Skip to main content
Category

News

Amazon Joins The OpenChain Project As A Platinum Member

By Featured, News

Amazon is the latest company to join the OpenChain Project as a Platinum Member and to take a seat at the Governing Board and Steering Committee. This highlights their unwavering commitment to leadership in open source technology, process management and in building trusted supply chains.

“At Amazon, we believe in strengthening the open source ecosystem through collaboration and shared best practices,” said Nithya Ruff, Director of Amazon’s Open Source Program Office. “By joining the OpenChain Project, we’re committed to contributing our experience across cloud services and consumer devices to support and evolve industry standards. We look forward to working with the OpenChain community to make supply chain collaboration easier and more effective for the industry.”

“Amazon pioneered modern digital management of complex supply chains at massive scale,” says Shane Coughlan, OpenChain General Manager. “Their engagement with the OpenChain Project, and more broadly with all aspect of open source process management, underlines the vital role that open standards and open communities play in building a more trusted supply chain. We look forward to benefiting from their thought-leadership as OpenChain enters the next stage of its evolution.”

About the OpenChain Project

The OpenChain Project has an extensive global community of over 1,000 companies collaborating to make the supply chain quicker, more effective and more efficient. It maintains OpenChain ISO/IEC 5230, the international standard for open source license compliance programs and OpenChain ISO/IEC 18974, the industry standard for open source security assurance programs.

About The Linux Foundation

The Linux Foundation is the world’s leading home for collaboration on open source software, hardware, standards, and data. Linux Foundation projects are critical to the world’s infrastructure, including Linux, Kubernetes, Node.js, ONAP, PyTorch, RISC-V, SPDX, OpenChain, and more. The Linux Foundation focuses on leveraging best practices and addressing the needs of contributors, users, and solution providers to create sustainable models for open collaboration. For more information, please visit us at linuxfoundation.org.

ZF Group Announces an ISO/IEC 5230 Conformant Program

By Featured, News

Today we are delighted to share the news that ZF Group has implemented an ISO/IEC 5230 conformant program.

This significant achievement underscores their commitment to excellence, innovation, and adherence to the highest standards of compliance and best practices in their open-source initiatives. As noted by Sarah Moser of the ZF Group team, implementing the ISO/IEC 5230 standard represents a crucial step in fostering a culture of transparency, collaboration, and continuous improvement.

ZF Group’s conformance was via third-party certification in collaboration with TIMETOACT. The approach they took, their motivations and their practical solutions will be highlight in a forthcoming OpenChain webinar and case study.

Huge thanks to Sarah, the ZF OSPO team and also Simon Pletschacher at TIMETOACT for not only making this happen, but helping to communicate it widely to inspire others.

About ZF Group

ZF is a global technology company represented with 161 production locations in 30 countries. With some 161,600 employees worldwide, ZF reported sales of €41.4 billion in fiscal year 2024.

Founded in 1915, ZF has evolved from a supplier specializing in aviation technology to a global mobility technology company.

Group shareholders include the Zeppelin Foundation, administered by the City of Friedrichshafen, holding 93.8 percent of shares, and the Dr. Jürgen and Irmgard Ulderup Foundation, Lemförde, with 6.2 percent.

About the OpenChain Project:

The OpenChain Project has an extensive global community of over 1,000 companies collaborating to make the supply chain quicker, more effective and more efficient. It maintains OpenChain ISO/IEC 5230, the international standard for open source license compliance programs and OpenChain ISO/IEC 18974, the industry standard for open source security assurance programs.

About The Linux Foundation:

The Linux Foundation is the world’s leading home for collaboration on open source software, hardware, standards, and data. Linux Foundation projects are critical to the world’s infrastructure, including Linux, Kubernetes, Node.js, ONAP, PyTorch, RISC-V, SPDX, OpenChain, and more. The Linux Foundation focuses on leveraging best practices and addressing the needs of contributors, users, and solution providers to create sustainable models for open collaboration. For more information, please visit us at linuxfoundation.org.

RECORDING: OpenChain AI Work Group – Monthly Workshop for North America and Europe – 2025-04-01

By News

We held our regular workshop for the OpenChain AI Work Group on April 1st. It was a two-hour session focused on finalizing a Guide to AI Bill of Material Compliance in the Supply Chain. The draft is reaching its final stages, and is expected to be ready by June.

The Draft Guide:

Watch the Recording:

Track This Work:

You can follow and contribute to the work of the OpenChain AI Work Group through its dedicated mailing list. This is open to everyone regardless of industry vertical or speciality. You will find it here:

Attend Future Meetings:

You can find and get the dial-in details for all future AI Work Group meetings from our participate page here:

RECORDING: OpenChain Tooling Work Group Meeting – 2025-03-19

By News

Our Agenda:

  • Update on the Tooling Capability Map (version 1.6.3).
  • A look at mkDocs and Tags as a way to organize our documentation
  • An update on the OpenChain and Friends event in Stuttgart, April 7th, 8th and 9th

Watch the Recording:

Learn More About This Work Group:

Our Tooling Work Group looks at the question of “how do we automate compliance process review, and can we do it using open source solutions?”

Get Involved:

✉️ We have a dedicated mailing list:
https://groups.io/g/oss-based-compliance-tooling

💻 We have a dedicated GitHub Repo:
https://github.com/Open-Source-Compliance/Sharing-creates-value

RECORDING: OpenChain Monthly Specification and Education Call (Europe – Asia) – 2025-03-19

By News

As well as our usual news and updates (you can check out the slides in our regular place), we had Ana from TODO Group as a special guest! She gave us an update on their latest activities in the world of Open Source Program Offices (OSPO), and we had a chance to chat, ask questions, and share other news.

One of the most powerful parts of the open source community, and organizations like The Linux Foundation, is providing a way for projects not only to grow but also to share. By supporting each other, and collaborating on events, material or code, innovation gets to more people, more quickly.

Coming Next:

We have a lot to do. The Freeze Period for proposed updates to ISO/IEC 5230 and ISO/IEC 18974 is over, so it’s time for formatting and handover to the Steering Committee. Meanwhile, the Education Work Group is about to dive into some pretty cool updates to existing material. It looks like our training course and the capability model will be first.

Join Our Work:

Everyone is welcome to be part of the Specification Work Group and work on our standards. You can join the mailing list here:
https://lists.openchainproject.org/g/specification/

Everyone is welcome to be part of the Education Work Group and build reference material for open source process management. You can join the mailing list here:
https://lists.openchainproject.org/g/education

You can find and be part of all OpenChain calls through our participation page here:
https://openchainproject.org/participate

RECORDING: OpenChain SBOM Study Group – Monthly Meeting – 2025-03-26

By News

As always, we focused on the question of “how do we use SBOMs in production, large-scale and complex supply chains?” We are dealing with the reality of supply chains with many participants who have different levels of skill, use different formats, and perhaps follow different regulations or policies.

In this meeting, we had a great presentation from Marc-Etienne Vargenau of Nokia about a forthcoming update to the Telco SBOM Guide (a guide to SBOM Quality in the Telco industry). Version 1.0 of the Telco Guide came out in July of 2024. Version 1.1, previewed in this call, was released to the OpenChain Telco Work Group in March 2025, and will be getting a general release in April 2025.

Learn More About This Study Group:

Our SBOM Study Group brings all our various SBOM-related activities together and helps answer the question of “how do we use SBOMs in production, large-scale and complex supply chains?” Our original kick-off call has all the details.

Get Involved:

✉️ We have a dedicated mailing list:
https://lists.openchainproject.org/g/sbom

💻 We have a dedicated GitHub Repo:
https://github.com/OpenChain-Project/SBOM-sg

QNAP Announces an OpenChain ISO/IEC 5230 Conformant Program

By Featured, News

QNAP Systems, Inc., a leading computing, networking, and storage solutions innovator based in Taipei, has announce and OpenChain ISO/IEC 5230 conformant program.

About QNAP

QNAP (Quality Network Appliance Provider) is devoted to providing comprehensive solutions in software development, hardware design and in-house manufacturing. Focusing on storage, networking and smart video innovations, QNAP now introduce a revolutionary Cloud NAS solution that joins our cutting-edge subscription-based software and diversified service channel ecosystem. QNAP envisions NAS as being more than simple storage and has created a cloud-based networking infrastructure for users to host and develop artificial intelligence analysis, edge computing and data integration on their QNAP solutions.

About the OpenChain Project:

The OpenChain Project has an extensive global community of over 1,000 companies collaborating to make the supply chain quicker, more effective and more efficient. It maintains OpenChain ISO/IEC 5230, the international standard for open source license compliance programs and OpenChain ISO/IEC 18974, the industry standard for open source security assurance programs.

About The Linux Foundation:

The Linux Foundation is the world’s leading home for collaboration on open source software, hardware, standards, and data. Linux Foundation projects are critical to the world’s infrastructure, including Linux, Kubernetes, Node.js, ONAP, PyTorch, RISC-V, SPDX, OpenChain, and more. The Linux Foundation focuses on leveraging best practices and addressing the needs of contributors, users, and solution providers to create sustainable models for open collaboration. For more information, please visit us at linuxfoundation.org.

Webinar: The Future of Insurance for Open Source – Are You Really Covered? – 2025-04-22 @ 08:00 UTC

By News

Open source software providers are facing a triple threat: tightening US and EU regulations, rising IP litigation, and the risks introduced by Gen AI. Soon, your board—and your customers and suppliers— might be asking that you have specific insurance that actually covers OSS-related liabilities. But, does such insurance exist? Does it work? And how should it work?

Historically, insurers have struggled to grasp OSS risks, offering inadequate or unclear coverage. Now, a new wave of insurance solutions is emerging, informed by OpenChain standards and best practices.

Join this session to explore how the insurance industry is evolving, what new OSS-specific coverage looks like, and how you can help shape it to meet the real needs of the open source community.

Join using this link up to ten minutes before the official start: 

More About Our Webinars:

This event is part of the overarching OpenChain Project Webinar Series. Our series highlights knowledge from throughout the global OpenChain eco-system. Participants are discussing approaches, processes and activities from their experience, providing a free service to increase shared knowledge in the supply chain. Our goal, as always, is to increase trust and therefore efficiency. No registration or costs involved. This is user companies producing great informative content for their peers.

Check Out The Rest Of Our Webinars

OpenChain Monthly Specification and Education Call (North America – Europe) – 2025-03-12

By News

This time we discussed strategic matters like next steps in our existing ISO standards, board strategy discussions underway, and community considerations. We also took a look at two items from sister projects related to project health and security:

OpenSSF Scorecard:
https://scorecard.dev/

CHAOSS Metrics
https://chaoss.community/software/

Check out the Meeting Slides:

Watch the Recording:

Coming Next:

We will be following up on the activities outlined above on the mailing lists, and we will continue our regular series of calls and meetings throughout the year.

Join Our Work:

Everyone is welcome to be part of the Specification Work Group. You can join their mailing list here:
https://lists.openchainproject.org/g/specification/

You can find and be part of all OpenChain calls through our participation page here:
https://openchainproject.org/participate

OpenChain Telco Work Group Meetings – 2025-03-06

By News

The OpenChain Telco Work Group is in the final stages of preparing Version 1.1 of the Telco SBOM Guide, an industry-specific but adaptable guide to addressing the question of SBOM quality in the supply chain. Learn more in their latest meetings.

Be part of this:

You can get involved with the OpenChain Telco Work Group through their dedicated mailing list. At this link, you will also find connections to other working groups around the world:

Please note: you do not have to be an expert in telecommunications or work for a telecommunications company to join the group. Work on subjects like the Telco SBOM Quality Guide is intended to also help other market sectors.