Skip to main content
Category

News

OpenChain Monthly Meeting North America – Europe – 2023-02-07 – Recording

By Featured, News

We had a fantastic meeting focused on editing previously submitted scope suggestions from ISO/IEC WG/SC 27 (Information Technology Security). This time we went over issues submitted by reviewer CERT. In addition to this, we closed an open issue syncing the definition of Open Source between the licensing (ISO 5230) and security specifications.

Co-chairs Helio and Chris lead the discussion, and we had some great contributions from the audience. It is clear that there is significant interest in reviewing the draft 3rd generation licensing standard and 2nd generation security standard. You are reminded that everyone is invited to participate on the monthly calls and via our main or specification mailing lists.

Specifically..

We closed this open source definition issue:
https://github.com/OpenChain-Project/Security-Assurance-Specification/issues/20

We set this action item based on a suggestion by CERT:
https://github.com/OpenChain-Project/Security-Assurance-Specification/issues/22

We decided not to pursue this suggestion by CERT:
https://github.com/OpenChain-Project/Security-Assurance-Specification/issues/23

We decided not to pursue this suggestion by CERT:
https://github.com/OpenChain-Project/Security-Assurance-Specification/issues/24

Watch The Recording

Check Out Our Meeting Slides

Join Our Specification Mailing List

See When Our Next Monthly Calls Take Place

OpenChain Japan Work Group Meeting #26 (Hybrid #1) – 2023-02-09 15:00-17:00 JST

By Featured, News

The first face-to-face OpenChain Japan Work Group meeting in three years is being hosted by Hitachi Solutions and will feature our usual exceptional schedule of case studies and discussion. Big thank you to Ayumi and team for providing a great place to bring the community together. Virtual attendees are also being supported via Zoom.

OpenChain Japan Work Group【第26回全体会合】【第1回ハイブリッド会合】
 ★2023年2月9日(木)15:00-17:00 JST
 ★ハイブリッド形式(リアル会場+オンライン参加)
 ★リアル会場:日立大森ビル
 ★オンライン会場:
   https://zoom.us/j/4377592799
 ★東芝さんの事例紹介2件と日立ソリューションズさんのOSSツール紹介1件を企画しています。
アジェンダ:
15:00 – 15:01  Opening
15:01 – 15:10  Keynote by Shane Coughlan
15:10 – 15:20  OpenChain Japan WGについて
15:20 – 15:30  日立ソリューションズのOSSへの取り組み 渡邊 
15:30 – 15:45  OSS紹介:「SPDX用拡張機能 on VSCode」明石(日立ソリューションズ)
15:45 – 15:55  休憩
15:55 – 16:25  事例紹介:「オープンソースコンプライアンスのためのプロセスマネジメント標準ISO/IEC 5230の適合に向けて」忍頂寺、樽家(東芝)
16:25 – 16:55  事例紹介:「OSSライセンスコンプライアンスを遵守するためのOSS教育の整備と全社展開」小山(東芝)
16:55 Closing

TIMETOACT GROUP Offers Open Source Certification Based On ISO/IEC 5230

By Featured, News

IT company deepens partnership with OpenChain Project and expands open source software offering.

TIMETOACT GROUP is now an official third-party certifier for the ISO/IEC 5230 standard managed by OpenChain, enabling it to offer official certifications in addition to consulting services on open source license compliance. With the deepening of the partnership between OpenChain and TIMETOACT, customers have even more choice around services available for open source software.

The use of open source software – just like proprietary software – is based on various license terms. It is important to maintain these requirements in order to ensure smooth business operations and avoid conflicts with third parties. The OpenChain ISO/IEC 5230 international standard aims to identify the key requirements for a high-quality open source license compliance program. It enables companies to reduce their risk potential by adapting the standard through self-certification, independent assessment or third-party certification such as TIMETOACT GROUP. Within TIMETOACT GROUP, ARS software engineering specialists provide the certifications.

“We are happy to join OpenChain’s certifier network, thus providing companies of all sizes and industries with the critical components for successful open source compliance programs. This partnership grants our customers added value through the opportunity to obtain the OpenChain ISO/IEC 5230 certification seal,“ says Simon Pletschacher, Manager IT Performance Strategy at TIMETOACT GROUP.

“We are delighted to welcome TIMETOACT GROUP to our comprehensive network of certifiers, allowing us to provide companies of all sizes and industries with easy access to the essential components of superior open source compliance programs,“ says Shane Coughlan, General Manager OpenChain.

