Skip to main content
Category

News

BlackBerry Announces First North American OpenChain Security Assurance Specification Conformance

By Featured, News

BlackBerry Limited (NYSE: BB; TSX: BB) announces adoption of the OpenChain Security Assurance Specification 1.1, creating a series of landmarks in doing so. BlackBerry is the first whole entity to announce conformance, the first conformance in the Americas, the first multinational company conformance, and first entity to achieve conformance with both OpenChain/ISO5230:2020 and OpenChain Security Assurance 1.1 with an OpenChain Partner, OSS Consultants. This announcement builds on their previous adoption of OpenChain ISO/IEC 5230:2020, the international standard for open source license compliance. OpenChain Security Assurance Specification 1.1 is the sister standard to ISO/IEC 5230, and is also slated to become an ISO standard later in 2023.

OpenChain has a collaborative global community of companies working to build a more effective and efficient supply chain to create trust between entities around open source; working to increase trust in the open source supply chain. With thousands of people from hundreds of companies actively involved, it is a key part of the governance fabric behind open source technology. BlackBerry is the first company in North America to gain company-wide OpenChain Security Assurance conformance, and the first to collaborate with an official OpenChain Partner Company, OSS Consultants.

“BlackBerry has long been synonymous with excellence in process management, and their engagement with OpenChain standards underlines this,” says Shane Coughlan, OpenChain General Manager. “Their previous whole-entity adoption of ISO/IEC 5230, the international standard for open source license compliance, set an important market example. Their market-leadership is continued today with the world’s first whole entity adoption of the OpenChain Security Assurance Specification, the industry standard for open source security assurance. We look forward to working closely together in continuing to drive sustainable, efficient software supply chains.”

“BlackBerry has one of the deepest commitments in this industry to bringing increased peace of mind to enterprise and governmental organizations,” said Russ Eling, CEO OSS Consultants. “This added certification highlights BlackBerry’s position as a trusted supply chain vendor and serves as an example for others to follow. BlackBerry was able to meet the specification through its existing policies and processes due to its long history and commitments to responsible management of open source. BlackBerry has a team of experts who have developed their practices, tooling, and operational capability to manage the vulnerabilities that arise within open source libraries.”

About BlackBerry

BlackBerry (NYSE: BB; TSX: BB) provides intelligent security software and services to enterprises and governments around the world. The company secures more than 500M endpoints including 215M vehicles. Based in Waterloo, Ontario, the company leverages AI and machine learning to deliver innovative solutions in the areas of cybersecurity, safety and data privacy solutions, and is a leader in the areas of endpoint security, endpoint management, encryption, and embedded systems.  BlackBerry’s vision is clear — to secure a connected future you can trust.

BlackBerry. Intelligent Security. Everywhere. 
For more information, visit BlackBerry.com and follow @BlackBerry.  

Trademarks, including but not limited to BLACKBERRY, EMBLEM Design and QNX are the trademarks or registered trademarks of BlackBerry Limited, its subsidiaries and/or affiliates, used under license, and the exclusive rights to such trademarks are expressly reserved.

About OSS Consultants:

OSS Consultants is a business dedicated to helping organizations of all sizes – from the world’s largest and well-known companies to small businesses and start-ups – design, implement, and manage the most efficient, comprehensive and robust open-source program offices and policies on the planet. Service offerings range from a scan and audit of your third-party and proprietary software to creating a full OSPO within your organization. Find more information at www.ossconsultants.com.

About the OpenChain Project

The OpenChain Project maintains the International Standard for open source license compliance. This allows companies of all sizes and in all sectors to adopt the key requirements of a quality open source compliance program. This is an open standard and all parties are welcome to engage with our community, to share their knowledge, and to contribute to the future of our standard.

About The Linux Foundation

The Linux Foundation is the organization of choice for the world’s top developers and companies to build ecosystems that accelerate open technology development and industry adoption. Together with the worldwide open source community, it is solving the hardest technology problems by creating the largest shared technology investment in history. Founded in 2000, The Linux Foundation today provides tools, training and events to scale any open source project, which together deliver an economic impact not achievable by any one company. More information can be found at www.linuxfoundation.org.

The Linux Foundation has registered trademarks and uses trademarks. For a list of trademarks of The Linux Foundation, please see our trademark usage page: https://www.linuxfoundation.org/trademark-usage.

Linux is a registered trademark of Linus Torvalds.

###

Media Contact:

OSS Consultants Media Relations
info@ossconsultants.com

Special Event: 2022 年 / 2023 年の OSS ライセンスコンプライアンス 日本と海外の最新事情 – 2023 年 2 月 2 日(木) 10:00~14:00

By News

OSS ライセンス監査ツールの FossID と OSS ライセンスコンプライアンスの ISO 標準 を推進している OpenChain が共同セミナーを開催します。このセミナーでは、OSS ラ イセンスに関する 2022 年のレビュー、2023 年の動向を通して、OSS プログラムマネ ジャー、知財エキスパート、マネジメント層のお役に立てる事を目的とします。

Oskar and Jon will be visiting Japan with other people from the newly independent FOSSID to help provide a market overview. The meeting takes place on the 2nd of February between 10:00 and 14:00 in Shinagawa. Of course I will be there with an OpenChain talk.

This will be a market strategy event, focused on getting knowledge from abroad because our travel is limited. It is also suitable for business managers and decision-makers or legal people. 

日時:

2023 年 2 月 2 日(木) 10:00~14:00

場所:

TKP 品川カンファレンスセンターANNEX カンファレンスルーム 4 東京都港区高輪3丁目13−1 高輪コート 3 階
http://www.kashikaigishitsu.net/facilitys/cc-shinagawa-annex/access/

お申し込み方法

参加される方の情報を 1 月 25 日までに E メールでお送りください。 会社・部署:
お名前・メールアドレス
ランチのご希望: はい / いいえ

送り先:

shoken.kim@fossid.com

OpenChain Monthly North America / Asia Meeting 2023-01-17 – Recording

By Featured, News

Our regular monthly call for North America / Asia saw some discussion around two key topics for the next generations of our specifications for license compliance and for security. One related to whether we need to be more prescriptive regarding the content of contribution policies, and another related to whether our existing approach to defining open source worked in both standards. The outcomes are covered in our recording and the slides from the meeting are also available.

OpenChain Automation Case Study #7 – VulnerableCode technical deep dive into VulnTotal

By Featured, News

Philippe Ombredanne from nexB will lead a technical deep dive into VulnTotal on the 7th of February at 09:00 CET (08:00 UTC). Join us in our usual room here:

This deep dive is about an aspect of the AboutCode Project, with VulnerableCode providing tools to collect, aggregate and refine software vulnerability information from more than 20 sources and tools to quickly create new “importers”. VulnTotal is something that came out of Google Summer of Code 2022:

VulnTotal: Cross-validate vulnerability coverage of VulnerableCode (Keshav Priyadarshi)

VulnerableCode is a unique project that collates and cross-references FOSS vulnerability data from multiple sources. Inspired by the VirusTotal multi-scanner virus scanning service, the VulnTotal project will cross-validate the vulnerability coverage of VulnerableCode against other publicly available vulnerability check tools and databases. For instance, a package may be reported as vulnerable by one tool or database but not by another. We can gradually work with these tool providers to keep each other apprised about newly discovered vulnerabilities, making FOSS more secure.

Bitsea Announces OpenChain Security Assurance Services

By Featured, News

Bitsea, a service provider specialized in software auditing and based in Germany, today announces support for the OpenChain Security Assurance Specification 1.1. They can help companies understand and adopt this standard for open source security in Germany and beyond. As a sister standard to OpenChain ISO/IEC 5230 – the international standard for open source license compliance – the OpenChain Security Assurance Specification 1.1 offers the same type of support for building a quality security assurance program.

“For over 10 years Bitsea has provided services to help organizations identifying hidden risks in software systems and managing their open source software supply chain,” says Dr. Andreas Kotulla, Founder and CEO of Bitsea. “Our services guide organizations to adopt and conform to both ISO 5230 OpenChain and OpenChain Security Assurance.”

“Bitsea has long been a provider of excellent reputation in the open source area,” says Shane Coughlan, OpenChain General Manager. “Their new services to support adoption of the OpenChain Security Assurance Specification 1.1 are a timely and useful contribution to the community in Germany and beyond. Open source security is a vital part of the global supply chain, and solid process management is key to addressing the ongoing challenges.”

About Bitsea

Big software systems are like a wild wide ocean of bits – our passion is to analyse and visualize software structure. We are keen to help our customers how to stabilize and optimize their systems. We assess software. We analyze, evaluate and optimize your development processes, software architecture and software design. We perform the technical due diligence for company takeovers. We reduce the economic risk by assessing open source components and ensure license compliance.

Our references include well-known Fortune 500 companies in communications, automotive, logistics, retail and aerospace industries. Highest standard for information security: We are VDA/ISA Tisax-certified since 2020. All data of our customers remain in Germany or, if required, in the territory of our customers. We are involved in the Bitkom Open Source working group. Bitsea is part of the OpenChain Community. We guarantee strictly confidential consulting in the context of technical due diligence for M&A activities. 

Learn more:
https://bitsea.de/en/

About the OpenChain Project

The OpenChain Project has an extensive global community that involves thousands of companies collaborating to make the supply chain quicker, more effective and more efficient. We work together to create trust between entities around open source. Our job is to increase trust in the open source supply chain. We do this by maintaining ISO/IEC 5230:2020, the International Standard for open source license compliance, and our Security Assurance Reference Specification. We also have a large global community where knowledge is shared to reduce friction and increase efficiency across all aspects of open source process management.

Learn more:
https://www.openchainproject.org

About The Linux Foundation

The Linux Foundation is the world’s largest non-profit connecting global technical experts, and providing them with a neutral and trusted platform to develop open source projects. Founded in 2000 as the home of the Linux Kernel, the Linux Foundation has grown to host hundreds of open source projects, with a community spanning 2,950+ members, 540,000+ contributing developers, and 19,000+ contributing companies.

Learn more:
https://www.linuxfoundation.org

EXTERNAL EVENT: FOSDEM 2023 Fringe event – FOSS license and security compliance tools developers and users workshop – Bruxelles 2023-02-03

By News

AboutCode is holding a one day workshop for open source compliance tooling developers and users on the fringe of FOSDEM 2023. You probably know Philippe Ombredanne from ScanCode, who is a key driver behind this. It takes place Friday, February 3, 2023, 9:00 AM – 5:00 PM (UTC+01:00).

Event structure as per their website:

Which tools is this about? FOSS tools for software provenance detection tools, license detection and compliance tools, code scanning tools, package dependency analysis tools, container analysis tools, SBOM creation and consumption tools, and license or vulnerability databases

Basically all the tools you need to figure out which FOSS code you use, where it is from, what is its license, how to comply with the license, and whether it contains vulnerable code. We organized this workshop last in 2020 (pre-COVID) and there were developers from the ORT, ScanCode, ClearlyDefined, FOSSology, Tern, VulnerableCode, SW360, DoubleOpen and OpenChain projects, and users from the finest organizations, technology and industrial companies worldwide. Whether you are a developer or user interested in the Software Supply Chain and SBOMs, a FOSS license-savvy lawyer, a compliance or security analyst, or an OSPO member: you will be warmly welcomed.

The day will be split in two:

• In the morning, the focus is on tool developers: they will announce and share their plans and we will discuss opportunities for collaboration, sharing and joint projects.    

• In the afternoon, the focus is on tool users: they will share their concerns, problems and requirements and we will discuss opportunities for collaboration and address these in the represented projects.    

Learn more:

https://opencollective.com/aboutcode/events/fosdem-2023-fringe-event-foss-license-and-security-compliance-tools-developers-and-users-workshop-bruxelles-2023-02-03-159433c1