THE LINUX FOUNDATION PROJECTS
Category

Featured

Hitachi Energy achieves OpenChain (ISO 5230) Certification, reinforcing commitment to Open Source excellence

By Featured, News

Hitachi Energy is proud to announce that it has achieved OpenChain (ISO 5230) certification, the leading global standard for open source compliance. This milestone underscores our dedication to delivering products that meet the highest standards of quality, security, and transparency.

By attaining ISO 5230 certification, Hitachi Energy demonstrates a mature and reliable open source compliance program that partners and customers can trust. This achievement reduces legal and operational risks, streamlines documentation, and ensures consistent, well-governed use of open source technologies across our organization. It also strengthens our position in global supply chains, where ISO 5230 certification is increasingly recognized as a mark of professionalism and readiness for evolving regulatory requirements such as the Cyber Resilience Act. The certification brings tangible benefits to our customers and partners. It enables faster collaboration and onboarding, minimizes audit requirements, and ensures predictable, high-quality products through standardized and repeatable compliance processes. Ultimately, it reflects our commitment to building trust and fostering strong relationships throughout the technology ecosystem.

Achieving OpenChain certification is more than a milestone, it is a statement of our ongoing dedication to responsible open source use, industry best practices, and continuous improvement. Hitachi Energy remains focused on driving innovation while maintaining the highest standards of governance and security across all our products and services.

About the Bureau Veritas:

Bureau Veritas is a globally recognized leader in inspection, conformity assessment, and certification services, with a presence in countries worldwide.

Founded in 1828, it supports clients in improving performance through innovative solutions and services aimed at verifying that products, assets and processes meet mandatory and voluntary standards in quality, health and safety, environment and social responsibility (QHSE-SA).

Bureau Veritas offers a comprehensive cybersecurity services portfolio, leveraging global expertise to ensure a consistent customer experience across all areas of cybersecurity.

About the OpenChain Project:

The OpenChain Project has an extensive global community of over 1,000 companies collaborating to make the supply chain quicker, more effective and more efficient. It maintains OpenChain ISO/IEC 5230, the international standard for open source license compliance programs and OpenChain ISO/IEC 18974, the industry standard for open source security assurance programs.

About The Linux Foundation:

The Linux Foundation is the world’s leading home for collaboration on open source software, hardware, standards, and data. Linux Foundation projects are critical to the world’s infrastructure, including Linux, Kubernetes, Node.js, ONAP, PyTorch, RISC-V, SPDX, OpenChain, and more. The Linux Foundation focuses on leveraging best practices and addressing the needs of contributors, users, and solution providers to create sustainable models for open collaboration. For more information, please visit us at linuxfoundation.org.

Check Out The Publicly Announced Community of Conformance:
https://openchainproject.org/community-of-conformance

Panasonic Automotive Systems Announces OpenChain ISO/IEC 5230 Conformance

By Featured, News

Today Panasonic Automotive Systems has announced an OpenChain ISO/IEC 5230 conferment program. As a leading Tier 1 automotive supplier, Panasonic Automotive Systems is at the forefront of both using and effectively managing open source technology.

“During the certification process, we worked to improve the reliability of our OSS usage and products by structuring OSS utilization processes and building a highly secure management system.” said Masashige Mizuyama, Executive Vice President and Chief Technology Officer at Panasonic Automotive Systems. “We have actively contributed to the industry by promoting the standardization and open-sourcing of VirtIO, an open-source virtualization technology. Taking this certification as an opportunity, we will continue to provide high-quality and highly reliable solutions leveraging OSS, and contribute to the expansion and sustainable growth of the open source ecosystem in the in-vehicle device industry.”

“We are delighted to welcome Panasonic Automotive Systems into our community of conformance,” says Shane Coughlan, OpenChain General Manager. “Adoption of OpenChain ISO/IEC 5230 has been exceptional across the automotive supply chain, and the influence and inspiration provided by Tier 1 adoption cannot be overstated. We look forward to working with the Panasonic Automotive Systems team in the months and years ahead.”

