OpenChain Project

OpenChain Project

IT Services and IT Consulting

San Francisco, California 1,638 followers

Maintaining The Standards for Open Source License Compliance and Security Assurance - ISO/IEC 5230 and ISO/IEC 18974

About us

We maintain OpenChain ISO/IEC 5230, the international standard for open source license compliance programs, and OpenChain ISO/IEC 18974, the industry standard for open source security assurance programs. Our vision is a supply chain where open source is delivered with trusted and consistent process management information. Our mission is to make that happen. The OpenChain Project has an extensive global community of over 1,000 companies collaborating to make the supply chain quicker, more effective and more efficient. We work with our sister projects at The Linux Foundation like SPDX (SBOM), OpenSSF (Security), TODO Group (OSPO) and CHAOSS (Metrics) to help drive forward business management of open source. Our community also develops best practices to reduce friction and increase efficiency across all aspects of open source process management. Everyone is invited to be part of what we do. There are no restrictions to join our mailing lists, our calls and most of our events. We have an extensive library covering everything from making an open source policy to training your staff to making decisions around risk allocation.

Website
http://www.openchainproject.org
Industry
IT Services and IT Consulting
Company size
2-10 employees
Headquarters
San Francisco, California
Type
Nonprofit
Founded
2016
Specialties
Open Source, Compliance, Supply Chain, Best Practices, Processes, Standardization, Industry Standard, Free Software, Community, Intellectual Property, Standard, Security, Process Management, Open Source License Compliance, Open Source Security Assurance, FinOps, InnerSource, OSPO, IP, and Legal

Locations

Employees at OpenChain Project

Updates

  • View organization page for OpenChain Project, graphic

    1,638 followers

    Most people know the OpenChain Project as the home of ISO/IEC 5203 (the international standard for open source license compliance) and ISO/IEC 18974 (the international standard for open source security assurance). Some people know us for our work around SBOM (for example, the Japan Work Group created the "SPDX Lite" part of SPDX SBOM). Some people know us for our new work in spaces like AI Compliance. But did you know about the OpenChain Onsen Study Group chaired by Norio Kobota of Sony?

    View profile for Norio Kobota, graphic

    Open Source Program Office - Sony

    A busy week has come to an end. I spent very interesting time, thank you for Linux Foundation and friends! Some of you may know that I am the chair of the OpenChain Onsen(hot spring) study group, and this is my regular activity. Here is one of the Onsen facilities nearby my house that I recommend. You can enjoy Manga along with the Onsen, so if you are interested, please let me know😀

    • No alternative text description for this image
    • No alternative text description for this image
    • No alternative text description for this image
  • View organization page for OpenChain Project, graphic

    1,638 followers

    Not a panacea: a nuanced take on the challenges of SBOM for open source compliance. This type of talk provides a bridge between understanding a task, a tool to assist and the realities of implementation. The Linux Foundation SBOM Summit was filled with such insight and helpful, practical consideration of using SBOM in the supply chain.

    View profile for Oscar V., graphic

    Principal Open Source Engineer

    Here is a copy of the slides I used for the SBOM Summit. Once I complete the review, I will share my original draft, summarized in those slides.

  • View organization page for OpenChain Project, graphic

    1,638 followers

    So many key contributors to the OpenChain Project community ❤️

    View profile for Masato Endo, graphic

    Japan Evangelist of The Linux Foundation, Group Manager of TOYOTA OSPO and Value Chain Innovation Project of Toyota, Automotive Chair and Board Member of OpenChain Project

    🇺🇸🇨🇳Great Panel about sharing international best practices about open source management🇰🇷🇯🇵 Thanks, Russ Eling, Seoyeon Lee and 杨 涵博!! #openchain #oss #opensource #linux

    • No alternative text description for this image
  • View organization page for OpenChain Project, graphic

    1,638 followers

    And that's a wrap! Open Source Summit Japan contained a wide (wide) range of tracks covering everything from code creation to IP management. It was also a wonderful networking opportunity. A big thank you to the organizers. OpenChain will be there again next year.

