THE LINUX FOUNDATION PROJECTS
Category

Webinar

Webinar – Software Hash ID: you will not be able to live without it

By community, licensing, standards, Webinar

The Software Hash Identifier (SWHID) is an intrinsic identifier for software source code and artifacts that became an international standard in April 2025 (ISO/IEC 18670:2025).

In this talk, Thomas Aynaud presented the Software Heritage mission and data model, introduced the concept of intrinsic identifiers, explained the SWHID specification, and presented its open standard governance model. He shared how open source projects and companies can adopt and benefit from SWHID through real-world use cases, and concluded with a summary of the key advantages of SWHID and an update on Software Heritage’s plans to support its development and adoption in the coming months.

Watch the Webinar:

More About Our Webinars:

This event is part of the overarching OpenChain Project Webinar Series. Our series highlights knowledge from throughout the global OpenChain eco-system. Participants are discussing approaches, processes and activities from their experience, providing a free service to increase shared knowledge in the supply chain. Our goal, as always, is to increase trust and therefore efficiency. No registration or costs involved. This is user companies producing great informative content for their peers.

Check Out The Rest Of Our Webinars:

This OpenChain Webinar was broadcast on 2025-11-27.

Webinar – OIN: A Conversation About the Journey So Far and Preview of OIN 2.0

By community, legal, News, Webinar

OpenChain hosted an open discussion between Keith Bergelt, CEO of OIN and Shane Coughlan, GM of OpenChain to unpack the evolution of patent non-aggression in the open source ecosystem, and explore what is coming next for existing and potential new licensees of the OIN System Definition.

This is a key webinar for those interested in addressing patent risk and containment strategy, and is recommended for legal, project management and executive teams.

Watch the Webinar:

More About Our Webinars:

This event is part of the overarching OpenChain Project Webinar Series. Our series highlights knowledge from throughout the global OpenChain eco-system. Participants are discussing approaches, processes and activities from their experience, providing a free service to increase shared knowledge in the supply chain. Our goal, as always, is to increase trust and therefore efficiency. No registration or costs involved. This is user companies producing great informative content for their peers.

Check Out The Rest Of Our Webinars:

This OpenChain Webinar was broadcast on 2025-11-26.

Webinar: Containers and Compliance

By legal, licensing, News, security, Webinar

This was an exceptionally popular (over 50 attendees). Unfortunately, we had a recording mishap and are unable to bring you the full panel discussion. However, we are providing a summary below alongside the slides used.

Quick Recap

Our Panelists:

  • Chair: Chris Wood
  • Caren Kresse
  • Heather Meeker
  • Mary Hardy
  • Till Jaeger

The meeting focused on discussing open-source containers, package managers, and compliance challenges, with panelists exploring issues around transparency, licensing information, and source code access. The group examined limitations in package manager information and binary scanning capabilities, discussing how incomplete or incorrect licensing data can hinder true compliance. The panel emphasized the importance of proper license declarations and developer awareness, while exploring potential solutions for addressing licensing issues in containerized environments and discussing the need for improved compliance automation tools.

Summary

Source Container Compliance Challenges:

The meeting focused on open-source containers, package managers, and compliance, with Chris chairing the discussion and introducing panelists including Karen from OSADL, Till, and others. Chris raised concerns about the transparency of package managers, noting that some widely used products lack sufficient licensing information and do not provide SBOMs or source code access, which may hinder true license compliance. The panelists were asked to share their thoughts on these issues.

Improving Open Source Compliance Tracking:

The panel discussed the limitations of package manager information for source compliance, with Caren, Heather, and Mary agreeing that package managers often provide incomplete, outdated, or incorrect licensing information. They emphasized the need to improve provenance tracking and source code analysis rather than relying solely on meta-information. Till explained that package managers can only use the information provided by open source projects, which is often insufficient. Mary noted a public database, ClearlyDefined, contains metadata for open source packages, including licenses discovered during scanning. It can be used as a reference during container content analysis. There is still some human curation for packages that have missing top-level license information, but at least it only needs to be completed once. The group also addressed the limitations of license scanners, noting that many only analyze the top-level license of binaries, which may not reflect the true complexity of the software’s licensing structure.

Binary Scanner Limitations and Potential:

The group discussed the limitations and potential of binary scanners in identifying licensing information. Caren emphasized the need for binary scanners to trace the origin and build information of binaries to extract licensing details, while Heather highlighted the evolution of scanning tools from line-by-line source code analysis to higher-level scans, noting a potential resurgence in detailed scanning due to AI coding tools. Mary mentioned ongoing experiments using AI to improve the detection of binary origins, and Till explained the convenience of binary scanning for large dependency trees but stressed the need for source code for comprehensive compliance. Florian raised concerns about relying solely on third-party binary scanning for compliance, and Stefan questioned the discrepancies in license declarations between Maven and GitHub, which Caren and Till acknowledged as a challenge due to incomplete or outdated meta-information.

