Skip to main content
Category

News

LG Electronics Announces OpenChain ISO/IEC DIS 18974 Conformant Program

By Featured, News

LG Electronics (LG) now has an OpenChain Security Assurance Specification 1.1 (ISO/IEC DIS 18974) conformant program. This standard defines the key requirements of a quality open source security assurance program, and helps to both reduce errors and increase efficiency across the global supply chain. This builds on their previous adoption of ISO/IEC 5230, the International Standard for open source license compliance.

“LG Electronics has a long history in open source and a well-known open source office,” says Shane Coughlan, OpenChain General Manager. “Their governance contributions like the FOSSLight tooling to help other companies has been an inspiration in South Korea and beyond. The conformance announcement today comes from the LG Cybersecurity Governance Team and underscores a company-wide commitment to excellence. As LG joins BlackBerry and Interneuron in driving the future of open source security assurance, we both welcome this announcement, and look forward to close collaboration in the future.”

Adoption of ISO/IEC DIS 18974 was driven by the LG Cybersecurity Governance Team. They are responsible for:

  • Establishing LG’s software development process (LG-SDL: Secure Development Lifecycle) to develop secure software for all LG Electronics products
  • Reflecting the latest Global Standards (ETSI, ENISA, NIST, etc.) and adapting them for the LG development ecosystem
  • Operating LG VulDOC (Vulnerability Detection Of Code) DevSecOps to Identify and resolve potential security vulnerabilities through various software verification methods 
  • Managing the LG Product Security Response Team (PSRT) to minimize security damage to our customers through authentic communication with security registrants and external stakeholders
  • Managing Third-Party developed software supply chain risk management

About LG Electronics

LG Electronics is a global innovator in technology and consumer electronics with a presence in almost every country and an international workforce of more than 74,000. LG’s four companies – Home Appliance & Air Solution, Home Entertainment, Vehicle component Solutions and Business Solutions – combined for global revenue of over KRW 80 trillion in 2022. LG is a leading manufacturer of consumer and commercial products ranging from TVs, home appliances, air solutions, monitors, service robots, automotive components and its premium LG SIGNATURE and intelligent LG ThinQ brands are familiar names world over.

About the OpenChain Project

The OpenChain Project maintains the International Standard for open source license compliance and the de-facto standard for open source security assurance. These allow companies of all sizes and in all sectors to adopt the key requirements of quality open source compliance or security assurance programs. They are open standards. All parties are welcome to engage with our community, to share their knowledge, and to contribute to the future of our standards.

About The Linux Foundation

The Linux Foundation is the organization of choice for the world’s top developers and companies to build ecosystems that accelerate open technology development and industry adoption. Together with the worldwide open source community, it is solving the hardest technology problems by creating the largest shared technology investment in history. Founded in 2000, The Linux Foundation today provides tools, training and events to scale any open source project, which together deliver an economic impact not achievable by any one company. More information can be found at www.linuxfoundation.org.

The Linux Foundation has registered trademarks and uses trademarks. For a list of trademarks of The Linux Foundation, please see our trademark usage page: https://www.linuxfoundation.org/trademark-usage.

Linux is a registered trademark of Linus Torvalds.

ByteDance Announces OpenChain ISO/IEC 5230 Conformant Program

By Featured, News

ByteDance, a leading social media company, and the innovator behind TikTok, has announced an OpenChain ISO/IEC 5230 conformant program. Their adoption of the international standard for open source license compliance underlines their commitment to engagement and excellence around open source projects, platforms and solutions.

“We are delighted to welcome ByteDance to the OpenChain ISO/IEC 5230 community of conformance,” says Shane Coughlan, OpenChain General Manager. “Their team has created social networks with stunning speed of scaling in Douyin (抖音) and TikTok. This innovation has been powered by open source, and their work around building an Open Source Program Office (OSPO), communicating their work, and now using international standards speaks to a bright future. We are looking forward to next steps in our collaboration.”

