THE LINUX FOUNDATION PROJECTS
Category

Featured

Basics and background: An introduction to Open Source Compliance

By Featured, News

Imagine you’re building a car. It doesn’t make sense to invent the engine from scratch, right? All cars have engines. But maybe your car’s specific design, color, or fancy gadgets are what make it unique.

This lecture explains exactly that concept for software:

1. Don’t Build Everything Yourself!

  • The Idea: Save time and money by not re-doing things that already exist or aren’t your “secret sauce.”
  • The Pyramid Rule:
    • Bottom (The Common Stuff): Everything that’s generic and doesn’t make your product special – like the basic operating system (Windows, Linux), drivers, or fundamental libraries. This is the perfect place to use “Open Source” things or collaborate with others. Why build your own operating system if that’s not your main goal?
    • Top (The Special Stuff): The things that make your product unique and make people choose it over others – like your unique user interface design, your special features, or your secret algorithms. Keep these things proprietary, just for yourself!
  • In Short: Use ready-made “common” parts so you can focus your energy on your “special” ideas.

2. What Does “Open Source” Mean?

  • More Than Just “Free” (as in beer): It’s not enough to just see the code. For software to be “Open Source,” it needs a special Open Source License.
  • What This License Allows You To Do: It gives you the freedom to:
    • Use it however you want.
    • Study it (look at the code).
    • Modify it (change it).
    • Distribute it (give copies to others).
  • Important: The license gives you these rights, but it might have conditions too (e.g., if you change it and give it to others, you might have to mention the original creator).

3. Why Do We Need Licenses? (A Little About Copyright)

  • Software is Like a Book: Copyright law protects “works” – books, music, photos… and software! It’s understood that someone “writes” code, just like an author writes a book.
  • Who is the Author? Always a human.
  • A License is Permission: By default, the law forbids you from copying or changing someone else’s work without their permission. A license is exactly that permission! It tells you: “Okay, you can do X, Y, and Z, but you have to follow these rules.”
  • What If You Don’t Follow the Rules? If you break the license’s rules, you can lose your rights to use the software.
  • Without license the “default” state occurs, which means copyright law applies and any copying or distributing is prohibited.

To put it simply:

Use “open” things for the common parts of your software to save effort. Keep your unique ideas secret. All of this works because “Open Source” licenses give you clear rules about what you can and can’t do with the software.

 

 

RECORDING: OpenChain Meridian 22 Work Group Call – 2025-02-02

By Featured, Recordings

The OpenChain Meridian 22 Work Group met on February 2, 2026. Meeting assets are below…

Be Part of Future Meetings:

We will arrange future meetings and hold online discussions via the official mailing list, and everyone is invited to join: https://lists.openchainproject.org/g/meridian22-wg.

All work group meetings can be found on the calendar at https://zoom-lfx.platform.linuxfoundation.org/meetings/openchain?view=list&committee=8c4466bd-c9f1-40d7-8d08-f87eb488791d.

OpenAnolis Announces Adoption of ISO/IEC 18974

By Conformance, Featured, News

OpenAnolis officially announced that it has met the OpenChain ISO/IEC 18974 standard, becoming one of the few open-source operating system communities worldwide to receive this authoritative security accreditation. As an open-source community jointly built by enterprises, academic institutions, research organizations and individual developers, OpenAnolis has long been committed to creating a secure, reliable, and compliant digital infrastructure foundation. This certification marks a significant milestone in the community’s progress in open-source security governance.

ISO/IEC 18974, initiated by the OpenChain Project, defines the core requirements for open-source software security assurance programs, focusing on an organization’s ability to identify, respond to, and manage known security vulnerabilities such as CVEs and dependency issues. By establishing a comprehensive lifecycle security governance framework, OpenAnolis has implemented standardized processes for vulnerability monitoring, incident response, code security auditing, and software supply chain protection, ensuring trustworthiness in critical scenarios such as cloud-native environments and AI computing. The community has also developed SBOM (Software Bill of Materials) capabilities to enable transparent dependency management. With automated toolchains and AI Agents, OpenAnolis continuously performs intelligent vulnerability detection and remediation, providing strong security assurance for downstream OS distributions and industry users.

Long Qin, Chairman of the OpenAnolis Security Alliance, said: “The OpenAnolis Community’s Openchain ISO/IEC 18974 certification is of great significance to the development of the community’s security capability. In the era of integration between AI and cloud-native technologies, the security boundaries of operating systems have evolved beyond traditional patching to a holistic and proactive defense system that addresses heterogeneous computing, complex software supply-chain dependencies, and emerging threats caused by intelligent technologies. OpenAnolis will continue to invest in security innovation and work with global developers to build a trustworthy open-source ecosystem that supports the intelligent computing era.”

Liu Dapeng, Head of the OpenAnolis Standardization SIG, said: “OpenChain ISO/IEC 18974 provides open source communities with an authoritative guideline for software supply chain security governance and compliance management, laying a solid foundation for OpenAnolis to enhance collaboration efficiency and build ecosystem-wide trust. Looking ahead, the OpenAnolis Standardization SIG will continue to actively engage in OpenChain standard development under the Linux Foundation, striving to contribute OpenAnolis’ practical experience to international standards and working hand-in-hand with partners to co-create a secure, transparent, trustworthy, and thriving open source operating system ecosystem.”

About OpenAnolis

Founded in 2020, OpenAnolis is an international open-source root community for Linux server operating systems, focusing on cloud computing, edge computing, and AI computing scenarios. The community has brought together more than 1,000 ecosystem partners and released core distributions such as Anolis OS 23, providing full support for x86, ARM, and RISC‑V architectures. OpenAnolis technologies are widely deployed across cloud-native and intelligent computing fields.

About the OpenChain Project

Led by the Linux Foundation, the OpenChain Project promotes open-source license compliance (ISO/IEC 5230) and security assurance standards (ISO/IEC 18974), helping organizations establish efficient open-source compliance and security management systems. With over 1,000 global enterprise participants, OpenChain is a key international force in securing and standardizing the open-source supply chain.

About the Linux Foundation

The Linux Foundation is the world’s largest open-source collaboration platform, supporting critical infrastructure projects such as Linux, Kubernetes, and Node.js. Through standardization, community operations, and industry collaboration, it drives sustainable development of open-source technologies across software, hardware, and data domains.

 

 

CJ OliveYoung Becomes the First in the Korean Beauty Industry to Declare Open Source International Standard Certification

By Featured, News

  • Olive Young becomes the first in the domestic health and beauty (H&B) industry to declare the open source international standard ‘ISO/IEC 5230:2020’ certification.
  • Proves the security and transparency of its open source management system… Lays the foundation for securing reliability for its overseas services.
  • “As the leading K-beauty platform, we will continue to advance our open source management system in accordance with global standards.”

CJ Olive Young (hereinafter “Olive Young”) announced on the 9th that it has declared the open source international standard ‘ISO/IEC 5230:2020’ certification, marking a first in the domestic health and beauty (H&B) industry.

‘ISO/IEC 5230:2020’ is the sole international standard that evaluates a company’s open source license compliance system and management capabilities. Open source refers to publicly available source code that anyone can use freely. While it offers the advantage of reducing development costs and time, its transparent nature can also expose security vulnerabilities, making it crucial to strictly adhere to relevant license regulations. Accordingly, the certification is awarded only to companies that meet the criteria through a comprehensive evaluation of their compliance capabilities, including open source software policies and processes, the expertise of dedicated organizations and personnel, and relevant training.

This certification is highly significant as it officially recognizes that the security and transparency of Olive Young’s open source management system—as the company leaps forward as a ‘global beauty-tech platform’—fully meet international standards. As Olive Young accelerates its global expansion, including the opening of its first offline store in the U.S. this coming May, this achievement is expected to serve as a pivotal momentum in enhancing the stability and reliability of its services overseas.

Olive Young has been meeting the criteria for this international standard by establishing a robust open source management system since 2023. The company designated a dedicated organization and personnel for open source verification and management, and formed an ‘Open Source Council’ to establish a systematic approach for identifying and managing potential risk factors. Furthermore, it implemented internal open source management regulations and a strict process that mandates open source verification during system development. It also currently operates an automated system for verifying open source licenses and inspecting security vulnerabilities.

An official from Olive Young stated, “This certification is an acknowledgment of Olive Young’s proactive efforts, including the nurturing of IT talent and the establishment of an internal management system.” The official added, “As the representative platform for K-beauty, we will continue to advance our open source management system in strict alignment with global standards.”

 

Our New Executive Director for OpenChain

By Featured, News

New Executive Director of OpenChain Project

We are pleased to announce that Mary Meixia Wang has joined the OpenChain Project as our new Executive Director.

We extend our sincere gratitude to our board members and contributors for their continued dedication and support. We would also like to recognize the pioneering leadership of Shane Coughlan whose vision and commitment have been instrumental in establishing OpenChain’s global success.

Mary Wang brings extensive experience in software development and open source governance, with particular expertise in the telecommunications and automotive sectors. Her leadership will be vital as we continue to advance our mission: to build a supply chain in which open source is delivered with trusted and consistent process management information.

Under Mary’s guidance, we are confident that OpenChain will further strengthen its global impact, expand cross-industry adoption, and drive practical innovation aligned with the evolving open source ecosystem.

Please join us in welcoming Mary to her new role. We look forward to the next chapter of OpenChain’s journey and will share further updates in the months ahead.

OpenChain and Friends Stuttgart 2026

By Featured, News

“OpenChain and Friends” is an in-person community event focused on open source software supply chain management, compliance, and collaboration. It’s organized by the OpenChain Project in partnership with local and international communities, such as The FOSS-LÄND Community. The event takes place in Stuttgart, Germany and gathers people working with open source across different industries.

A preliminary schedule is available on the event website: OpenChain and Friends in Stuttgart 2026

Please register for this free in-person event on the 24th , 25th and 26th of march 2026 in Stuttgart and regularly visit our event website to monitor the progress or even get involved yourself!

Hitachi Energy achieves OpenChain (ISO 5230) Certification, reinforcing commitment to Open Source excellence

By Featured, News

Hitachi Energy is proud to announce that it has achieved OpenChain (ISO 5230) certification, the leading global standard for open source compliance. This milestone underscores our dedication to delivering products that meet the highest standards of quality, security, and transparency.

By attaining ISO 5230 certification, Hitachi Energy demonstrates a mature and reliable open source compliance program that partners and customers can trust. This achievement reduces legal and operational risks, streamlines documentation, and ensures consistent, well-governed use of open source technologies across our organization. It also strengthens our position in global supply chains, where ISO 5230 certification is increasingly recognized as a mark of professionalism and readiness for evolving regulatory requirements such as the Cyber Resilience Act. The certification brings tangible benefits to our customers and partners. It enables faster collaboration and onboarding, minimizes audit requirements, and ensures predictable, high-quality products through standardized and repeatable compliance processes. Ultimately, it reflects our commitment to building trust and fostering strong relationships throughout the technology ecosystem.

Achieving OpenChain certification is more than a milestone, it is a statement of our ongoing dedication to responsible open source use, industry best practices, and continuous improvement. Hitachi Energy remains focused on driving innovation while maintaining the highest standards of governance and security across all our products and services.

About the Bureau Veritas:

Bureau Veritas is a globally recognized leader in inspection, conformity assessment, and certification services, with a presence in countries worldwide.

Founded in 1828, it supports clients in improving performance through innovative solutions and services aimed at verifying that products, assets and processes meet mandatory and voluntary standards in quality, health and safety, environment and social responsibility (QHSE-SA).

Bureau Veritas offers a comprehensive cybersecurity services portfolio, leveraging global expertise to ensure a consistent customer experience across all areas of cybersecurity.

About the OpenChain Project:

The OpenChain Project has an extensive global community of over 1,000 companies collaborating to make the supply chain quicker, more effective and more efficient. It maintains OpenChain ISO/IEC 5230, the international standard for open source license compliance programs and OpenChain ISO/IEC 18974, the industry standard for open source security assurance programs.

About The Linux Foundation:

The Linux Foundation is the world’s leading home for collaboration on open source software, hardware, standards, and data. Linux Foundation projects are critical to the world’s infrastructure, including Linux, Kubernetes, Node.js, ONAP, PyTorch, RISC-V, SPDX, OpenChain, and more. The Linux Foundation focuses on leveraging best practices and addressing the needs of contributors, users, and solution providers to create sustainable models for open collaboration. For more information, please visit us at linuxfoundation.org.

Check Out The Publicly Announced Community of Conformance:
https://openchainproject.org/community-of-conformance

Panasonic Automotive Systems Announces OpenChain ISO/IEC 5230 Conformance

By Featured, News

Today Panasonic Automotive Systems has announced an OpenChain ISO/IEC 5230 conferment program. As a leading Tier 1 automotive supplier, Panasonic Automotive Systems is at the forefront of both using and effectively managing open source technology.

“During the certification process, we worked to improve the reliability of our OSS usage and products by structuring OSS utilization processes and building a highly secure management system.” said Masashige Mizuyama, Executive Vice President and Chief Technology Officer at Panasonic Automotive Systems. “We have actively contributed to the industry by promoting the standardization and open-sourcing of VirtIO, an open-source virtualization technology. Taking this certification as an opportunity, we will continue to provide high-quality and highly reliable solutions leveraging OSS, and contribute to the expansion and sustainable growth of the open source ecosystem in the in-vehicle device industry.”

“We are delighted to welcome Panasonic Automotive Systems into our community of conformance,” says Shane Coughlan, OpenChain General Manager. “Adoption of OpenChain ISO/IEC 5230 has been exceptional across the automotive supply chain, and the influence and inspiration provided by Tier 1 adoption cannot be overstated. We look forward to working with the Panasonic Automotive Systems team in the months and years ahead.”

About Panasonic Automotive Systems Co., Ltd.:

Panasonic Automotive Systems Co., Ltd., (PAS) was launched on April 1, 2022 as an operating company responsible for the automotive systems business in line with the start of the Panasonic Group’s operating company system, and on December 2, 2024 the company moved to a management structure in which 80% of its shares are held by the funds managed by an affiliate of Apollo Global Management, Inc. and 20% by Panasonic Holdings Corporation.

Headquartered in Japan, PAS is a global company with subsidiaries in eight other countries and, as a Tier 1 company, it provides advanced proprietary technologies such as infotainment systems to automakers in Japan and overseas, helping to create comfortable, safe, and secure automobiles. PAS is committed to meeting the expectations of its customers around the world with technologies that stand by people in pursuit of its corporate vision of becoming the “Joy in Motion” design company. To learn more about our company, please visit https://automotive.panasonic.com/en

About the OpenChain Project:

The OpenChain Project has an extensive global community of over 1,000 companies collaborating to make the supply chain quicker, more effective and more efficient. It maintains OpenChain ISO/IEC 5230, the international standard for open source license compliance programs and OpenChain ISO/IEC 18974, the industry standard for open source security assurance programs.

About The Linux Foundation:

The Linux Foundation is the world’s leading home for collaboration on open source software, hardware, standards, and data. Linux Foundation projects are critical to the world’s infrastructure, including Linux, Kubernetes, Node.js, ONAP, PyTorch, RISC-V, SPDX, OpenChain, and more. The Linux Foundation focuses on leveraging best practices and addressing the needs of contributors, users, and solution providers to create sustainable models for open collaboration. For more information, please visit us at linuxfoundation.org.

Check Out The Publicly Announced Community of Conformance:
https://openchainproject.org/community-of-conformance

Analog Devices, Inc. has announced OpenChain ISO/IEC 5230:2020 conformance

By Featured, News

Analog Devices, Inc. (ADI) has announced an OpenChain ISO/IEC 5230:2020 conformant program, making another important step forward for open source governance and management in the global silicon supply chain.

“Achieving OpenChain conformance underscores our belief that open source stewardship is foundational to engineering excellence,” said Rob Oshana, Senior Vice President, Software & Digital Platforms at ADI. “It reinforces our commitment to transparent processes, clear compliance standards and continuous improvement across the software lifecycle.”

“ADI is an excellent steward of open source,” says Shane Coughlan, OpenChain General Manager. “Their contributions to the open source community have been notable too, not least their direct engagement with the OpenChain Project as we have developed and deployed standards and reference material related to open source compliance. It is a genuine pleasure to welcome them to our community of conformance, and we look forward to continued collaboration in the future.”

About ADI

ADI is a global semiconductor leader that bridges the physical and digital worlds to enable breakthroughs at the Intelligent Edge. ADI combines analog, digital, AI, and software technologies into solutions that help drive advancements in automation and robotics, mobility, energy and data centers, and healthcare, combat climate change, and reliably connect humans and the world. With revenue of more than $11 billion in FY25, ADI ensures today’s innovators stay Ahead of What’s Possible. Learn more at www.analog.com and on LinkedIn and X (formerly Twitter).

About the OpenChain Project:

The OpenChain Project has an extensive global community of over 1,000 companies collaborating to make the supply chain quicker, more effective and more efficient. It maintains OpenChain ISO/IEC 5230, the international standard for open source license compliance programs and OpenChain ISO/IEC 18974, the industry standard for open source security assurance programs.

About The Linux Foundation:

The Linux Foundation is the world’s leading home for collaboration on open source software, hardware, standards, and data. Linux Foundation projects are critical to the world’s infrastructure, including Linux, Kubernetes, Node.js, ONAP, PyTorch, RISC-V, SPDX, OpenChain, and more. The Linux Foundation focuses on leveraging best practices and addressing the needs of contributors, users, and solution providers to create sustainable models for open collaboration. For more information, please visit us at linuxfoundation.org.

Open Compliance Summit 2025 – Review and Photos

By Featured, News

The Open Compliance Summit 2025 was a tremendous success, with strong representation from China, Japan, Korea, Germany, Sweden, the United States, the United Kingdom, India and more. Over a packed schedule on the 11th and 12th December, attendees shared knowledge, networked and provided an exceptionally strong analysis of what is coming for licensing, security and regulatory compliance in 2026.

This event provided a substantial amount of analysis around OpenChain Project-related activities, ranging from the ISO standards to capability modeling, SBOM quality and AI System Bill of Material management.

The Open Compliance Summit is expected be held again in December 2026, and talk submissions are welcome. Learn more about the event on the official LF website around April 2026: https://events.linuxfoundation.org

This event also marked the last public event of our current General Manager, Shane Coughlan. We had a little ceremony and took some photos.