SlideShare a Scribd company logo
2nd meeting open
source tooling for open
source compliance work
group
Cpoyright © the open source tooling group 2019
Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt
Agenda
Top Name Actors
1. News All
2. Introduction of the existing work All
3. Areas to focus on Oliver
4. Next steps All
Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt
News
• We have a logo
• First version of the website is online https://oss-compliance-tooling.org/
• Presentation template available in impress format: https://github.com/Open-Source-Compliance/Sharing-
creates-value/tree/master/Templates
• New contribution from Michael Picht Vulas and CLA assistant were added to the tools – Thank you Michael
• Events
• Past Events
• OSS Summit NA
• Upcoming Events
• OSS working team meeting of BITKOM
• OSS Summit Europe in Lyon
Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt
Agenda
Top Name Actors
1. News All
2. Introduction of the existing work All
3. Areas to focus on Oliver
4. Next steps All
Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt
Integrated, automated – end to end OSS compliance
toolchain made with OSS
To build an integrated end to end compliance toolchain is not about to build a monolithic monster, it is
about to use current available Open Source tools and define and implement the needed APIs/Data
structures they need to provide, in order to plug them into the current set up CI/CD workflow and to
enable them to trigger other Open Source compliance tools in a way that they seamlessly interact which
each other and potential external data sources.
The already existing projects remain independent projects
We are making turn-key Open Source tooling for Open Source Compliance
Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt
Big Picture – Integrated Compliance Toolchain
CI / CD Infrastructure
License &
Copyright
Scanner
Component
Analysis
Service
Compliance
artifact
consistency
Component
inventory
(Metadata
Repository)
Dependency
resolver
Source
package
downloader
Container
content
resolver
License
Obligations
Database
Policy
checker
(Compliance
Checker)
Obligation
fulfillment
Build Tools
Continous IntegrationArtifact Repository
Source Code Repo
outbound
software
&
compliance
artifacts
FOSS
Compliance
Bundle
generator
Binary
analyser
Inbound
software
Public
compliance
artifact
repos
contributions
Integration layer (API/Data) Integration layer (API/Data)
Integration layer (API/Data)
Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data)
Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data)
Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt
Integrated, automated – end to end OSS compliance
toolchain made with OSS
We are making turn-key Open Source tooling for Open Source Compliance
• Identify the functional blocks required
• Identify the workflows
• Identify the required data and data flows
• Implement provide the needed APIs (as contributions)
• Provide the glue Code
• Provide easy to deploy building blocks
• Documentation
• Spread the word
Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt
UML Big Picture View
https://github.com/Open-Source-Compliance/Sharing-
creates-value/blob/master/Tooling-
Landscape/Unanimous-
Understanding/OSS_Tooling_Landscape_UML_Deploy.pl
antuml
Glossary
https://github.com/Open-Source-Compliance/Sharing-
creates-value/blob/master/Tooling-
Landscape/Unanimous-Understanding/OSS-Tooling-
Landscape-Glossary.md
Introduction of the existing work
Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt
Introduction of the existing work
Process flows:
https://github.com/Open-Source-
Compliance/Sharing-creates-
value/tree/master/Tooling-Landscape/Unanimous-
Understanding/Process%20Flows
Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt
Data Model:
https://github.com/Open-Source-
Compliance/Sharing-creates-
value/tree/master/Tooling-Landscape/Unanimous-
Understanding/Data%20Structures
Introduction of the existing work
Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt
Agenda
Top Name Actors
1. News All
2. Introduction of the existing work All
3. Areas to focus on Oliver
4. Next steps All
Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt
Areas to focus on
Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt
Big Picture – Integrated Compliance Toolchain
CI / CD Infrastructure
License &
Copyright
Scanner
Component
Analysis
Service
Compliance
artifact
consistency
Component
inventory
(Metadata
Repository)
Dependency
resolver
Source
package
downloader
Container
content
resolver
License
Obligations
Database
Policy
checker
(Compliance
Checker)
Obligation
fulfillment
Build Tools
Continous IntegrationArtifact Repository
Source Code Repo
outbound
software
&
compliance
artifacts
FOSS
Compliance
Bundle
generator
Binary
analyser
Inbound
software
Public
compliance
artifact
repos
contributions
Integration layer (API/Data) Integration layer (API/Data)
Integration layer (API/Data)
Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data)
Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data)
License: CC-BY-SA-4.0
Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt
Big Picture – Integrated Compliance Toolchain
Instance
CI / CD Infrastructure
Component
Analysis
Service
Compliance
artifact
consistency
Build Tools
Continous IntegrationArtifact Repository
Source Code Repo
outbound
software
&
compliance
artifacts
BANG
Inbound
software
contributions
Integration layer (API/Data) Integration layer (API/Data)
Integration layer (API/Data)
Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data)
Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data)
ScanCode
Dependency resolver Binary analyserContainer content resolver Source package downloader Component inventory
License & Copyright Scanner
Policy checker Obligation fulfillment
FOSS Compliance
Bundle generator
License Obligations
Database
License Classifier
Public
compliance
artifact repos
Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt
Next steps
Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt
Restructuring of the repo sharing-creates-value
Move to OSS-compliance-work-
results a new repo of the group
Open-Source-Compliance
Update and move content to
OSS-compliance-work-results a
new repo of the group Open-
Source-Compliance
Preparing a slide deck with an overview of the tooling working group – that can be used when someone wants to give a
presentation about the tooling working group
2019 Licensed under CC-BY-SA-4.0 Oliver Fendt
User stories
We are making turn-key Open Source tooling for Open Source Compliance
• As a Software developer I …
• As a compliance officer I …
• As a product owner I …
• As a legal assessor I …
• As a compliance assistant I …
• ….
Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt
Next Meeting
Date: 18th of Sept
Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt
Links / Communication
Github:
https://github.com/Open-Source-Compliance/Sharing-creates-value
Slack:
https://join.slack.com/t/ossbasedcompl-
bhx9742/shared_invite/enQtNzA5OTc3OTAwMjExLWNhYWVkZDk2Y2RlNDI4ODI2N
zQyNDU5ZWE4ODRmZWI1ZmM1MzA4ZTc2MTdkZGFhMzc2NmUyODRhNDZjNWI
5Njc
Mailing List:
Subscription page: https://groups.io/g/oss-based-compliance-tooling
Email address: oss-based-compliance-tooling@groups.io
Where to communicate what?
Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt
Credits
Picture by Splitshireon
https//pixabay.com license:
pixabay license