Read Their Full Announcement In Simplified Chinese

ByteDance Website

About ByteDance

ByteDance was founded in 2012 by a team led by Yiming Zhang and Rubo Liang, who saw opportunities in the then-nascent mobile internet market, and aspired to build platforms that could enrich people’s lives. The company launched Toutiao, one of its flagship products, in August 2012. It followed that success with the launch of Douyin in September 2016. Approximately a year later, ByteDance accelerated globalization with the launch of its global short video product, TikTok. It quickly took off in markets like Southeast Asia, signaling a new opportunity for the company. ByteDance acquired Musical.ly in November 2017 and subsequently merged it with TikTok. Today, the TikTok platform, which is available outside of China, has become the leading destination for short-form mobile videos worldwide.

In support of its mission to Inspire Creativity and Enrich Life, ByteDance has made it easy and fun for people to connect with, create and consume content. People are also able to discover and transact with a suite of more than a dozen products and services such as TikTok, CapCut, TikTok Shop, Lark, Pico and Mobile Legends: Bang Bang, as well as products and services specific to the China market, including Toutiao, Douyin, Fanqie, Xigua, Feishu and Douyin E-commerce.

ByteDance has over 150,000 employees based out of nearly 120 cities globally, including Austin, Barcelona, Beijing, Berlin, Dubai, Dublin, Hong Kong, Jakarta, London, Los Angeles, New York, Paris, Seattle, Seoul, Shanghai, Shenzhen, Singapore, and Tokyo.

About the OpenChain Project

The OpenChain Project maintains the International Standard for open source license compliance and the de-facto standard for open source security assurance. These allow companies of all sizes and in all sectors to adopt the key requirements of quality open source compliance or security assurance programs. They are open standards. All parties are welcome to engage with our community, to share their knowledge, and to contribute to the future of our standards.

About The Linux Foundation

The Linux Foundation is the organization of choice for the world’s top developers and companies to build ecosystems that accelerate open technology development and industry adoption. Together with the worldwide open source community, it is solving the hardest technology problems by creating the largest shared technology investment in history. Founded in 2000, The Linux Foundation today provides tools, training and events to scale any open source project, which together deliver an economic impact not achievable by any one company. More information can be found at www.linuxfoundation.org.

The Linux Foundation has registered trademarks and uses trademarks. For a list of trademarks of The Linux Foundation, please see our trademark usage page: https://www.linuxfoundation.org/trademark-usage.

Linux is a registered trademark of Linus Torvalds.

OpenChain Education Work Group – 2023-04-13

By News

We had a really busy and productive OpenChain Education Work Group call last week. The focus was on our Wikipedia page and on a new, smart and easy way to recreate flowcharts and other material in MarkDown.

Wikipedia Page (changes recorded):

MarkDown:

Video

Slides

GPLv2 Compliance Flowcharts Updated

By News

The OpenChain Project GPLv2 Compliance Flowcharts have been updated. Originally published in the book Practical GPL Compliance, these flowcharts are intended to help address some common compliance workflows. Thanks to Jacob Wilson, they have been moved into MarkDown format, and can now be easily added to websites, elearning platforms and more.

Example: Flowchart #0 – How Do I Distribute

You can access and download these flowcharts in our Reference Library. Like the rest of our material, they are released under CC-0 licensing.

Get The Flowcharts Now

The Tool We Used

These flowcharts were created using the Mermaid Live Editor.

Monthly Meeting North America and Europe 2023-04-04

By News

This time around we focused on editing the OpenChain license compliance specification. This is the potential future update of ISO/IEC 5230. Helio lead the discussion with support from Chris as co-chairs.

We covered two issues during the call:

Check out the full recording and our slides below. On the next call (3rd Tuesday, North America and Asia) we will cover some of the open issues around the potential future update of the OpenChain security specification (ISO/IEC DIS 18974).

