Skip to main content


Register now for the OpenChain Mini-Summit September 2023 @ OSS EU – 2023-09-21

By Featured, News

OpenChain Mini-Summit September 2023

September 21st 2023 at 09:00-12:00 Spanish Time (CEST)

You are invited to join the OpenChain Mini-Summit adjacent to Open Source Summit Europe.

Our focus will be on:

  1. Discussing the new ISO standard for security
  2. Automation for open source compliance and security

This is an hybrid physical and virtual event. It is free of charge for all participants.

Due to in-person space being limited, we invite everyone to register for the virtual event, and to email if they want a seat at the physical event.

We previously planned to hold this Mini-Summit on Monday the 18th of September, but we have moved it to Thursday the 21st of September to avoid overlap with the SPDX Mini-Summit covering SPDX 3.0.

Register for the OpenChain Mini-Summit Here

OpenChain Taiwan Meetup 2023 @ 2023-08-15

By News

= Language 語言 = 

This event will be held mainly in English. Part of the sessions will be delivered in Mandarin. Please see the agenda below for details.


= Register = 

= Overview = 

OpenChain 協助產業在碰觸或思索開源合規 (Open Source Compliance) 爭議或政策時,有一套流程可以提供參考!

這場工作坊將會介紹 OpenChain 專案,同時也邀請國內外的開源合規專家來分享實務經驗,特別是在日本流行起來的 SBOM (Software Bill of Materials) 及 OSPO (Open Source Program Office) 。OpenChain 的推動過程中如何會遭遇到什麼樣的困難,又有什麼克服的方法 ? 若是你正在使用、正要接觸開源軟體,或者是單純想要了解開源軟體,都歡迎你一起加入討論!

什麼是 OpenChain ?

OpenChain 已在 2020/12/16 正式成為 ISO 認證(ISO/IEC 5230:2020),透過導入 OpenChain ISO 標準,供應鏈裡各參與廠商將能清楚了解在哪個開發環節使用哪些自由開源軟體,並進一步釐清發生授權問題的解決方案。

開源軟體在全世界的應用非常廣泛,隨著開源軟體的商業化,複雜的開源授權規定也讓許多商業使用者不知所措,而層出不窮的侵權糾紛,也讓開源合規的議題逐漸受到企業重視。隸屬於 Linux Foundation Project 的 OpenChain 專案透過簡化及標準化開源合規實務,使企業、組織可更為有效滿足開源合規,從而建立產業供應鏈對開源軟體的信任。包含微軟、Google、高通、西門子、Sony 與 Uber 等都已採用OpenChain 進行開源合規管理並通過 OpenChain 認證。

 = Agenda 議程 = 


14:00~14:10|Opening 開場

14:10~14:40|OpenChain – From One Standard To A Family
English / Shane Coughlan, General Manager at OpenChain Project, The Linux Foundation

14:40~15:10|如何建立開源管理機制,做到安全又合規? How to construct an open source managing system to achieve security & compliance?
Mandarin / 中文 / Singing Li, CEO, Open Culture Foundation (李欣穎,開放文化基金會執行長)

15:10~15:40|Break – Tea Time 

15:40~16:10| “SBOM” and “OSPO” in JAPAN
English / Masato Endo, Group Manager of Driver Monitoring Group, Toyota.

16:10~16:40| 深入淺出國際開源資安標準 OpenChain Security Assurance Specification
Mandarin / 中文 / SZ Lin (林上智), Chief Expert, Bureau Veritas

16:40~17:00|Q & A

= Information / 相關資訊 =

 = Location / 場地位置 =

集思北科大會議中心 205 瑞特廳 

地址:台北市忠孝東路 3 段 1 號-億光大樓 2 樓 ( 197 號旁邊棟)

 = Contact / 聯絡信箱 = 

若您對於本活動有任何的問題或意見,歡迎透過電子郵件信箱 或直接到 OpenChain telegram 頻道提出。

OpenChain Export Control Work Group 2023-08-01

By News

The Export Control work group is collaborating on a pre-existing website conversion project.

This involves:

  • Getting reviews going for the per-country files.
  • Thinking about common attributes of country files.

This is the website we are working on converting from HTML to MarkDown:

We are working on it here:

We have a bunch of issues opened:

Since the last call we have closed a few:

Check out the recording below to see what we did next.

OpenChain Automation Work Group 2023-08-02

By News

Provisional minutes. Recording below.

(1) We are doing to do a reset of the group to help people engage more, especially with regards bringing back more technical people and technical updates.
(2) First, we use the Sharing Creates Value GitHub repo as the single source of truth for organizing things from now on, including (a) new content, (b) polls for next steps and (c) arranging future meetings.
(3) We move to a new agenda that brings back the emphasis on engineering as follows:
– News (~10 mins?);
– Technical discussions unpacking open source tools etc (~30-40 mins?);
– Update on the meta level (capabilities map) (~10 mins?).
(4) We will also introduce a fix group of chairs (volunteers) to help ensure the meetings are driven forward while not overloading any one person. Redundancy and mutual support is the goal.

