Skip to main content
Category

News

Happening Today: OpenChain China Work Group – Regular Meeting 3 – 2024-11-29 @ 14:00 to 17:30

By News

Keynote Slides

Agenda:

  1. “Warmly Welcome” – 胡灵灵, Ant group counsel
  2. “Global News Update for OpenChain” – Shane Coughlan, OpenChain
  3. “We Connect Now in OpenChain” – Zhenhua Sun, ByteDance
  4. “How the OSPO (or other departments) manages open source” – Richard Bian, Ant
  5. “King of SPDX Journey / The Untold Stories of SPDX” – King Gao, SecTrend
  6. “What I saw and heard at the Open Compliance Summit 2024 & A Philosophy of GPL” – Tao Ye, Grandall Law Firm

OpenChain @ InnerSource Summit 2024 – 2024-11-20 – Slides

By News

Shane Coughlan, OpenChain General Manager, delivered a speech entitled ‘Understanding how OpenChain ISO/IEC 5230 and ISO/IEC 18974 support InnerSource’ at the InnerSource Summit 2024.

Abstract:

This talk discussed how OpenChain ISO/IEC 5230 (the international standard for open source license compliance) and ISO/IEC 18974 (the international standard for open source security assurance) support the work of InnerSource program offices. While supply chain management is often seen as external relationships between customers and suppliers, internal supply chain management is just as critical. Using industry standards in this context ensures alignment with broader market expectations, and ensures that remediation, catch-up and process mis-match is minimized.

Slides:

Learn More On The Event Website:

Coming Soon: OpenChain SBOM Study Group – November – 2024-11-27 @ 08:00 UTC

By News

In this SBOM Study Group meeting, Okada San from OWASP Japan will lead an overview of ”Vulnerabilities and the Future – Multilayered Software Vulnerabilities and Response Tactics.” This discussion will build on a talk he recently delivered at the first Japan SBOM Summit on a similar topic.

Join Using This Link:

How Did We Start This Study Group?

Get Involved Through Our Mailing List

OpenChain China Work Group – Regular Meeting 3 – 2024-11-29 @ 14:00 to 17:30

By News

Hosted by

Location:

杭州市西湖区西溪路569号蚂蚁A空间

Time and Date:

2024-11-29 14:00 ~ 17:30

Agenda:

  1. “Warmly Welcome” – 胡灵灵, Ant group counsel
  2. “Global News Update for OpenChain” – Shane Coughlan, OpenChain
  3. “We Connect Now in OpenChain” – Zhenhua Sun, ByteDance
  4. “How the OSPO (or other departments) manages open source” – Richard Bian, Ant
  5. “King of SPDX Journey / The Untold Stories of SPDX” – King Gao, SecTrend
  6. “What I saw and heard at the Open Compliance Summit 2024 & A Philosophy of GPL” – Tao Ye, Grandall Law Firm

Register:

Coming Soon: Webinar – CHAOSS Practitioner Guides for Healthy & Sustainable OSS Projects @ 2024-12-05 – 09:00 UTC

By News

The next OpenChain Webinar will be highlighting the work of a sister project – CHAOSS – which provides a way to apply metrics to open source. Their new practitioner guides are a resource that can help everyone manage projects in a sustainable way. Dr. Dawn Foster will lead the conversation.


Abstract:

Sustaining OSS projects and communities over the long-term can be a challenge. Project leaders, maintainers, and contributors are busy people who don’t always have the time or experience to focus on growing a community and maintaining their software. Using metrics is one way to help OSS projects identify potential issues and identify areas where they can improve their community to make it more sustainable over the long-term. Being proactive about improving sustainability before it becomes a crisis can help make our software more sustainable and reliable for all of us. However, not everyone has the experience or skills required to know how to interpret their metrics and use what they learn to make improvements within their community.

The CHAOSS project has been creating a series of MIT licensed Practitioner Guides focused on improving the sustainability of our software and communities. The guides are designed to make it easier for people to draw meaningful and actionable insights using community metrics, even when those people do not necessarily have a deep background in data analysis or much experience working within OSS communities.

This talk will identify several categories of metrics from the Practitioner Guide Series, including responsiveness, contributor sustainability, organizational participation, and security. This session will cover not just how to interpret the metrics, but will focus on providing ideas for improving in areas identified using the metrics. The audience will walk away with a better understanding of how to use metrics to proactively improve the long-term sustainability of their OSS projects and communities.

Bio:

Dr. Dawn Foster works as the Director of Data Science for CHAOSS where she is also a board member / maintainer. She is co-chair of CNCF TAG Contributor Strategy and an OpenUK board member. She has 20+ years of experience at companies like VMware and Intel with expertise in community, strategy, governance, metrics, and more. She has spoken at over 100 industry events and has a BS in computer science, an MBA, and a PhD. In her spare time she enjoys reading science fiction, running, and traveling.

Join @ 2024-12-05 – 09:00 UTC using this link:

More About Our Webinars:

This event is part of the overarching OpenChain Project Webinar Series. Our series highlights knowledge from throughout the global OpenChain eco-system. Participants are discussing approaches, processes and activities from their experience, providing a free service to increase shared knowledge in the supply chain. Our goal, as always, is to increase trust and therefore efficiency. No registration or costs involved. This is user companies producing great informative content for their peers.

Check Out The Rest Of Our Webinars

OpenChain Education Work Group – Monthly Meeting – 2024-11-06 – Full Recording

By News

In This Call…

After a great trip to Tokyo (for the Open Compliance Summit) and Beijing, there was a lot to report on the Capability Model, and Martin Yagi has (as ever) done a great job on the explainers. See https://github.com/OpenChain-Project/Reference-Material/tree/myagi2019-explainer-drafts1/Education-For-Internal-Teams for his work on these. We are also proposing an explainer for the Capability Model.

It is proposed to have a short work-stream involving co-ordinating the various case studies which the OpenChain Project has collated over time. We had some great examples at the Open Compliance summit and it would be fantastic to be able to incorporate these into the portfolio, and to make the portfolio as a whole more accessible and better structured.

Be part of this:

You can get involved with the OpenChain Education Work Group through their dedicated mailing list. At this link, you will also find connections to other working groups around the world:

HARMAN International Announces An OpenChain ISO/IEC 5230 Conformant Program

By Featured, News
This image has an empty alt attribute; its file name is Harman_International_logo.svg-1.png

“It is a pleasure to list HARMAN International in our community of conformance,” says Shane Coughlan, OpenChain General Manager. “Their alignment with ISO/IEC 5230, the international standard for open source license compliance, underscores their commitment to excellence in the use and deployment of open source software. We deeply appreciate their work, and listing them in the OpenChain Community of Conformance.”

About HARMAN

HARMAN (harman.com) designs and engineers connected products and solutions for automakers, consumers, and enterprises worldwide, including connected car systems, audio and visual products, enterprise automation solutions; and services supporting the Internet of Things. With leading brands including AKG®, Harman Kardon®, Infinity®, JBL®, Lexicon®, Mark Levinson® and Revel®, HARMAN is admired by audiophiles, musicians and the entertainment venues where they perform around the world. More than 50 million automobiles on the road today are equipped with HARMAN audio and connected car systems. Our software services power billions of mobile devices and systems that are connected, integrated and secure across all platforms, from work and home to car and mobile. HARMAN has a workforce of approximately 30,000 people across the Americas, Europe, and Asia. In March 2017, HARMAN became a wholly-owned subsidiary of Samsung Electronics Co., Ltd.

About the OpenChain Project

The OpenChain Project has an extensive global community of over 1,000 companies collaborating to make the supply chain quicker, more effective and more efficient. It maintains OpenChain ISO/IEC 5230, the international standard for open source license compliance programs and OpenChain ISO/IEC 18974, the industry standard for open source security assurance programs.

About The Linux Foundation

The Linux Foundation is the world’s leading home for collaboration on open source software, hardware, standards, and data. Linux Foundation projects are critical to the world’s infrastructure, including Linux, Kubernetes, Node.js, ONAP, PyTorch, RISC-V, SPDX, OpenChain, and more. The Linux Foundation focuses on leveraging best practices and addressing the needs of contributors, users, and solution providers to create sustainable models for open collaboration. For more information, please visit us at linuxfoundation.org.

OpenChain Project – Main Monthly North America and Europe Call – 2024-11-05 – Full Recording

By News

We held our regular Monthly North America and Europe Call on the 5th of November. The focus was on discussing the Public Comment period for our draft proposed updates to the licensing and security specifications, and closing any open comments / issues around the draft documents.

We keep all the slides from our monthly calls online and they can be a useful way to access direct links and more details:

Join Our Work

Everyone is welcome to be part of the Specification Work Group. You can join their mailing list here:
https://lists.openchainproject.org/g/specification/

You can find and be part of all OpenChain calls through our participation page here:
https://openchainproject.org/participate

OpenChain AI Study Group – Monthly Workshop for North America and Europe – 2024-11-05 – Recording

By News

The OpenChain AI Study Group held its regular workshop on the 5th of November. This meeting focused on discussion around the draft scratchpad for management of AI BOMs, and the conversion of this study group into a formal working group.

Watch the Recording

Track This Work

You can follow and contribute to the work of the OpenChain AI Study Group through its dedicated mailing list. This is open to everyone regardless of industry vertical or speciality. You will find it here:

Attend Future Meetings

You can find and get the dial-in details for all future AI Study Group meetings from our participate page here: