owned this note changed 4 years ago
Linked with GitHub

Open Source and ISO Standards - OpenChain and the Future of Compliance - Shane Coughlan

tags: COSCUP2021 Beginner en COSCUP2021 COSCUP 主議程軌 RB105 - Main Track

歡迎來到 https://hackmd.io/@coscup/2021 共筆

Image Not Showing Possible Reasons
  • The image file may be corrupted
  • The server hosting the image is unavailable
  • The image path is incorrect
  • The image format is not supported
Learn More →

點擊本頁上方的 開始用 Markdown 一起寫筆記!
手機版請點選上方 按鈕展開議程列表。

請從這裡開始

OpenChain Project
maintains the International Standard for open source license compliance.

OpenChain

Process Management across software

SPDX Software Package Data Exchange

SPDX is an open standard for communicating software

Benefits: saving time saving money

  • 避免跟客戶來回溝通,不用瘋狂修補/查找問題。
  • 尤其台灣很多中小企業不太有資源去整理所有使用中的開源軟體,建議 follow standards like OpenChain
  • follow openchain 標準能夠容易達成 ISO Standard
  • 很多大企業都有使用, Toyota/Google/LG/SamSung
  • Big company aims to follow OpenChain & SPDX as their real supply chains, so may ask their supply chain to follow the standard

ISO/IEC 5230:2020

ISO/IEC 5230:2020 is a simple, clear and effective process management standard for open source license compliance

Q&A

  • price of the OpenChain: FREE
  • This year/ Next year, American & Europe are aims to use Openchain so will possible ask their supply chain follow this standard. e.g. Bosch Microsoft
Select a repo