work Group through its dedicated mailing list. This is open to everyone regardless of industry vertical or speciality. You will find it here:

Attend Future Meetings:

You can find and get the dial-in details for all future AI Work Group meetings from our participate page here:

Full Recording: OpenChain AI Study Group Call – Asia Sync Call – 2024-11-14

By News

The OpenChain AI Study Group held its regular Asia sync on the 14th of November. This focused on a recap of the earlier monthly workshop, which had a discussion around the draft scratchpad for management of AI BOMs, and the conversion of this study group into a formal working group.

Track This Work

You can follow and contribute to the work of the OpenChain AI Study Group through its dedicated mailing list. This is open to everyone regardless of industry vertical or speciality. You will find it here:

Attend Future Meetings

You can find and get the dial-in details for all future AI Study Group meetings from our participate page here:

HLB Surlatina Chile Announces An OpenChain ISO/IEC 5230 Conformant Program

By Featured, News

HLB Surlatina Chile, a firm established in 1971 and with 50 years of experience in the Chilean market, has announced an OpenChain ISO/IEC 5230 conformant program.

About HLB Surlatina Chile:

HLB Surlatina Chile is part of HLB International, a global audit and advisory organization headquartered in London, and has a long-standing history of advising clients and priding itself on being an organization based on values, committed to delivering the highest quality standards. HLB International employees over 30 thousand professionals in 160 countries from across the world to help clients grow across borders.

Visit Their Website:

Full Recording: Understanding How OpenChain ISO/IEC 5230 and ISO/IEC 18974 Support InnerSource (InnerSource Commons Summit 2024)

By News

Shane Coughlan, OpenChain General Manager, delivered a speech entitled ‘Understanding how OpenChain ISO/IEC 5230 and ISO/IEC 18974 support InnerSource’ at the InnerSource Summit 2024.

Abstract:

This talk discussed how OpenChain ISO/IEC 5230 (the international standard for open source license compliance) and ISO/IEC 18974 (the international standard for open source security assurance) support the work of InnerSource program offices. While supply chain management is often seen as external relationships between customers and suppliers, internal supply chain management is just as critical. Using industry standards in this context ensures alignment with broader market expectations, and ensures that remediation, catch-up and process mis-match is minimized.

Coming Soon: OpenChain Webinar – Enabling SBOMs Across The Linux Foundation – 2024-12-04 @ 00:00 UTC

By News

The latest OpenChain Webinar will feature Jeff Shapiro and Gary O’Neall.

At the time of the event you can join us at:
https://zoom-lfx.platform.linuxfoundation.org/meeting/98013366941?password=02a35380-0692-497d-b5a9-05e650965da4

Abstract:

We have been doing source level license scans for Linux Foundation (LF) projects for a long time including generating SPDX formatted files, but what about SBOMs that can meet (and exceed) the government minimum specification? Here at the LF, we are now leveraging our existing scanning capabilities to generate SBOMs for these same critical open source projects.

In the LF spirit, we are using existing open source tools to scan project dependencies to produce an SBOM that meets the minimum spec. We are also producing dependency level license data to complement our source level scans. In the near future we will be combining these to produce a grand unified SBOM that will meet a newly defined LF minimum specification for SBOMs.

We will talk about our process to generate these SBOMs, the challenges we faced, our future plans, and share more about how you can make use of these for the projects you care about most.

Speakers:

Gary O’Neall

Gary is a contributor to the Software Package Data Exchange® (SPDX™) – an open standard for communicating software bill of material information, including components, licenses, copyrights, and security references. Gary has contributed several open source tools. Gary O’Neall is responsible for product development and technology for Source Auditor Inc., a software and service company helping software companies manage the technical and legal risks of open-source software.

Jeff Shapiro

Jeff Shapiro is the Director of License Scanning for The Linux Foundation. He has over 30 years of experience in the software industry, including 10 years in software auditing, open source scanning, and training developers in OSS license compliance.