About Panasonic Automotive Systems Co., Ltd.:

Panasonic Automotive Systems Co., Ltd., (PAS) was launched on April 1, 2022 as an operating company responsible for the automotive systems business in line with the start of the Panasonic Group’s operating company system, and on December 2, 2024 the company moved to a management structure in which 80% of its shares are held by the funds managed by an affiliate of Apollo Global Management, Inc. and 20% by Panasonic Holdings Corporation.

Headquartered in Japan, PAS is a global company with subsidiaries in eight other countries and, as a Tier 1 company, it provides advanced proprietary technologies such as infotainment systems to automakers in Japan and overseas, helping to create comfortable, safe, and secure automobiles. PAS is committed to meeting the expectations of its customers around the world with technologies that stand by people in pursuit of its corporate vision of becoming the “Joy in Motion” design company. To learn more about our company, please visit https://automotive.panasonic.com/en

About the OpenChain Project:

The OpenChain Project has an extensive global community of over 1,000 companies collaborating to make the supply chain quicker, more effective and more efficient. It maintains OpenChain ISO/IEC 5230, the international standard for open source license compliance programs and OpenChain ISO/IEC 18974, the industry standard for open source security assurance programs.

About The Linux Foundation:

The Linux Foundation is the world’s leading home for collaboration on open source software, hardware, standards, and data. Linux Foundation projects are critical to the world’s infrastructure, including Linux, Kubernetes, Node.js, ONAP, PyTorch, RISC-V, SPDX, OpenChain, and more. The Linux Foundation focuses on leveraging best practices and addressing the needs of contributors, users, and solution providers to create sustainable models for open collaboration. For more information, please visit us at linuxfoundation.org.

Check Out The Publicly Announced Community of Conformance:
https://openchainproject.org/community-of-conformance

Analog Devices, Inc. has announced OpenChain ISO/IEC 5230:2020 conformance

By Featured, News

Analog Devices, Inc. (ADI) has announced an OpenChain ISO/IEC 5230:2020 conformant program, making another important step forward for open source governance and management in the global silicon supply chain.

“Achieving OpenChain conformance underscores our belief that open source stewardship is foundational to engineering excellence,” said Rob Oshana, Senior Vice President, Software & Digital Platforms at ADI. “It reinforces our commitment to transparent processes, clear compliance standards and continuous improvement across the software lifecycle.”

“ADI is an excellent steward of open source,” says Shane Coughlan, OpenChain General Manager. “Their contributions to the open source community have been notable too, not least their direct engagement with the OpenChain Project as we have developed and deployed standards and reference material related to open source compliance. It is a genuine pleasure to welcome them to our community of conformance, and we look forward to continued collaboration in the future.”

About ADI

ADI is a global semiconductor leader that bridges the physical and digital worlds to enable breakthroughs at the Intelligent Edge. ADI combines analog, digital, AI, and software technologies into solutions that help drive advancements in automation and robotics, mobility, energy and data centers, and healthcare, combat climate change, and reliably connect humans and the world. With revenue of more than $11 billion in FY25, ADI ensures today’s innovators stay Ahead of What’s Possible. Learn more at www.analog.com and on LinkedIn and X (formerly Twitter).

About the OpenChain Project:

The OpenChain Project has an extensive global community of over 1,000 companies collaborating to make the supply chain quicker, more effective and more efficient. It maintains OpenChain ISO/IEC 5230, the international standard for open source license compliance programs and OpenChain ISO/IEC 18974, the industry standard for open source security assurance programs.

About The Linux Foundation:

The Linux Foundation is the world’s leading home for collaboration on open source software, hardware, standards, and data. Linux Foundation projects are critical to the world’s infrastructure, including Linux, Kubernetes, Node.js, ONAP, PyTorch, RISC-V, SPDX, OpenChain, and more. The Linux Foundation focuses on leveraging best practices and addressing the needs of contributors, users, and solution providers to create sustainable models for open collaboration. For more information, please visit us at linuxfoundation.org.

Open Compliance Summit 2025 – Review and Photos

By Featured, News

The Open Compliance Summit 2025 was a tremendous success, with strong representation from China, Japan, Korea, Germany, Sweden, the United States, the United Kingdom, India and more. Over a packed schedule on the 11th and 12th December, attendees shared knowledge, networked and provided an exceptionally strong analysis of what is coming for licensing, security and regulatory compliance in 2026.

This event provided a substantial amount of analysis around OpenChain Project-related activities, ranging from the ISO standards to capability modeling, SBOM quality and AI System Bill of Material management.

The Open Compliance Summit is expected be held again in December 2026, and talk submissions are welcome. Learn more about the event on the official LF website around April 2026: https://events.linuxfoundation.org

This event also marked the last public event of our current General Manager, Shane Coughlan. We had a little ceremony and took some photos.

OpenChain and Friends 2026 – Stuttgart – March 24~26

By Featured, News

Registration is required for this free event / kostenlose Veranstaltung, aber Registrierung ist erforderlich

In-person only.  (Please actively select/de-select the topics you plan to attend or not, we will only consider your registration for the actively selected tracks on a first come first serve base. By submitting your registration you confirm to follow the event code of conduct.)

We will hold the second annual OpenChain and Friends event in Stuttgart from the 24th to the 26th of March 2026. (learn about last year’s edition here: https://openchainproject.org/news/2025/02/20/openchain-and-friends-stuttgart )

Main Event Location:

Satellite Event Locations:

In Partnership With:

The FOSS-LÄND Community

Topic Streams:

  1. Open Source Compliance and OSPOs  – Open Source Compliance & OSPO – processes, automation, governance & NFRs
  2. Cybersecurity – Cybersecurity in the Software Supply Chain – CRA, SBOM requirements, ISO 18974, and good practices
  3. Women in Open Source – networking and cross-track contributions
  4. Embedded and Open Source Hardware – from chip design to licensing and IP questions
  5. Artificial Intelligence – AI Systems Engineering & Data Platforms – methods, tools, open platforms, open AI agents for resilient supply chains
  6. Digital Sovereignty and Open Source in Business – public/private collaboration, open source as a competitive factor
  7. Education – open trainings, infrastructure, new formats
  8. Automotive /SDV – Open Automotive Platform, Ecosystems, Tool Interoperability
  9. Cross-Innovation and Innovation Practicespotential of mixing creative industries and digital sovereignty ideas with industrial Open Source
  10. Linux OS and beyondsoftware supply chain from the Linux ecosystem perspective

KEYNOTES

on tuesday march 24th 2026:

Bjoern Schiessle Nextcloud

“Digital sovereignty isn’t about choosing your dependencies — it’s about eliminating them.”

Björn Schiessle,  Co-founder and Director of Sales Engineering at Nextcloud

Charley Mann & Florian Wohlrab OpenHW Foundation

“The Unified RISC-V IP Access Platform is absolutely critical to supporting technological sovereignty in Europe, and the OpenHW Foundation is committed to developing it into a sustainable, interoperable, and community driven resource for the wider RISC-V ecosystem. Open source collaboration is essential to ensuring a competitive playing field, and by working together, we will be able to go further, faster.”

Florian Wohlrab, CEO, OpenHW Foundation

Dr.-Ing. Thomas Usländer Fraunhofer IOSB

„Beyond and precisely because of the AI hype there is need for a systematic approach to engineer, develop, deploy and operate AI systems. If not applied along the whole lifecycle, there is no sustainable and commercial benefit of an AI system.”

– Dr.-Ing. Thomas Usländer, Business Developer AI Systems Engineering, Fraunhofer IOSB, and head of the subprojects “AI Data Platform” and “AI Challenge” of the AI Alliance Baden-Württemberg

 

on wednesday march 25th 2026:

Prof. Dr. Ingo Weber (Fraunhofer Gesellschaft / TU Munich)

   “George Box famously said: ‘All models are wrong, but some models are useful.’ This is also true for LLMs.
But to know how we can make them useful, openness in code, data, and governance helps.”