More Related Content

What's hot

Whats new in ep3
Whats new in ep3Whats new in ep3
Whats new in ep3
Jonathan Beardsley
 
Overview of the OpenChain Reference Tooling Work Group, OW2online20, June 2020
Overview of the OpenChain Reference Tooling Work Group, OW2online20, June 2020Overview of the OpenChain Reference Tooling Work Group, OW2online20, June 2020
Overview of the OpenChain Reference Tooling Work Group, OW2online20, June 2020
OW2
 
Whats new in the OpenText EcoSystem Products for EP2
Whats new in the OpenText EcoSystem Products for EP2Whats new in the OpenText EcoSystem Products for EP2
Whats new in the OpenText EcoSystem Products for EP2
Jonathan Beardsley
 
What's New in Content Services - Release 16 EP4
What's New in Content Services - Release 16 EP4What's New in Content Services - Release 16 EP4
What's New in Content Services - Release 16 EP4
OpenText
 
apidays LIVE Paris 2021 - Building an Accessible API Spec with Traditional En...
apidays LIVE Paris 2021 - Building an Accessible API Spec with Traditional En...apidays LIVE Paris 2021 - Building an Accessible API Spec with Traditional En...
apidays LIVE Paris 2021 - Building an Accessible API Spec with Traditional En...
apidays
 
Cloud-native Integration in the Oracle Cloud
Cloud-native Integration in the Oracle CloudCloud-native Integration in the Oracle Cloud
Cloud-native Integration in the Oracle Cloud
Sven Bernhardt
 
10 reasons to upgrade OpenText Documentum
10 reasons to upgrade OpenText Documentum10 reasons to upgrade OpenText Documentum
10 reasons to upgrade OpenText Documentum
OpenText
 

What's hot (7)

Whats new in ep3
Whats new in ep3Whats new in ep3
Whats new in ep3
 
Overview of the OpenChain Reference Tooling Work Group, OW2online20, June 2020
Overview of the OpenChain Reference Tooling Work Group, OW2online20, June 2020Overview of the OpenChain Reference Tooling Work Group, OW2online20, June 2020
Overview of the OpenChain Reference Tooling Work Group, OW2online20, June 2020
 
Whats new in the OpenText EcoSystem Products for EP2
Whats new in the OpenText EcoSystem Products for EP2Whats new in the OpenText EcoSystem Products for EP2
Whats new in the OpenText EcoSystem Products for EP2
 
What's New in Content Services - Release 16 EP4
What's New in Content Services - Release 16 EP4What's New in Content Services - Release 16 EP4
What's New in Content Services - Release 16 EP4
 
apidays LIVE Paris 2021 - Building an Accessible API Spec with Traditional En...
apidays LIVE Paris 2021 - Building an Accessible API Spec with Traditional En...apidays LIVE Paris 2021 - Building an Accessible API Spec with Traditional En...
apidays LIVE Paris 2021 - Building an Accessible API Spec with Traditional En...
 
Cloud-native Integration in the Oracle Cloud
Cloud-native Integration in the Oracle CloudCloud-native Integration in the Oracle Cloud
Cloud-native Integration in the Oracle Cloud
 
10 reasons to upgrade OpenText Documentum
10 reasons to upgrade OpenText Documentum10 reasons to upgrade OpenText Documentum
10 reasons to upgrade OpenText Documentum
 

Similar to OpenChain Tooling Work Group Meeting #2 - Agenda Slides

Open Source Compliance Toolchain - A Proposal
Open Source Compliance Toolchain - A ProposalOpen Source Compliance Toolchain - A Proposal
Open Source Compliance Toolchain - A Proposal
Shane Coughlan
 
OpenChain Reference Tooling Work Group @ FOSDEM - February 2020
OpenChain Reference Tooling Work Group @ FOSDEM - February 2020OpenChain Reference Tooling Work Group @ FOSDEM - February 2020
OpenChain Reference Tooling Work Group @ FOSDEM - February 2020
Shane Coughlan
 
OpenChain Tooling Work Group Meeting #4 - Agenda Slides
OpenChain Tooling Work Group Meeting #4 - Agenda SlidesOpenChain Tooling Work Group Meeting #4 - Agenda Slides
OpenChain Tooling Work Group Meeting #4 - Agenda Slides
Shane Coughlan
 
OpenChain Reference Tooling Work Group in 2020
OpenChain Reference Tooling Work Group in 2020OpenChain Reference Tooling Work Group in 2020
OpenChain Reference Tooling Work Group in 2020
Shane Coughlan
 
Bosch: AN UPDATE ON OUR ACTIVITIES IN AUTOMATING OSS COMPLIANCE: A WORKING SH...
Bosch: AN UPDATE ON OUR ACTIVITIES IN AUTOMATING OSS COMPLIANCE: A WORKING SH...Bosch: AN UPDATE ON OUR ACTIVITIES IN AUTOMATING OSS COMPLIANCE: A WORKING SH...
Bosch: AN UPDATE ON OUR ACTIVITIES IN AUTOMATING OSS COMPLIANCE: A WORKING SH...
Shane Coughlan
 
Improving the software integration with the use of REST API
Improving the software integration with the use of REST APIImproving the software integration with the use of REST API
Improving the software integration with the use of REST API
Ilya Beketov
 
FOSSology & GSOC Journey
FOSSology & GSOC JourneyFOSSology & GSOC Journey
FOSSology & GSOC Journey
Gaurav Mishra
 
WEBINAR: API Clouds for Faster APIs: Leveraging Existing Assets for the API ...
WEBINAR: API Clouds for Faster APIs:  Leveraging Existing Assets for the API ...WEBINAR: API Clouds for Faster APIs:  Leveraging Existing Assets for the API ...
WEBINAR: API Clouds for Faster APIs: Leveraging Existing Assets for the API ...
Jason Bloomberg
 
