Skip to main content
Category

News

External Event Coming Soon: The Path to a Sustainable Software Supply Chain

By Featured, News

Shane Coughlan, OpenChain General Manager, will take the lead in a FOSSA webinar on the 16th of March.

From their site:

Software supply chain security has dominated the headlines in recent months following a series of events (including the SolarWinds hack and the Biden Administration’s executive order). But maintaining the integrity of your software supply chain is about more than just traditional vulnerability remediation. Our modern threat landscape has elevated the importance of supply chain sustainability, which includes areas like software provenance and lifecycle management in addition to known vulnerability mitigation.

Join Shane Coughlan, GM of OpenChain (a Linux Foundation project) for a conversation on the importance of supply chain sustainability and practical steps your organization can take to strengthen supply chain integrity.

We’ll discuss:

  • The evolution of software supply chain threats
  • The importance of software provenance, such as package origin, maintainers, and quality
  • Questions to ask vendors to gauge the sustainability of proprietary software
  • Indicators of sustainable open source software

Register here:

Webinar: The Mulan License

By community, Featured, legal, licensing, News, Webinar

This webinar unpacked the Mulan license family, an emerging activity from China with implications regarding the governance of open source as it expands around the world. Providing licenses designed in non-English languages is a topic that will be increasingly important, and is something companies will benefit from being aware of.

Check Out The Rest Of Our Webinars

This is OpenChain Webinar #37, released on 2022-02-23.

OpenChain Security Summit 2022 – Recording

By Featured, News

Learn About OpenSSF In The Current Landscape From Brian Behlendorf, General Manager Open Source Security Foundation

OpenSSF is committed to collaboration and working both upstream and with existing communities to advance open source security for all.

Learn About SPDX In The Current Landscape From Kate Stewart, VP, Dependable Embedded Systems At The Linux Foundation

SPDX is an open standard for communicating software bill of material information, including provenance, license, security, and other related information.

And Learn More About Industry Responses To Log4J With A Practical Case Study About How Things Unfolded “On The Ground”

You can expect to come away with a clear understanding of market conditions, how the Linux Foundation is addressing them, and where OpenChain fits into the picture. The goal – as always – is to ensure you have the information necessary to make informed, effective decisions around the open source supply chain.

We seek to build trust in the quality of programs used by you, your customers and your suppliers. We are proud to have taken significant strides in our field throughout 2021. We expect to push the boundaries of what is possible once again in 2022. You can learn more about what we are doing around security – including our reference assurance guide – here:

We are turning this into a Reference Security Specification via our bi-weekly global work team calls. You can via the current draft on GitHub and open issues here: 

Open Source Policy Template – Now in Japanese

By Featured, News

The OpenChain Open Source Policy Template helps apply the key requirements for a quality open source compliance program. It provides sample policy text that helps organisations select, classify, incorporate and publish open source code with a focus on legal compliance of open source.

This template has been available in English for several years thanks to the hard work of Andrew Katz, the teams at Moorcrofts and Orcro, and the broader OpenChain community. Now, thanks to Masahiko Hayashi and the team at NEC, this policy template is available in Japanese.

This is an excellent resource to help you conform to OpenChain ISO/IEC 5230:2020 or to simply improve your internal process management for open source.

Download the Japanese version here:

Download the English version here:

Contribute to this work on GitHub:

OpenChain Event In Beijing: CAICT Hosts 37 Companies

By News

The China Academy of Information and Communications Technology (CAICT) hosted an OpenChain event today at their HQ in Beijing. Thirty-seven representatives from various companies attended in-person. As the world opens, the OpenChain community hopes to hold similar events across Asia, Europe and North America.

This event highlighted the recent Third-Party Certification by General Data Technology Co., Ltd., CETC Kingbase and PingCap while providing attendees with extensive information on OpenChain ISO/IEC 5230, conformance options, and support for conformance in the Chinese market.

The event featured an introduction by Shane Coughlan, OpenChain General Manager, before switching fully into Mandarin and providing attendees with a chance to discuss matters in a frank, open and productive manner.

We would invite all interested parties to take part in the OpenChain China activities. Everyone is invited. We keep the discussion informal, focused and helpful.

You can learn more about the work CAICT is doing around OpenChain through a recent news item in English and Chinese:

HONOR Joins The Governing Board Of The OpenChain Project

By Featured, News

HONOR, a leading global provider of smart devices, officially joined the OpenChain Project as a Platinum Member. HONOR will continue to devote efforts to help maintain OpenChain ISO/IEC 5230, the International Standard for open source license compliance.

中文版: 荣耀加入 OpenChain项目理事会 

“HONOR is delighted to join the OpenChain Project. HONOR has consistently taken compliance management as the basis of business process. HONOR adheres to the principle of open innovation to provide high quality smart devices that exceeds the expectations of customers around the world,” said Samuel Deng, President of Research & Development Mgmt Dept, HONOR Device Co., Ltd. “HONOR will actively participate in the OpenChain project to work with global partners to build a more secure and efficient open source software management system. ”

“HONOR will playing an essential role in the OpenChain Project in 2022 and beyond,” says Shane Coughlan, OpenChain General Manager. “Chloe and the rest of the team will be providing strategic guidance on our governing board, building on their existing engagement across our global community. Our shared mission is to build greater trust in the supply chain, and this represents another significant milestone in our ability to execute effectively.”

About HONOR

HONOR is a leading global provider of smart devices. It is dedicated to becoming a global iconic technology brand and creating a new intelligent world for everyone through its powerful products and services. With an unwavering focus on R&D, it is committed to developing technology that empowers people around the globe to go beyond, giving them the freedom to achieve and do more. Offering a range of high-quality smartphones, tablets, laptops and wearables to suit every budget, HONOR’s portfolio of innovative, premium and reliable products enable people to become a better version of themselves.

For more information, please visit HONOR online at www.hihonor.com.
https://community.hihonor.com/
https://www.facebook.com/honorglobal/
https://twitter.com/Honorglobal
https://www.instagram.com/honorglobal/
https://www.youtube.com/c/HonorOfficial

About the OpenChain Project

The OpenChain Project maintains the International Standard for open source license compliance. This allows companies of all sizes and in all sectors to adopt the key requirements of a quality open source compliance program. This is an open standard and all parties are welcome to engage with our community, to share their knowledge, and to contribute to the future of our standard.

About The Linux Foundation

The Linux Foundation is the organization of choice for the world’s top developers and companies to build ecosystems that accelerate open technology development and industry adoption. Together with the worldwide open source community, it is solving the hardest technology problems by creating the largest shared technology investment in history. Founded in 2000, The Linux Foundation today provides tools, training and events to scale any open source project, which together deliver an economic impact not achievable by any one company. More information can be found at www.linuxfoundation.org.

The Linux Foundation has registered trademarks and uses trademarks. For a list of trademarks of The Linux Foundation, please see our trademark usage page: https://www.linuxfoundation.org/trademark-usage.

Linux is a registered trademark of Linus Torvalds.

荣耀加入 OpenChain项目理事会

By News

荣耀,全球领先的智能终端提供商,正式加入OpenChain项目理事会。荣耀将持续努力,共同维护开源许可证合规领域的国际标准,OpenChain ISO/IEC 5230。

“荣耀很高兴加入OpenChain项目。一直以来,荣耀将合规管理作为业务流程的基础,始终坚持开放创新的理念,打造超越消费者期待的高品质智能设备。” 荣耀终端有限公司研发管理部总裁邓斌表示:“荣耀将积极参与OpenChain项目,与全球合作伙伴一起建立更为安全高效的开源软件管理体系。”

“荣耀在2022年及以后将在OpenChain项目中扮演重要角色”,OpenChain的总经理Shane Coughlan说到:“荣耀的开源团队将基于在全球社区的现有合作,为我们的理事会提供战略指导。我们的共同使命是在供应链中进一步增强信任,这也将是我们执行力建设的另一个重要的里程碑。”

关于荣耀
HONOR荣耀,于2013年诞生,是全球领先的智能终端提供商。我们致力于成为构建全场景、 面向全渠道、服务全人群的全球标志性科技品牌,荣耀以创新、品质和服务作为三大战略控制点,坚持研发及前瞻性技术的持续投入,为全球消费者带来不断创新的智能设备, 创造属于每个人的智慧新世界。