Skip to main content
Category

Featured

OpenChain 2.1 is ISO/IEC 5230:2020, the International Standard for open source compliance.

By Featured, News

The Linux Foundation, Joint Development Foundation and the OpenChain Project are delighted to announce the publication of ISO/IEC 5230:2020 as an International Standard. Formally known as OpenChain 2.1, ISO/IEC 5230:2020 is a simple, clear and effective process management standard for open source license compliance. It allows companies of all sizes and in all sectors to adopt the key requirements of a quality open source compliance program.

Companies around the world can learn more about ISO/IEC 5230:2020, methods of self-certification, independent assessment or third-party certification, as well as access a large library of reference material at: https://www.openchainproject.org

ISO/IEC 5230:2020 is an open standard and all parties are welcome to engage with our community, learn from their peers, share their knowledge, and to contribute to the future of our standard. There is no charge to access and use our reference material, self-certification or to engage with our numerous calls, webinars, mailing lists and meetings.

“ISO/IEC 5230:2020 will improve OSS compliance, enhance trust in the supply chain, and reduce friction in transactions. It has been deployed as a de facto standard for four years and fostered exceptional engagement from a diversity of companies across multiple sectors,” says Shane Coughlan, OpenChain General Manager. “Our transition to a formal International Standard as ISO/IEC 5230:2020 marks an important inflection point for OpenChain and open source as a whole. For the first time there is an International Standard that defines open source compliance and process management. We look forward to expanding our community from hundreds to thousands of companies in the coming months, and we look forward to supporting many of these companies access and apply best practice material developed in real world market conditions.”

Toyota is the first company to formally announce conformance to ISO/IEC 5230:2020. Additionally, companies that have an OpenChain 2.0 conformant program will automatically conform with the requirements of ISO/IEC 5230:2020. You can learn more about the Toyota announcement here:
https://www.openchainproject.org/featured/2020/12/15/toyota-iso-5230

Arm

“Arm joined the OpenChain Project as a founding member because building trust across the supply chain and ensuring IP rights are fully respected has long been one of the highest priorities for Arm,” says Sami Atabani, Director of Third Party IP Licensing at Arm. “Establishing OpenChain as a formal ISO/IEC International Standard is an important milestone for open source governance as a field, and we look forward to collaborating with our peers and the wider open source community in seeking excellence and efficiency in software delivery.”

BMW CarIT

“At BMW CarIT we continually work on improving the quality of our processes,” says Helio Chissini de Castro, Senior Software Engineer at BMW CarIT. “We welcome the approval of ISO/IEC 5230:2020 as the right path for the future of software compliance and how companies will perceive it. We are proud to be part of the OpenChain governing board and wider community that make this possible.”

Bosch

“Bosch and its affiliates have a firm commitment to quality in all aspects of creating, deploying and supporting solutions and products,” says Hans Malte Kern, Head of the Center of Competence Open Source, Robert Bosch GmbH. “Our engagement with the OpenChain industry standard for open source compliance is part of this larger vision, and we are delighted to see it graduate ISO as a formal International Standard. We now have a global, universal and easily understood mechanism to build increased clarity and trust across the supply chain.”

Cisco

“Cisco is honored to partner with an incredible team on the OpenChain project. Earlier this year (June 2020), our conformance with the OpenChain’s latest 2.0 specification for open source compliance has been the needle mover towards streamlining compliance as an indispensable entity across our organization, building Trust and improving overall productivity,” says Prasad Iyer Director, Product Operations at Cisco. “Now with ISO/IEC standardization of this latest OpenChain specification, it really solidifies Cisco’s commitment to excellence in Open source governance along with OpenChain which is well positioned at the top of the Compliance stack. We’re sincerely looking forward to our continued collaboration and partnership with all our OpenChain project peers across industry in the successful evolution of more such formal standards in the years ahead.”

Fujitsu

“Fujitsu has contributed to the development of OpenChain as an industry standard for several years,” says Yasuko Aoki, Manager of Open Source Software Technology Center, Fujitsu Limited. “Our engagement is part of our broader engagement throughout the supply chain to promote excellence in governance and sustainability in practical deployment. The publication of OpenChain as a formal ISO/IEC International Standard is a significant milestone in the evolution of open source. We are proud of the accomplishment of all the contributors involved, and we look forward to the next steps in ensuring simple, reliable open source license compliance across the world.”

Google

“Google has been at the forefront of open source development and the use of open source in business since its inception,” says Max Sills, Lead Open Source Attorney at Google. “Our collaboration with the OpenChain Project has been an important part of supporting greater maturity and predictability in this space. The release of ISO/IEC 5230:2020 provides a clear path to future inter-company collaboration. Defining a standard for quality open source compliance lowers the cost of doing business, and makes it easier for the entire industry to comply with open source obligations.”

Microsoft

“OpenChain has played a leading role in building trust in the open source ecosystem,” said David Rudin, Microsoft Assistant General Counsel. “When you receive software that has been produced through an OpenChain conformant program, it’s a great indication that the open source compliance obligations were taken seriously. With Microsoft’s OpenChain conformant program, we are keeping the trust our customers have placed in us to make sure their software is compliant and reducing friction in software transactions. As OpenChain takes the next step of becoming an international standard, we’re looking forward to continuing to advance open source adoption and trust in the community.”

MOXA

“As the first Taiwanese company working with the OpenChain governing board, our work with the OpenChain Project is part of a larger vision for mature, sustainable open-source governance,” said David Chen, Engineering Director of the Technology & Research Corporate Division at Moxa. “Today’s announcement is a milestone in building efficiency and trust among companies using open source for innovative products and solutions. We look forward to working with our fellow board members in the deployment of OpenChain as an ISO/IEC International Standard to an audience of thousands of companies in the world.”

OPPO

“As a member of OpenChain, OPPO is very pleased to see OpenChain being accepted as an ISO/IEC International Standard,” says Andy Wu, Vice President of OPPO and President of Software Engineering. “We believe this will help to further promote open source compliance. OPPO very much hopes to promote OpenChain with its partners, so that open source compliance becomes more consistent and simple.”

Siemens

“Siemens is a founding member of the OpenChain Project and we have contributed to OpenChain since its beginning. Today we reached an outstanding milestone – the OpenChain specification is now an ISO/IEC International Standard,” says Oliver Fendt, Senior Manager Open Source. “Our engagement with OpenChain is based on a clear understanding that effective governance in open source must be practical, efficient, sustainable and affordable for everyone. With the ISO/IEC Standard we will enter a new stage in the evolution of our collective work, and we look forward to working with our peers in building further trust in the open source supply chain.”

Sony

“Sony has been part of the OpenChain industry standard and its related community for a substantial amount of time,” says Hisashi Tamai, SVP, Sony Corporation, representative of the Software Strategy Committee. “We have had the great pleasure to host the first meeting in Japan and support growth across this nation and abroad in the subsequent years. The publication of OpenChain by ISO as a formal International Standard is an important milestone in our shared mission to ensure excellence in open source. We look forward to working with our fellow board members, our diverse community and our colleagues at ISO in bringing this standard to thousands of new companies across the globe.”

Qualcomm

“This achievement by OpenChain brings into reality the effort that so many across the software ecosystem has recognized for years – that when you can build trust into the open source compliance ecosystem, you create a path towards consistent, efficient, and reliable license compliance,” says Dave Marr, Vice President, Qualcomm Technologies, Inc. “We applaud the many contributors to OpenChain for achieving this terrific milestone, and for collaboratively building the internationally recognized standard for open source license compliance.”

Uber

“Uber has supported the development and deployment of the OpenChain industry standard from its early stages to becoming today’s de facto standard,” says Matthew Kuipers, Senior Counsel, Intellectual Property at Uber Technologies. “Today’s publication as an ISO International Standard is a key milestone in bringing clear, practical and effective open source license compliance to thousands of companies across the supply chain. We look forward to collaborating with our peers in accomplishing this mission and supporting our growing international community.”