– Prof. Dr. Ingo Weber, Director for AI & Innovation at the Fraunhofer Gesellschaft, Full Professor and Chair of Information System Development and Operation in the Computer Science Department at the TUM School of Computation, Information and Technology (Technical University of Munich)

Dr. Ingo Simonis (CTO Open Geospatial Consortium)


“The most powerful AI systems won’t be built in isolation. They’ll emerge from open platforms where diverse communities collaborate, share data, and validate solutions together”

– Dr. Ingo Simonis (CTO Open Geospatial Consortium)

Program details and schedule are collaboratively developed and can be tracked in our repository: OpenChain and Friends Program 2026.

 

Preliminary schedule (as of 2026-02-19 increment 1 – updates will be regularly provided – stay tuned!)

OpenChainAndFriends_preliminary_schedule_inc1.pdf.


SPONSORS

DIAMOND

BRONZE

Contact FOSS@e-mobilbw.de or helpdesk@lists.openchainproject.org for more information. We would love for you to be part of this, and to help contribute to our welcoming community of open source governance professionals. We welcome everyone from small, medium and large companies, local and national government, non-profit organizations, academica and also independent parties curious about what is happening in this space.


Event is listed in https://foss.events/ ;  submitted to https://confs.tech/ and https://dev.events/

A Message from the Governing Board of the OpenChain Project

By Featured, News

A message from the Governing Board of the OpenChain Project:

We wanted to let you know that there will be a rotation in the administrative leadership of the OpenChain Project in Mid-December 2025. Shane Coughlan, our General Manager over the last eight years, will be transitioning to work on a personal venture, and we will shortly be announcing a new executive leader in the same role. In the meantime, the Governing Board, The Linux Foundation project management office, the Work Group Chairs and the Ambassadors will collaborate as usual to continue our normal meetings, releases and community building.

The Governing Board would like to express their gratitude to Shane for all the work he has put into the project over the years, constantly going above and beyond. Shane’s work with the OpenChain Project is nothing short of spectacular, he has been a community builder, role model, and friend to the OpenChain community and he will be missed. The board want to wish him the best of luck in his new endeavors and for him to know that he will forever remain part of the OpenChain family he helped create.

“I have been honored to work on this project, with this board and with everyone in our exceptional community over the last eight and a half years,” says Shane Coughlan, OpenChain General Manager. “After such a long period, and enjoying so much collective success, it is a difficult decision to move on to a new venture. However, there is a personal project that I want to attend to, and the passage of time has suggested to me that it is appropriate to begin work on that activity. I will speak more to this in early 2026, but for now my focus is on finalizing the transition of the administrative leadership of the OpenChain Project. We have extensive internal process material and a purposefully distributed management system to aide in sustainability and such transitions, and I am fully confident in the health and continued momentum of the project and our activities.

In closing, I want to take a moment to thank everyone who has made this journey possible for me. While there are too many people to name individually – such is the scale of our community and accomplishment – I would like to give special thanks to David Marr of Qualcomm for leading the foundation of the OpenChain Project, to Jimmy Ahlberg of Ericsson for leading us through the evolution into a multi-ISO standard project, to Watanabe San, Kobota San, Owada San and Fukuchi San for being instrumental in the development of our work in Japan, to Haksung Jang for leading our work in Korea to such success, to Zhenhua Sun in China for his leadership and driving frequent local meetings, to Oliver Fendt and Marcel Kurzmann in Germany for endlessly encouraging and supporting one of the exceptional local communities in the domain of processes and automation, and finally to the dearly departed Ueda San for providing inspiration in community building that has always helped guide and ensure the success of what we do.

And finally my thanks to you all, who have attended calls, come to meetings and read (and reshared) our news across the world. You made this community, and you made this success. I am grateful to call you my colleagues in open source.”

An administrative note: For those of you interested in learning more about this transition for 2026 – and about the executive leadership role – you can contact Renu from the Project Management office at helpdesk@lists.openchainproject.org

CJ Logistics Becomes First in Korean Logistics Industry to Adopt OpenChain ISO/IEC 5230

By Featured, News

CJ Logistics announced on the 5th that it has obtained ‘OpenChain ISO/IEC 5230:2020′ international standard certification.