June 22nd 2016 - Foundation State of the Union - London Meetup @ Red Deer
June 22nd 2016 - Foundation State of the Union - London Meetup @ Red DeerJune 22nd 2016 - Foundation State of the Union - London Meetup @ Red Deer
June 22nd 2016 - Foundation State of the Union - London Meetup @ Red Deer
Symphony Software Foundation
 
Evolve 19 | Sarah Xu & Kanika Gera | Adobe I/O - Why You Need it to Execute o...
Evolve 19 | Sarah Xu & Kanika Gera | Adobe I/O - Why You Need it to Execute o...Evolve 19 | Sarah Xu & Kanika Gera | Adobe I/O - Why You Need it to Execute o...
Evolve 19 | Sarah Xu & Kanika Gera | Adobe I/O - Why You Need it to Execute o...
Evolve The Adobe Digital Marketing Community
 
Alfresco Webinar: Jive Toolkit
Alfresco Webinar: Jive ToolkitAlfresco Webinar: Jive Toolkit
Alfresco Webinar: Jive Toolkit
Alfresco Software
 
Managing Open Source Software Supply Chains
Managing Open Source Software Supply ChainsManaging Open Source Software Supply Chains
Managing Open Source Software Supply Chains
nexB Inc.
 
Open Source governance and the Eclipse Foundation, OW2online, June 2020
Open Source governance and the Eclipse Foundation, OW2online, June 2020Open Source governance and the Eclipse Foundation, OW2online, June 2020
Open Source governance and the Eclipse Foundation, OW2online, June 2020
OW2
 
Open data vs open api
Open data vs open apiOpen data vs open api
Open data vs open api
Marjukka Niinioja
 
IoTivity Connects RVI from GENIVI's Develoment Platform to Tizen devices
IoTivity Connects RVI from GENIVI's Develoment Platform to Tizen devicesIoTivity Connects RVI from GENIVI's Develoment Platform to Tizen devices
IoTivity Connects RVI from GENIVI's Develoment Platform to Tizen devices
Samsung Open Source Group
 
Let’s Talk About the Ipro Platform
Let’s Talk About the Ipro PlatformLet’s Talk About the Ipro Platform
Let’s Talk About the Ipro Platform
Ipro Tech
 
Using SW360 for OSS Compliance Management Process - A Toshiba Case Study for ...
Using SW360 for OSS Compliance Management Process - A Toshiba Case Study for ...Using SW360 for OSS Compliance Management Process - A Toshiba Case Study for ...
Using SW360 for OSS Compliance Management Process - A Toshiba Case Study for ...
Shane Coughlan
 
INTERFACE, by apidays - Lessons learned from implementing our custom ‘Big Da...
INTERFACE, by apidays  - Lessons learned from implementing our custom ‘Big Da...INTERFACE, by apidays  - Lessons learned from implementing our custom ‘Big Da...
INTERFACE, by apidays - Lessons learned from implementing our custom ‘Big Da...
apidays
 
Serverless SAP Fiori Apps in SAP Cloud Platfrom
Serverless SAP Fiori Apps in SAP Cloud PlatfromServerless SAP Fiori Apps in SAP Cloud Platfrom
Serverless SAP Fiori Apps in SAP Cloud Platfrom
Marius Obert
 
AnyFirewall Engine v10.0 Developer Guide
AnyFirewall Engine v10.0 Developer GuideAnyFirewall Engine v10.0 Developer Guide
AnyFirewall Engine v10.0 Developer Guide
Eyeball Networks
 

Similar to OpenChain Tooling Work Group Meeting #2 - Agenda Slides (20)

Open Source Compliance Toolchain - A Proposal
Open Source Compliance Toolchain - A ProposalOpen Source Compliance Toolchain - A Proposal
Open Source Compliance Toolchain - A Proposal
 
OpenChain Reference Tooling Work Group @ FOSDEM - February 2020
OpenChain Reference Tooling Work Group @ FOSDEM - February 2020OpenChain Reference Tooling Work Group @ FOSDEM - February 2020
OpenChain Reference Tooling Work Group @ FOSDEM - February 2020
 
OpenChain Tooling Work Group Meeting #4 - Agenda Slides
OpenChain Tooling Work Group Meeting #4 - Agenda SlidesOpenChain Tooling Work Group Meeting #4 - Agenda Slides
OpenChain Tooling Work Group Meeting #4 - Agenda Slides
 
OpenChain Reference Tooling Work Group in 2020
OpenChain Reference Tooling Work Group in 2020OpenChain Reference Tooling Work Group in 2020
OpenChain Reference Tooling Work Group in 2020
 
Bosch: AN UPDATE ON OUR ACTIVITIES IN AUTOMATING OSS COMPLIANCE: A WORKING SH...
Bosch: AN UPDATE ON OUR ACTIVITIES IN AUTOMATING OSS COMPLIANCE: A WORKING SH...Bosch: AN UPDATE ON OUR ACTIVITIES IN AUTOMATING OSS COMPLIANCE: A WORKING SH...
Bosch: AN UPDATE ON OUR ACTIVITIES IN AUTOMATING OSS COMPLIANCE: A WORKING SH...
 
Improving the software integration with the use of REST API
Improving the software integration with the use of REST APIImproving the software integration with the use of REST API
Improving the software integration with the use of REST API
 
FOSSology & GSOC Journey
FOSSology & GSOC JourneyFOSSology & GSOC Journey
FOSSology & GSOC Journey
 
WEBINAR: API Clouds for Faster APIs: Leveraging Existing Assets for the API ...
WEBINAR: API Clouds for Faster APIs:  Leveraging Existing Assets for the API ...WEBINAR: API Clouds for Faster APIs:  Leveraging Existing Assets for the API ...
WEBINAR: API Clouds for Faster APIs: Leveraging Existing Assets for the API ...
 
June 22nd 2016 - Foundation State of the Union - London Meetup @ Red Deer
June 22nd 2016 - Foundation State of the Union - London Meetup @ Red DeerJune 22nd 2016 - Foundation State of the Union - London Meetup @ Red Deer
June 22nd 2016 - Foundation State of the Union - London Meetup @ Red Deer
 
Evolve 19 | Sarah Xu & Kanika Gera | Adobe I/O - Why You Need it to Execute o...
Evolve 19 | Sarah Xu & Kanika Gera | Adobe I/O - Why You Need it to Execute o...Evolve 19 | Sarah Xu & Kanika Gera | Adobe I/O - Why You Need it to Execute o...
Evolve 19 | Sarah Xu & Kanika Gera | Adobe I/O - Why You Need it to Execute o...
 
Alfresco Webinar: Jive Toolkit
Alfresco Webinar: Jive ToolkitAlfresco Webinar: Jive Toolkit
Alfresco Webinar: Jive Toolkit
 
Managing Open Source Software Supply Chains
Managing Open Source Software Supply ChainsManaging Open Source Software Supply Chains
Managing Open Source Software Supply Chains
 
Open Source governance and the Eclipse Foundation, OW2online, June 2020
Open Source governance and the Eclipse Foundation, OW2online, June 2020Open Source governance and the Eclipse Foundation, OW2online, June 2020
Open Source governance and the Eclipse Foundation, OW2online, June 2020
 
Open data vs open api
Open data vs open apiOpen data vs open api
Open data vs open api
 
IoTivity Connects RVI from GENIVI's Develoment Platform to Tizen devices
IoTivity Connects RVI from GENIVI's Develoment Platform to Tizen devicesIoTivity Connects RVI from GENIVI's Develoment Platform to Tizen devices
IoTivity Connects RVI from GENIVI's Develoment Platform to Tizen devices
 
Let’s Talk About the Ipro Platform
Let’s Talk About the Ipro PlatformLet’s Talk About the Ipro Platform
Let’s Talk About the Ipro Platform
 
Using SW360 for OSS Compliance Management Process - A Toshiba Case Study for ...
Using SW360 for OSS Compliance Management Process - A Toshiba Case Study for ...Using SW360 for OSS Compliance Management Process - A Toshiba Case Study for ...
Using SW360 for OSS Compliance Management Process - A Toshiba Case Study for ...
 
INTERFACE, by apidays - Lessons learned from implementing our custom ‘Big Da...
INTERFACE, by apidays  - Lessons learned from implementing our custom ‘Big Da...INTERFACE, by apidays  - Lessons learned from implementing our custom ‘Big Da...
INTERFACE, by apidays - Lessons learned from implementing our custom ‘Big Da...
 
Serverless SAP Fiori Apps in SAP Cloud Platfrom
Serverless SAP Fiori Apps in SAP Cloud PlatfromServerless SAP Fiori Apps in SAP Cloud Platfrom
Serverless SAP Fiori Apps in SAP Cloud Platfrom
 
AnyFirewall Engine v10.0 Developer Guide
AnyFirewall Engine v10.0 Developer GuideAnyFirewall Engine v10.0 Developer Guide
AnyFirewall Engine v10.0 Developer Guide
 

More from Shane Coughlan

openEuler Case Study - The Journey to Supply Chain Security
openEuler Case Study - The Journey to Supply Chain SecurityopenEuler Case Study - The Journey to Supply Chain Security
openEuler Case Study - The Journey to Supply Chain Security
Shane Coughlan
 
OpenChain @ LF Japan Executive Briefing - May 2024
OpenChain @ LF Japan Executive Briefing - May 2024OpenChain @ LF Japan Executive Briefing - May 2024
OpenChain @ LF Japan Executive Briefing - May 2024
Shane Coughlan
 
OpenChain Webinar: AboutCode and Beyond - End-to-End SCA
OpenChain Webinar: AboutCode and Beyond - End-to-End SCAOpenChain Webinar: AboutCode and Beyond - End-to-End SCA
OpenChain Webinar: AboutCode and Beyond - End-to-End SCA
Shane Coughlan
 
OpenChain - The Ramifications of ISO/IEC 5230 and ISO/IEC 18974 for Legal Pro...
OpenChain - The Ramifications of ISO/IEC 5230 and ISO/IEC 18974 for Legal Pro...OpenChain - The Ramifications of ISO/IEC 5230 and ISO/IEC 18974 for Legal Pro...
OpenChain - The Ramifications of ISO/IEC 5230 and ISO/IEC 18974 for Legal Pro...
Shane Coughlan
 
OpenChain Education Work Group Monthly Meeting - 2024-04-10 - Full Recording
OpenChain Education Work Group Monthly Meeting - 2024-04-10 - Full RecordingOpenChain Education Work Group Monthly Meeting - 2024-04-10 - Full Recording
OpenChain Education Work Group Monthly Meeting - 2024-04-10 - Full Recording
Shane Coughlan
 
OpenChain AI Study Group - Europe and Asia Recap - 2024-04-11 - Full Recording
OpenChain AI Study Group - Europe and Asia Recap - 2024-04-11 - Full RecordingOpenChain AI Study Group - Europe and Asia Recap - 2024-04-11 - Full Recording
OpenChain AI Study Group - Europe and Asia Recap - 2024-04-11 - Full Recording
Shane Coughlan
 
OpenChain Monthly Meeting North America and Asia - 2024-03-19
OpenChain Monthly Meeting North America and Asia - 2024-03-19OpenChain Monthly Meeting North America and Asia - 2024-03-19
OpenChain Monthly Meeting North America and Asia - 2024-03-19
Shane Coughlan
 
OpenChain Webinar: Universal CVSS Calculator
OpenChain Webinar: Universal CVSS CalculatorOpenChain Webinar: Universal CVSS Calculator
OpenChain Webinar: Universal CVSS Calculator
Shane Coughlan
 
openEuler Community Overview - a presentation showing the current scale
openEuler Community Overview - a presentation showing the current scaleopenEuler Community Overview - a presentation showing the current scale
openEuler Community Overview - a presentation showing the current scale
Shane Coughlan
 
OpenChain AI Study Group - North America and Europe - 2024-02-20
OpenChain AI Study Group - North America and Europe - 2024-02-20OpenChain AI Study Group - North America and Europe - 2024-02-20
OpenChain AI Study Group - North America and Europe - 2024-02-20
Shane Coughlan
 
AI Study Group North America - Europe 2024-02-06
AI Study Group North America - Europe 2024-02-06AI Study Group North America - Europe 2024-02-06
AI Study Group North America - Europe 2024-02-06
Shane Coughlan
 
OpenChain Monthly North America / Europe Call - 2024-02-06
OpenChain Monthly North America / Europe Call - 2024-02-06OpenChain Monthly North America / Europe Call - 2024-02-06
OpenChain Monthly North America / Europe Call - 2024-02-06
Shane Coughlan
 
OpenChain Export Control Work Group 2024-01-09
OpenChain Export Control Work Group 2024-01-09OpenChain Export Control Work Group 2024-01-09
OpenChain Export Control Work Group 2024-01-09
Shane Coughlan
 
OpenChain Legal Work Group - 2024-01-17
OpenChain Legal Work Group -  2024-01-17OpenChain Legal Work Group -  2024-01-17
OpenChain Legal Work Group - 2024-01-17
Shane Coughlan
 
Openchain AI Study Group 2024-01-23.pptx
Openchain AI Study Group 2024-01-23.pptxOpenchain AI Study Group 2024-01-23.pptx
Openchain AI Study Group 2024-01-23.pptx
Shane Coughlan
 
OpenChain Webinar #58 - FOSS License Management through aliens4friends in Ecl...
OpenChain Webinar #58 - FOSS License Management through aliens4friends in Ecl...OpenChain Webinar #58 - FOSS License Management through aliens4friends in Ecl...
OpenChain Webinar #58 - FOSS License Management through aliens4friends in Ecl...
Shane Coughlan
 
Maturity Models - Open Compliance Summit 2023
Maturity Models - Open Compliance Summit 2023Maturity Models - Open Compliance Summit 2023
Maturity Models - Open Compliance Summit 2023
Shane Coughlan
 
OpenChain Annual Report 2023 - Key Metrics Slides
OpenChain Annual Report 2023 - Key Metrics SlidesOpenChain Annual Report 2023 - Key Metrics Slides
OpenChain Annual Report 2023 - Key Metrics Slides
Shane Coughlan
 
OpenChain Webinar 57 - The Open Source Initiative - 2023-11-27
OpenChain Webinar 57 - The Open Source Initiative - 2023-11-27OpenChain Webinar 57 - The Open Source Initiative - 2023-11-27
OpenChain Webinar 57 - The Open Source Initiative - 2023-11-27
Shane Coughlan
 
FOSSLight Community Day 2023-11-30
FOSSLight Community Day 2023-11-30FOSSLight Community Day 2023-11-30
FOSSLight Community Day 2023-11-30
Shane Coughlan
 

More from Shane Coughlan (20)

openEuler Case Study - The Journey to Supply Chain Security
openEuler Case Study - The Journey to Supply Chain SecurityopenEuler Case Study - The Journey to Supply Chain Security
openEuler Case Study - The Journey to Supply Chain Security
 
OpenChain @ LF Japan Executive Briefing - May 2024
OpenChain @ LF Japan Executive Briefing - May 2024OpenChain @ LF Japan Executive Briefing - May 2024
OpenChain @ LF Japan Executive Briefing - May 2024
 
OpenChain Webinar: AboutCode and Beyond - End-to-End SCA
OpenChain Webinar: AboutCode and Beyond - End-to-End SCAOpenChain Webinar: AboutCode and Beyond - End-to-End SCA
OpenChain Webinar: AboutCode and Beyond - End-to-End SCA
 
OpenChain - The Ramifications of ISO/IEC 5230 and ISO/IEC 18974 for Legal Pro...
OpenChain - The Ramifications of ISO/IEC 5230 and ISO/IEC 18974 for Legal Pro...OpenChain - The Ramifications of ISO/IEC 5230 and ISO/IEC 18974 for Legal Pro...
OpenChain - The Ramifications of ISO/IEC 5230 and ISO/IEC 18974 for Legal Pro...
 
OpenChain Education Work Group Monthly Meeting - 2024-04-10 - Full Recording
OpenChain Education Work Group Monthly Meeting - 2024-04-10 - Full RecordingOpenChain Education Work Group Monthly Meeting - 2024-04-10 - Full Recording
OpenChain Education Work Group Monthly Meeting - 2024-04-10 - Full Recording
 
OpenChain AI Study Group - Europe and Asia Recap - 2024-04-11 - Full Recording
OpenChain AI Study Group - Europe and Asia Recap - 2024-04-11 - Full RecordingOpenChain AI Study Group - Europe and Asia Recap - 2024-04-11 - Full Recording
OpenChain AI Study Group - Europe and Asia Recap - 2024-04-11 - Full Recording
 
OpenChain Monthly Meeting North America and Asia - 2024-03-19
OpenChain Monthly Meeting North America and Asia - 2024-03-19OpenChain Monthly Meeting North America and Asia - 2024-03-19
OpenChain Monthly Meeting North America and Asia - 2024-03-19
 
OpenChain Webinar: Universal CVSS Calculator
OpenChain Webinar: Universal CVSS CalculatorOpenChain Webinar: Universal CVSS Calculator
OpenChain Webinar: Universal CVSS Calculator
 
openEuler Community Overview - a presentation showing the current scale
openEuler Community Overview - a presentation showing the current scaleopenEuler Community Overview - a presentation showing the current scale
openEuler Community Overview - a presentation showing the current scale
 
OpenChain AI Study Group - North America and Europe - 2024-02-20
OpenChain AI Study Group - North America and Europe - 2024-02-20OpenChain AI Study Group - North America and Europe - 2024-02-20
OpenChain AI Study Group - North America and Europe - 2024-02-20
 
AI Study Group North America - Europe 2024-02-06
AI Study Group North America - Europe 2024-02-06AI Study Group North America - Europe 2024-02-06
AI Study Group North America - Europe 2024-02-06
 
OpenChain Monthly North America / Europe Call - 2024-02-06
OpenChain Monthly North America / Europe Call - 2024-02-06OpenChain Monthly North America / Europe Call - 2024-02-06
OpenChain Monthly North America / Europe Call - 2024-02-06
 
OpenChain Export Control Work Group 2024-01-09
OpenChain Export Control Work Group 2024-01-09OpenChain Export Control Work Group 2024-01-09
OpenChain Export Control Work Group 2024-01-09
 
OpenChain Legal Work Group - 2024-01-17
OpenChain Legal Work Group -  2024-01-17OpenChain Legal Work Group -  2024-01-17
OpenChain Legal Work Group - 2024-01-17
 
Openchain AI Study Group 2024-01-23.pptx
Openchain AI Study Group 2024-01-23.pptxOpenchain AI Study Group 2024-01-23.pptx
Openchain AI Study Group 2024-01-23.pptx
 
OpenChain Webinar #58 - FOSS License Management through aliens4friends in Ecl...
OpenChain Webinar #58 - FOSS License Management through aliens4friends in Ecl...OpenChain Webinar #58 - FOSS License Management through aliens4friends in Ecl...
OpenChain Webinar #58 - FOSS License Management through aliens4friends in Ecl...
 
Maturity Models - Open Compliance Summit 2023
Maturity Models - Open Compliance Summit 2023Maturity Models - Open Compliance Summit 2023
Maturity Models - Open Compliance Summit 2023
 
OpenChain Annual Report 2023 - Key Metrics Slides
OpenChain Annual Report 2023 - Key Metrics SlidesOpenChain Annual Report 2023 - Key Metrics Slides
OpenChain Annual Report 2023 - Key Metrics Slides
 
OpenChain Webinar 57 - The Open Source Initiative - 2023-11-27
OpenChain Webinar 57 - The Open Source Initiative - 2023-11-27OpenChain Webinar 57 - The Open Source Initiative - 2023-11-27
OpenChain Webinar 57 - The Open Source Initiative - 2023-11-27
 
FOSSLight Community Day 2023-11-30
FOSSLight Community Day 2023-11-30FOSSLight Community Day 2023-11-30
FOSSLight Community Day 2023-11-30
 

Recently uploaded

Need for Speed: Removing speed bumps from your Symfony projects ⚡️
Need for Speed: Removing speed bumps from your Symfony projects ⚡️Need for Speed: Removing speed bumps from your Symfony projects ⚡️
Need for Speed: Removing speed bumps from your Symfony projects ⚡️
Łukasz Chruściel
 
2024 eCommerceDays Toulouse - Sylius 2.0.pdf
2024 eCommerceDays Toulouse - Sylius 2.0.pdf2024 eCommerceDays Toulouse - Sylius 2.0.pdf
2024 eCommerceDays Toulouse - Sylius 2.0.pdf
Łukasz Chruściel
 
Essentials of Automations: The Art of Triggers and Actions in FME
Essentials of Automations: The Art of Triggers and Actions in FMEEssentials of Automations: The Art of Triggers and Actions in FME
Essentials of Automations: The Art of Triggers and Actions in FME
Safe Software
 
Graspan: A Big Data System for Big Code Analysis
Graspan: A Big Data System for Big Code AnalysisGraspan: A Big Data System for Big Code Analysis
Graspan: A Big Data System for Big Code Analysis
Aftab Hussain
 
Revolutionizing Visual Effects Mastering AI Face Swaps.pdf
Revolutionizing Visual Effects Mastering AI Face Swaps.pdfRevolutionizing Visual Effects Mastering AI Face Swaps.pdf
Revolutionizing Visual Effects Mastering AI Face Swaps.pdf
Undress Baby
 
What is Augmented Reality Image Tracking
What is Augmented Reality Image TrackingWhat is Augmented Reality Image Tracking
What is Augmented Reality Image Tracking
pavan998932
 
Energy consumption of Database Management - Florina Jonuzi
Energy consumption of Database Management - Florina JonuziEnergy consumption of Database Management - Florina Jonuzi
Energy consumption of Database Management - Florina Jonuzi
Green Software Development
 
E-commerce Application Development Company.pdf
E-commerce Application Development Company.pdfE-commerce Application Development Company.pdf
E-commerce Application Development Company.pdf
Hornet Dynamics
 
Using Xen Hypervisor for Functional Safety
Using Xen Hypervisor for Functional SafetyUsing Xen Hypervisor for Functional Safety
Using Xen Hypervisor for Functional Safety
Ayan Halder
 
E-commerce Development Services- Hornet Dynamics
E-commerce Development Services- Hornet DynamicsE-commerce Development Services- Hornet Dynamics
E-commerce Development Services- Hornet Dynamics
Hornet Dynamics
 
Mobile App Development Company In Noida | Drona Infotech
Mobile App Development Company In Noida | Drona InfotechMobile App Development Company In Noida | Drona Infotech
Mobile App Development Company In Noida | Drona Infotech
Drona Infotech
 
GreenCode-A-VSCode-Plugin--Dario-Jurisic
GreenCode-A-VSCode-Plugin--Dario-JurisicGreenCode-A-VSCode-Plugin--Dario-Jurisic
GreenCode-A-VSCode-Plugin--Dario-Jurisic
Green Software Development
 
Why Choose Odoo 17 Community & How it differs from Odoo 17 Enterprise Edition
Why Choose Odoo 17 Community & How it differs from Odoo 17 Enterprise EditionWhy Choose Odoo 17 Community & How it differs from Odoo 17 Enterprise Edition
Why Choose Odoo 17 Community & How it differs from Odoo 17 Enterprise Edition
Envertis Software Solutions
 
GOING AOT WITH GRAALVM FOR SPRING BOOT (SPRING IO)
GOING AOT WITH GRAALVM FOR  SPRING BOOT (SPRING IO)GOING AOT WITH GRAALVM FOR  SPRING BOOT (SPRING IO)
GOING AOT WITH GRAALVM FOR SPRING BOOT (SPRING IO)
Alina Yurenko
 
Transform Your Communication with Cloud-Based IVR Solutions
Transform Your Communication with Cloud-Based IVR SolutionsTransform Your Communication with Cloud-Based IVR Solutions
Transform Your Communication with Cloud-Based IVR Solutions
TheSMSPoint
 
Automated software refactoring with OpenRewrite and Generative AI.pptx.pdf
Automated software refactoring with OpenRewrite and Generative AI.pptx.pdfAutomated software refactoring with OpenRewrite and Generative AI.pptx.pdf
Automated software refactoring with OpenRewrite and Generative AI.pptx.pdf
timtebeek1
 