About TIMETOACT GROUP

TIMETOACT GROUP modernizes and integrates IT applications for upper mid-sized companies and corporations in order to increase their agility, efficiency and transparency. For innovative customers, TIMETOACT GROUP also develops and implements digital business models and opens up new market opportunities.

Services include: Consulting, Cloud Transformation, Data, Software and Systems Engineering in the area of Employee Experience, Business Applications and Customer Experience.

For more information see www.timetoact-group.com/en or www.timetoact-group.com/en/details/open-source-license-management 

About OpenChain

The OpenChain Project has an extensive global community that involves thousands of companies collaborating to make the supply chain quicker, more effective and more efficient. We do this by maintaining ISO/IEC 5230:2020, the International Standard for open source license compliance, and our Security Assurance Reference Specification. We also have a large global community where knowledge is shared to reduce friction and increase efficiency across all aspects of open source process management.

About The Linux Foundation

The Linux Foundation is the organization of choice for the world’s top developers and companies to build ecosystems that accelerate open technology development and industry adoption. Together with the worldwide open source community, it is solving the hardest technology problems by creating the largest shared technology investment in history. Founded in 2000, The Linux Foundation today provides tools, training and events to scale any open source project, which together deliver an economic impact not achievable by any one company. More information can be found at www.linuxfoundation.org

The Linux Foundation has registered trademarks and uses trademarks. For a list of trademarks of The Linux Foundation, please see our trademark usage page: https://www.linuxfoundation.org/trademark-usage

Linux is a registered trademark of Linus Torvalds.

Press contact TIMETOACT GROUP:

Christin Louise Weber

christin.weber@timetoact.de

OSPOCO and Taylor English Join The OpenChain Partner Program

By Featured, News

OSPOCO and Taylor English are the latest participants in the OpenChain Project official partner program. OSPOCO provides on-demand, scalable open source program office support across community, technical and communication areas. Taylor English provides attorney oversight for all compliance matters and legal advice integrated with OSPOCO technical findings.

“We are delighted to work with OSPOCO on expanding the professional service ecosystem dedicated to OpenChain ISO/IEC 5230 and the OpenChain Security Assurance Specification,” says Shane Coughlan, OpenChain General Manager. “The increased awareness of predictable, sustainable open source process management in the supply chain is matched by an increased need for experienced providers. We look forward to investing time into ensuring growth in the North American market throughout 2023 matches the traction we have seen in Asia and Europe in 2022.”

“Following the OpenChain specifications is the best way for companies to understand and have control over their open source processes,” says Van Lindberg, CEO of OSPOCO and partner at Taylor English. “The OpenChain specifications are our blueprint for helping our clients mitigate supply chain risk and improve their open source ROI. We look forward to helping many more organizations achieve and maintain full compliance.”

OpenChain Telco Special Interest Group – 2023-02-02 – Recording

By News

In the February 2nd 2023 call, we reviewed the open pull requests on GitHub. All pull requests except one have been merged, with some modifications. The remaining pull request is about when the SBOM should be created. This needs further discussion. See section 3.7. Please review the current document and provide your comments.

Some topics that need review and input:

  • The list of mandatory elements in section 3.4
  • Section 3.7 SBOM Build information
  • Section 3.13 SBOM Verification
  • What level of detail do we mandate (package, file, snippet)?

Several “Verification and reference material” and “Rationale” sections are still empty.
The words “shall” and “should” are used. They must be defined.

Also, we need a good name for the specification. Currently in the document we have:

  • OpenChain Telecommunications Group SBOM Specification
  • OpenChain Telco SBOM specification
  • Telco Standard SBOM
  • telco standard SBOM
  • Telco Group SBOM specification
  • Telco SBOM specification
  • Telco Profile of SPDX

Best regards,
Marc-Etienne, Telco SIG Chair

Be Part Of This

OpenChain Newsletter #50

By Featured, Monthly Newsletter, News

Newsletter – Issue 50 – January 2023

After focusing on rolling news in 2022, the OpenChain Newsletter is back to provide a monthly summary of our work. You can expect an overview of what the OpenChain Project is doing to build trust around license compliance and security in the open source supply chain. You will also find other news directly related to our field. We accept suggestions and ideas. Just mail us at any time.

Cool Statistic To Start The Year

20% of German companies with over 2,000 employees have already implemented OpenChain ISO/IEC 5230:2020, the International Standard for open source license compliance.
Source: Bitkom Open Source Monitor 2021

Key Project Governance News

In Q4 2022 the OpenChain Project elected a new Governing Board Chair (Jimmy Ahlberg of Ericsson) as well as new co-chairs of the Specification Work Group (Helio Chissini de Castro, CARIAD + Chris Wood, Lockheed Martin) and a new chair of the Education Work Group (Nathan Kumagai, Qualcomm). This is all part of an initiative to ensure that the project has sustainable, clear and fair processes for leadership transition to ensure long-term sustainability.

Google Announces ISO/IEC 5230:2020 Conformant Program

We ended Q4 2022 with some exciting news. Google, an OpenChain Governing Board member and early adopter of the first generation OpenChain standard for open source license compliance, announced formal adoption of ISO/IEC 5230, the International Standard for open source license compliance.

Meanwhile, Around Security…

We have submitted the OpenChain Security Assurance Specification to the ISO/IEC JTC-1 PAS Transposition Process. We expect it to graduate as an ISO/IEC standard around mid-2023.

Security Assurance Specification Conformance

BlackBerry became the first multinational to go whole entity conformant with the OpenChain Security Assurance Specification. They also set a milestone as the first entity to achieve conformance with both OpenChain ISO5230:2020 and the OpenChain Security Assurance Specification 1.1.

That said, the very first company to announce adoption of the OpenChain Security Assurance Specification was Interneuron in the UK. This builds on their previous adoption of OpenChain ISO/IEC 5230:2020, and underlines their continued mission to seek excellence in open source software governance for the British National Health Service.

Security Assurance Specification Gains Additional Support

At the end of December 2022 we saw some significant announcements regarding support for the OpenChain Security Assurance Specification:

This support continued to grow in January 2023 with an announcement from Bitsea about their new services for customers around adoption.

OpenChain Meetings, Webinars And Events

Our monthly meetings kicked off with next generation specification reviews for North America / Europe and North American / Asia. We are seeing some solid discussion around the open issues on both the license compliance and security specifications. It is recommended to take part in these meetings if you have ideas, suggestions or comments about where you want our standards to go next.

We also held a Telco Special Interest Group meeting on the 12th of January and an Education Work Group meeting on the 19th of January. Telco are working on a meta specification about Software Bill of Materials. The Education Work Group is focused on renewal of core material to help people onboard with our standards. Everyone is welcome to join the calls and help out.

Want to join our calls? Just check out our global calendar.

The global calendar is also a great way to keep track of our webinars. We started the year with a great one: OpenChain Webinar #47 covered OSSelot: The Open Source Curation Database. OSSelot is a new project incubated by OSADL in Germany and promises to be an important part of automation tooling support moving forward.

Continuing our program of external collaboration, the OpenChain Project was also part of an external webinar about Applying OpenChain and SBOMs for InnerSource.

Our Training Material Continues To Support The Market

In 2021 and 2022 the OpenChain Education Work Group released online courses in collaboration with LF Training. During January we received some updates providing context for market impact.

Introduction to Open Source License Compliance Management (LFC193) has had 1,209 enrollments and 398 digital completion badges issued with a satisfaction rating of 4.65 out of 5. Implementing Open Source License Compliance Management (LFC194) has had 579 enrollments and 38 digital completion badges issued with a satisfaction rating of 4.55 out of 5. LFC194 has only been out a few months, so we look forward to continued adoption growth in 2023.

It is also noteworthy that Continental Corporation made LFC193 a required course for their software developers from late Q3 2022. This is a concrete example of a company leveraging free resources provided by OpenChain Project and The Linux Foundation to support their open source governance processes.

Check Out All Our Previous Newsletters:
https://www.openchainproject.org/newsletter

Quick Links

Legal: All trademarks belong to their respective owners. This newsletter is licensed under Creative Commons Attribution-NoDerivatives 4.0 International (CC BY-ND 4.0).

Webinar: OSSelot: The Open Source Curation Database

By automation, Featured, licensing, News, Webinar

This OpenChain Webinar features OSSelot, an open source curation database recently launched by OSADL in Germany. This project addresses one of the most requested features around open source automation for open source compliance: an open, public database supporting SBOM (via SPDX ISO/IEC 5962) for common software packages. This could be a game-changer.

Check Out The Project Website:

Check Out The Rest Of Our Webinars

This is OpenChain Webinar #47, released on 2023-01-25.