A *lot* of people in our community are speaking about OpenChain at meetings, events and through social media. To help with their communication the OpenChain Project publishes a regularly updated slide deck with speaker notes. You can find the latest version here.
This time we explored Software Heritage, an initiative whose goal is to collect, preserve, and share software code, and continued our discussion of containers from the perspective of scalable compliance.

Our speakers
Roberto Di Cosmo, Director at Software Heritage, explained why this initiative collects and preserves software in source code form with the understanding that software embodies key technical and scientific knowledge that humanity cannot afford to risk losing. His presentation helped provide insight into how such initiatives can link into activities like compliance automation in open source compliance, an area of immediate interest to the OpenChain community.

Scott Peterson, Senior Commercial Counsel at Red Hat, talked about how we can make compliance scalable in a container world. This talk will build on other recent presentations with a particular focus on efficiency and portability, with a “registry-native” approach to source code availability. Scott explained how this does not require updating container registries to include source code specific features, but instead can exploit features that are already contained in current registries.
Check Out the Slides
Check Out The Rest Of Our Webinars
This is OpenChain Webinar #5, released on 2020-06-02.
The OpenChain Project has launched a series of bi-weekly free webinars that provide access to people and knowledge that we would otherwise obtain at events. We hold our fifth meeting on Monday the 1st of June at 9am Pacific with two guest speakers.
This time we are exploring Software Heritage, an initiative whose goal is to collect, preserve, and share software code, and continuing our discussion of containers from the perspective of scalable compliance.

Roberto Di Cosmo, Director at Software Heritage, will explain why this initiative collects and preserves software in source code form with the understanding that software embodies key technical and scientific knowledge that humanity cannot afford to risk losing. This presentation will help provide insight into how such initiatives can link into activities like compliance automation in open source compliance, an area of immediate interest to the OpenChain community.

Scott Peterson, Senior Commercial Counsel at Red Hat, will talk about how we can make compliance scalable in a container world. This talk will build on other recent presentations with a particular focus on efficiency and portability, with a “registry-native” approach to source code availability. Scott will explain how this does not require updating container registries to include source code specific features, but instead can exploit features that are already contained in current registries.
Each talk will run for 10~15 minutes and there will be plenty of time for questions, comments and suggestions. As with all OpenChain Project activities, our goal is to facilitate knowledge-sharing between peers.
Everyone is invited to join this free webinar via zoom. It will also be recorded and made available later on our website.
Join Our Zoom Meeting
Password *
- 123456
One Tap Telephone (no screensharing)
- +358 9 4245 1488,,9990120120# Finland
- +33 7 5678 4048,,9990120120# France
- +49 69 7104 9922,,9990120120# Germany
- +852 5808 6088,,9990120120# Hong Kong
- +39 069 480 6488,,9990120120# Italy
- +353 6 163 9031,,9990120120# Ireland
- +81 524 564 439,,9990120120# Japan
- +82 2 6105 4111,,9990120120# Korea
- +34 917 873 431,,9990120120# Spain
- +46 850 539 728,,9990120120# Sweden
- +41 43 210 71 08,,9990120120# Switzerland
- +44 330 088 5830,,9990120120# UK
- +16699006833,,9990120120# US (San Jose)
- +12532158782,,9990120120# US
Find your local number: https://zoom.us/u/abeUqy3kYQ
Not all countries have available numbers.
After dialing the local number enter 9990120120#

Newsletter – Issue 37 – May 2020

- In May the Linux Foundation publicly announced the Joint Development Foundation (JDF) as an ISO/IEC JTC 1 PAS submitter and provided more information on how JDF will support OpenChain and other specifications to become ISO standards moving forward. This is an extremely important media inflection point for our community and for the broader global collaborations creating effective, adopted and mature de facto standards:
https://www.openchainproject.org/featured/2020/05/20/joint-development-foundation-recognized-as-an-iso-iec-jtc-1-pas-submitter-and-submits-openchain-for-international-review
Latest OpenChain Member

- In May the OpenChain Project also announced OPPO as the latest Platinum Member. Find out more here:
https://www.openchainproject.org/featured/2020/05/26/oppo-is-now-an-openchain-platinum-member
OpenChain @ Webinars #3 & 4:
- Find the OpenChain Webinar #3 video recording here:
https://www.openchainproject.org/news/2020/05/07/openchain-webinar-3-video-recording
and the presentation slides here:
https://www.openchainproject.org/featured/2020/05/12/openchain-webinar-3-presentation-slides - Find the OpenChain Webinar #4 video recording here:
https://www.openchainproject.org/featured/2020/05/21/openchain-webinar-4-unpacking-spdx-2-2-spdx-lite-full-recording
OpenChain @ Work Groups (Selected Highlight)
- The OpenChain Reference Tooling Work Group held its 15th meeting on the 13th of May. This meeting covered general updates in the tooling space and a deep dive into TERN for container compliance.
Find the recording here:
https://www.openchainproject.org/featured/2020/05/15/openchain-reference-tooling-work-group-meeting-15-full-recording
OpenChain @ Events (Selected Highlight)
- The OpenChain Project was introduced by Shane Coughlan, General Manager at the latest NTIA Software Bill of Materials Framing Group meeting. Watch the presentation here:
https://www.openchainproject.org/featured/2020/05/11/openchain-introduction-ntia-software-bill-of-materials-framing-group
A Brief Introduction to OpenChain – May 2020
- OpenChain provides introduction slides to help individuals and organizations understand our mission and goal. These slides include speaker notes to help our community present to interested parties. The latest version is now available for viewing, downloading and sharing:
https://www.openchainproject.org/featured/2020/05/07/a-brief-introduction-to-openchain-may-2020
More News
- Plenty more happened. Check out the full stream here:
https://www.openchainproject.org/news
Check Out All Our Previous Newsletters
In this webinar we unpacked how the newly released SPDX 2.2. SPDX, as a leading industry standard for Software Bill of Materials, plays a pivotal role in the implementation of practical manual and automated compliance programs.
Kate Stewart, Sr. Director of Strategic Programs at the Linux Foundation, explained how SPDX 2.2 works and what it means for the community. Kate has been a key driver of this standard over the last 10 years and can answer all your questions about what the current standard means, what projects support it, and the current state of the tooling landscape.
Yoshiyuki Ito, Principal Expert at RENESAS Electronics, provided an overview of SPDX Lite. This is a “Profile” for the SPDX 2.2 standard that helps companies deploy the Software Bill of Materials to match certain workflows, particularly with respect to suppliers to large companies using existing processes. Ito San and others in the OpenChain Japan Work Group created SDPX Lite to help ensure that the standard could seek adoption in as many production environments as possible with minimal friction.
Check Out The Rest Of Our Webinars
This is OpenChain Webinar #4, released on 2020-05-21.
株式会社日立製作所 岩田吉隆
はじめに
今回は、OpenChain Japan WG「役割ごとの教育資料」SWGについて紹介します。
活動概要
メンバ
ソニー、オリンパス、日立(リーダ)
活動状況
- F2F会議での検討、作業(現在まで9回開催)
- Japan WG会議での報告(第7回~第11回)
- Planning SWG他での共通教育資料案のレビュー
- GitHubでの検討資料公開
検討資料
資料案
OSSのコンプライアンスにかかる教育の状況
先ず、コンプライアンスにかかる教育の状況について議論しました。
a. OpenChain設立前から、OSSに関する教育を実施している会社もある。
b. これから、教育を実施する会社は、どういう教育内容、対象者からスタートすべきか、検討が必要。
c. 会社毎のビジネス形態により、 OSSに関わる必要なビジネスフローは異なる。
d. OSSに関わる上で、役割ごとに本当に必要最小限な教育観点は異なっている。
e. Curriculum※ を全て教育内容に盛り込むと、分量が多すぎる。
f. Specification※, Curriculumとの整合性も考慮が必要。
(※:SpecificationはOpenChainの一連の要件を定義している仕様書、CurriculumはOpenChainのSpecificationを下支えするトレーニング教材)
進め方の方針
コンプライアンスにかかる教育の状況を踏まえ、進め方の方針について検討しました。
a. 既に各社実施されている教育の体系、対象者、形態(講演会、集合研修、e-learning、資料閲覧、他)、タイミング、英語版有無を、可能な範囲で事例として提示。
b. a.に関して、各教育がビジネスフロー上で、どの対象者をカバーしているかを明示。
c. 各教育の目次、章/節の概要程度まで、可能な範囲で提示。
d. a, b, cの事例を元に、下記を整理する。
①最初にsmall startするための必要最小限の項目は?
②役割ごとに、教育資料として必要な項目は?共通項目、役割ごとの独自項目は?
③ライセンス関連で必要な項目は?
④SPDXの活用方法は?
⑤役割ごとの共通教育資料の案を作成
4社の事例の分析
先ずステップ1として、4社の事例の分析からスタートしました。
a. 各社のOSSに関する教育の例を収集
No. | 会社 | 事例数 |
---|---|---|
1 | 製品ベンダー1 | 9 |
2 | 製品ベンダー2 | 5 |
3 | 製品ベンダー3 | 1 |
4 | 製品ベンダー4 | 2 |
b.下記の分析観点について、分析、報告
i. OSSに関する教育のニーズ
ii. OpenChainのSpecificationに準拠する。
iii. Curriculumの過不足を考慮
iv. 役割ごとの教育の検討 (4社のケーススタディ)
⇒ GitHubへアップ
4社の事例からの提案と検討
次にステップ2として、4社の事例の分析結果を基に、共通教育資料の案の作成を行っています。
a. 4社の事例の分析結果を元に、共通教育資料の検討を実施
i. Specificationを満たすためにコンプライアンスプログラムの記載は必須
ii. Curriculumの過不足を配慮
iii. リーフレットで使用されている語彙、表現を考慮
iv. 各社の一般向け基礎教育の共通内容を考慮
b. 製品ベンダーのソフトウェア開発者向け共通教育資料のコンプライアンスプログラム・バージョンの案の提案を行う。a.のi.~ⅲ.は必須項目とし、ⅳ.の共通内容を重点的に、ⅳ.の一部内容は概略的に、説明する方向で詳細化を図る。OSSを使用して製品を開発するために、製品ベンダーのソフトウェア開発者向けというターゲットを設定した。
c. 役割ごとの分担と責任の明確化の例示
Specification上での役割の必須要件の例示を行う。
d. 案作成の検討を通して、下記章立てにて作成中
- OSS概説
- 知的財産権
- OSSライセンス
- OSSコンプライアンスプログラム
- OSS導入時の検討
- OSSレビュー
- OSS配布
- まとめ
- 問い合わせ先
- 参考文献・団体
e. d.の各章毎に、GitHub上でJapan WG内のレビューを行う。
おわりに
以上、OpenChain Japan WG「役割ごとの教育資料」SWGについて簡単に紹介しました。更に、教育資料の事例の拡充や、共通教育資料案の紹介とレビューを行う予定です。皆様の参加をお待ちしています。
In this webinar Tobie Langel spoke about ‘Open Source Contribution Policies That Don’t Suck.’ Leon Schwartz and Tony Decicco from GTC Law provided an overview of open source-related topics in the context of mergers, acquisitions, financings, investments, IPOs, divestitures, loans, customer license agreements, rep and warranty insurance and other transactions. Andrew Katz presented a due diligence questionnaire and sample warranties based on the the OpenChain specification.
More About This Webinar
Tobie Langel spoke about ‘Open Source Contribution Policies That Don’t Suck.’ In his own words: Open source contribution policies are long, boring, overlooked documents, that generally suck. They’re designed to protect the company at all costs. But in the process, end up hurting engineering productivity, and morale. Sometimes they even unknowingly put corporate IP at risk. But that’s not inevitable. It’s possible to write open source contribution policies that make engineers lives easier, boost morale and productivity, reduce attrition, and attract new talent. And it’s possible to do so while reducing the company’s IP risk, not increasing it.
Leon Schwartz and Tony Decicco from GTC Law provided an overview of open source-related topics in the context of mergers, acquisitions, financings, investments, IPOs, divestitures, loans, customer license agreements, rep and warranty insurance and other transactions. This covered:
- Types of open source risk
- Open source due diligence as part of transactions
- Open source-related terms in agreements
- The strategic use of open source in transactions
Andrew Katz presented a due diligence questionnaire and sample warranties based on the the OpenChain specification, and explained how adoption of this framework will drive further adoption of the standard. This builds on the observation that the OpenChain specification provides a great framework for due diligence and share purchase agreement warranties, even where the target is a software company which is not OpenChain compliant.
Check Out The Rest Of Our Webinars
This is OpenChain Webinar #3, released on 2020-05-07.

Newsletter – Issue 36 – April 2020
OpenChain in Q2 – Continuing Leadership, Continuing Support
The global lockdown due to the spread of COVID-19 is a unique historical moment. We are seeing both great success and great challenges in addressing this disease, and at all times there is an awareness that it can impact our close friends and families. To a large extent the OpenChain community is fortunate. Many of our companies allow us to work from home. Many of us are near excellent health services. We are well-positioned to weather this storm. We will do so with the health of our community and the societies in which we work as our highest priority.
Read more here:
OpenChain @ Webinars:
- Over the last three years the OpenChain Project has held bi-weekly calls on the First Monday (9am Pacific) and Third Monday (5pm Pacific) of each month. These calls have driven forward our standard for open source compliance and a large corpus of supportive reference material. Today we are at an inflection point and we have an opportunity to enhance our service to the global community.With less emphasis right now on editing our standard (the forthcoming ISO version is fully baked) and our reference material largely produced via local work teams, there is an opportunity to launch an on-going series of webinars that provide access to people and knowledge that we would otherwise obtain at events.
We kicked off on Monday the 6th of April at 9am Pacific with speakers covering Supply Chain Governance and Container Compliance.
- https://www.openchainproject.org/news/2020/04/08/openchain-webinar-1-supply-chain-governance-container-compliance-full-recordingWe got some pretty great feedback in a survey:
https://www.openchainproject.org/news/2020/04/17/openchain-webinar-1-survey-results
Our second Webinar was held on the 20th of April and covered compliance in China and OpenChain at Facebook.
We also announced our third Webinar for the 4th of May covering Contribution Policies + OpenChain in M&A. Watch this space for the recording in the next issue.
OpenChain @ Translations
OpenChain Specification 2.0 Available In Russian
- The official reference translation of the OpenChain Specification 2.0 is now available in Russian thanks to Denis Dorotenko (Yandex) and Pavel Lugovoy (independent counsel). This marks another important milestone for our project, providing greatly increased geographic coverage for our work, and helping to support engagement in a country with a long history of technology leadership.
https://www.openchainproject.org/featured/2020/04/03/openchain-specification-2-0-available-in-russian
OpenChain @ Conformance
Siemens Announces OpenChain 2.0 Conformance
- Siemens, an OpenChain Platinum Member and pioneer of adoption around our standard, has announced OpenChain 2.0 conformance. This builds on their previous public work in describing their journey and announcing 1.1 conformance in April 2017.
https://www.openchainproject.org/featured/2020/04/09/siemens-announces-openchain-2-0-conformance
OpenChain @ Partners
OSS Engineering Consultants is an OpenChain Partner
- On the 20th of April we announced OSS Engineering Consultants (OSSEC) as a partner organization. This is a consulting firm based in North America, providing solutions for managing OSS use for organizations with complex software supply chains.
https://www.openchainproject.org/featured/2020/04/20/oss-engineering-consultants-is-the-latest-openchain-partner
Osborne Clarke is an OpenChain Partner
- On the 27th of April we announced that Osborne Clarke as a partner organization. This is an international legal practice with offices situated around Europe, Asia and the USA with a strong focus on technology law.
https://www.openchainproject.org/featured/2020/04/27/osborne-clarke-is-the-latest-openchain-partner
OpenChain @ Work Groups
- The OpenChain Taiwan Work Group launched a local website:
https://www.openchainproject.org/featured/2020/04/01/openchain-taiwan-work-group-launches-new-website - OpenChain Japan Work Group held a special webinar to discuss the outcomes of six sub-groups:
https://www.openchainproject.org/news/2020/04/29/openchain-japan-virtual-all-member-meeting-1-reports-from-six-sub-groups-april-23rd-2020
OpenChain @ Events
- Shane Coughlan, OpenChain General Manager, delivered a webinar covering the OpenChain Reference Training slides as part of his contribution to the open source advisory council of UNTIL:
https://www.openchainproject.org/news/2020/04/09/openchain-reference-training-united-nations-technology-innovation-labs - Shane Coughlan also co-hosted a webinar with the team from FOSSID on OpenChain, standardization and the path to real world utilization:
https://www.openchainproject.org/featured/2020/04/15/fossid-webinar-openchain-standardization-and-real-world-deployment-april-29th-2pm-pacific
Coming Next
- This newsletter marks 36 months since we started a major outward push for awareness and adoption in the OpenChain Project. During this time we have seen our industry standard enter a multitude of new markets. You can expect this continue and you can expect initiatives like our webinars to grow over time. Our next newsletter will both provide a new look and a great way for people to get started with our activities. Watch this space.
This webinar is about the current Chinese market and it also provides an update on what Facebook is doing around open source governance and licensing.
Our Presenters

