Skip to main content
THE LINUX FOUNDATION PROJECTS
Category

News

Briefing for OpenChain India Work Group: Digital Personal Data Protection Act

By News

Join a webinar on the Digital Personal Data Protection Act, 2023 to understand key compliance obligations, consent mechanisms, and cross-border data transfer requirements. This 60-minute session offers a general overview and practical understanding to help both individuals and companies align  with India’s DPDPA 2023. The event will be lead by Biju Nair, Chair of the OpenChain India Work Group.

Please register to join the webinar:

OpenChain @ OpenFest 2025 in Bulgaria

By News

The OpenChai Meridian 22 Work Group will be represented by Vladimir Slavov at OpenFest 2025 this weekend.

OpenFest is the biggest Bulgarian conference dedicated to free culture, free knowledge sharing, free and open source software. It is the most anticipated annual gathering of fans, creators and supporters of open source and free art in Bulgaria.

Learn more:

Check out the talk:

  • https://www.linkedin.com/posts/vladimir-slavov-%F0%9F%87%AA%F0%9F%87%BA-578726180_%D0%B4%D0%BD%D0%B5%D1%81-%D0%BD%D0%B0-openfest-bulgaria-%D0%BD%D0%B0%D0%BF%D1%80%D0%B0%D0%B2%D0%B8%D1%85-lightning-activity-7385350682226114560-a6pb?utm_source=share&utm_medium=member_desktop&rcm=ACoAAACvKzUByb5VJsorojLALtdi-cBeq-StgR4

Coming Soon: OpenChain Meridian 22 Work Group Call – the CRA, AI Act, DMA, DSA, PLD – Requirements and Meeting Them?

By News
Ciaran O’Riordan of the Eclipse Foundation will join our newest work group to discuss the diverse European Union regulation incoming, how it impacts open source, and what we need to do to meet requirements. Our Meridian 22 community will also discuss what’s happening in their locality, including similar (or compatible) regulations. We will start with Bulgaria. All welcome! This is a community meeting in English.

This event takes place:

2025-10-20 @ 07:30 UTC / 08:30 BST / 09:30 CEST / 16:30 JST

Dial-in at the time of the event:

JUN Legal GmbH is the Latest OpenChain Partner

By Featured, News


JUN Legal GmbH is the latest official OpenChain Partner, expanding coverage and diversity of options in the German market.

“Open source is a strategic topic for the European Union,” says Florian Hackel, specialized lawyer for IT law. “Projects like OpenChain, and the ISO process standards they maintain, offer a path to sustainable, reliable and trustworthy management. We are delighted to be able to support our clients and the broader community in the continued professionalization of open source.”

“Germany is a key market for the OpenChain Project,” says Shane Coughlan, OpenChain General Manager. “I am delighted to see our options for the community expanding, and our avenues for advocacy and support doing the same. I look forward to future collaboration with JUN and their team.”

About JUN Legal GmbH
JUN Legal is a medium-sized German law firm specializing in IT law, AI and open source compliance. Our team currently includes 27 attorneys with FOSS experience, eight of whom are Certified Specialist Lawyers for IT Law. For more than a decade, we have supported major corporate clients in ensuring license-compliant integration of open source software components and in developing strategic policies for the use of open source and its diverse licensing models. Our experience also includes delivering expert lectures, publishing on open source legal topics, and representing clients in selected court proceedings.

Learn more: https://jun.legal/en/

 

OpenChain @ ZF Group Open Source Conference 2025 in Germany

By News

The OpenChain Project delivered a keynote at the recent ZF Conference in Germany. This event, targeted towards internal terms across the ZF Group, and to customers and suppliers, provided a platform to discuss open source strategy and practical management. As an adopter of OpenChain ISO/IEC 5230, ZG Group has taken a leadership position in seeking excellence in the open source automotive supply chain.

Check Out The OpenChain Keynote Slides Below:

RECORDING: OpenChain Monthly Specification and Education Call (North America – Europe) – 2025-10-08

By News

We Discussed:

Lead by Chris Wood (Chair, Specification Work Group) and Martin Yagi (Chair Education Work Group), the call covered the following agenda:

  • OpenChain Project News
  • Specification Work Group – CRA, other regulations and our standards
  • Education Work Group – Update on Status and Community Work Items
  • Any Other Business?

A reminder for those in Asia – while this edition of the monthly call is happening in the darkest hours of the night (01:30 in Japan!), we also have a monthly Europe / Asia call that works better for those in Eastern time zones. Check out the schedule for this and all our other meetings here:
https://openchainproject.org/participate

Watch the Recording:

Coming Next:

  • A ton of work pending on education, and a survey to be released for the spec. Expect a strong focus on looking at what we have accomplished, looking at feedback, and making it better.

Join Our Work:

Everyone is welcome to be part of the Specification Work Group. You can join their mailing list here:
https://lists.openchainproject.org/g/specification/

You can find and be part of all OpenChain calls through our participation page here:
https://openchainproject.org/participate

RECORDING: OpenChain AI Work Group – Monthly Workshop for North America and Europe – 2025-10-07

By News

During our regular OpenChain AI Work Group meeting for North America and Europe the agenda was:

  • Item #1: We have completed the AI SBOM Compliance Management Guide
  • Item #2: We are going live on 20th October – your help with promotion is requested
  • Item #3: We have started coordination with Lord Clement-Jones in the UK, UK working group, Spec Group, LF legal conference and PyTorch conference
  • Item #4: Early market feedback can be used to update the guide for solution/market fit – Your help is requested
  • Item #5: FINOS working group
  • Item #6: Any Other Business

Watch the Recording:

Get Involved:

Everyone is welcome to be part of this activity! OpenChain has free, open access to all its work groups and study groups. Just turn up, and listen in, and contribute comments, ideas and suggestions.

✉️ We have a dedicated mailing list for the AI Work Group: https://lists.openchainproject.org/g/ai

Attend Future Meetings:

You can find and get the dial-in details for all future meetings from our participate page here: https://www.openchainproject.org/participate

Coming Soon: OpenChain @ OSS Security Technology Workshop (OWS) 2025

By News

The Event:

OSS Security Technology Workshop (OWS) aims to encourage interaction between the corporate OSS community and academia, thereby stimulating research on OSS security and movement toward its practical application. OWS 2025 will be a key event to share knowledge and experience.

The Speakers:

Kobota San and Namae San of Sony (and the OpenChain community) will be speaking in Okayama on the 28th of October at 15:50.

Title:

Improving SBOM Quality: Practitioner Challenges and Initiatives to Strengthen Software Supply Chain Trust

Abstract:

This presentation examines the critical role of high-quality SBOMs in regulatory compliance and software supply chain hardening. SBOM is essential for robust security management and compliance with OSS licenses. However, as things stand at present, many implementations are inadequate – for example, “Source SBOM” is often unable to capture real binaries or runtime components, while “Build SBOM” generated via CI/CD pipelines tends to rely on package metadata, resulting in incomplete or mismatched data. Sony is focusing its efforts on the OpenChain project, developing SBOM Document Quality Guides based on ISO/IEC 5230 and ISO/IEC 18974, implementing measures such as ESSTRA, software for embedding source code details of executable binaries released by Sony as OSS, and providing upstream OSS packages in collaboration with the Debian community.

Learn More:

OpenChain Newsletter #82

By Monthly Newsletter, News

Newsletter – Issue 82 – September 2025

The OpenChain Newsletter provides a monthly summary of our work. It contains an overview of what we are doing to build trust around license compliance and security in the open source supply chain. We accept suggestions and ideas. Feel free to mail us at any time.

Key Announcements and Updates

  • Seven Services Announces OpenChain ISO/IEC 5230 Conformant Program: Seven Services has announced a new program to help organizations conform to the OpenChain ISO/IEC 5230 standard for open source license compliance. You can learn more about this announcement here.
  • OpenChain ISO/IEC 18974 and the Cyber Resilience Act (CRA): The OpenChain security standard, ISO/IEC 18974, has been referenced in the EU Cyber Resilience Act (CRA) harmonized standards discussion. This is a significant development for the project and its role in the future of cybersecurity. Read the full update here.
  • Introducing the OpenChain Ambassador Program: A new Ambassador Program has been launched to recognize and support community members who are actively promoting OpenChain. Learn more about the program and how to get involved here.
  • SBOM Study Group Becomes a Work Group: The successful SBOM Study Group has now transitioned into a formal SBOM Work Group. This change reflects the group’s focus on producing tangible outputs, starting with a new guide to SBOM quality. You can find more information here.
  • Developing a New Guide to SBOM Quality: The SBOM Work Group is developing a new, cross-industry guide to SBOM quality. You can review the draft and contribute your feedback here.

Community Insights

  • OpenChain at Open Source Summit North America: A presentation at OSS NA by representatives from Sony Group Corporation highlighted the challenges and importance of managing a global community, with a focus on language and cognitive load. This is a must-read for anyone involved in international open source projects. You can find the details here.

Recent Meeting Recordings

For those who missed recent meetings, recordings are available:

  • OpenChain Monthly Specification and Education Call (Europe / Asia) – 2025-09-17: Recording
  • OpenChain Monthly Specification and Education Call (North America – Europe) – 2025-09-10: Recording
  • OpenChain SBOM Work Group – Monthly Meeting – 2025-09-24: Recording
  • OpenChain AI Work Group – Asia Sync – 2025-09-11: Recording
  • OpenChain Telco Work Group – September – 2025-09-04: Recording
  • OpenChain AI Work Group – Monthly Workshop for North America and Europe – 2025-09-02: Recording

Recent Webinars

  • Webinar: Introduction to the Cyber Resilience Act (CRA): An overview of the new EU law covering “products with digital elements.” You can watch the webinar here.
  • Webinar: Compliant containers with the OSADL Base Image: Learn how to manage FOSS license obligations for containers using the OSADL Base Image. The webinar recording is available here.

Potential Further Actions

  • Get Involved with the SBOM Work Group: With the SBOM Study Group now a Work Group, this is an excellent opportunity to contribute to the development of a crucial industry guide.
  • Attend Future Meetings: The best way to stay informed and contribute is to attend the various work group and specification calls. The schedule and connection details for all meetings can be found on the OpenChain participation page.
  • Watch Past Recordings: If you are new to a topic or a working group, watching the past recordings is a great way to get up to speed.

To participate further in the OpenChain Project, including joining mailing lists and attending meetings, please visit: https://openchainproject.org/participate

Note: This newsletter usually only contains primary meetings. Some community meetings are not recorded or are released through other channels.

Read Previous Newsletters:

AI Usage:

This newsletter is created by using a template, curating links from a month of OpenChain news posted on the blog and using these prompts on Google Gemini to fill out the central news:

  • “Summarize the following newsletter for folks interested in the open source compliance to learn the latest changes in the space and find possible items that can act on. Include the links in this newsletter. Add notes on potential further actions by readers, particularly around attending future meetings. Direct people to this link to participate further: https://openchainproject.org/participate”

The newsletter is then subject to an edit cycle. If you spot any errors we missed, please contact us.

Seven Services Announces an OpenChain ISO/IEC 5230 Conformant Program

By Featured, News

Seven Services is the latest company to announce an OpenChain ISO/IEC 5230 conformant program. Based in Saudi Arabia, they are the first organization to enter the OpenChain Community of Conformance from that region.

Seven Services is a multi-industry company, delivering advanced services and solutions tailored to meet the evolving demands of multiple industries. With a strong commitment to innovation, reliability, and excellence, we specialize in providing comprehensive solutions across key sectors, including:

  • Information Technology
  • Security
  • Oil & Gas
  • Industrial Support
  • Facility Management
  • General Trading
  • Logistics

Committed to innovation and customer success, Seven Services empowers businesses with secure, efficient, and scalable solutions.

You Will Find Their Listing In The Community of Conformance Here:

Learn More About The Organization: