Skip to main content
Category

News

QNAP Announces an OpenChain ISO/IEC 5230 Conformant Program

By Featured, News

QNAP Systems, Inc., a leading computing, networking, and storage solutions innovator based in Taipei, has announce and OpenChain ISO/IEC 5230 conformant program.

About QNAP

QNAP (Quality Network Appliance Provider) is devoted to providing comprehensive solutions in software development, hardware design and in-house manufacturing. Focusing on storage, networking and smart video innovations, QNAP now introduce a revolutionary Cloud NAS solution that joins our cutting-edge subscription-based software and diversified service channel ecosystem. QNAP envisions NAS as being more than simple storage and has created a cloud-based networking infrastructure for users to host and develop artificial intelligence analysis, edge computing and data integration on their QNAP solutions.

About the OpenChain Project:

The OpenChain Project has an extensive global community of over 1,000 companies collaborating to make the supply chain quicker, more effective and more efficient. It maintains OpenChain ISO/IEC 5230, the international standard for open source license compliance programs and OpenChain ISO/IEC 18974, the industry standard for open source security assurance programs.

About The Linux Foundation:

The Linux Foundation is the world’s leading home for collaboration on open source software, hardware, standards, and data. Linux Foundation projects are critical to the world’s infrastructure, including Linux, Kubernetes, Node.js, ONAP, PyTorch, RISC-V, SPDX, OpenChain, and more. The Linux Foundation focuses on leveraging best practices and addressing the needs of contributors, users, and solution providers to create sustainable models for open collaboration. For more information, please visit us at linuxfoundation.org.

Webinar: The Future of Insurance for Open Source – Are You Really Covered? – 2025-04-22 @ 08:00 UTC

By News

Open source software providers are facing a triple threat: tightening US and EU regulations, rising IP litigation, and the risks introduced by Gen AI. Soon, your board—and your customers and suppliers— might be asking that you have specific insurance that actually covers OSS-related liabilities. But, does such insurance exist? Does it work? And how should it work?

Historically, insurers have struggled to grasp OSS risks, offering inadequate or unclear coverage. Now, a new wave of insurance solutions is emerging, informed by OpenChain standards and best practices.

Join this session to explore how the insurance industry is evolving, what new OSS-specific coverage looks like, and how you can help shape it to meet the real needs of the open source community.

Join using this link up to ten minutes before the official start: 

More About Our Webinars:

This event is part of the overarching OpenChain Project Webinar Series. Our series highlights knowledge from throughout the global OpenChain eco-system. Participants are discussing approaches, processes and activities from their experience, providing a free service to increase shared knowledge in the supply chain. Our goal, as always, is to increase trust and therefore efficiency. No registration or costs involved. This is user companies producing great informative content for their peers.

Check Out The Rest Of Our Webinars

OpenChain Monthly Specification and Education Call (North America – Europe) – 2025-03-12

By News

This time we discussed strategic matters like next steps in our existing ISO standards, board strategy discussions underway, and community considerations. We also took a look at two items from sister projects related to project health and security:

OpenSSF Scorecard:
https://scorecard.dev/

CHAOSS Metrics
https://chaoss.community/software/

Check out the Meeting Slides:

Watch the Recording:

Coming Next:

We will be following up on the activities outlined above on the mailing lists, and we will continue our regular series of calls and meetings throughout the year.

Join Our Work:

Everyone is welcome to be part of the Specification Work Group. You can join their mailing list here:
https://lists.openchainproject.org/g/specification/

You can find and be part of all OpenChain calls through our participation page here:
https://openchainproject.org/participate

OpenChain Telco Work Group Meetings – 2025-03-06

By News

The OpenChain Telco Work Group is in the final stages of preparing Version 1.1 of the Telco SBOM Guide, an industry-specific but adaptable guide to addressing the question of SBOM quality in the supply chain. Learn more in their latest meetings.

Be part of this:

You can get involved with the OpenChain Telco Work Group through their dedicated mailing list. At this link, you will also find connections to other working groups around the world:

Please note: you do not have to be an expert in telecommunications or work for a telecommunications company to join the group. Work on subjects like the Telco SBOM Quality Guide is intended to also help other market sectors.

OpenChain Tooling Group – Special Presentation – 2025-02-19

By News

This meeting featured a special presentation by Jeronimo Ortiz of SCANOSS. It provided an overview of the open source SCA tooling and technologies that SANOSS has open sourced and maintains, and looked at some of the user guides and documentation to reduce the adoption effort.

In addition, Jeronimo demoed how to make use of the osskb.org service from Software Transparency Foundation at scale using GitHub Actions, and how you can leverage scanoss.py to make use of such a service for detecting open source at file and snippet level, getting license and copyright information, or creating simple and quick SBOMs in different formats.

The presentation also included an overview of the work being done to integrate osskb.org with well known tools like ORT or FOSSology.

Webinar: DeepSeek – How Open Source AI is unlocking the future – 2025-03-28 @ 07:00 UTC

By News

An introduction to DeepSeek, its technical highlights, its history, its company, and its vision. The main presentation for this webinar will be by Jerry Tan, a long-time contributor to the open source ecosystem in China.

Join using this link up to ten minutes before the official start: 

More About Our Webinars:

This event is part of the overarching OpenChain Project Webinar Series. Our series highlights knowledge from throughout the global OpenChain eco-system. Participants are discussing approaches, processes and activities from their experience, providing a free service to increase shared knowledge in the supply chain. Our goal, as always, is to increase trust and therefore efficiency. No registration or costs involved. This is user companies producing great informative content for their peers.

Check Out The Rest Of Our Webinars

RECORDING: OpenChain AI Work Group – Monthly Workshop for North America and Europe – 2025-03-05

By News

We held our regular workshop for the OpenChain AI Work Group on March 5th. It was a two-hour session to allow topics related to AI compliance to be discussed, explored and defined. The key focus for the Work Group is to develop and finalize a Guide to AI Bill of Material Compliance in the Supply Chain, and there is active drafting going on during each meeting.

The Draft Guide:

Watch the Recording:

Track This Work:

You can follow and contribute to the work of the OpenChain AI Work Group through its dedicated mailing list. This is open to everyone regardless of industry vertical or speciality. You will find it here:

Attend Future Meetings:

You can find and get the dial-in details for all future AI Work Group meetings from our participate page here:

COMING SOON: Webinar – The Future of Insurance for Open Source: Are You Really Covered? – 2025-04-22 @ 08:00 UTC

By News

Open source and insurance has long been a topic of interest to commercial providers of products and solutions. This webinar will help unpack the reality of insurance considerations in this space. All welcome.

Abstract:

Open source software providers are facing a triple threat: tightening US and EU regulations, rising IP litigation, and the risks introduced by Gen AI. Soon, your board—and your customers and suppliers— might be asking that you have specific insurance that actually covers OSS-related liabilities. But, does such insurance exist? Does it work? And how should it work?

Historically, insurers have struggled to grasp OSS risks, offering inadequate or unclear coverage. Now, a new wave of insurance solutions is emerging, informed by OpenChain standards and best practices.

Join this session to explore how the insurance industry is evolving, what new OSS-specific coverage looks like, and how you can help shape it to meet the real needs of the open source community.

Meet Your Presenters:

Lewis Parle, Head of Intellectual Property Risks @ Lockton

Andrew Katz, CEO @ Orcro

Stephen Pollard, Director Open Source Advisory @ Orcro

Join the Webinar:

LINK PENDING

COMING SOON: OpenChain Korea Work Group – Meeting #25 – 2025-03-25

By News

The 25th Meeting of the OpenChain Korea Work Group is coming soon! Join one of the most energetic, friendly and productive open source communities dedicated to better supply chain management. All welcome, even if you do not speak Korean.

Time and Date: 25th of March (2025-03-25) 14:00 – 17:00

Location: Korea Digital Certification Association (Yeouido Park One Building Tower 2, 48th floor) – https://maps.app.goo.gl/YnxTkz8LjHPXFJBv6

Check out the agenda and learn more here:

Please note: Format registration will launch soon. You can already express your interest on the OpenChain Korea Work Group mailing list (https://lists.openchainproject.org/g/korea-wg).

RECORDING: OpenChain SBOM Study Group – Monthly Meeting – 2025-02-26

By News

As always, we focused on the question of “how do we use SBOMs in production, large-scale and complex supply chains?” We are dealing with the reality of supply chains with many participants who have different levels of skill, use different formats, and perhaps follow different regulations or policies.

This meeting looked at two important pieces of analysis from the OpenChain Japan SBOM Sub-Group. The goal was to find common challenges, and how we can address them when we consider:

  • Process management as our focus (the management layer)
  • Previous OpenChain work in this field (e.g. the Telco SBOM Guide)
  • Other work around the world (e.g. emerging regulation etc.)

Background Analysis #1 – SBOM Quality Considerations:

Background Analysis #2 – Further SBOM Quality Considerations:

Watch the Meeting:

Learn More About This Study Group:

Our SBOM Study Group brings all our various SBOM-related activities together and helps answer the question of “how do we use SBOMs in production, large-scale and complex supply chains?” Our original kick-off call has all the details.

Get Involved:

✉️ We have a dedicated mailing list:
https://lists.openchainproject.org/g/sbom

💻 We have a dedicated GitHub Repo:
https://github.com/OpenChain-Project/SBOM-sg