Open Compliance Summit 2022 – State of the Union from Mike Dolan, SVP and GM of Projects at The Linux Foundation

Shane Coughlan
Shane CoughlanOpenChain Program Manager à The Linux Foundation
State of the Union
Open Compliance Summit 2022
Mike Dolan, SVP and GM of Projects
1
15+ years ago, we starting collaborating to reduce
issues with open source license compliance
What license is
this code?
What license(s)
are in my code?
What license(s) are
in this code you
gave me?
2007
2007 2010
Legal and
developer
education
Scan and
document
SBOMs
2
15+ years ago, we starting collaborating to reduce
issues with open source license compliance
What license is
this code?
What license(s)
are in my code?
What license(s) are
in this code you
gave me?
2007
2007 2010
Scan and
document
SBOMs
I know what’s in
this code!
Success
Legal and
developer
education
3
These efforts used transparency to solve our
challenges with open source compliance
Greater transparency enables
decision makers to make
better decisions
With open source software, we
weren’t concerned about
confidential or proprietary
information in the open
source software
4
The business reason for open compliance was
cost effective legal risk management
● We were concerned about legal loss
events that could impact our
companies
● License non-compliance could
present various loss events:
○ Lawsuits
○ Damage to reputation
○ Business interruption due to injunctions
● “Compliance” became a quasi-legal
concern (but it’s not just that
anymore)
5
New! WebAssembly for legal professionals
https://www.linuxfoundation.org/research/webassembly-for-legal-professionals
English, Japanese (日本), Chinese (中国人) available
6
法律専門家のための WebAssembly 真新しい
https://www.linuxfoundation.jp/publications/2022/12/webassembly-for-legal-professionals/
7
As our challenges evolved, we
worked on new solutions… by
adding more transparency.
8
We then openly collaborated to reduce issues
with open source management
What license is
this code?
What license(s)
are in my code?
What license(s) are
in this code you
gave me?
How do I manage
my license
information?
2007
2007 2010
Educate others Scan and
document
SBOMs SBOM
management
2015
How do I
manage my
supply chain?
Process
Standards
2015
9
We built open source management groups
(OSPOs) to help scale risk management
● OSPOs started as “the open
source group” in many companies
● Ultimately OSPOs were designed
to manage risk for the company
○ Risk of licensing issues in products
○ Risk of licensing issues in supplier
artifacts
○ Risk of inappropriate product
dependencies
○ Community engagement risks
https://todogroup.org/guides/
10
The legal risks have continued to evolve …
requiring evolution in risk management
● Losses from trolls
○ Copyright trolls
○ Patent trolls
● We worked on new solutions
○ Developer Certificate of Origin (2004)
○ Linux Kernel Enforcement Statement
(2020)
○ Collaborations with Unified Patents and
Open Invention Network
https://www.kernel.org/doc/html/latest/process/kernel-enforcement-statement.html 11
We can work together even on complex issues
12
https://lore.kernel.org/netdev/Ye6jCQm7z0Yr3bqA@salvia/T/
With the legal risks managed, open source was
able to grow … massively
https://www.sonatype.com/state-of-the-software-supply-chain/open-source-supply-demand-security
13
And now we face cybersecurity risk, and a need
for open source security risk management
https://www.sonatype.com/state-of-the-software-supply-chain/open-source-supply-demand-security
14
And now we are openly collaborating to extend license
risk management tools, processes, and standards to
address security risks
What are we
building into
our product?
How do I share
what packages
are in this?
How do I verify this
is the package you
said it is?
CI/CD Build
Systems
SBOMs Attestation
service
How do I
manage my
supply chain?
Process
Standards
SLSA
Is that OSS
community
security
focused?
Scorecard
What is the
integrity?
Levels of
assurance
S2C2F
15
Our existing risk management standards are evolving
to address security risk mitigation requirements
16
https://www.linuxfoundation.org/blog/the-openchain-security-assurance-
specification-1.1-now-available
https://www.chainguard.dev/unchained/whats-new-in-spdx-2-3
Major Changes in SPDX 2.3
Security: One of the main uses of SBOMs today
is dependency and vulnerability management.
This version introduces advisory, fix, URL and
SWID as categories in the security identifiers to
link the package to additional security context.
GitBOM: Joining the list of persistent identifiers
comes gitoid, the identifier used by the GitBOM
project to cryptographically track where a
package fits in the dependency tree.
New investments in OSPOs are needed to help
CISO teams address open source cybersecurity
risks.
Licensing
Risks
Security
Risks
OSPOs that partner with product security teams help define policies,
processes, build system requirements, and supply chain transparency
for managing security risk in open source and commercial product
systems
17
ありがとうございました
Thank you!
18
1 sur 18

Recommandé

SFScon 2020 - Luisa Romano - Cybersecurity Managers Liability and Use of Open... par
SFScon 2020 - Luisa Romano - Cybersecurity Managers Liability and Use of Open...SFScon 2020 - Luisa Romano - Cybersecurity Managers Liability and Use of Open...
SFScon 2020 - Luisa Romano - Cybersecurity Managers Liability and Use of Open...South Tyrol Free Software Conference
87 vues15 diapositives
A_Statistical_Study_and_Analysis_to_Identify_the_Importance_of_Open-source_So... par
A_Statistical_Study_and_Analysis_to_Identify_the_Importance_of_Open-source_So...A_Statistical_Study_and_Analysis_to_Identify_the_Importance_of_Open-source_So...
A_Statistical_Study_and_Analysis_to_Identify_the_Importance_of_Open-source_So...hani727151
7 vues6 diapositives
Commemorating 20 years of open source successes in building awareness and ado... par
Commemorating 20 years of open source successes in building awareness and ado...Commemorating 20 years of open source successes in building awareness and ado...
Commemorating 20 years of open source successes in building awareness and ado...OW2
91 vues32 diapositives
Great Open Source Compliance For Everyone (Version 3) par
Great Open Source Compliance For Everyone (Version 3)Great Open Source Compliance For Everyone (Version 3)
Great Open Source Compliance For Everyone (Version 3)Shane Coughlan
148 vues43 diapositives
KEYNOTE ComfyconAU 2020: disclose.io Vulnerability disclosure and Safe Harbor... par
KEYNOTE ComfyconAU 2020: disclose.io Vulnerability disclosure and Safe Harbor...KEYNOTE ComfyconAU 2020: disclose.io Vulnerability disclosure and Safe Harbor...
KEYNOTE ComfyconAU 2020: disclose.io Vulnerability disclosure and Safe Harbor...Casey Ellis
524 vues24 diapositives
An Analysis Of Open Source Business Models par
An Analysis Of Open Source Business ModelsAn Analysis Of Open Source Business Models
An Analysis Of Open Source Business ModelsSandra Long
6 vues21 diapositives

Contenu connexe

Similaire à Open Compliance Summit 2022 – State of the Union from Mike Dolan, SVP and GM of Projects at The Linux Foundation

INSECURE Magazine - 35 par
INSECURE Magazine - 35INSECURE Magazine - 35
INSECURE Magazine - 35Felipe Prado
43 vues63 diapositives
OSSF 2018 - Andrew Katz of Moorcrofts - OpenChain: a Tested Framework for Ope... par
OSSF 2018 - Andrew Katz of Moorcrofts - OpenChain: a Tested Framework for Ope...OSSF 2018 - Andrew Katz of Moorcrofts - OpenChain: a Tested Framework for Ope...
OSSF 2018 - Andrew Katz of Moorcrofts - OpenChain: a Tested Framework for Ope...FINOS
52 vues82 diapositives
OpenChain Monthly Meeting North America - Europe - 2023-02-07 par
OpenChain Monthly Meeting North America - Europe - 2023-02-07OpenChain Monthly Meeting North America - Europe - 2023-02-07
OpenChain Monthly Meeting North America - Europe - 2023-02-07Shane Coughlan
100 vues21 diapositives
OpenChain Monthly Meeting 2023-02-21 (North America and Asia) par
OpenChain Monthly Meeting 2023-02-21 (North America and Asia)OpenChain Monthly Meeting 2023-02-21 (North America and Asia)
OpenChain Monthly Meeting 2023-02-21 (North America and Asia)Shane Coughlan
62 vues21 diapositives
Open Source Governance in Highly Regulated Companies par
Open Source Governance in Highly Regulated CompaniesOpen Source Governance in Highly Regulated Companies
Open Source Governance in Highly Regulated Companiesiasaglobal
463 vues6 diapositives
A tale of two cities: Merging Yahoo and Aol’s open source programs par
A tale of two cities: Merging Yahoo and Aol’s open source programsA tale of two cities: Merging Yahoo and Aol’s open source programs
A tale of two cities: Merging Yahoo and Aol’s open source programsAshley Wolf
222 vues22 diapositives

Similaire à Open Compliance Summit 2022 – State of the Union from Mike Dolan, SVP and GM of Projects at The Linux Foundation(20)

OSSF 2018 - Andrew Katz of Moorcrofts - OpenChain: a Tested Framework for Ope... par FINOS
OSSF 2018 - Andrew Katz of Moorcrofts - OpenChain: a Tested Framework for Ope...OSSF 2018 - Andrew Katz of Moorcrofts - OpenChain: a Tested Framework for Ope...
OSSF 2018 - Andrew Katz of Moorcrofts - OpenChain: a Tested Framework for Ope...
FINOS52 vues
OpenChain Monthly Meeting North America - Europe - 2023-02-07 par Shane Coughlan
OpenChain Monthly Meeting North America - Europe - 2023-02-07OpenChain Monthly Meeting North America - Europe - 2023-02-07
OpenChain Monthly Meeting North America - Europe - 2023-02-07
Shane Coughlan100 vues
OpenChain Monthly Meeting 2023-02-21 (North America and Asia) par Shane Coughlan
OpenChain Monthly Meeting 2023-02-21 (North America and Asia)OpenChain Monthly Meeting 2023-02-21 (North America and Asia)
OpenChain Monthly Meeting 2023-02-21 (North America and Asia)
Shane Coughlan62 vues
Open Source Governance in Highly Regulated Companies par iasaglobal
Open Source Governance in Highly Regulated CompaniesOpen Source Governance in Highly Regulated Companies
Open Source Governance in Highly Regulated Companies
iasaglobal463 vues
A tale of two cities: Merging Yahoo and Aol’s open source programs par Ashley Wolf
A tale of two cities: Merging Yahoo and Aol’s open source programsA tale of two cities: Merging Yahoo and Aol’s open source programs
A tale of two cities: Merging Yahoo and Aol’s open source programs
Ashley Wolf222 vues
Exploring Open Source Licensing par Stefano Fago
Exploring Open Source LicensingExploring Open Source Licensing
Exploring Open Source Licensing
Stefano Fago329 vues
OpenChain Monthly Meeting (US / Europe) 2023-01-03 par Shane Coughlan
OpenChain Monthly Meeting (US / Europe) 2023-01-03OpenChain Monthly Meeting (US / Europe) 2023-01-03
OpenChain Monthly Meeting (US / Europe) 2023-01-03
Shane Coughlan76 vues
apidays LIVE Paris 2021 - The GDPR Developer Guide by Jerome Gorin, CNIL par apidays
apidays LIVE Paris 2021 - The GDPR Developer Guide by Jerome Gorin, CNIL apidays LIVE Paris 2021 - The GDPR Developer Guide by Jerome Gorin, CNIL
apidays LIVE Paris 2021 - The GDPR Developer Guide by Jerome Gorin, CNIL
apidays1.3K vues
Open Source Insight: Security Breaches and Cryptocurrency Dominating News par Black Duck by Synopsys
Open Source Insight: Security Breaches and Cryptocurrency Dominating NewsOpen Source Insight: Security Breaches and Cryptocurrency Dominating News
Open Source Insight: Security Breaches and Cryptocurrency Dominating News
OpenBrighton Event - Nov 2014 par Paolo Vecchi
OpenBrighton Event - Nov 2014OpenBrighton Event - Nov 2014
OpenBrighton Event - Nov 2014
Paolo Vecchi118 vues
Open Brighton - Open Source and your business par Omnis Systems
Open Brighton - Open Source and your businessOpen Brighton - Open Source and your business
Open Brighton - Open Source and your business
Omnis Systems255 vues
OpenChain @ RIOS Open-Source Hardware IP Licensing and Policy Workshop par Shane Coughlan
OpenChain @ RIOS Open-Source Hardware IP Licensing and Policy WorkshopOpenChain @ RIOS Open-Source Hardware IP Licensing and Policy Workshop
OpenChain @ RIOS Open-Source Hardware IP Licensing and Policy Workshop
Shane Coughlan51 vues
Why open source is good for your economy par Dirk Riehle
Why open source is good for your economyWhy open source is good for your economy
Why open source is good for your economy
Dirk Riehle565 vues
Open Source Insight: Samba Vulnerability, Connected Car Risks, and Are You R... par Black Duck by Synopsys
Open Source Insight: Samba Vulnerability, Connected Car Risks,  and Are You R...Open Source Insight: Samba Vulnerability, Connected Car Risks,  and Are You R...
Open Source Insight: Samba Vulnerability, Connected Car Risks, and Are You R...
OSS - enterprise adoption strategy and governance par Prabir Kr Sarkar
OSS -  enterprise adoption strategy and governanceOSS -  enterprise adoption strategy and governance
OSS - enterprise adoption strategy and governance
Prabir Kr Sarkar307 vues

Plus de Shane Coughlan

FOSSLight Community Day 2023-11-30 par
FOSSLight Community Day 2023-11-30FOSSLight Community Day 2023-11-30
FOSSLight Community Day 2023-11-30Shane Coughlan
7 vues18 diapositives
From One Standard to a Family - Taiwan Work Group - 2023-08-15.pptx par
From One Standard to a Family - Taiwan Work Group - 2023-08-15.pptxFrom One Standard to a Family - Taiwan Work Group - 2023-08-15.pptx
From One Standard to a Family - Taiwan Work Group - 2023-08-15.pptxShane Coughlan
46 vues15 diapositives
OpenChain Japan Work Group Meeting #28 - 2023-07-11 par
OpenChain Japan Work Group Meeting #28 - 2023-07-11OpenChain Japan Work Group Meeting #28 - 2023-07-11
OpenChain Japan Work Group Meeting #28 - 2023-07-11Shane Coughlan
50 vues32 diapositives
OpenChain Legal Work Group - 2023-06-29 par
OpenChain Legal Work Group - 2023-06-29OpenChain Legal Work Group - 2023-06-29
OpenChain Legal Work Group - 2023-06-29Shane Coughlan
134 vues7 diapositives
OpenChain Webinar #53 – OpenSCA par
OpenChain Webinar #53 – OpenSCAOpenChain Webinar #53 – OpenSCA
OpenChain Webinar #53 – OpenSCAShane Coughlan
127 vues19 diapositives
OpenChain Korea Work Group Meeting #18 par
OpenChain Korea Work Group Meeting #18OpenChain Korea Work Group Meeting #18
OpenChain Korea Work Group Meeting #18Shane Coughlan
86 vues17 diapositives

Plus de Shane Coughlan(20)

From One Standard to a Family - Taiwan Work Group - 2023-08-15.pptx par Shane Coughlan
From One Standard to a Family - Taiwan Work Group - 2023-08-15.pptxFrom One Standard to a Family - Taiwan Work Group - 2023-08-15.pptx
From One Standard to a Family - Taiwan Work Group - 2023-08-15.pptx
Shane Coughlan46 vues
OpenChain Japan Work Group Meeting #28 - 2023-07-11 par Shane Coughlan
OpenChain Japan Work Group Meeting #28 - 2023-07-11OpenChain Japan Work Group Meeting #28 - 2023-07-11
OpenChain Japan Work Group Meeting #28 - 2023-07-11
Shane Coughlan50 vues
OpenChain Legal Work Group - 2023-06-29 par Shane Coughlan
OpenChain Legal Work Group - 2023-06-29OpenChain Legal Work Group - 2023-06-29
OpenChain Legal Work Group - 2023-06-29
Shane Coughlan134 vues
OpenChain Webinar #53 – OpenSCA par Shane Coughlan
OpenChain Webinar #53 – OpenSCAOpenChain Webinar #53 – OpenSCA
OpenChain Webinar #53 – OpenSCA
Shane Coughlan127 vues
OpenChain Korea Work Group Meeting #18 par Shane Coughlan
OpenChain Korea Work Group Meeting #18OpenChain Korea Work Group Meeting #18
OpenChain Korea Work Group Meeting #18
Shane Coughlan86 vues
OpenChain Japan Work Group - Meeting 27 par Shane Coughlan
OpenChain Japan Work Group - Meeting 27OpenChain Japan Work Group - Meeting 27
OpenChain Japan Work Group - Meeting 27
Shane Coughlan109 vues
FOSSLight at the OpenChain Mini-Summit May 2023 par Shane Coughlan
FOSSLight at the OpenChain Mini-Summit May 2023FOSSLight at the OpenChain Mini-Summit May 2023
FOSSLight at the OpenChain Mini-Summit May 2023
Shane Coughlan232 vues
OpenChain Mini-Summit 2023 - State of Tooling in Open Source Automation par Shane Coughlan
OpenChain Mini-Summit 2023 - State of Tooling in Open Source AutomationOpenChain Mini-Summit 2023 - State of Tooling in Open Source Automation
OpenChain Mini-Summit 2023 - State of Tooling in Open Source Automation
Shane Coughlan245 vues
How the Linux Foundation Standards for Compliance and Security will Fix Your ... par Shane Coughlan
How the Linux Foundation Standards for Compliance and Security will Fix Your ...How the Linux Foundation Standards for Compliance and Security will Fix Your ...
How the Linux Foundation Standards for Compliance and Security will Fix Your ...
Shane Coughlan51 vues
Standardizing Open Source Risk - LLW - 2023-04 par Shane Coughlan
Standardizing Open Source Risk - LLW - 2023-04Standardizing Open Source Risk - LLW - 2023-04
Standardizing Open Source Risk - LLW - 2023-04
Shane Coughlan29 vues
OpenChain Education Work Group - 2023-04-13 par Shane Coughlan
OpenChain Education Work Group - 2023-04-13OpenChain Education Work Group - 2023-04-13
OpenChain Education Work Group - 2023-04-13
Shane Coughlan33 vues
The State of Open Source for Software Alliance Germany 2023-04-14 par Shane Coughlan
The State of Open Source for Software Alliance Germany 2023-04-14The State of Open Source for Software Alliance Germany 2023-04-14
The State of Open Source for Software Alliance Germany 2023-04-14
Shane Coughlan59 vues
OpenChain North America and Europe Meeting - 2023-04-04 par Shane Coughlan
OpenChain North America and Europe Meeting - 2023-04-04OpenChain North America and Europe Meeting - 2023-04-04
OpenChain North America and Europe Meeting - 2023-04-04
Shane Coughlan24 vues
OpenChain Webinar #50 - An Overview of SPDX 3.0 par Shane Coughlan
OpenChain Webinar #50 - An Overview of SPDX 3.0OpenChain Webinar #50 - An Overview of SPDX 3.0
OpenChain Webinar #50 - An Overview of SPDX 3.0
Shane Coughlan395 vues

Dernier

Top-5-production-devconMunich-2023.pptx par
Top-5-production-devconMunich-2023.pptxTop-5-production-devconMunich-2023.pptx
Top-5-production-devconMunich-2023.pptxTier1 app
9 vues40 diapositives
The Era of Large Language Models.pptx par
The Era of Large Language Models.pptxThe Era of Large Language Models.pptx
The Era of Large Language Models.pptxAbdulVahedShaik
7 vues9 diapositives
Introduction to Git Source Control par
Introduction to Git Source ControlIntroduction to Git Source Control
Introduction to Git Source ControlJohn Valentino
7 vues18 diapositives
Dapr Unleashed: Accelerating Microservice Development par
Dapr Unleashed: Accelerating Microservice DevelopmentDapr Unleashed: Accelerating Microservice Development
Dapr Unleashed: Accelerating Microservice DevelopmentMiroslav Janeski
15 vues29 diapositives
EV Charging App Case par
EV Charging App Case EV Charging App Case
EV Charging App Case iCoderz Solutions
9 vues1 diapositive
JioEngage_Presentation.pptx par
JioEngage_Presentation.pptxJioEngage_Presentation.pptx
JioEngage_Presentation.pptxadmin125455
8 vues4 diapositives

Dernier(20)

Top-5-production-devconMunich-2023.pptx par Tier1 app
Top-5-production-devconMunich-2023.pptxTop-5-production-devconMunich-2023.pptx
Top-5-production-devconMunich-2023.pptx
Tier1 app9 vues
Dapr Unleashed: Accelerating Microservice Development par Miroslav Janeski
Dapr Unleashed: Accelerating Microservice DevelopmentDapr Unleashed: Accelerating Microservice Development
Dapr Unleashed: Accelerating Microservice Development
JioEngage_Presentation.pptx par admin125455
JioEngage_Presentation.pptxJioEngage_Presentation.pptx
JioEngage_Presentation.pptx
admin1254558 vues
Team Transformation Tactics for Holistic Testing and Quality (Japan Symposium... par Lisi Hocke
Team Transformation Tactics for Holistic Testing and Quality (Japan Symposium...Team Transformation Tactics for Holistic Testing and Quality (Japan Symposium...
Team Transformation Tactics for Holistic Testing and Quality (Japan Symposium...
Lisi Hocke35 vues
How To Make Your Plans Suck Less — Maarten Dalmijn at the 57th Hands-on Agile... par Stefan Wolpers
How To Make Your Plans Suck Less — Maarten Dalmijn at the 57th Hands-on Agile...How To Make Your Plans Suck Less — Maarten Dalmijn at the 57th Hands-on Agile...
How To Make Your Plans Suck Less — Maarten Dalmijn at the 57th Hands-on Agile...
Stefan Wolpers42 vues
predicting-m3-devopsconMunich-2023.pptx par Tier1 app
predicting-m3-devopsconMunich-2023.pptxpredicting-m3-devopsconMunich-2023.pptx
predicting-m3-devopsconMunich-2023.pptx
Tier1 app8 vues
Generic or specific? Making sensible software design decisions par Bert Jan Schrijver
Generic or specific? Making sensible software design decisionsGeneric or specific? Making sensible software design decisions
Generic or specific? Making sensible software design decisions
Navigating container technology for enhanced security by Niklas Saari par Metosin Oy
Navigating container technology for enhanced security by Niklas SaariNavigating container technology for enhanced security by Niklas Saari
Navigating container technology for enhanced security by Niklas Saari
Metosin Oy15 vues
Top-5-production-devconMunich-2023-v2.pptx par Tier1 app
Top-5-production-devconMunich-2023-v2.pptxTop-5-production-devconMunich-2023-v2.pptx
Top-5-production-devconMunich-2023-v2.pptx
Tier1 app8 vues
aATP - New Correlation Confirmation Feature.pptx par EsatEsenek1
aATP - New Correlation Confirmation Feature.pptxaATP - New Correlation Confirmation Feature.pptx
aATP - New Correlation Confirmation Feature.pptx
EsatEsenek1205 vues

Open Compliance Summit 2022 – State of the Union from Mike Dolan, SVP and GM of Projects at The Linux Foundation

  • 1. State of the Union Open Compliance Summit 2022 Mike Dolan, SVP and GM of Projects 1
  • 2. 15+ years ago, we starting collaborating to reduce issues with open source license compliance What license is this code? What license(s) are in my code? What license(s) are in this code you gave me? 2007 2007 2010 Legal and developer education Scan and document SBOMs 2
  • 3. 15+ years ago, we starting collaborating to reduce issues with open source license compliance What license is this code? What license(s) are in my code? What license(s) are in this code you gave me? 2007 2007 2010 Scan and document SBOMs I know what’s in this code! Success Legal and developer education 3
  • 4. These efforts used transparency to solve our challenges with open source compliance Greater transparency enables decision makers to make better decisions With open source software, we weren’t concerned about confidential or proprietary information in the open source software 4
  • 5. The business reason for open compliance was cost effective legal risk management ● We were concerned about legal loss events that could impact our companies ● License non-compliance could present various loss events: ○ Lawsuits ○ Damage to reputation ○ Business interruption due to injunctions ● “Compliance” became a quasi-legal concern (but it’s not just that anymore) 5
  • 6. New! WebAssembly for legal professionals https://www.linuxfoundation.org/research/webassembly-for-legal-professionals English, Japanese (日本), Chinese (中国人) available 6
  • 8. As our challenges evolved, we worked on new solutions… by adding more transparency. 8
  • 9. We then openly collaborated to reduce issues with open source management What license is this code? What license(s) are in my code? What license(s) are in this code you gave me? How do I manage my license information? 2007 2007 2010 Educate others Scan and document SBOMs SBOM management 2015 How do I manage my supply chain? Process Standards 2015 9
  • 10. We built open source management groups (OSPOs) to help scale risk management ● OSPOs started as “the open source group” in many companies ● Ultimately OSPOs were designed to manage risk for the company ○ Risk of licensing issues in products ○ Risk of licensing issues in supplier artifacts ○ Risk of inappropriate product dependencies ○ Community engagement risks https://todogroup.org/guides/ 10
  • 11. The legal risks have continued to evolve … requiring evolution in risk management ● Losses from trolls ○ Copyright trolls ○ Patent trolls ● We worked on new solutions ○ Developer Certificate of Origin (2004) ○ Linux Kernel Enforcement Statement (2020) ○ Collaborations with Unified Patents and Open Invention Network https://www.kernel.org/doc/html/latest/process/kernel-enforcement-statement.html 11
  • 12. We can work together even on complex issues 12 https://lore.kernel.org/netdev/Ye6jCQm7z0Yr3bqA@salvia/T/
  • 13. With the legal risks managed, open source was able to grow … massively https://www.sonatype.com/state-of-the-software-supply-chain/open-source-supply-demand-security 13
  • 14. And now we face cybersecurity risk, and a need for open source security risk management https://www.sonatype.com/state-of-the-software-supply-chain/open-source-supply-demand-security 14
  • 15. And now we are openly collaborating to extend license risk management tools, processes, and standards to address security risks What are we building into our product? How do I share what packages are in this? How do I verify this is the package you said it is? CI/CD Build Systems SBOMs Attestation service How do I manage my supply chain? Process Standards SLSA Is that OSS community security focused? Scorecard What is the integrity? Levels of assurance S2C2F 15
  • 16. Our existing risk management standards are evolving to address security risk mitigation requirements 16 https://www.linuxfoundation.org/blog/the-openchain-security-assurance- specification-1.1-now-available https://www.chainguard.dev/unchained/whats-new-in-spdx-2-3 Major Changes in SPDX 2.3 Security: One of the main uses of SBOMs today is dependency and vulnerability management. This version introduces advisory, fix, URL and SWID as categories in the security identifiers to link the package to additional security context. GitBOM: Joining the list of persistent identifiers comes gitoid, the identifier used by the GitBOM project to cryptographically track where a package fits in the dependency tree.
  • 17. New investments in OSPOs are needed to help CISO teams address open source cybersecurity risks. Licensing Risks Security Risks OSPOs that partner with product security teams help define policies, processes, build system requirements, and supply chain transparency for managing security risk in open source and commercial product systems 17