Western Digital

“Western Digital has been part of the development and deployment of the industry standard for open source compliance since its formative years,” says Alan Tse, Associate General Counsel at Western Digital. “Today’s announcement marks a significant milestone in the maturity of both this standard and the wider field of open source governance. We look forward to working with our fellow board members and the diverse community of community participants in the growing adoption of a single, simple way to identify quality open source compliance programs.”

Global Community Quotes

“Today is the historic day for the OpenChain project and The Linux Foundation that the open standard has become an ISO/IEC standard,” said Masato Endo, Chair of the OpenChain Automotive Work Group. “Open Source is becoming more and more important in the automotive industry as well. The automotive industry’s supply chain is large and every company in the supply chain needs to manage OSS properly. I believe the OpenChain Specification will be a strong support for companies to build their OSS governance structure. I’d like to thank David Rudin and members of the JDF community for their efforts in obtaining ISO/IEC. I want to express my gratitude to Mark Gisi, David Marr and all OpenChain community members for their significant contributions to the project. Finally, I congratulate our leader Shane Coughlan on this great achievement!”

About the OpenChain Project

OpenChain began when a group of open source compliance professionals met in a conference lounge and chatted about how so much duplicative, redundant open source license compliance work was being done inefficiently in the software supply chain simply. They realized that while each company did the same work behind the scenes in a different manner the output for downstream recipients could not realistically be relied on because there was no visibility into the process that generated the output.

The answer the early principles of this discussion arrived at was to standardize open source compliance, make it transparent and build trust across the ecosystem. The project began as outreach to the community with the idea of a new standard for open source license compliance with slides titled, “When Conformity is Innovative.” A growing community quickly recognized the value of this approach and contributed to the nascent collaboration soon named The OpenChain Project.

Toyota Is The First Company To Announce Adoption Of ISO/IEC 5230, The International Standard For Open Source Compliance

By Featured

Toyota announces adoption of ISO/IEC 5230 in the IP Planning Group, a process led by Masato Endo and Miyu Tanaka. ISO/IEC 5230 is the International Standard for open source compliance.

ISO/IEC 5230 is maintained by the OpenChain Project as OpenChain 2.1 and edited for ISO via the Joint Development Foundation OpenChain Working Group. ISO/IEC 5230 is supported by Arm, BMW CarIT, Bosch, Cisco, Comcast, Facebook, Fujitsu, Google, Hitachi, Microsoft, MOXA, OPPO, Panasonic, Qualcomm, Siemens, Sony, Toshiba, Toyota, Uber and Western Digital as governing board members, and a wide community of companies across three continents.

“Toyota Motor Corporation has participated in and actively promoted the OpenChain Project since 2017,” says Yosuke Ida, General Manager of Toyota’s Intellectual Property Division. “We are proud to be the first company to announce the adoption of ISO/IEC 5230. The departments covered by the scope of this certification are the “Connected Advanced Development Division (Including the Automotive Grade Linux team)”, the “R-Frontier Division (including Partner Robot Technology)” and the “S-Frontier Division (including Innovative Infrastructure Technology).” These departments have a long history of approaching OSS management based on ISO requirements and the new developments in the OpenChain Project fit perfectly into this approach. Our company hopes that the OpenChain International Standard via ISO will be used as an opportunity to expand the acquisition of certification for companies in the supply chain of the automobile industry.”

“ISO/IEC 5230 is an International Standard focused on building trust in the supply chain. It does this by defining the key requirements of a quality open source compliance program and ensuring companies of all sizes and in all markets can adopt the standard,” says Shane Coughlan, OpenChain General Manager. “It has been developed with contributions from over 100 participants of the project and has been used in various market sectors since 2016. Our recent graduation from de-facto to formal International Standard provides a strong platform to scale from hundreds to thousands of companies, and to accelerate our mission to ensure minimal friction in the use and distribution of open source technology. Toyota’s adoption is a significant milestone in the growth and maturity of our standard, and underlines our strong commitment to pursuing excellence throughout the automotive supply chain.”

To learn more about ISO/IEC 5230 visit:
https://www.openchainproject.org

To adopt ISO/IEC 5230 via self-certification visit:
https://www.openchainproject.org/get-started

To get help with adoption of ISO/IEC 5230 visit:
https://www.openchainproject.org/reference-material

To discuss ISO/IEC 5230 usage, adoption and deployment visit:
https://www.openchainproject.org/contact

To get vendor support around ISO/IEC 5230 visit:
https://www.openchainproject.org/partners

NCSOFT Is The Second Company To Announce Adoption Of ISO/IEC 5230, The International Standard For Open Source Compliance

By Featured

NCSOFT is the first global game company to formally announce conformance with ISO/IEC 5230:2020, the International Standard for open source license compliance. It is the second company in Korea to announce conformance to a version of the OpenChain specification after LG Electronics. This historic development underlines the global reach and value of the standard.

ISO/IEC 5230 is maintained by the OpenChain Project as OpenChain 2.1 and edited for ISO via the Joint Development Foundation OpenChain Working Group. ISO/IEC 5230 is supported by Arm, BMW CarIT, Bosch, Cisco, Comcast, Facebook, Fujitsu, Google, Hitachi, Microsoft, MOXA, OPPO, Panasonic, Qualcomm, Siemens, Sony, Toshiba, Toyota, Uber and Western Digital as governing board members, and a wide community of companies across three continents.

“The OpenChain Project has a long history in Korea and our local work group has provided great support to the project as we have grown,” says Shane Coughlan, OpenChain General Manager. “The announcement by NCSOFT today is a superb example of how companies can improve their processes to align with other companies across the market. It makes open source license compliance faster, more effective and more efficient.”

About NCSOFT

NCSOFT is a premiere digital entertainment company and global publisher with worldwide locations and more than 4,000 employees focused on bringing extraordinary games to life for millions of fans around the world. Established in 1997 and headquartered in Seoul, South Korea, we quickly became a key leader in online games. Best known for critically acclaimed franchises including Lineage, Aion, Guild Wars, and Blade & Soul, NCSOFT is also one of the world’s top mobile developers with Lineage 2M occupying the #1 grossing revenue slot on Google Play. Our core goal is making people in this world happier by delivering games that entertain a globally connected audience has remained the same. Our culture is innovative, creative, collaborative and impactful, and we are passionate about creating the best gaming experiences for our players. https://kr.ncsoft.com/en/index.do

About the OpenChain Project

OpenChain began when a group of open source compliance professionals met in a conference lounge and chatted about how so much duplicative, redundant open source license compliance work was being done inefficiently in the software supply chain simply. They realized that while each company did the same work behind the scenes in a different manner the output for downstream recipients could not realistically be relied on because there was no visibility into the process that generated the output.

The answer the early principles of this discussion arrived at was to standardize open source compliance, make it transparent and build trust across the ecosystem. The project began as outreach to the community with the idea of a new standard for open source license compliance with slides titled, “When Conformity is Innovative.” A growing community quickly recognized the value of this approach and contributed to the nascent collaboration soon named The OpenChain Project.

OpenChain 2.1 (ISO/IEC 5230) Self-Certification Available in Chinese (Simplified and Traditional), German, Japanese and Korean

By Featured

Free self-certification for OpenChain 2.1 (ISO/IEC 5230) is now available in Chinese (Simplified and Traditional), German, Japanese and Korean on the OpenChain Project website.

This release is part of our on-going effort to help companies of all sizes and in all markets adopt the International Standard for open source license compliance.

Begin Your Journey

Webinar: Michael Poe on His Journey to Open Source

By community, Featured, licensing, News, standards, Webinar

We heard from Michael G. Poe, a newcomer to the world of Open Source Compliance and current Sales Manager with FossID.  He shared his thoughts on his surprising journey from consumer products to software, and how the underlying principles of the open source community have enabled him along the way.  

Michael also touched on what he believes can be some of the challenges to the frictionless adoption of OpenChain conformance. And lastly, based on his experiences and learning agenda thus far, what are some areas that can be improved when it comes to Open Source, Compliance, and the tech industry in general.

Check Out The Rest Of Our Webinars

This is OpenChain Webinar #15, released on 2020-12-11.

OpenChain Korea Work Group Meeting #8 – Full Recording

By Featured

The OpenChain Korea Work Group Meeting #8 featured an excellent schedule of presentations to end the year. You will find everything from SCA analysis to reviews of various aspects of Hyundai and Kakao’s work in the compliance space. A big thanks to Haksung and Soim for a lot of work organizing and editing everything, and a huge thanks to the presenters and community members who made this a wonderful event.

Introductions and Update

Hyundai’s Open Source Governance System

Trends in Software Component Analysis (SCA)

Kakao’s Olive System

OpenChain China Work Group Meeting #5 – Full Recording

By Featured

The fifth meeting of the OpenChain China Work Group took place on December 7th. Big thanks to Chloe at Huawei and Kris at OPPO for providing information and updates!

Key Items

  • OPENATOM, the new foundation for open source in China
  • The new copyleft variant of the Mulan license, joining the pre-existing permissive license.

In 2021 the OpenChain China Work Group will switch to using Mandarin in meetings. This is the ideal English-language meeting to get an introduction to the type of topics covered.

Conform to OpenChain 2.1 From Today

By Featured

OpenChain 2.1 self-certification is available through our online web app from today, December 7th 2020. This is in advance of the release of ISO/IEC 5230:2020, currently scheduled for December 14th according to the ISO database.

Please note that OpenChain 2.1 is functionally identical to both OpenChain 2.0 and ISO/IEC PRF 5230 (proof of international standard, soon to be formally published as ISO/IEC 5230:2020). If you conform to one, you conform to the other.

Self-Certify For Free

Review the OpenChain 2.1 Specification

Disclaimer

Please note that our main outreach for OpenChain 2.1 and ISO/IEC 5230:2020 will occur after December 14th, the date of publication marked in the ISO database. If you are an early adopter and have suggestions for improvement or any errors to report in the specification document or self-certification questionnaire please report them to info@openchainproject.org.

OpenChain Education Work Group Meeting #4 – Full Recording

By Featured

OpenChain Education Work Group Meeting #4 focused on practicalities. The team is getting ready to produce a free online training course in collaboration with LF Training. It will be hosted on edX and the source will also be available as public domain (CC-0). Get involved via the mailing list to learn more and lend a hand.

OpenChain Education Mailing List

OpenChain Advent Calendar Day #2 – Why is OpenChain a Standard?

By Featured

This advent calendar has been created by our Japanese Work Group as part of their community outreach. We hope you enjoy their recap of compliance topics to end the year.

(日本語は下にあります)

Introduction

Hello. If this is your first visit, nice to meet you. I think it is most likely your second time reading my article this December, right?
As the second day of OpenChain Japan Advent Calendar, today I will write about the OpenChain Specification, which is the main theme of this year.
I would like to skip my self introduction today because of my continuous posts, but if you are interested in that, please do read this.

Background (Issues in Software Supply Chains)

These days, OSS is essential for software development. It is even common to use hundreds to thousands of OSS components in one product or service. To develop software with advanced features by one single company has became very difficult, so a lot of companies have cooperated with each other and built software supply chains.
In a software supply chain, once an inappropriate use of OSS or an insufficient delivery of OSS license information occurs, it affects the entire supply chain. It comes to be claimed by the copyright holder or it is prohibited to distribute products.
In this situation, it is required to take control of problems at the upstream of the supply chain.

About OpenChain

To deal with those issues, the Open Chain Project has built an OSS compliance standard for every organization or company in supply chains to do things that they should do, build trust with each other, and deliver every necessary need (e.g. source code, license or documents).
One of the most important activities of the OpenChain Project is development and promotion of Open Chain Specification. The OpenChain Specification defines inflection points in business workflows where a compliance process, policy or training should exist to minimize the potential for errors and maximize the efficiency of bringing solutions to market. It can be used as a requirement for organizations to do OSS license compliance properly.

About OpenChain Specification

As of December this year, the latest version of OpenChain Specification is version 2.1. It is available at version 2.1.

The updated history of OpenChain Specification is below:

versionupdate date
version 1.0October 2016
version 1.1April 2017
version 1.2April 2018
version 2.0April 2019
version 2.1(latest)December 2020

The contents of the latest version of OpenChain Specification is below:

Contents
Foreword
Introduction
1. Scope
2. Terms and definitions
3. Requirements
Appendix A(informative)

The key contents of Specification is written in chapter 3. From tomorrow, OpenChain Japan members will explain the contents of each requirement and related topics in turns.

The Next Topic is…

Osaki-san will explain the topics around OpenChain Specificatoin as an ISO Standard, the biggest news of this year. 
See you tomorrow!!!

はじめに

こんにちは。あるいは、はじめまして。たぶんかなりの確率で、二度目ですね。
OpenChain Japan Advent Calendar 2020の2日目は、今年のメインテーマであるOpenChain仕様についてお届けします。
本日は連投のため自己紹介はスキップしますが、もし読んでくださるのであれば、こちらをご参照くださいませ。

背景(ソフトウェアサプライチェーンが抱える課題)

昨今のソフトウェア開発においては、OSSの利活用はもはや当たり前になっており、一つの製品・サービスの開発に数百から数千個のOSSコンポーネントが使われることもあります。また、ソフトウェアの高機能化に合わせて分散開発も一般化しており、一つの製品の開発において複数の企業が複雑に関連しあうサプライチェーンが構築されています。
サプライチェーンにおいて、ひとたびOSSの不適切な利用やライセンス情報の連携不足が発生すると、その影響はサプライチェーン全体に及び、第三者やOSSの著作権者からの指摘を受けたり、最終製品が出荷できなくなったりすることも考えられます。このような状況において、サプライチェーンの上流で問題を把握し、対策を講じることが求められています。

OpenChainについて

このような課題に対して、サプライチェーンを構成する企業・団体それぞれがすべきことを的確に実施し、相互に信頼関係を構築し、互いに適切な情報や必要なソースコード等の素材の受け渡しをしっかりと行うことのできる文化を醸成しようとしているのが、OpenChainプロジェクトです。
OpenChainプロジェクトの活動の一つに、OpenChain仕様の策定と普及があります。OpenChain仕様では、ソリューションを市場に投入する効率を最大化するために、コンプライアンス・プロセス、ポリシー、トレーニングを行うビジネスワークフローのインフレクションポイントを定義しており、組織がOSSライセンスコンプライアンスを適切に実行するための要件として活用できます。

OpenChain仕様について

2020年12月現在のOpenChain仕様の最新バージョンはversion 2.1で、詳しくはOpenChain仕様バージョン2.1から参照できます。

OpenChain仕様はこれまで、下記の通り更新されてきています。

バージョン名称改訂時期
version 1.02016年10月
version 1.12017年4月
version 1.22018年4月
version 2.02019年4月
version 2.1(最新)2020年12月

最新版のOpenChain仕様は、下記のような構成になっており、要件は3. Requirementsに記載されています。

Contents
Foreword
Introduction
1. Scope
2. Terms and definitions
3. Requirements
Appendix A(informative)

明日以降は、OpenChain Japanのメンバーが交代で、個々のRequirementsの解説と関連するトピックスについて投稿します。

明日のテーマは・・・

明日は、今年の大ニュースOpenChain仕様のISO国際標準化について、大崎さんが解説してくれます。
では明日の記事をお楽しみに!!