The OpenChain Project, an initiative led by the U.S. non-profit organization The Linux Foundation, maintains  ‘ISO/IEC 5230:2020’ and provides self-certification support to companies. These companies can use the standard and self-certification material to audit and develop a robust open source license compliance program and management capabilities.

This achievement is the first of its kind among Korean logistics companies and signifies that CJ Logistics has received international recognition for its responsible management of open source software throughout its digital transformation.

About the OpenChain Project:

The OpenChain Project has an extensive global community of over 1,000 companies collaborating to make the supply chain quicker, more effective and more efficient. It maintains OpenChain ISO/IEC 5230, the international standard for open source license compliance programs and OpenChain ISO/IEC 18974, the industry standard for open source security assurance programs.

About The Linux Foundation:

The Linux Foundation is the world’s leading home for collaboration on open source software, hardware, standards, and data. Linux Foundation projects are critical to the world’s infrastructure, including Linux, Kubernetes, Node.js, ONAP, PyTorch, RISC-V, SPDX, OpenChain, and more. The Linux Foundation focuses on leveraging best practices and addressing the needs of contributors, users, and solution providers to create sustainable models for open collaboration. For more information, please visit us at linuxfoundation.org.

Check Out The Publicly Announced Community of Conformance:

Telechips Announces an OpenChain ISO/IEC 5230 Conformant Program

By Featured, News

Telechips, a leading global fabless company specializing in SoC (System on Chip) solutions for automotive and smart devices, has announced an OpenChain ISO/IEC 5230 conformant program.

“The acquisition of OpenChain certification demonstrates that Telechips has advanced beyond simply utilizing open source to establishing systematic management capabilities and transparent governance in compliance with global standards,” said Jiyoung Yeon, Open Source Manager at Telechips. “Building on our technological expertise and trusted reputation in automotive semiconductor design, we will continue to strengthen transparent open source operations—such as Software Bill of Materials (SBOM) management—and actively contribute to the growth of the global open source ecosystem and the establishment of sustainable technology standards.”

“We are delighted to welcome Telechips to the OpenChain Community of Conformance,” says Shane Coughlan, OpenChain General Manager. “This is another landmark in demonstrating the applicability of our ISO standard for open source license compliance with industries of all types across the global supply chain. We look forward to working with our colleagues at Telechips and with other companies in the silicon domain on the management of open source.”

About Telechips:

Telechips is a leading global fabless company specializing in SoC (System on Chip) solutions for automotive and smart devices. With more than 25 years of innovation and expertise, Telechips provides high-performance and secure semiconductor platforms that power next-generation infotainment, digital cluster, ADAS, and connectivity systems. As the industry rapidly shifts toward SDVs (software-defined vehicles), we are expanding beyond our core in-vehicle infotainment application processors (APs) to a next-generation lineup that includes MCUs, ADAS solutions, and in-vehicle networking.
Backed by globally competitive high-performance, low-power SoC design capabilities and customer-tailored solutions, Telechips is accelerating its entry into the global SDV market. We also practice ESG management to help build a sustainable future. Guided by our vision—“New innovations for the future our customers want”—we partner with global customers to shape a better tomorrow.

About the OpenChain Project:

The OpenChain Project has an extensive global community of over 1,000 companies collaborating to make the supply chain quicker, more effective and more efficient. It maintains OpenChain ISO/IEC 5230, the international standard for open source license compliance programs and OpenChain ISO/IEC 18974, the industry standard for open source security assurance programs.

About The Linux Foundation:

The Linux Foundation is the world’s leading home for collaboration on open source software, hardware, standards, and data. Linux Foundation projects are critical to the world’s infrastructure, including Linux, Kubernetes, Node.js, ONAP, PyTorch, RISC-V, SPDX, OpenChain, and more. The Linux Foundation focuses on leveraging best practices and addressing the needs of contributors, users, and solution providers to create sustainable models for open collaboration. For more information, please visit us at linuxfoundation.org.

Check Out The Publicly Announced Community of Conformance:
https://openchainproject.org/community-of-conformance

NXP Semiconductors Announces an ISO/IEC 5230 Conformant Program

By Featured, News

NXP Semiconductor, a company that designs purpose-built, rigorously tested technologies that enable devices to sense, think, connect and act intelligently, has announced an OpenChain ISO/IEC 5230 conformant program.

“This achievement shows our strong commitment to both using and contributing to Open Source Software and our effort to keep the highest standards for software integrity and legal adherence,” says Ileana Bratu, Open-Source Operations Manager at NXP. “Compliance goes beyond certification; it is part of our engineering mindset. We will keep improving our open source compliance program, give continuous training and encourage a culture of awareness and responsibility in all development teams.”

“It is a deep pleasure to welcome NXP to the OpenChain community,” Shane Coughlan, OpenChain General Manager. “The automotive and semiconductor industries share a deep bond not only in product, but also in how they apply rigor to process management, regulatory compliance and excellence in management. I am grateful to work alongside companies like NXP in developing a more trusted global supply chain”

About NXP Semiconductors:

NXP Semiconductors N.V. (NASDAQ: NXPI) is the trusted partner for innovative solutions in the automotive, industrial & IoT, mobile, and communications infrastructure markets. NXP’s “Brighter Together” approach combines leading-edge technology with pioneering people to develop system solutions that make the connected world better, safer, and more secure. The company has operations in more than 30 countries and posted revenue of $12.61 billion in 2024. Find out more at http://www.nxp.com/.

NXP and the NXP logo are trademarks of NXP B.V. All other product or service names are the property of their respective owners. All rights reserved. © 2025 NXP B.V

About the OpenChain Project:

The OpenChain Project has an extensive global community of over 1,000 companies collaborating to make the supply chain quicker, more effective and more efficient. It maintains OpenChain ISO/IEC 5230, the international standard for open source license compliance programs and OpenChain ISO/IEC 18974, the industry standard for open source security assurance programs.

About The Linux Foundation:

The Linux Foundation is the world’s leading home for collaboration on open source software, hardware, standards, and data. Linux Foundation projects are critical to the world’s infrastructure, including Linux, Kubernetes, Node.js, ONAP, PyTorch, RISC-V, SPDX, OpenChain, and more. The Linux Foundation focuses on leveraging best practices and addressing the needs of contributors, users, and solution providers to create sustainable models for open collaboration. For more information, please visit us at linuxfoundation.org.

Check Out The Publicly Announced Community of Conformance:
https://openchainproject.org/community-of-conformance

Hancom Announces an OpenChain ISO/IEC 5230 Conformant Program

By Featured, News

Hancom has announced an OpenChain ISO/IEC 5230 conformant program.

“We are delighted to welcome Hancom to the OpenChain community of conformance,” says Shane Coughlan, OpenChain General Manager. “Korea has a vibrant technology ecosystem, and the companies in the local area have an exceptional commitment to process excellent. Hancom is a great example of this, and we look forward to working with them to inspire other companies to adopt and use the international standard for open source license compliance.”

About Hancom:

Hancom Inc. (KOSDAQ: 030520) is software development company based in South Korea. It was founded in 1990 and is well-known for Hangul, a word processer for the Korean language. They maintain a broad portfolio of products, including in the field of AI.

About the OpenChain Project:

The OpenChain Project has an extensive global community of over 1,000 companies collaborating to make the supply chain quicker, more effective and more efficient. It maintains OpenChain ISO/IEC 5230, the international standard for open source license compliance programs and OpenChain ISO/IEC 18974, the industry standard for open source security assurance programs.

About The Linux Foundation:

The Linux Foundation is the world’s leading home for collaboration on open source software, hardware, standards, and data. Linux Foundation projects are critical to the world’s infrastructure, including Linux, Kubernetes, Node.js, ONAP, PyTorch, RISC-V, SPDX, OpenChain, and more. The Linux Foundation focuses on leveraging best practices and addressing the needs of contributors, users, and solution providers to create sustainable models for open collaboration. For more information, please visit us at linuxfoundation.org.

Check Out The Publicly Announced Community of Conformance: