SlideShare ist ein Scribd-Unternehmen logo
1 von 20
Downloaden Sie, um offline zu lesen
2nd meeting open
source tooling for open
source compliance work
group
Cpoyright © the open source tooling group 2019
Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt
Agenda
Top Name Actors
1. News All
2. Introduction of the existing work All
3. Areas to focus on Oliver
4. Next steps All
Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt
News
• We have a logo
• First version of the website is online https://oss-compliance-tooling.org/
• Presentation template available in impress format: https://github.com/Open-Source-Compliance/Sharing-
creates-value/tree/master/Templates
• New contribution from Michael Picht Vulas and CLA assistant were added to the tools – Thank you Michael
• Events
• Past Events
• OSS Summit NA
• Upcoming Events
• OSS working team meeting of BITKOM
• OSS Summit Europe in Lyon
Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt
Agenda
Top Name Actors
1. News All
2. Introduction of the existing work All
3. Areas to focus on Oliver
4. Next steps All
Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt
Integrated, automated – end to end OSS compliance
toolchain made with OSS
To build an integrated end to end compliance toolchain is not about to build a monolithic monster, it is
about to use current available Open Source tools and define and implement the needed APIs/Data
structures they need to provide, in order to plug them into the current set up CI/CD workflow and to
enable them to trigger other Open Source compliance tools in a way that they seamlessly interact which
each other and potential external data sources.
The already existing projects remain independent projects
We are making turn-key Open Source tooling for Open Source Compliance
Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt
Big Picture – Integrated Compliance Toolchain
CI / CD Infrastructure
License &
Copyright
Scanner
Component
Analysis
Service
Compliance
artifact
consistency
Component
inventory
(Metadata
Repository)
Dependency
resolver
Source
package
downloader
Container
content
resolver
License
Obligations
Database
Policy
checker
(Compliance
Checker)
Obligation
fulfillment
Build Tools
Continous IntegrationArtifact Repository
Source Code Repo
outbound
software
&
compliance
artifacts
FOSS
Compliance
Bundle
generator
Binary
analyser
Inbound
software
Public
compliance
artifact
repos
contributions
Integration layer (API/Data) Integration layer (API/Data)
Integration layer (API/Data)
Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data)
Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data)
Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt
Integrated, automated – end to end OSS compliance
toolchain made with OSS
We are making turn-key Open Source tooling for Open Source Compliance
• Identify the functional blocks required
• Identify the workflows
• Identify the required data and data flows
• Implement provide the needed APIs (as contributions)
• Provide the glue Code
• Provide easy to deploy building blocks
• Documentation
• Spread the word
Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt
UML Big Picture View
https://github.com/Open-Source-Compliance/Sharing-
creates-value/blob/master/Tooling-
Landscape/Unanimous-
Understanding/OSS_Tooling_Landscape_UML_Deploy.pl
antuml
Glossary
https://github.com/Open-Source-Compliance/Sharing-
creates-value/blob/master/Tooling-
Landscape/Unanimous-Understanding/OSS-Tooling-
Landscape-Glossary.md
Introduction of the existing work
Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt
Introduction of the existing work
Process flows:
https://github.com/Open-Source-
Compliance/Sharing-creates-
value/tree/master/Tooling-Landscape/Unanimous-
Understanding/Process%20Flows
Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt
Data Model:
https://github.com/Open-Source-
Compliance/Sharing-creates-
value/tree/master/Tooling-Landscape/Unanimous-
Understanding/Data%20Structures
Introduction of the existing work
Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt
Agenda
Top Name Actors
1. News All
2. Introduction of the existing work All
3. Areas to focus on Oliver
4. Next steps All
Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt
Areas to focus on
Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt
Big Picture – Integrated Compliance Toolchain
CI / CD Infrastructure
License &
Copyright
Scanner
Component
Analysis
Service
Compliance
artifact
consistency
Component
inventory
(Metadata
Repository)
Dependency
resolver
Source
package
downloader
Container
content
resolver
License
Obligations
Database
Policy
checker
(Compliance
Checker)
Obligation
fulfillment
Build Tools
Continous IntegrationArtifact Repository
Source Code Repo
outbound
software
&
compliance
artifacts
FOSS
Compliance
Bundle
generator
Binary
analyser
Inbound
software
Public
compliance
artifact
repos
contributions
Integration layer (API/Data) Integration layer (API/Data)
Integration layer (API/Data)
Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data)
Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data)
License: CC-BY-SA-4.0
Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt
Big Picture – Integrated Compliance Toolchain
Instance
CI / CD Infrastructure
Component
Analysis
Service
Compliance
artifact
consistency
Build Tools
Continous IntegrationArtifact Repository
Source Code Repo
outbound
software
&
compliance
artifacts
BANG
Inbound
software
contributions
Integration layer (API/Data) Integration layer (API/Data)
Integration layer (API/Data)
Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data)
Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data)
ScanCode
Dependency resolver Binary analyserContainer content resolver Source package downloader Component inventory
License & Copyright Scanner
Policy checker Obligation fulfillment
FOSS Compliance
Bundle generator
License Obligations
Database
License Classifier
Public
compliance
artifact repos
Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt
Next steps
Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt
Restructuring of the repo sharing-creates-value
Move to OSS-compliance-work-
results a new repo of the group
Open-Source-Compliance
Update and move content to
OSS-compliance-work-results a
new repo of the group Open-
Source-Compliance
Preparing a slide deck with an overview of the tooling working group – that can be used when someone wants to give a
presentation about the tooling working group
2019 Licensed under CC-BY-SA-4.0 Oliver Fendt
User stories
We are making turn-key Open Source tooling for Open Source Compliance
• As a Software developer I …
• As a compliance officer I …
• As a product owner I …
• As a legal assessor I …
• As a compliance assistant I …
• ….
Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt
Next Meeting
Date: 18th of Sept
Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt
Links / Communication
Github:
https://github.com/Open-Source-Compliance/Sharing-creates-value
Slack:
https://join.slack.com/t/ossbasedcompl-
bhx9742/shared_invite/enQtNzA5OTc3OTAwMjExLWNhYWVkZDk2Y2RlNDI4ODI2N
zQyNDU5ZWE4ODRmZWI1ZmM1MzA4ZTc2MTdkZGFhMzc2NmUyODRhNDZjNWI
5Njc
Mailing List:
Subscription page: https://groups.io/g/oss-based-compliance-tooling
Email address: oss-based-compliance-tooling@groups.io
Where to communicate what?
Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt
Credits
Picture by Splitshireon
https//pixabay.com license:
pixabay license