Top Features to Include in Your Winzo Clone App for Business Growth (4).pptx
Top Features to Include in Your Winzo Clone App for Business Growth (4).pptxTop Features to Include in Your Winzo Clone App for Business Growth (4).pptx
Top Features to Include in Your Winzo Clone App for Business Growth (4).pptx
rickgrimesss22
 
Introducing Crescat - Event Management Software for Venues, Festivals and Eve...
Introducing Crescat - Event Management Software for Venues, Festivals and Eve...Introducing Crescat - Event Management Software for Venues, Festivals and Eve...
Introducing Crescat - Event Management Software for Venues, Festivals and Eve...
Crescat
 
Empowering Growth with Best Software Development Company in Noida - Deuglo
Empowering Growth with Best Software  Development Company in Noida - DeugloEmpowering Growth with Best Software  Development Company in Noida - Deuglo
Empowering Growth with Best Software Development Company in Noida - Deuglo
Deuglo Infosystem Pvt Ltd
 
AI Fusion Buddy Review: Brand New, Groundbreaking Gemini-Powered AI App
AI Fusion Buddy Review: Brand New, Groundbreaking Gemini-Powered AI AppAI Fusion Buddy Review: Brand New, Groundbreaking Gemini-Powered AI App
AI Fusion Buddy Review: Brand New, Groundbreaking Gemini-Powered AI App
Google
 

Recently uploaded (20)

Need for Speed: Removing speed bumps from your Symfony projects ⚡️
Need for Speed: Removing speed bumps from your Symfony projects ⚡️Need for Speed: Removing speed bumps from your Symfony projects ⚡️
Need for Speed: Removing speed bumps from your Symfony projects ⚡️
 
2024 eCommerceDays Toulouse - Sylius 2.0.pdf
2024 eCommerceDays Toulouse - Sylius 2.0.pdf2024 eCommerceDays Toulouse - Sylius 2.0.pdf
2024 eCommerceDays Toulouse - Sylius 2.0.pdf
 
Essentials of Automations: The Art of Triggers and Actions in FME
Essentials of Automations: The Art of Triggers and Actions in FMEEssentials of Automations: The Art of Triggers and Actions in FME
Essentials of Automations: The Art of Triggers and Actions in FME
 
Graspan: A Big Data System for Big Code Analysis
Graspan: A Big Data System for Big Code AnalysisGraspan: A Big Data System for Big Code Analysis
Graspan: A Big Data System for Big Code Analysis
 
Revolutionizing Visual Effects Mastering AI Face Swaps.pdf
Revolutionizing Visual Effects Mastering AI Face Swaps.pdfRevolutionizing Visual Effects Mastering AI Face Swaps.pdf
Revolutionizing Visual Effects Mastering AI Face Swaps.pdf
 
What is Augmented Reality Image Tracking
What is Augmented Reality Image TrackingWhat is Augmented Reality Image Tracking
What is Augmented Reality Image Tracking
 
Energy consumption of Database Management - Florina Jonuzi
Energy consumption of Database Management - Florina JonuziEnergy consumption of Database Management - Florina Jonuzi
Energy consumption of Database Management - Florina Jonuzi
 
E-commerce Application Development Company.pdf
E-commerce Application Development Company.pdfE-commerce Application Development Company.pdf
E-commerce Application Development Company.pdf
 
Using Xen Hypervisor for Functional Safety
Using Xen Hypervisor for Functional SafetyUsing Xen Hypervisor for Functional Safety
Using Xen Hypervisor for Functional Safety
 
E-commerce Development Services- Hornet Dynamics
E-commerce Development Services- Hornet DynamicsE-commerce Development Services- Hornet Dynamics
E-commerce Development Services- Hornet Dynamics
 
Mobile App Development Company In Noida | Drona Infotech
Mobile App Development Company In Noida | Drona InfotechMobile App Development Company In Noida | Drona Infotech
Mobile App Development Company In Noida | Drona Infotech
 
GreenCode-A-VSCode-Plugin--Dario-Jurisic
GreenCode-A-VSCode-Plugin--Dario-JurisicGreenCode-A-VSCode-Plugin--Dario-Jurisic
GreenCode-A-VSCode-Plugin--Dario-Jurisic
 
Why Choose Odoo 17 Community & How it differs from Odoo 17 Enterprise Edition
Why Choose Odoo 17 Community & How it differs from Odoo 17 Enterprise EditionWhy Choose Odoo 17 Community & How it differs from Odoo 17 Enterprise Edition
Why Choose Odoo 17 Community & How it differs from Odoo 17 Enterprise Edition
 
GOING AOT WITH GRAALVM FOR SPRING BOOT (SPRING IO)
GOING AOT WITH GRAALVM FOR  SPRING BOOT (SPRING IO)GOING AOT WITH GRAALVM FOR  SPRING BOOT (SPRING IO)
GOING AOT WITH GRAALVM FOR SPRING BOOT (SPRING IO)
 
Transform Your Communication with Cloud-Based IVR Solutions
Transform Your Communication with Cloud-Based IVR SolutionsTransform Your Communication with Cloud-Based IVR Solutions
Transform Your Communication with Cloud-Based IVR Solutions
 
Automated software refactoring with OpenRewrite and Generative AI.pptx.pdf
Automated software refactoring with OpenRewrite and Generative AI.pptx.pdfAutomated software refactoring with OpenRewrite and Generative AI.pptx.pdf
Automated software refactoring with OpenRewrite and Generative AI.pptx.pdf
 
Top Features to Include in Your Winzo Clone App for Business Growth (4).pptx
Top Features to Include in Your Winzo Clone App for Business Growth (4).pptxTop Features to Include in Your Winzo Clone App for Business Growth (4).pptx
Top Features to Include in Your Winzo Clone App for Business Growth (4).pptx
 
Introducing Crescat - Event Management Software for Venues, Festivals and Eve...
Introducing Crescat - Event Management Software for Venues, Festivals and Eve...Introducing Crescat - Event Management Software for Venues, Festivals and Eve...
Introducing Crescat - Event Management Software for Venues, Festivals and Eve...
 
Empowering Growth with Best Software Development Company in Noida - Deuglo
Empowering Growth with Best Software  Development Company in Noida - DeugloEmpowering Growth with Best Software  Development Company in Noida - Deuglo
Empowering Growth with Best Software Development Company in Noida - Deuglo
 
AI Fusion Buddy Review: Brand New, Groundbreaking Gemini-Powered AI App
AI Fusion Buddy Review: Brand New, Groundbreaking Gemini-Powered AI AppAI Fusion Buddy Review: Brand New, Groundbreaking Gemini-Powered AI App
AI Fusion Buddy Review: Brand New, Groundbreaking Gemini-Powered AI App
 

OpenChain Tooling Work Group Meeting #2 - Agenda Slides

  • 1. 2nd meeting open source tooling for open source compliance work group Cpoyright © the open source tooling group 2019
  • 2. Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt Agenda Top Name Actors 1. News All 2. Introduction of the existing work All 3. Areas to focus on Oliver 4. Next steps All
  • 3. Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt News • We have a logo • First version of the website is online https://oss-compliance-tooling.org/ • Presentation template available in impress format: https://github.com/Open-Source-Compliance/Sharing- creates-value/tree/master/Templates • New contribution from Michael Picht Vulas and CLA assistant were added to the tools – Thank you Michael • Events • Past Events • OSS Summit NA • Upcoming Events • OSS working team meeting of BITKOM • OSS Summit Europe in Lyon
  • 4. Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt Agenda Top Name Actors 1. News All 2. Introduction of the existing work All 3. Areas to focus on Oliver 4. Next steps All
  • 5. Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt Integrated, automated – end to end OSS compliance toolchain made with OSS To build an integrated end to end compliance toolchain is not about to build a monolithic monster, it is about to use current available Open Source tools and define and implement the needed APIs/Data structures they need to provide, in order to plug them into the current set up CI/CD workflow and to enable them to trigger other Open Source compliance tools in a way that they seamlessly interact which each other and potential external data sources. The already existing projects remain independent projects We are making turn-key Open Source tooling for Open Source Compliance
  • 6. Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt Big Picture – Integrated Compliance Toolchain CI / CD Infrastructure License & Copyright Scanner Component Analysis Service Compliance artifact consistency Component inventory (Metadata Repository) Dependency resolver Source package downloader Container content resolver License Obligations Database Policy checker (Compliance Checker) Obligation fulfillment Build Tools Continous IntegrationArtifact Repository Source Code Repo outbound software & compliance artifacts FOSS Compliance Bundle generator Binary analyser Inbound software Public compliance artifact repos contributions Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data)
  • 7. Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt Integrated, automated – end to end OSS compliance toolchain made with OSS We are making turn-key Open Source tooling for Open Source Compliance • Identify the functional blocks required • Identify the workflows • Identify the required data and data flows • Implement provide the needed APIs (as contributions) • Provide the glue Code • Provide easy to deploy building blocks • Documentation • Spread the word
  • 8. Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt UML Big Picture View https://github.com/Open-Source-Compliance/Sharing- creates-value/blob/master/Tooling- Landscape/Unanimous- Understanding/OSS_Tooling_Landscape_UML_Deploy.pl antuml Glossary https://github.com/Open-Source-Compliance/Sharing- creates-value/blob/master/Tooling- Landscape/Unanimous-Understanding/OSS-Tooling- Landscape-Glossary.md Introduction of the existing work
  • 9. Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt Introduction of the existing work Process flows: https://github.com/Open-Source- Compliance/Sharing-creates- value/tree/master/Tooling-Landscape/Unanimous- Understanding/Process%20Flows
  • 10. Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt Data Model: https://github.com/Open-Source- Compliance/Sharing-creates- value/tree/master/Tooling-Landscape/Unanimous- Understanding/Data%20Structures Introduction of the existing work
  • 11. Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt Agenda Top Name Actors 1. News All 2. Introduction of the existing work All 3. Areas to focus on Oliver 4. Next steps All
  • 12. Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt Areas to focus on
  • 13. Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt Big Picture – Integrated Compliance Toolchain CI / CD Infrastructure License & Copyright Scanner Component Analysis Service Compliance artifact consistency Component inventory (Metadata Repository) Dependency resolver Source package downloader Container content resolver License Obligations Database Policy checker (Compliance Checker) Obligation fulfillment Build Tools Continous IntegrationArtifact Repository Source Code Repo outbound software & compliance artifacts FOSS Compliance Bundle generator Binary analyser Inbound software Public compliance artifact repos contributions Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) License: CC-BY-SA-4.0
  • 14. Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt Big Picture – Integrated Compliance Toolchain Instance CI / CD Infrastructure Component Analysis Service Compliance artifact consistency Build Tools Continous IntegrationArtifact Repository Source Code Repo outbound software & compliance artifacts BANG Inbound software contributions Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) ScanCode Dependency resolver Binary analyserContainer content resolver Source package downloader Component inventory License & Copyright Scanner Policy checker Obligation fulfillment FOSS Compliance Bundle generator License Obligations Database License Classifier Public compliance artifact repos
  • 15. Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt Next steps
  • 16. Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt Restructuring of the repo sharing-creates-value Move to OSS-compliance-work- results a new repo of the group Open-Source-Compliance Update and move content to OSS-compliance-work-results a new repo of the group Open- Source-Compliance Preparing a slide deck with an overview of the tooling working group – that can be used when someone wants to give a presentation about the tooling working group
  • 17. 2019 Licensed under CC-BY-SA-4.0 Oliver Fendt User stories We are making turn-key Open Source tooling for Open Source Compliance • As a Software developer I … • As a compliance officer I … • As a product owner I … • As a legal assessor I … • As a compliance assistant I … • ….
  • 18. Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt Next Meeting Date: 18th of Sept
  • 19. Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt Links / Communication Github: https://github.com/Open-Source-Compliance/Sharing-creates-value Slack: https://join.slack.com/t/ossbasedcompl- bhx9742/shared_invite/enQtNzA5OTc3OTAwMjExLWNhYWVkZDk2Y2RlNDI4ODI2N zQyNDU5ZWE4ODRmZWI1ZmM1MzA4ZTc2MTdkZGFhMzc2NmUyODRhNDZjNWI 5Njc Mailing List: Subscription page: https://groups.io/g/oss-based-compliance-tooling Email address: oss-based-compliance-tooling@groups.io Where to communicate what?
  • 20. Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt Credits Picture by Splitshireon https//pixabay.com license: pixabay license