    • No alternative text description for this image
  • View organization page for OpenChain Project, graphic

    1,638 followers

    During The Linux Foundation Open Compliance Summit and SBOM Summit in Tokyo, Oscar Valenzuela gave three excellent talks around different aspects of managing open source processes, compliance, automation and scaling. The talk with Diego Jorquera was a great conversation-starter early in the event cycle. We are fortunate to have such international speakers come over and network with our local community contributors. With strong representation from China, Japan and Korea, the conference week provided a solid bridge between open source in the Americas, Europe and Asia. (big thanks to Linux Foundation Japan for all their local coordination!)

    View profile for Oscar V., graphic

    Principal Open Source Engineer

    It was an incredible week in Tokyo, Japan, sharing insights with the open-source compliance community! I had the privilege of giving two talks at the Open Source Compliance Summit with Diego Jorquera and later with Armijn Hemel, and today, I closed the week by delivering the opening talk at the SBOM Summit.  Thanks to Nithya Ruff for her invaluable mentorship leading up to this moment and Shane Coughlan and Noriaki-san for being exceptional hosts. It was a memorable experience connecting with colleagues and friends and advancing Open Source Compliance and Secure Supply Chain together!

    • No alternative text description for this image
  • View organization page for OpenChain Project, graphic

    1,638 followers

    高(Gao)琨(King)( Shanghai Sectrend Information Technology Co., Ltd.) , Tony Yang (openEuler) and Shane Coughlan (OpenChain Project) had a chance to catch up at The Linux Foundation Open Compliance Summit. This event, focused on sharing knowledge around open source license, security and other compliance topics, is held once a year in Tokyo. We had a very international audience this year, and an excellent roster of speakers. A big thank you to everyone involved.

    View profile for Tony Yang, graphic

    openEuler - Security Committee Contributor

    Attended #OpenCompliance Summit today as a speaker on the case study panel, sharing openEuler case study on self-certification to the OpenChain #security Standard ISO/IEC 18974 and the stories behind it. It was an unforgettable experience to talk with open source compliance experts from all over the world, and it was my first time to speak at such an excellent event. Many thanks to all the panelists Russ Eling, Masato Endoさん, Seoyeon Lee; my former colleague 高(Gao)琨(King), and #LinuxFoundation Shane Coughlan for organizing this event and all the help along the way. Looking forward to working with you all in the community in the future. Let us make the open source world better.

    • No alternative text description for this image
    • No alternative text description for this image
    • No alternative text description for this image
  • View organization page for OpenChain Project, graphic

    1,638 followers

    When we think about Software Build of Materials, we are looking at what might be a multi-dimensional space consisting of hierarchy, linking, modification, export restrictions, security vulnerabilities, distribution type, versions, etc. Care must be taken when setting up the SBOMs to both list the components used and to show how they are incorporated into your products. This OpenChain Project webinar discusses how a visualization of such meta-information was implemented to display the relationships and potential risks in a quick and in easy-to-understand way. It was part of a research project funded by the Federal Ministry for Economic Affairs and Climate Protection (BMWi) and with the Bonn-Rhein-Sieg University of Applied Sciences and Bitsea GmbH. Learn more and watch the webinar: https://hubs.la/Q02WpyHk0

    • No alternative text description for this image
  • View organization page for OpenChain Project, graphic

    1,638 followers

    Driving forward open source management with new open reference material, new initiatives for modeling and new stakeholders - including those from areas like insurance.

    View profile for Andrew Katz, graphic

    Consultant, Bristows LLP; CEO, Orcro Limited

    Great to be talking about open source risk management in M&A with Stephen Pollard, Byron Frost, Ayako Suga, Heather Meeker and Lewis P. at the Open Compliance Summit in Tokyo. Take aways: - Warranties and Indemnities insurance continues to become more popular in M&A transactions. - Open source risk is too often considered to be a black box. - Risk and trust are two sides of the same coin - OpenChain (ISO 5230:2020) can be used as a mechanism to assess and manage risk - The Capability Model that we are developing through the OpenChain Education Work Group can be used to fine tune the assessment of that risk, and help to provide a road map for continual improvement and risk management - Open source risk is much more nuanced than "just an IP risk". Effective open source businesses treat it more like an ESG (environment, social, governance) issue, because they realise that the value in open source comes from a two-way relationship with the open source community, and society at large. - Famichiki are possibly the finest foodstuff known to humanity.* *not discussed on the panel, but if you know, you know. I'm looking forward very much to day 2.

    • No alternative text description for this image

Similar pages

Browse jobs