Weitere ähnliche Inhalte

Was ist angesagt?

Was ist angesagt? (7)

Whats new in ep3
Whats new in ep3Whats new in ep3
Whats new in ep3
 
Overview of the OpenChain Reference Tooling Work Group, OW2online20, June 2020
Overview of the OpenChain Reference Tooling Work Group, OW2online20, June 2020Overview of the OpenChain Reference Tooling Work Group, OW2online20, June 2020
Overview of the OpenChain Reference Tooling Work Group, OW2online20, June 2020
 
Whats new in the OpenText EcoSystem Products for EP2
Whats new in the OpenText EcoSystem Products for EP2Whats new in the OpenText EcoSystem Products for EP2
Whats new in the OpenText EcoSystem Products for EP2
 
What's New in Content Services - Release 16 EP4
What's New in Content Services - Release 16 EP4What's New in Content Services - Release 16 EP4
What's New in Content Services - Release 16 EP4
 
apidays LIVE Paris 2021 - Building an Accessible API Spec with Traditional En...
apidays LIVE Paris 2021 - Building an Accessible API Spec with Traditional En...apidays LIVE Paris 2021 - Building an Accessible API Spec with Traditional En...
apidays LIVE Paris 2021 - Building an Accessible API Spec with Traditional En...
 
Cloud-native Integration in the Oracle Cloud
Cloud-native Integration in the Oracle CloudCloud-native Integration in the Oracle Cloud
Cloud-native Integration in the Oracle Cloud
 
10 reasons to upgrade OpenText Documentum
10 reasons to upgrade OpenText Documentum10 reasons to upgrade OpenText Documentum
10 reasons to upgrade OpenText Documentum
 

Ähnlich wie OpenChain Tooling Work Group Meeting #2 - Agenda Slides

Ähnlich wie OpenChain Tooling Work Group Meeting #2 - Agenda Slides (20)

Open Source Compliance Toolchain - A Proposal
Open Source Compliance Toolchain - A ProposalOpen Source Compliance Toolchain - A Proposal
Open Source Compliance Toolchain - A Proposal
 