Software Licensing Awareness and Management:

The panel discussed the importance of proper license declarations in software development, emphasizing the need for awareness training among developers to ensure accurate declarations. They highlighted the role of configuration management in preventing issues related to incorrect licensing, with Marcel explaining that the default Apache license in Maven requires explicit changes for different licensing. The group also addressed the limitations of binary scanning in identifying license information, with Till suggesting a theoretical approach using a database to link source code and binary information. Chris raised a question about remediation options for non-compatible licenses in containerized environments, which the panel acknowledged as an open issue.

Container Licensing Compliance Challenges:

The panel discussed challenges in container and package manager compliance, focusing on how to address licensing issues when using non-modified binary formats. Heather noted that license disclosures for pre-built containers have improved over time, and suggested working with upstream sources for remediation, while Caren emphasized engaging with source projects to resolve licensing problems. The group agreed that developer awareness of licensing requirements is crucial, particularly for containers, and Till highlighted the importance of using compliant and trusted base images. The panel expressed hope for improved tools to automate compliance processes in the future.

Read the Slides:

More About Our Webinars:

This event is part of the overarching OpenChain Project Webinar Series. Our series highlights knowledge from throughout the global OpenChain eco-system. Participants are discussing approaches, processes and activities from their experience, providing a free service to increase shared knowledge in the supply chain. Our goal, as always, is to increase trust and therefore efficiency. No registration or costs involved. This is user companies producing great informative content for their peers.

Check Out The Rest Of Our Webinars

This OpenChain Webinar was broadcast on 2025-10-29.

Webinar: Introduction to the Cyber Resilience Act (CRA)

By community, legal, licensing, News, standards, Webinar

About This Webinar:

The European Union (EU) Cyber Resilience Act (CRA) is a new law that covers almost all “products with digital elements”, including software, released in the EU. Enforcement will begin in 2026, even on organizations who aren’t based in the EU. This presentation explains the scope and requirements of the CRA. This webinar was lead by David A. Wheeler, Director of Open Source Supply Chain Security at the Linux Foundation.

Check out our online training course diving deeper into this topic:
https://training.linuxfoundation.org/express-learning/understanding-the-eu-cyber-resilience-act-cra-lfel1001/

Watch the Webinar:

Review the Slides:

More About Our Webinars:

This event is part of the overarching OpenChain Project Webinar Series. Our series highlights knowledge from throughout the global OpenChain eco-system. Participants are discussing approaches, processes and activities from their experience, providing a free service to increase shared knowledge in the supply chain. Our goal, as always, is to increase trust and therefore efficiency. No registration or costs involved. This is user companies producing great informative content for their peers.

Check Out The Rest Of Our Webinars

This OpenChain Webinar was broadcast on 2025-09-12.

Webinar: Compliant containers with the OSADL Base Image

By legal, licensing, News, Webinar

About This Webinar:

While containers certainly simplify deploying software, fulfilling FOSS license obligations for containers is made difficult by their layered structure and the lack of compliance material in public repositories. Although every container is customized for its particular use and therefore comprises different software components, many are built on a base image that provides essential system components. It seems obvious to apply the Open Source principle of sharing development of non-differentiating technologies and services to license obligations of container base images. Therefore, OSADL offers the OSADL Base Images that are provided together with all required legal information and material needed to be distributed compliantly. A company may build their individual container images on top of the OSADL Docker Base Image and use the provided instructions to fulfill license obligations for the additional software to achieve license compliant container distribution. This presentation explained how the base images and in particular the license compliance material are created, list what flavors, versions and variants are available and show how they can be used to facilitate licensing of individual containers.

Project page: https://www.osadl.org/base-image

Docker Hub: https://hub.docker.com/r/osadl/

Watch the Webinar:

More About Our Webinars:

This event is part of the overarching OpenChain Project Webinar Series. Our series highlights knowledge from throughout the global OpenChain eco-system. Participants are discussing approaches, processes and activities from their experience, providing a free service to increase shared knowledge in the supply chain. Our goal, as always, is to increase trust and therefore efficiency. No registration or costs involved. This is user companies producing great informative content for their peers.

Check Out The Rest Of Our Webinars

This OpenChain Webinar was broadcast on 2025-09-12.

Webinar: Understanding the CHAOSS Project

By automation, community, News, Webinar

About This Webinar:

CHAOSS is a Linux Foundation project focused on creating metrics, metrics models, and software to better understand open source community health on a global scale. This webinar delves into how it accomplishes these goals, and how you can get involved. Huge thanks to Dr. Dawn Foster and Prof. Matt Germonprez for presenting, and to Andrew Katz for hosting!

Watch the Webinar:

More About Our Webinars:

This event is part of the overarching OpenChain Project Webinar Series. Our series highlights knowledge from throughout the global OpenChain eco-system. Participants are discussing approaches, processes and activities from their experience, providing a free service to increase shared knowledge in the supply chain. Our goal, as always, is to increase trust and therefore efficiency. No registration or costs involved. This is user companies producing great informative content for their peers.

Check Out The Rest Of Our Webinars

This OpenChain Webinar was broadcast on 2025-08-13.

Webinar: Unlocking Potential – Case Study on ZF’s ISO/IEC 5230 Third-Party Certification with TIMETOACT

By community, legal, licensing, News, standards, Webinar

The OpenChain Project held a webinar on the 29th of July 2025 to provide a case study on how ZF – one of the world’s largest automotive suppliers – collaborated with TIMETOACT to obtain third-party certification for OpenChain ISO/IEC 5230.

Abstract:

This case study is suitable for organizations new to the OpenChain standards, organizations in the process of adopting the standards, or organizations reviewing how others met this milestone in open source process management. It will be structured as a series of short section presentations that provide:

  • A brief introduction to ISO/IEC 5230
  • The importance of ISO/IEC in the automotive industry
  • ZF’s certification journey
  • Forming an OSPO
  • Steps taken to accomplish ISO/IEC 5230 certification
  • Challenges faced
  • Role of TIMETOACT in the certification process
  • Gap analysis with TIMETOACT and ZF
  • How ZF used OpenChain and InnerSource Commons resources
  • Lessons learned
  • Closing thoughts

More About Our Webinars:

This event is part of the overarching OpenChain Project Webinar Series. Our series highlights knowledge from throughout the global OpenChain eco-system. Participants are discussing approaches, processes and activities from their experience, providing a free service to increase shared knowledge in the supply chain. Our goal, as always, is to increase trust and therefore efficiency. No registration or costs involved. This is user companies producing great informative content for their peers.

Check Out The Rest Of Our Webinars

This OpenChain Webinar was broadcast on 2025-07-29.

Webinar – How we are doing compliance at CARIAD with ORT

By automation, legal, licensing, News, security, Webinar

This webinar covered how the team in VW Group are doing compliance at CARIAD with ORT. Helio Chissini de Castro lead the discussion, and we had some interesting Q&A.

This is an outcome webinar from the OpenChain and Friends event in Stuttgart, Germany during April 2025. This event saw speakers from Germany and beyond come together to share best practices around open source process management, compliance and automation.

Watch the Webinar:

More About Our Webinars:

This event is part of the overarching OpenChain Project Webinar Series. Our series highlights knowledge from throughout the global OpenChain eco-system. Participants are discussing approaches, processes and activities from their experience, providing a free service to increase shared knowledge in the supply chain. Our goal, as always, is to increase trust and therefore efficiency. No registration or costs involved. This is user companies producing great informative content for their peers.

Check Out The Rest Of Our Webinars

This OpenChain Webinar was broadcast on 2025-07-03.

Webinar – Project OCCTET.eu – The Why, What and How

By automation, community, legal, licensing, News, security, Webinar

This webinar covered an interesting new EU-funded project that brings together various open source tooling for open source security and compliance like Open Source Review Toolkit (ORT) and AboutCode, and other experts in the domain of open source compliance, security and automation. It featured Andreas Kotulla (Bitsea) and Martin von Willebrand (DoubleOpen), and had lively interaction from our audience.

This is an outcome webinar from the OpenChain and Friends event in Stuttgart, Germany during April 2025. This event saw speakers from Germany and beyond come together to share best practices around open source process management, compliance and automation.

Watch the Webinar:

More About Our Webinars:

This event is part of the overarching OpenChain Project Webinar Series. Our series highlights knowledge from throughout the global OpenChain eco-system. Participants are discussing approaches, processes and activities from their experience, providing a free service to increase shared knowledge in the supply chain. Our goal, as always, is to increase trust and therefore efficiency. No registration or costs involved. This is user companies producing great informative content for their peers.

Check Out The Rest Of Our Webinars

This OpenChain Webinar was broadcast on 2025-07-01.

Webinar – AboutCode – Practical Compliance in One Stack – Licensing, Vulnerabilities, and More

By ai, automation, licensing, News, security

Our speaker was a good friend of the OpenChain Project, and the founder of AboutCode, Philippe Ombredanne. Our focus was on recent advances in the open source and open data AboutCode stack for licensing and security compliance.

This is an outcome webinar from the OpenChain and Friends event in Stuttgart, Germany during April 2025. This event saw speakers from Germany and beyond come together to share best practices around open source process management, compliance and automation.

Watch the Webinar:

Review the Slides:

More About Our Webinars:

This event is part of the overarching OpenChain Project Webinar Series. Our series highlights knowledge from throughout the global OpenChain eco-system. Participants are discussing approaches, processes and activities from their experience, providing a free service to increase shared knowledge in the supply chain. Our goal, as always, is to increase trust and therefore efficiency. No registration or costs involved. This is user companies producing great informative content for their peers.

Check Out The Rest Of Our Webinars

This OpenChain Webinar was broadcast on 2025-06-10.