Maggie Wang spoke about OpenChain in China. Maggie’s background ranges from working as an in-house at Huawei to acting as the China representative for Ladas and Parry. Her unique experience in-house and as outside counsel positions her perfectly to help contextualize where we are with regards compliance, standardization and business reality in one of our most important markets.

Michael Cheng spoke about OpenChain at Facebook, a topic that ranges from adoption activity and broader leadership in the compliance space by the company. His perspective will provide added value given the simultaneous decision by Facebook, Google and Uber to join OpenChain as Platinum Members in late 2018, and plenty of runway for our audience to ask questions about real-life lessons learned.
Check Out The Rest Of Our Webinars
This is OpenChain Webinar #2, released on 2020-04-22.
The first OpenChain Webinar took place on the First Monday of April with talks on Supply Chain Governance and Container Compliance. You can learn more about the specifics of the event here.
OpenChain will continue to hold webinars on a bi-weekly schedule throughout the next months. You can find out more about our second webinar on the 20th of April, featuring OpenChain in China + OpenChain @ Facebook, right here. Our goal is to provide our community with access to the knowledge and the people they would normally discover at events.
To ensure we do the best job possible we will run surveys alongside some of the webinars and here are the results from the very first one. We had 11 respondents from an audience of 55 live and 50 for the recording. A small sample but useful for our forward planning.




All in all, a pretty good start. It was interesting that we had one respondent note that Nick’s research on supply chain governance was not relevant (and all others mark it as very relevant). A follow-up question would be why this is so? We will give people more space in future surveys to provide such feedback.
A big thank you to everyone who took the time to respond. You are helping to make things better.