  • Seeking a volunteer to help run the 3rd Tuesday of August 🙂
  • Shane can help run both meetings in September.
  • Marcel is going to help run the first meeting in October.

Other items:

Make the Global Calendar clearer – including timezone offsets – so people can use this as the single-source of truth for confirming our call times. Done. See:

OpenChain Legal Work Group 2023-07-28 – Outcomes

By Featured, News

We covered a lot of ground in this meeting. Check out the full recording below. The current document is here:

Andrew updated the core language substantially and it looks like we are near release:

Carlo submitted a patch with new language covering the verification that a Declaration is not just pro-forma:

We decided to move non-core language to the Risk Grid and then have that queued as an item for review and reorder after the core is published:

We also discussed what to do when we move to a milestone release document rather than this initial drafting phase:

Next Steps

We move towards release of the core language with a final Request for Comments, and then we turn our attention to updating the Risk Grid.

External Survey: Investigating Needs of Legal Practitioners in the Context of Software License Compliance

By News

The Software Engineering Maintenance and Evolution Research Unit (SEMERU) lab at William and Mary is running a new survey relating to third-party software license compliance. The target audience is “people with a background in law, preferably with a law degree and some amount of experience in practice.”

Research Goal and Procedure

The purpose of this study is to investigate issues, needs, and opportunities related to open source software licensing. In particular, this study aims to investigate how legal practitioners address concerns related to software licensing and identifying pain points and unmet needs.

If you decide to participate, you will take a brief survey via the Qualtrics platform. The study will last about 15 minutes during which time you will be asked questions regarding your familiarity and experience with several topics related to open source software licensing that pertain to your work.

With your permission, we may contact you by email and invite you to participate in a follow-up interview.

Access the Survey

About the College of William & Mary

The College of William & Mary is a public research university in Williamsburg, Virginia. Founded in 1693 by a royal charter issued by King William III and Queen Mary II, it is the second-oldest institution of higher education in the United States and the ninth-oldest in the English-speaking world.

OpenChain Newsletter #56

By Monthly Newsletter, News

​ Newsletter – Issue 56 – July 2023

The OpenChain Newsletter provides a monthly summary of our work. It contains an overview of what we are doing to build trust around license compliance and security in the open source supply chain. We accept suggestions and ideas. Feel free to mail us at any time.

Headline News


Shane Coughlan, OpenChain General Manager, was the guest presenter on a webinar for InnerSource Commons:


The OpenChain webinar series continued with presentations about open source in automotive and on InnerSource:


Our multiple work groups had regular meetings:

Check Out All Our Previous Newsletters:

Collabora is the latest organization to announce an OpenChain ISO/IEC 5230 conformant program

By Featured, News

Collabora, a leading open source software consultancy, has become the latest organization to announce an OpenChain ISO/IEC 5230 conformant program.

“One of the key benefits of ISO standards created by the OpenChain Project is to signal the adoption and use of the processes necessary for quality compliance or security programs related to open source,” says Shane Coughlan, OpenChain General Manager. “The announcement by Collabora of an ISO/IEC 5230 conformant program is an example of their commitment to excellence around open source license compliance management. We are delighted to welcome them to our community of conformance, and we look forward to fostering a productive long-term collaboration around our shared industry.”

“Being a ISO9001:2015 and ISO27001:2017 certified organization, we are delighted to join the OpenChain Project’s extensive global community,” says Eleni Katsoula, Engineering Operations Manager at Collabora. Along with so many of Collabora’s esteemed customers being Platinum members of the OpenChain community, we look forward to promoting the project’s focus on commercial and non-commercial open source process management.”

About Collabora

Collabora is a global consultancy specializing in delivering the benefits of Open Source software to the commercial world. Whether it’s the Linux kernel, graphics, multimedia or machine learning, Collabora’s expertise spans across all key areas of Open Source software development. By harnessing the potential of community-driven projects, and re-using existing components, Collabora helps its clients focus on creating product differentiation, enabling them to develop the best solutions. From tailoring the latest Open Source technologies to your projects, to integrating Open Source methodologies into your organization, Collabora can help you navigate the ever-evolving world of Open Source. Learn more at

Webinar: Understanding InnerSource

By community, Featured, News, Webinar

This webinar was lead by Clare Dillon, the Executive Director of InnerSource Commons, and it highlighted the activities and value behind the InnerSource movement. InnerSource is the use of open source best practices for software development within the confines of an organization. Understanding this has become a key part of business strategy for forward-looking organizations.

Two Resource Flagged By Our Speaker

Check Out The Rest Of Our Webinars

This is OpenChain Webinar #55, released on 2024-07-27.

OpenChain Japan Work Group Meeting #28 – Hybrid #3 – 2023-07-11

By News

The OpenChain Japan Work Group held its 28th meeting (3rd hybrid) on the 11th of July. This meeting contained an exceptional roster of speakers and topics covered. OpenSSF, SPDX 3.0, OSPO leadership, education material and addressing common licensing misunderstandings. You name it, we covered it. Check out the recording below in Japanese for details:

Be part of this:

Everyone is invited to be part of the OpenChain Japan Work Group and contribute to (or simply participate in) future activities.