Skip to main content
Category

Featured

S-Core Strengthens Open Source Compliance With ISO/IEC 5230

By Featured, News

S-core, Self-Certified for OpenChain ISO/IEC 5230 International Standard

S-core has officially obtained the OpenChain ISO/IEC 5230 certification, a globally recognised standard for open source compliance. This certification acknowledges the reliability and transparency of S-Core’s open source management system on an international scale.

OpenChain ISO/IEC 5230 is an open source compliance management standard created by The Linux Foundation’s OpenChain Project and published by the International Organization for Standardization (ISO). It provides guidelines to help companies effectively manage open source and mitigate legal risks.

Open Source Specialist S-core’s Journey

S-core is a company that specializes in open source services, leveraging its extensive experience in open source-based infrastructure development.

This company offers full-care service for open source use, from open source adoption, migration, technical support, to governance consulting in order to help customers establish management systems for safe and strategic use of open source.

It has recently strengthened its capability of open source compliance to deliver more reliable and secure services to customers by aligning its open source management system with OpenChain ISO/IEC 5230.

Internally, a dedicated team continuously reviews licenses, assesses risks and operates in-house training programmes to ensure developers use open source correctly. Additionally, S-core has implemented a structured system using open source management tools to proactively identify and mitigate potential risks throughout the development process.

Sunghan Suh, Head of the Open Source Business Division at S-core, stated, “Open source has already become fundamental components in software development and operation across all industries.” He added, “With the acquisition of the OpenChain certification, we will take the lead in the development of the open source ecosystem to enable companies and developers to use open source more safely and efficiently by sharing our extensive expertise accumulated from adoption, development, operation, management to technical support.”

S-core’s Future Efforts

S-core plans to obtain ISO/IEC 18974 certification to further enhance open source security management, reinforcing its ability to address open source vulnerabilities. Looking ahead, the company aims to commit to the growth and development of the open source ecosystem with continued innovation and progress.

Netcore Cloud is the latest company to announce an OpenChain ISO/IEC 18974 Conformant Program

By Featured, News

Netcore Cloud is the latest company to announce adoption of OpenChain ISO/IEC 18974, the international standard for open source security assurance.

“We are pleased to see a diversity of companies adopting ISO/IEC 18974,” says Shane Coughlan, OpenChain General Manager. “Our goal was always to create and support improved trust across the supply chain regardless of industry, and Netcore Cloud is an example of this in action. We look forward to next steps together in helping even more of the supply chain understand the need for and benefit of process standards for managing open source technology.”

About Netcore Cloud

Netcore Cloud is a global MarTech product company that helps B2C brands create amazing digital experiences with a range of products that help in acquisition, engagement, and retention. The first and leading AI/ML-powered marketing automation and customer engagement platform, Netcore Cloud was established in 1997 by Rajesh Jain, an internet pioneer. Today Netcore Cloud is revolutionizing the way marketing & product teams engage with the consumers.

Learn more at: https://netcorecloud.com/about-us/

About the OpenChain Project:

The OpenChain Project has an extensive global community of over 1,000 companies collaborating to make the supply chain quicker, more effective and more efficient. It maintains OpenChain ISO/IEC 5230, the international standard for open source license compliance programs and OpenChain ISO/IEC 18974, the industry standard for open source security assurance programs.

About The Linux Foundation:

The Linux Foundation is the world’s leading home for collaboration on open source software, hardware, standards, and data. Linux Foundation projects are critical to the world’s infrastructure, including Linux, Kubernetes, Node.js, ONAP, PyTorch, RISC-V, SPDX, OpenChain, and more. The Linux Foundation focuses on leveraging best practices and addressing the needs of contributors, users, and solution providers to create sustainable models for open collaboration. For more information, please visit us at linuxfoundation.org.

The Erlang/OTP Project Announces an OpenChain ISO/IEC 5230 Conformant Program

By Featured, News

The Erlang Ecosystem Foundation has set goals for 2025 of raising the community infrastructure, processes and tooling profile to accommodate the latest industry standards for supply chain and cybersecurity. The Erlang/OTP team is thrilled to announce that the Erlang/OTP project now are conformant to OpenChain ISO/IEC 5230, the international standard for open source license compliance. The team would like to extend their thanks to EEF staff and community, the OpenChain community, and Ericssons Open Source Program Office for their support in getting to this point.

Erlang/OTP is an open source programming language made for programming concurrent, distributed, and fault-tolerant systems. The language is more than 30 years old, and has had 1,000s of contributions. By being OpenChain ISO/IEC 5230 conformant, we can build confidence among our ecosystem that Erlang/OTP manages licensing effectively, and has processes in place to do this in a sustainable way.

About Erlang:

Erlang is a programming language originally developed at the Ericsson Computer Science Laboratory. OTP (Open Telecom Platform) is a collection of middleware and libraries in Erlang. Erlang/OTP has been battle tested in a number of Ericsson products for building robust fault-tolerant distributed applications, for example AXD301 (ATM switch). Main developer and maintainer is the Erlang/OTP unit at Ericsson.

erlang.org

The source code for this webpage is available on GitHub. It is built using ErlangJekyllBootstrap 5 and Node.js.

License

Since OTP 18.0, Erlang/OTP is released under Apache License 2.0. The older releases were released under Erlang Public License (EPL), a derivative work of the Mozilla Public License (MPL).

About the OpenChain Project:

The OpenChain Project has an extensive global community of over 1,000 companies collaborating to make the supply chain quicker, more effective and more efficient. It maintains OpenChain ISO/IEC 5230, the international standard for open source license compliance programs and OpenChain ISO/IEC 18974, the industry standard for open source security assurance programs.

About The Linux Foundation:

The Linux Foundation is the world’s leading home for collaboration on open source software, hardware, standards, and data. Linux Foundation projects are critical to the world’s infrastructure, including Linux, Kubernetes, Node.js, ONAP, PyTorch, RISC-V, SPDX, OpenChain, and more. The Linux Foundation focuses on leveraging best practices and addressing the needs of contributors, users, and solution providers to create sustainable models for open collaboration. For more information, please visit us at linuxfoundation.org.

The OpenChain Capability Model Reaches General Release

By Featured, News

Background

The OpenChain Project frequently talks about how open source is more professionally managed, and how this helps make using open source quicker, more efficient and more effective across the supply chain.

What is Happening?

Today we take a huge step forward in supporting this evolution of maturity by releasing capability modeling as CC-0 (effectively public domain) to help companies around the world do open source license compliance and other types of compliance using the same approaches as the world’s best and most funded companies.

This model was developed by Orcro, DeLoitte and the rest of the community of contributors who make up the OpenChain Education Work Group.

Why?

Capacity or maturity modeling in Software Asset Management (SAM) plays a vital role in understanding an organization’s current state regarding SAM practices. Here’s a structured overview of its importance:

  1. Assessment of Current Practices: It evaluates the organization’s existing SAM processes, identifying strengths and gaps that need attention.
  2. Improved Decision-Making: By highlighting gaps, it enables informed decisions on software investments, tool acquisitions, and optimization strategies, enhancing efficiency and compliance.
  3. Enhanced Efficiency and Compliance: A mature SAM practice can reduce redundant purchases, minimize license overuse, and mitigate audit risks, ensuring better management of assets.
  4. Support for Open Source Management: It aids in managing open-source usage, ensuring compliance to avoid licensing issues, thereby facilitating innovation by allowing proper use and adaptation of open-source tools.
  5. Facilitation of Open Innovation: In collaborative environments, it helps track external code usage, ensuring compliance and fostering better collaboration without legal risks.

In summary, capacity modeling is essential for establishing a robust SAM framework, enhancing operational efficiency, and supporting both open source management and open innovation, thereby driving organizational success.

Get the Model

We host the model in our Reference Library in GitHub. You can find it in a dedicated directory called “Capability-Maturity-Model” and you will find latest releases sorted by date.

Access and download it here:
https://github.com/OpenChain-Project/Reference-Material

You can also open GitHub issues with ideas, suggestions and bug-fixes:
https://github.com/OpenChain-Project/Reference-Material/issues

Contribute to Further Development

The Capability model was developed by the OpenChain Education Work Group after initial work through the OpenChain UK Work Group. You can participate in further development by joining the Education Work Group mailing list:
https://lists.openchainproject.org/g/education

You can also join our monthly call by checking out the calendar on our participation page:
https://openchainproject.org/participate

Please Note

This is reference material to help inspire individual organizations in their own development and use of models. It is not designed to be (a) legal advice, (b) assured to work in your context or (c) replace internal or third-party professional support and advice.

KFTC Announces an OpenChain ISO/IEC 5230 Conformant Program

By Featured, News

Korea Financial Telecommunications & Clearings Institute (KFTC), has announced an OpenChain ISO/IEC 5230 Conformant program. KFTC is a leading financial institution that provides essential infrastructure and services for the Korean financial industry.

To meet the requirements of the OpenChain ISO/IEC 5230:2020 standard, KFTC has implemented a comprehensive open source program within the organization. This includes establishing an Open Source Program Office (OSPO), enacting guidelines for open source utilization, and developing an in-house open source management platform. The platform automatically identifies open source components and licenses used in the software development lifecycle, providing guidance to employees.

“In today’s rapidly evolving IT landscape, characterized by AI, big data, and cloud computing technologies, leveraging open source software is not just beneficial—it’s essential,” said Lee Songwon, CIO of KFTC. “Based on our capabilities in open source utilization and management, KFTC will continue to foster a robust open source ecosystem through collaboration with other financial and public sector organizations across Korea.”

About KFTC (Korea Financial Telecommunications & Clearings Institute):

Korea Financial Telecommunications and Clearings Institute (KFTC), jointly founded by the Bank of Korea and commercial banks in 1986, has been a leading institution in developing and operating Korea’s national payment and settlement infrastructure. Over the years, KFTC has introduced various advanced payment systems, including the CD/ATM network and the Real-time Fund Transfer network. In the digital era, KFTC launched the Payment Gateway for e-commerce, Point of Sales (POS) networks for payment card transactions, and mobile payment networks. As the country transitioned to Open Finance, KFTC played a pivotal role in developing Korea’s Open Banking platform, enabling seamless and secure data sharing between financial institutions and fintech companies.

Learn more at https://eng.kftc.or.kr

About the OpenChain Project:

The OpenChain Project has an extensive global community of over 1,000 companies collaborating to make the supply chain quicker, more effective and more efficient. It maintains OpenChain ISO/IEC 5230, the international standard for open source license compliance programs and OpenChain ISO/IEC 18974, the industry standard for open source security assurance programs.

About The Linux Foundation:

The Linux Foundation is the world’s leading home for collaboration on open source software, hardware, standards, and data. Linux Foundation projects are critical to the world’s infrastructure, including Linux, Kubernetes, Node.js, ONAP, PyTorch, RISC-V, SPDX, OpenChain, and more. The Linux Foundation focuses on leveraging best practices and addressing the needs of contributors, users, and solution providers to create sustainable models for open collaboration. For more information, please visit us at linuxfoundation.org.

AVL List GmbH Announces an ISO/IEC 5230 Conformant Program

By Featured, News

AVL List GmbH has announced an ISO/IEC 5230 conformant program.

About AVL

AVL is a world-leading technology company specialising in development, simulation and testing in the automotive industry and other sectors such as rail, marine and energy. Through extensive research, AVL delivers concepts, technology solutions, methodologies and development tools for sustainable, safe and advanced mobility and beyond.

AVL supports international partners and customers in sustainable and digital transformation, with a focus on electrification, software, AI and automation. AVL also supports companies in energy-intensive sectors on their way to green and efficient energy generation and supply.

For more information: www.avl.com

About the OpenChain Project

The OpenChain Project has an extensive global community of over 1,000 companies collaborating to make the supply chain quicker, more effective and more efficient. It maintains OpenChain ISO/IEC 5230, the international standard for open source license compliance programs and OpenChain ISO/IEC 18974, the industry standard for open source security assurance programs.

About The Linux Foundation

The Linux Foundation is the world’s leading home for collaboration on open source software, hardware, standards, and data. Linux Foundation projects are critical to the world’s infrastructure, including Linux, Kubernetes, Node.js, ONAP, PyTorch, RISC-V, SPDX, OpenChain, and more. The Linux Foundation focuses on leveraging best practices and addressing the needs of contributors, users, and solution providers to create sustainable models for open collaboration. For more information, please visit us at linuxfoundation.org.

ETRI Recertification of ISO/IEC 5230

By Featured, News

The Electronics and Telecommunications Research Institute of South Korea (ETRI) has announced recertification of their ISO/IEC 5230 conformant program. Learn about their original ISO/IEC 5230 conformance on our previous blog post.