Telco Work Group – Morning and Afternoon – 2023-04-06

By News

Summary of Meetings from the Chair (Marc-Etienne)

Meeting 2023-04-06 morning

Attendees:

  • Stephen Kilbane, Analog Devices Inc.
  • Nikola Babadzhanov, Bosch
  • Anton Bashlykov, MBition
  • Marc-Etienne Vargenau, Nokia

We reviewed the pull requests and merged them:

  • added the definition of “SBOM Type” from CISA and used it in section 3.7 “SBOM Build information”
  • updated section “3.13 SBOM Verification”, added recommendation to provide a digital signature of the SBOM
  • updated section 3.5.2, added rationale for the tag:value format, indicating it is the most human-readable format
  • updated several “Verification and reference material” and “Rationale” sections
  • added “5. References” section, providing references for SPDX, OpenChain and “NTIA minimum elements”

Meeting 2023-04-06 afternoon

Attendees:

  • Alfred Strauch, SmartTalk Security Inc.
  • Chris
  • Marc-Etienne Vargenau, Nokia

We review the pull requests that were merged in the morning meeting.

Alfred points out the use case of a software that has its name changed and asks how this should be handled.

Alfred suggests that I join the SBOM Forum. He will introduce me to Tom Alrich. The forum groups several companies including Red Hat, Oracle, Microsoft and companies producing medical devices. One of the creators of CycloneDX is a member.

Outcome

The draft document is now complete. Please review it and share you comments and suggestions in the mailing list or on GitHub by creating issues or pull requests.

Morning Meeting Recording

Afternoon Meeting Recording

SAIC Z-ONE has adopted the ISO/IEC 5230 standard

By Featured, News

As a subsidiary of SAIC Group, SAIC Z-ONE Technology Co., Ltd always adheres to the research and development of smart car technology, provides customers with trustworthy and competitive solutions, products and services with an open and flexible cooperation model, and provides full life-cycle operation and maintenance upgrade services to empower customers to quickly build smart cars with differentiation capability, full-scene and ultimate experience.

SAIC is the leading automotive company in China in terms of scale, and as of 2022, SAIC has been the No. 1 in China in vehicle sales for 17 consecutive years.

Achieving ISO/IEC 5230 certification will help ensure that SAIC Z-ONE has a high-quality open source compliance program and requirements in place to effectively and efficiently use open source software in its supply chain and to align with high-quality global open source license compliance management practices.

“The announcement by SAIC Z-ONE provides an exceptional example of the evolving automotive industry,” says Shane Coughlan, OpenChain General Manager. “Cars are key outcomes of the software supply chain, and global leaders like SAIC have a clear, strategic vision for the future. Their engagement and their experience will help drive an improved ecosystem for the benefit of customers around the world.”

OpenChain Mini-Summit at OSS North America – 2023-05-09 @ 14:30 PDT

By News

The OpenChain Project will host an afternoon mini-summit with a focus on:

  • How OpenChain process standards support business optimization and sustainability. 
  • Open source tooling for open source compliance
  • Open source tooling for security assurance
  • Software Bill of Materials

Expect a packed session with plenty of networking opportunities. This event will help OSPO, IP, product development and management teams deal with trust management in the open source supply chain.

Agenda

  • 14:30 – Introduction: The OpenChain License Compliance and Security Assurance Standards in 2023
  • 14:50 – Keynote: Moving Down The Pyramid – SBOMs in 2023; Speaker TBD
  • 15:10 – Break
  • 15:20 – Keynote: Moving Down The Pyramid – “State of the Tooling” in Open Source Automation; Helio Chissini de Castro, CARIAD
  • 15:40 – Special Keynote: FOSSLight – Next Generation Open Source Automation for Compliance and Security; Kyoungae Kim and Soim Kim, LG Electronics
  • 16:00 – Break
  • 16:10 – Roundtable Session – Process Standards
  • 16:25 – Roundtable Session – SBOMs
  • 16:45 – Roundtable Session – Automation
  • 17:00 – Close

How to Register: Pre-registration is required. To register for the OpenChain Project Mini Summit, add it to your Open Source Summit North America registration.

Learn More