Skip to main content
Category

News

OpenChain Monthly North America – Europe Call – 2024-05-07 – Full Recording

By Featured, News

The OpenChain Specification Work Group held its regular monthly call on the 7th of May. You can review the full recording below.

We were working on the draft next generation security assurance specification:
https://github.com/OpenChain-Project/Security-Assurance-Specification/blob/main/Security-Assurance-Specification/2.0/en/openchain-security-specification-2.0.md
and
The draft next generation licensing compliance specification:
https://github.com/OpenChain-Project/License-Compliance-Specification/blob/master/3.0/en/openchain-license-compliance-3.0.md

For security we were coming to a conclusion on this issue:

[Improvement] Expand definitions section for (1) Secure Software Development to include Secure Programming Techniques and (2) Security Testing to include Static and Dynamic #36
https://github.com/OpenChain-Project/Security-Assurance-Specification/issues/36

And for licensing we were coming to a conclusion on this issue:

Verification Material For Training – next iteration #38
https://github.com/OpenChain-Project/License-Compliance-Specification/issues/38

Both issue are read to close pending any objections, and therefore there is a two-week period – before the forthcoming North America / Asia call – to review and add any notes.

We also opened one new issue for review in future calls:

[Improvement] Review Cycle Potentially Needs Adjustment #71
https://github.com/OpenChain-Project/License-Compliance-Specification/issues/71

Join Our Work

Everyone is welcome to be part of the Specification Work Group. You can join their mailing list here:
https://lists.openchainproject.org/g/specification/

Coming Soon: OpenChain Webinar: AboutCode and beyond – End-to-end SCA with open source code and open data

By News

On 2024-05-15 at 09:00 CEST, an OpenChain Webinar will dig into open source tooling for open source compliance.

As per the authors: “Ensuring software license and security compliance can be difficult. Managing open source components – especially their licensing, provenance, and vulnerability risk – is a critical part of Software Composition Analysis (SCA), which is now a prerequisite for modern organizations to comply with mandated SBOMs and other regulations.

Expensive, proprietary SCA solutions rely on proprietary data that can be outdated or just wrong. To make using open source easier for everyone, we need FOSS tools and open data for FOSS SCA.

Philippe Ombredanne will explain how using 100% open source software and open data, the AboutCode stack offers a new approach for the practical management of open source software for licensing and vulnerability risks for organizations of all sizes. Philippe will share how modular open source projects like ScanCode, VulnerableCode, and DejaCode fit together to identify components and their license, provenance, and known vulnerabilities, and aggregate this and SBOM data across products, teams, and organizations to address security, legal, and regulatory requirements for software license and security compliance in an integrated solution.

Philippe will also discuss exciting updates on new open source projects for better software supply chain integrity and security like CRAVEX, which delivers modern open source tools for developers to manage, triage, rate, review, and determine exploitability of package vulnerabilities in a package-centric world.”

Join the meeting here up to ten minutes before it starts:

OpenChain Education Work Group – Monthly Meeting – 2024-05-01

By News

On the 1st of May we held our regular meeting of the OpenChain Education Work Group. As part of the outreach activities of the OpenChain Project, it focuses on help to make it easier to understand and adopt OpenChain ISO/IEC 5230:2020 for license compliance and OpenChain ISO/IEC 18974:2023 for security assurance. Discussion ranges from handouts to education leaflets to training slides to case studies and guides. Editing is normally done on GitHub. All are welcome.

Be Part Of Next Steps

Join the Education Work Group mailing list to participate in the calls and async editing:

OpenChain Project Meetings This Week (all times UTC)

By News

This week we have the following international meetings:

Tuesday 7th May:

– OpenChain AI Study Group – Monthly Workshop for North America and Europe @ 14:00 UTC
– OpenChain Monthly Call – North America / Europe @ 16:00 UTC

Wednesday 8th May:

– OpenChain Automation Work Group Meeting (European Morning) @ 08:00 UTC

Thursday 9th May:

– OpenChain AI Study Group Call – Asia Sync Call @ 08:00 UTC

You can check out all our international meetings and get instructions on adding our calendar to your client here:

OpenChain Newsletter #65

By Monthly Newsletter, News
logo

​ Newsletter – Issue 65 – April 2024

The OpenChain Newsletter provides a monthly summary of our work. It contains an overview of what we are doing to build trust around license compliance and security in the open source supply chain. We accept suggestions and ideas. Feel free to mail us at any time.

Headline News

Outreach

Webinars

Meetings

Our community released the following meeting recordings via our main channel:

Note: Some community meetings are not recorded or are released through other channels

Check Out All Our Previous Newsletters:

OpenChain Monthly North America – Asia Call – 2024-04-16 – Full Recording

By Featured, News

May is coming fast, and ahead of that it is time to catch up on the recording of the most recent North America / Asia call, where we edited proposed next generation versions of our licensing and security specifications.

We covered two open GitHub issues on this call:

Security Assurance Review:
– Expand definitions section for (1) Secure Software Development to include Secure Programming Techniques and (2) Security Testing to include Static and Dynamic 
https://github.com/OpenChain-Project/Security-Assurance-Specification/issues/36

License Compliance Review:
– Verification Material For Training – next iteration
https://github.com/OpenChain-Project/License-Compliance-Specification/issues/38

Check out the full recording here:

Be part of this:

You can join our calls (and our mailing lists) by following the instructions on our “Participate” page: https://openchainproject.org/participate

OpenChain Project Meetings This Week (all times UTC)

By News

This week we have the following international meetings:

Wednesday 1st May:

– OpenChain @ FINOS Open Source Readiness SIG @ 14:00 UTC
– OpenChain Education Work Group – Monthly Meeting @ 16:00 UTC

Thursday 2nd May:

– OpenChain Telco Work Group Meeting (European Morning) @ 07:00 UTC
– OpenChain Telco Work Group Meeting (European Afternoon) @ 14:00 UTC

You can check out all our international meetings and get instructions on adding our calendar to your client here:

Webinar: OFE Briefing on the Cyber Resilience Act

By Featured, legal, licensing, News, security, Webinar

This webinar is a special briefing lead by Ciarán O’Riordan, Senior Policy Advisor at OpenForum Europe (OFE), on European policy matters that impact open source, business processes and risk management. OFE is a not-for-profit, Brussels-based independent think tank which explains the merits of openness in computing to policy makers and communities across Europe. Originally launched in 2002 to accelerate and broaden the use of Open Source Software (OSS) among businesses, consumers and governments, OFE’s focus has since evolved to also cover issues related to Open standards, Cybersecurity, Digital Government, Public Procurement, Intellectual Property, Cloud Computing and Internet Policy.

More Details

“The proposal for a regulation on cybersecurity requirements for products with digital elements, known as the Cyber Resilience Act, bolsters cybersecurity rules to ensure more secure hardware and software products. Hardware and software products are increasingly subject to successful cyberattacks, leading to an estimated global annual cost of cybercrime of €5.5 trillion by 2021.”
https://digital-strategy.ec.europa.eu/en/library/cyber-resilience-act

Our Speaker is Ciarán O’Riordan, Senior Policy Advisor at OpenForum Europe. His background is as a free software / open source software policy and communications expert.

OFE is a not-for-profit, Brussels-based independent think tank which explains the merits of openness in computing to policy makers and communities across Europe. Originally launched in 2002 to accelerate and broaden the use of Open Source Software (OSS) among businesses, consumers and governments, OFE’s focus has since evolved to also cover issues related to Open standards, Cybersecurity, Digital Government, Public Procurement, Intellectual Property, Cloud Computing and Internet Policy.
https://openforumeurope.org/

More in the OFE Series

We held three special briefings from OFE for the OpenChain community from May to June 2024.

More About Our Webinars:

This event is part of the overarching OpenChain Project Webinar Series. Our series highlights knowledge from throughout the global OpenChain eco-system. Participants are discussing approaches, processes and activities from their experience, providing a free service to increase shared knowledge in the supply chain. Our goal, as always, is to increase trust and therefore efficiency. No registration or costs involved. This is user companies producing great informative content for their peers.

Check Out The Rest Of Our Webinars

This OpenChain Webinar was broadcast on 2024-04-23.