ETRI is a global information and communication technology (ICT) research institute under the Ministry of Science and ICT. It has led the growth of the information and communication industry in Korea for 45 years. The research institute is working to realize the concept of ‘Korea, an AI powerhouse’ with a vision of “a national intelligence research institute that creates a future society.” ETRI has been conducting open source verification as a software quality management since 2008, and established the Open Source Center as an enterprise-wide organization to support open source R&D activities, governance and compliance in 2017.

“We are delighted to have ETRI underscore their commitment to our standardization approach and the development of a more trusted open source supply chain,” says Shane Coughlan, OpenChain General Manager. “We will continue to work together in Korea and beyond to help educate, inform and inspire others in our field.”

About the OpenChain Project

The OpenChain Project has an extensive global community of over 1,000 companies collaborating to make the supply chain quicker, more effective and more efficient. It maintains OpenChain ISO/IEC 5230, the international standard for open source license compliance programs and OpenChain ISO/IEC 18974, the industry standard for open source security assurance programs.

About The Linux Foundation

The Linux Foundation is the world’s leading home for collaboration on open source software, hardware, standards, and data. Linux Foundation projects are critical to the world’s infrastructure, including Linux, Kubernetes, Node.js, ONAP, PyTorch, RISC-V, SPDX, OpenChain, and more. The Linux Foundation focuses on leveraging best practices and addressing the needs of contributors, users, and solution providers to create sustainable models for open collaboration. For more information, please visit us at linuxfoundation.org.

Honda Joins The OpenChain Project As A Platinum Member

By Featured, News

Honda is the latest company to join the OpenChain Project as a Platinum Member and to take a seat at the Governing Board and Steering Committee. This builds on their engagement with the OpenChain Project in adopting ISO/IEC 5230 and ISO/IEC 18974.

“Joining the OpenChain Project board is an example of how Honda takes a leadership position in managing open source,” says Yuichi Kusakabe, IVI software PF and OSPO Tech Lead at Honda. 

“Honda is an exceptional company in the management of large, complex supply chains,” says Shane Coughlan, OpenChain General Manager. “Today’s announcement underlines their commitment to developing excellence in open source, and in building trusted supply chains. The OpenChain Project Governing Board is delighted to formally welcome them, and looks forward to doing great things together in 2025.”

About Honda

Honda is a mobility company powered by everyone’s dreams, creating mobility that helps and inspires people, in a wide range of fields such including motorcycles, automobiles, power products and aircraft.

About the OpenChain Project

The OpenChain Project has an extensive global community of over 1,000 companies collaborating to make the supply chain quicker, more effective and more efficient. It maintains OpenChain ISO/IEC 5230, the international standard for open source license compliance programs and OpenChain ISO/IEC 18974, the industry standard for open source security assurance programs.

About The Linux Foundation

The Linux Foundation is the world’s leading home for collaboration on open source software, hardware, standards, and data. Linux Foundation projects are critical to the world’s infrastructure, including Linux, Kubernetes, Node.js, ONAP, PyTorch, RISC-V, SPDX, OpenChain, and more. The Linux Foundation focuses on leveraging best practices and addressing the needs of contributors, users, and solution providers to create sustainable models for open collaboration. For more information, please visit us at linuxfoundation.org.

UnionTech Software Announces An ISO/IEC 18974 Conformant Program

By Featured, News

UnionTech Software – known for Deepin Linux – has announced an ISO/IEC 18974 conformant program.

About UnionTech Software

UnionTech Software is a research and development leader in the operating system
industry in China, ranking among the top tier in terms of market share and
ecological maturity. It has a focus on technical accumulation in research and development,
internationalization, industry customization, migration and adaptation, and
interactive design. UnionTech Software has established a diverse range of operating system product lines, including desktops, servers, intelligent terminals, and more. Over 6 million installations of UOS operating systems have been deployed in key sectors across 40,000 customers.

Learn More About UnionTech Software

HLB Surlatina Chile Announces An OpenChain ISO/IEC 5230 Conformant Program

By Featured, News

HLB Surlatina Chile, a firm established in 1971 and with 50 years of experience in the Chilean market, has announced an OpenChain ISO/IEC 5230 conformant program.

About HLB Surlatina Chile:

HLB Surlatina Chile is part of HLB International, a global audit and advisory organization headquartered in London, and has a long-standing history of advising clients and priding itself on being an organization based on values, committed to delivering the highest quality standards. HLB International employees over 30 thousand professionals in 160 countries from across the world to help clients grow across borders.

Visit Their Website: