Skip to main content


OpenChain Summit 2022 – Full Recording

By Featured, News

The OpenChain Project held its annual an all-day summit adjacent to Open Source Summit Europe (OSS EU) on the 14th of September. This event featured news from our latest board meeting (including the decision to launch our new security specification), a deep dive into a significant new automation landscape to assist with license, security and export control compliance, SBOM discussions and more.

Check out the full recording below alongside copies of our excellent keynote presentation from Andrew Katz of Orcro and the automation landscape capability map presentation delivered by Jan Thielscher of EACG on behalf of the OpenChain Reference Tooling Work Group.

Here are the key takeaways:

  • The OpenChain Project now maintains a family of specifications to build trust in the supply chain. We started with license compliance and now we have a sister standard for security.
  • Open source automation for open source license, security and export control compliance is getting a clear capability map to guide investment of resources and save time.
  • Software Bill of Materials (SBOM) has seen great progress in the last year or two, and the OpenChain Telco Work Group is working on very practical items related to market adoption.
  • Open source licensing discussions have become somewhat stale and there is scope for considering the future of open source licensing approaches.

Andrew’s Keynote Slides

The Automation Capability Map Presentation Slides

OpenChain Security Assurance Specification 1.0 Now Available

By Featured, News

The OpenChain Security Assurance Specification 1.0 is now available. This is the result of over one year of work throughout the global OpenChain community. It is applicable to an open source management activity related to security compliance. We regard this as adjacent but different to license compliance.

The OpenChain Project’s core mission is to build trust in the supply chain. Our flagship specification, ISO/IEC 5230:2020, is International Standard for Open Source Compliance and builds trust in that domain. It defines the key requirements of a quality open source compliance program. The natural next step is to identify the key requirements of a quality open source security assurance program.

Initially the scope of this specification is limited to ensuring that an organization vets open source with regards to known publicly available security vulnerability issues (e.g., CVEs, GitHub dependency alerts, package manager alerts and so on). The security assurance specification’s scope may expand over time based on community feedback.

This specification is built from the Security Assurance Reference Guide 2.0 (Release Candidate 1) published on 2022-03-28. That completed reference specification document went through a final approval process via editing on our specification list and calls, before graduating to a governing board vote to transform into this published security specification on 2022-09-14.

Next Steps

We will proceed to ISO/IEC JTC-1 PAS submission with an estimated completion date of circa mid-2023. In the meantime, our security assurance specification is ready for market adoption as a de facto standard.

Prior to the ISO/IEC JTC-1 PAS submission, we have some time for sanity-checks and minor adjustments. We begin that process today and will complete it on October 4th 2022 (2022-10-04). There are two tasks for the community ahead of that date:

  1. Check our Security Assurance Specification 1.0 against the Security Assurance Reference Guide 2.0 (Release Candidate 1) to ensure Sections 1, 2 and 3 match. You can find the Security Assurance Reference Guide 2.0 (Release Candidate 1) here:
  2. Check the OpenChain Security Assurance Specification 1.0 for any typographical errors that have snuck through our existing editing process. You can find the document linked at the start of this email or here:

You can submit issues highlighting areas you would like review on our GitHub repository. Please note, due to this being a specification, we will only accept issues for discussion. We will not accept pull requests or remixes.

In the coming days we will have broader distribution of the specification launch, including on social media and via blog posts. However, you can begin sharing it immediately with your teams and peers. 

Please note:

The scope of this reference specification may expand over time based on community feedback. However, comments and notes should be confined to the existing scope at this juncture. Our specification is complete barring minor adjustments for readability, editing and clarity. 

Please note:

This specification is licensed under Creative Commons Attribution License 4.0 (CC-BY-4.0). You can submit issues highlighting areas you would like review on our GitHub repository. Due to this being a specification, we will only accept issues for discussion. We will not accept pull requests or remixes. You can get more involved with our work beyond submitting issues via our community calls, mailing lists and events:

OpenChain Summit 2022 – Dublin, Ireland – September 14th

By Featured, News

The OpenChain Project will hold an all-day summit adjacent to Open Source Summit Europe (OSS EU) on the 14th of September. This event will take place 3 minutes walk from the OSS EU venue. It is open to all parties regardless of LF Membership.


  • Orion Room 1 @ Spencer Hotel, Excise Walk, International Financial Services Centre, Dublin 1, D01 X4C9, Ireland
  • 3 minutes from Dublin Convention Center (OSS EU venue).
  • Google Map link

Provisional Agenda

  • 11:00 to 11:30: Opening Keynote, Andrew Katz of Orcro
  • 11:30 to 12:30: The OpenChain License Compliance and Security Compliance specification material
  • 12:30 to 14:30: Open source tooling for open source compliance (automation for everyone)
  • 14:30 to 15:30: SBOM Deep Dive – Telco and More
  • 15:30 to 16:30: OSPO and other activities (theory, practice and what is actually happening in market)
  • 16:30 to 17:00: Summary Session

Join via Zoom:

External Webinar: OSS License Compliance: Practical Strategies for OpenChain ISO/IEC 5230:2020

By Featured, News

The OpenChain Project had the pleasure of working with the FOSSA team for another webinar explaining aspects of open source license compliance. This time, the practical way you actually adopt ISO/IEC 5230, the international standard for compliance.

Check out the webinar:

Get the slide deck:

While you are reviewing FOSSA webinars you may also want to check out ‘The Lawyer’s Guide to OSS License Compliance Tools, Featuring Heather Meeker.’ Heather has long been one of the main lawyers providing useful, practical insight into industry optimization around open source. You will find it here:

Call to Action: Playbooks – Meeting #2 – 2022-08-17

By Featured, News

We recently held our second meeting to review the OpenChain Playbooks. Above you will find the full recording.

For context: we are collaboratively editing version 2 of these documents at this link:

Our focus during this call was the small company playbook here:

The work we did on this playbook substantially refined the approach in the early parts of the document and will be merged into the other documents (for medium and large companies) ahead of our next meeting in around a week.

Your contributions and comments are most welcome. This is a great opportunity to brief and encourage strategic management understanding and support of effective, efficient compliance.

Four Hyundai Motor Group Companies Announce Adoption of the ISO International Standard for Open Source Compliance

By Featured, News

Four Hyundai Motor Group companies, joint certification of the ISO international standard for open source compliance
– Acquired ISO certifications of four companies simultaneously through collaboration of Hyundai Motor Company, Kia, Hyundai Mobis, and Hyundai Autoever … The industry’s first the international standard for open source compliance(ISO/IEC 5230:2020) joint certification … Securing public confidence in software and increasing utilization through systematic management of the entire supply chain
– Provides a comprehensive portal and user guide to support developers in the mobility field and expand the ecosystem
– “Beyond the group, we will lead the expansion and development of the open source ecosystem throughout the automobile industry”

The four Hyundai Motor Group companies were internationally recognized for having a systematic management system (compliance) for the use of open source.

Hyundai Motor Group announced on the 17th that it has simultaneously acquired the open source compliance-related standard certification(ISO/IEC 5230) from the International Organization for Standardization(ISO) through collaboration with four group companies(Hyundai Motor Company, Kia, Hyundai Mobis, and Hyundai Autoever) that make up the automotive supply chain.

In the last 20 years, the International Organization for Standardization and the International Electrotechnical Commission (IEC) adopted the standard of the ‘Open Chain Project’ led by the Linux Foundation, a non-profit organization in the United States, as the only international standard related to open source software compliance (ISO/IEC 5230). The International Organization for Standardization evaluates whether the certification is achieved by examining the appropriateness of establishing open source policies and processes, establishing a compliance system, and meeting the standards for developer education and evaluation.

When using open source for software development, there are advantages such as shortening the development period and reducing costs, but it is important to systematically manage the use of open source because problems such as security vulnerabilities and copyright disputes may occur.

Hyundai Motor Group’s open source software compliance international standard certification is characterized by the cooperation of four companies, Hyundai Motor, Kia, Hyundai Mobis, and Hyundai Autoever, that make up the automotive supply chain.

The group companies specialized in software development, component packaging, and mass production obtained ISO certification through collaboration, securing public confidence in open source software across the automotive industry for the first time in the industry.

Through a business agreement with National IT Industry Promotion Agency (NIPA), Hyundai Motor Group has expanded its open source management scope to the supply chain while providing (1) establishment of open source management system and education for experts training and (2) open source license verification service to supporting suppliers. The Hyundai Motor Group open source compliance system will be provided in the form of a comprehensive portal at the end of this month.

In addition, Hyundai Motor Group will strengthen its support by providing a guide to users who want to utilize it, and will continue to expand the open source ecosystem and promote win-win cooperation with partners in the future.

“As the importance of open source in the future mobility field is increasing day by day, we will take the lead in expanding and developing the open source ecosystem across the supply chain in automotive industry beyond the group,” said Yonghwa Kim, vice president of Hyundai Motor Company and Kia R&D Division.

Meanwhile, the Hyundai Motor Group is continuously expanding its software support activities throughout the mobility industry by providing open APIs through the Hyundai Motor Company, Kia, and Genesis Developers platforms. 

OpenChain Onboarding Mini-Summit – 2022-08-01

By Featured, News

We discussed one of the most critical aspects of our project outside of the ISO/IEC 5230 standard: how do we onboard people? It covered outreach, what happens when people arrive on our site, and how we arrange community support.

We looked for input around:
(1) How should we “market” OpenChain?
(2) How can entry to our website and community work best for new participants?
(3) How can we do great community support regionally and globally?
(4) How should the Onboarding Committee of the project work in the future?

Nathan Kumagai, our onboarding chair, lead the discussion.

KKCompany Receives The First OpenChain ISO/IEC 5230 Third-Party Certification in Taiwan

By Featured, News

KKCompany, a leading media technology group in Asia, today received the first OpenChain ISO / IEC 5230 third-party certification in Taiwan. KKCompany is cooperating with Open Culture Foundation (OCF) and Bureau Veritas to successfully meet certification requirements. Together with KKBOX, KKStream, and other relevant business units in the group, KKCompany delivers innovative products and services with open source technologies. It also sponsors open source communities and incentivizes employees to contribute their technical experiences. KKCompany will continue to support communities. With open and sharing in mind, it is committed to a trustworthy software supply chain and an open source ecosystem with technology partners.

“KKCompany believes in the power of technology to provide solutions and tackle challenges faced by various industries today,” said KKCompany Group President & COO Steve Wang. “Empowering creators has always been the core of our philosophy. We value the creations of creators and developers. This OpenChain ISO/IEC 5230 certification further demonstrated our commitment to creators and developers.”

The OpenChain Project was established in 2016 by The Linux Foundation. Its mission is to increase trust in the global supply chain around the use of open source software. The project is best known for developing ISO/IEC 5230, the International Standard for open source license compliance. The ISO/IEC standard, released in 2020, has helped to make process for managing open source more effective and efficient, reducing resources spent and increasing the speed of products to market.

“KKCompany’s OpenChain ISO/IEC 5230 third-party certification underlines their commitment to operating a quality open source compliance program,” said Shane Coughlan, OpenChain General Manager, “The processes they have adopted provide substantial benefit in reducing errors, fixing any issues that arise, and decreasing time spent bringing products and services to market. KKCompany is the first company in Taiwan to obtain third-party certification, a step that illustrates how they value creator rights and support open source technologies. With leadership from companies like KKCompany, we aspire to expand our coverage in Asia further into the supply chain, and promote excellence in open innovation.”

As supply chains in tech industries become fragmented, vertical and horizontal collaborations have become the norm. Enterprises need to monitor if their source codes comply with licensing terms, and also ensure compliances from suppliers. With OpenChain ISO/IEC 5230 and third-party audits, it is possible to integrate open source compliance into business processes. This practice reduces risks on operation and reputation, and manages software components easier.

OCF has been promoting open source codes for years. “Open source codes do not ‘reinvent the wheel’,” said OCF Chief Executive Officer Singing Li. “Open and sharing are a global trend that enhances enterprise development efficiency. OCF serves as an advisor to KKCompany in the OpenChain ISO/IEC 5230 certification process. We support the group to pass compliance and audit requirements. It’s a milestone for Taiwanese companies to align with international industry chains.”

OpenChain ISO/IEC 5230 is the first and only International Standard for open source license compliance. The standard allows companies of all sizes and sectors to adopt the key requirements of a quality open source compliance program in order to reduce inherent risk in supply chain management.

Pascal LE-RAY, the General Manager of Bureau Veritas Consumer Products Services Technology Taiwan, said, “Bureau Veritas has become the first OpenChain certifier in Greater China in 2021. We are delighted to have this opportunity to support KKCompany to successfully obtain the first ISO/IEC 5230 Certificate in Taiwan, which demonstrates that KKCompany’s capabilities in open source application is not only proven, but also effectively enhances the sense of trust within the industry. This cooperation represents collaboration between Bureau Veritas’ deep expertise and experience, and KKCompany’s effective compliance practices. Furthermore, OpenChain aids open source transparency by using software bill of material to identify and manage security vulnerabilities that synergize with cybersecurity standards to reduce compliance and security risks effectively. We look forward to continuing to promote the development of open source technology and develop an open source ecosystem in the future.”

About KKCompany

KKCompany is Asia’s leading media technology group headquartered in Taipei, Taiwan. The company’s mission is to make transformational technology accessible, affordable and enjoyable to the burgeoning global creator economy. KKCompany Receives the First OpenChain ISO/IEC 5230 International Open Source Third-Party Certification in Taiwan.For more information and updates, please visit our [Website] / [Blog]