OpenChain Reference Tooling Work Group @ FOSDEM - February 2020
OpenChain Reference Tooling Work Group @ FOSDEM - February 2020OpenChain Reference Tooling Work Group @ FOSDEM - February 2020
OpenChain Reference Tooling Work Group @ FOSDEM - February 2020
 
OpenChain Tooling Work Group Meeting #4 - Agenda Slides
OpenChain Tooling Work Group Meeting #4 - Agenda SlidesOpenChain Tooling Work Group Meeting #4 - Agenda Slides
OpenChain Tooling Work Group Meeting #4 - Agenda Slides
 
OpenChain Reference Tooling Work Group in 2020
OpenChain Reference Tooling Work Group in 2020OpenChain Reference Tooling Work Group in 2020
OpenChain Reference Tooling Work Group in 2020
 
Bosch: AN UPDATE ON OUR ACTIVITIES IN AUTOMATING OSS COMPLIANCE: A WORKING SH...
Bosch: AN UPDATE ON OUR ACTIVITIES IN AUTOMATING OSS COMPLIANCE: A WORKING SH...Bosch: AN UPDATE ON OUR ACTIVITIES IN AUTOMATING OSS COMPLIANCE: A WORKING SH...
Bosch: AN UPDATE ON OUR ACTIVITIES IN AUTOMATING OSS COMPLIANCE: A WORKING SH...
 
Improving the software integration with the use of REST API
Improving the software integration with the use of REST APIImproving the software integration with the use of REST API
Improving the software integration with the use of REST API
 
FOSSology & GSOC Journey
FOSSology & GSOC JourneyFOSSology & GSOC Journey
FOSSology & GSOC Journey
 
WEBINAR: API Clouds for Faster APIs: Leveraging Existing Assets for the API ...
WEBINAR: API Clouds for Faster APIs:  Leveraging Existing Assets for the API ...WEBINAR: API Clouds for Faster APIs:  Leveraging Existing Assets for the API ...
WEBINAR: API Clouds for Faster APIs: Leveraging Existing Assets for the API ...
 
June 22nd 2016 - Foundation State of the Union - London Meetup @ Red Deer
June 22nd 2016 - Foundation State of the Union - London Meetup @ Red DeerJune 22nd 2016 - Foundation State of the Union - London Meetup @ Red Deer
June 22nd 2016 - Foundation State of the Union - London Meetup @ Red Deer
 
Evolve 19 | Sarah Xu & Kanika Gera | Adobe I/O - Why You Need it to Execute o...
Evolve 19 | Sarah Xu & Kanika Gera | Adobe I/O - Why You Need it to Execute o...Evolve 19 | Sarah Xu & Kanika Gera | Adobe I/O - Why You Need it to Execute o...
Evolve 19 | Sarah Xu & Kanika Gera | Adobe I/O - Why You Need it to Execute o...
 
Alfresco Webinar: Jive Toolkit
Alfresco Webinar: Jive ToolkitAlfresco Webinar: Jive Toolkit
Alfresco Webinar: Jive Toolkit
 
Managing Open Source Software Supply Chains
Managing Open Source Software Supply ChainsManaging Open Source Software Supply Chains
Managing Open Source Software Supply Chains
 
Open Source governance and the Eclipse Foundation, OW2online, June 2020
Open Source governance and the Eclipse Foundation, OW2online, June 2020Open Source governance and the Eclipse Foundation, OW2online, June 2020
Open Source governance and the Eclipse Foundation, OW2online, June 2020
 
Open data vs open api
Open data vs open apiOpen data vs open api
Open data vs open api
 
IoTivity Connects RVI from GENIVI's Develoment Platform to Tizen devices
IoTivity Connects RVI from GENIVI's Develoment Platform to Tizen devicesIoTivity Connects RVI from GENIVI's Develoment Platform to Tizen devices
IoTivity Connects RVI from GENIVI's Develoment Platform to Tizen devices
 
Let’s Talk About the Ipro Platform
Let’s Talk About the Ipro PlatformLet’s Talk About the Ipro Platform
Let’s Talk About the Ipro Platform
 
Using SW360 for OSS Compliance Management Process - A Toshiba Case Study for ...
Using SW360 for OSS Compliance Management Process - A Toshiba Case Study for ...Using SW360 for OSS Compliance Management Process - A Toshiba Case Study for ...
Using SW360 for OSS Compliance Management Process - A Toshiba Case Study for ...
 
INTERFACE, by apidays - Lessons learned from implementing our custom ‘Big Da...
INTERFACE, by apidays  - Lessons learned from implementing our custom ‘Big Da...INTERFACE, by apidays  - Lessons learned from implementing our custom ‘Big Da...
INTERFACE, by apidays - Lessons learned from implementing our custom ‘Big Da...
 
Serverless SAP Fiori Apps in SAP Cloud Platfrom
Serverless SAP Fiori Apps in SAP Cloud PlatfromServerless SAP Fiori Apps in SAP Cloud Platfrom
Serverless SAP Fiori Apps in SAP Cloud Platfrom
 
AnyFirewall Engine v10.0 Developer Guide
AnyFirewall Engine v10.0 Developer GuideAnyFirewall Engine v10.0 Developer Guide
AnyFirewall Engine v10.0 Developer Guide
 

Mehr von Shane Coughlan

Mehr von Shane Coughlan (20)

OpenChain - The Ramifications of ISO/IEC 5230 and ISO/IEC 18974 for Legal Pro...
OpenChain - The Ramifications of ISO/IEC 5230 and ISO/IEC 18974 for Legal Pro...OpenChain - The Ramifications of ISO/IEC 5230 and ISO/IEC 18974 for Legal Pro...
OpenChain - The Ramifications of ISO/IEC 5230 and ISO/IEC 18974 for Legal Pro...
 
OpenChain Education Work Group Monthly Meeting - 2024-04-10 - Full Recording
OpenChain Education Work Group Monthly Meeting - 2024-04-10 - Full RecordingOpenChain Education Work Group Monthly Meeting - 2024-04-10 - Full Recording
OpenChain Education Work Group Monthly Meeting - 2024-04-10 - Full Recording
 
OpenChain AI Study Group - Europe and Asia Recap - 2024-04-11 - Full Recording
OpenChain AI Study Group - Europe and Asia Recap - 2024-04-11 - Full RecordingOpenChain AI Study Group - Europe and Asia Recap - 2024-04-11 - Full Recording
OpenChain AI Study Group - Europe and Asia Recap - 2024-04-11 - Full Recording
 
OpenChain Monthly Meeting North America and Asia - 2024-03-19
OpenChain Monthly Meeting North America and Asia - 2024-03-19OpenChain Monthly Meeting North America and Asia - 2024-03-19
OpenChain Monthly Meeting North America and Asia - 2024-03-19
 
OpenChain Webinar: Universal CVSS Calculator
OpenChain Webinar: Universal CVSS CalculatorOpenChain Webinar: Universal CVSS Calculator
OpenChain Webinar: Universal CVSS Calculator
 
openEuler Community Overview - a presentation showing the current scale
openEuler Community Overview - a presentation showing the current scaleopenEuler Community Overview - a presentation showing the current scale
openEuler Community Overview - a presentation showing the current scale
 
OpenChain AI Study Group - North America and Europe - 2024-02-20
OpenChain AI Study Group - North America and Europe - 2024-02-20OpenChain AI Study Group - North America and Europe - 2024-02-20
OpenChain AI Study Group - North America and Europe - 2024-02-20
 
AI Study Group North America - Europe 2024-02-06
AI Study Group North America - Europe 2024-02-06AI Study Group North America - Europe 2024-02-06
AI Study Group North America - Europe 2024-02-06
 
OpenChain Monthly North America / Europe Call - 2024-02-06
OpenChain Monthly North America / Europe Call - 2024-02-06OpenChain Monthly North America / Europe Call - 2024-02-06
OpenChain Monthly North America / Europe Call - 2024-02-06
 
OpenChain Export Control Work Group 2024-01-09
OpenChain Export Control Work Group 2024-01-09OpenChain Export Control Work Group 2024-01-09
OpenChain Export Control Work Group 2024-01-09
 
OpenChain Legal Work Group - 2024-01-17
OpenChain Legal Work Group -  2024-01-17OpenChain Legal Work Group -  2024-01-17
OpenChain Legal Work Group - 2024-01-17
 
Openchain AI Study Group 2024-01-23.pptx
Openchain AI Study Group 2024-01-23.pptxOpenchain AI Study Group 2024-01-23.pptx
Openchain AI Study Group 2024-01-23.pptx
 
OpenChain Webinar #58 - FOSS License Management through aliens4friends in Ecl...
OpenChain Webinar #58 - FOSS License Management through aliens4friends in Ecl...OpenChain Webinar #58 - FOSS License Management through aliens4friends in Ecl...
OpenChain Webinar #58 - FOSS License Management through aliens4friends in Ecl...
 
Maturity Models - Open Compliance Summit 2023
Maturity Models - Open Compliance Summit 2023Maturity Models - Open Compliance Summit 2023
Maturity Models - Open Compliance Summit 2023
 
OpenChain Annual Report 2023 - Key Metrics Slides
OpenChain Annual Report 2023 - Key Metrics SlidesOpenChain Annual Report 2023 - Key Metrics Slides
OpenChain Annual Report 2023 - Key Metrics Slides
 
OpenChain Webinar 57 - The Open Source Initiative - 2023-11-27
OpenChain Webinar 57 - The Open Source Initiative - 2023-11-27OpenChain Webinar 57 - The Open Source Initiative - 2023-11-27
OpenChain Webinar 57 - The Open Source Initiative - 2023-11-27
 
FOSSLight Community Day 2023-11-30
FOSSLight Community Day 2023-11-30FOSSLight Community Day 2023-11-30
FOSSLight Community Day 2023-11-30
 
OpenChain Webinar #56: Generative AI and Your Code
OpenChain Webinar #56: Generative AI and Your CodeOpenChain Webinar #56: Generative AI and Your Code
OpenChain Webinar #56: Generative AI and Your Code
 
From One Standard to a Family - Taiwan Work Group - 2023-08-15.pptx
From One Standard to a Family - Taiwan Work Group - 2023-08-15.pptxFrom One Standard to a Family - Taiwan Work Group - 2023-08-15.pptx
From One Standard to a Family - Taiwan Work Group - 2023-08-15.pptx
 
OpenChain Japan Work Group Meeting #28 - 2023-07-11
OpenChain Japan Work Group Meeting #28 - 2023-07-11OpenChain Japan Work Group Meeting #28 - 2023-07-11
OpenChain Japan Work Group Meeting #28 - 2023-07-11
 

Kürzlich hochgeladen

Love witchcraft +27768521739 Binding love spell in Sandy Springs, GA |psychic...
Love witchcraft +27768521739 Binding love spell in Sandy Springs, GA |psychic...Love witchcraft +27768521739 Binding love spell in Sandy Springs, GA |psychic...
Love witchcraft +27768521739 Binding love spell in Sandy Springs, GA |psychic...
chiefasafspells
 
%+27788225528 love spells in Atlanta Psychic Readings, Attraction spells,Brin...
%+27788225528 love spells in Atlanta Psychic Readings, Attraction spells,Brin...%+27788225528 love spells in Atlanta Psychic Readings, Attraction spells,Brin...
%+27788225528 love spells in Atlanta Psychic Readings, Attraction spells,Brin...
masabamasaba
 
Abortion Pills In Pretoria ](+27832195400*)[ 🏥 Women's Abortion Clinic In Pre...
Abortion Pills In Pretoria ](+27832195400*)[ 🏥 Women's Abortion Clinic In Pre...Abortion Pills In Pretoria ](+27832195400*)[ 🏥 Women's Abortion Clinic In Pre...
Abortion Pills In Pretoria ](+27832195400*)[ 🏥 Women's Abortion Clinic In Pre...
Medical / Health Care (+971588192166) Mifepristone and Misoprostol tablets 200mg
 
Abortion Pill Prices Tembisa [(+27832195400*)] 🏥 Women's Abortion Clinic in T...
Abortion Pill Prices Tembisa [(+27832195400*)] 🏥 Women's Abortion Clinic in T...Abortion Pill Prices Tembisa [(+27832195400*)] 🏥 Women's Abortion Clinic in T...
Abortion Pill Prices Tembisa [(+27832195400*)] 🏥 Women's Abortion Clinic in T...
Medical / Health Care (+971588192166) Mifepristone and Misoprostol tablets 200mg
 

Kürzlich hochgeladen (20)

Love witchcraft +27768521739 Binding love spell in Sandy Springs, GA |psychic...
Love witchcraft +27768521739 Binding love spell in Sandy Springs, GA |psychic...Love witchcraft +27768521739 Binding love spell in Sandy Springs, GA |psychic...
Love witchcraft +27768521739 Binding love spell in Sandy Springs, GA |psychic...
 
WSO2Con2024 - Enabling Transactional System's Exponential Growth With Simplicity
WSO2Con2024 - Enabling Transactional System's Exponential Growth With SimplicityWSO2Con2024 - Enabling Transactional System's Exponential Growth With Simplicity
WSO2Con2024 - Enabling Transactional System's Exponential Growth With Simplicity
 
WSO2CON 2024 - Does Open Source Still Matter?
WSO2CON 2024 - Does Open Source Still Matter?WSO2CON 2024 - Does Open Source Still Matter?
WSO2CON 2024 - Does Open Source Still Matter?
 
Announcing Codolex 2.0 from GDK Software
Announcing Codolex 2.0 from GDK SoftwareAnnouncing Codolex 2.0 from GDK Software
Announcing Codolex 2.0 from GDK Software
 
%in kaalfontein+277-882-255-28 abortion pills for sale in kaalfontein
%in kaalfontein+277-882-255-28 abortion pills for sale in kaalfontein%in kaalfontein+277-882-255-28 abortion pills for sale in kaalfontein
%in kaalfontein+277-882-255-28 abortion pills for sale in kaalfontein
 
%+27788225528 love spells in Atlanta Psychic Readings, Attraction spells,Brin...
%+27788225528 love spells in Atlanta Psychic Readings, Attraction spells,Brin...%+27788225528 love spells in Atlanta Psychic Readings, Attraction spells,Brin...
%+27788225528 love spells in Atlanta Psychic Readings, Attraction spells,Brin...
 
Artyushina_Guest lecture_YorkU CS May 2024.pptx
Artyushina_Guest lecture_YorkU CS May 2024.pptxArtyushina_Guest lecture_YorkU CS May 2024.pptx
Artyushina_Guest lecture_YorkU CS May 2024.pptx
 
%in Soweto+277-882-255-28 abortion pills for sale in soweto
%in Soweto+277-882-255-28 abortion pills for sale in soweto%in Soweto+277-882-255-28 abortion pills for sale in soweto
%in Soweto+277-882-255-28 abortion pills for sale in soweto
 
Abortion Pills In Pretoria ](+27832195400*)[ 🏥 Women's Abortion Clinic In Pre...
Abortion Pills In Pretoria ](+27832195400*)[ 🏥 Women's Abortion Clinic In Pre...Abortion Pills In Pretoria ](+27832195400*)[ 🏥 Women's Abortion Clinic In Pre...
Abortion Pills In Pretoria ](+27832195400*)[ 🏥 Women's Abortion Clinic In Pre...
 
%in tembisa+277-882-255-28 abortion pills for sale in tembisa
%in tembisa+277-882-255-28 abortion pills for sale in tembisa%in tembisa+277-882-255-28 abortion pills for sale in tembisa
%in tembisa+277-882-255-28 abortion pills for sale in tembisa
 
WSO2Con2024 - From Code To Cloud: Fast Track Your Cloud Native Journey with C...
WSO2Con2024 - From Code To Cloud: Fast Track Your Cloud Native Journey with C...WSO2Con2024 - From Code To Cloud: Fast Track Your Cloud Native Journey with C...
WSO2Con2024 - From Code To Cloud: Fast Track Your Cloud Native Journey with C...
 
%in tembisa+277-882-255-28 abortion pills for sale in tembisa
%in tembisa+277-882-255-28 abortion pills for sale in tembisa%in tembisa+277-882-255-28 abortion pills for sale in tembisa
%in tembisa+277-882-255-28 abortion pills for sale in tembisa
 
%in Rustenburg+277-882-255-28 abortion pills for sale in Rustenburg
%in Rustenburg+277-882-255-28 abortion pills for sale in Rustenburg%in Rustenburg+277-882-255-28 abortion pills for sale in Rustenburg
%in Rustenburg+277-882-255-28 abortion pills for sale in Rustenburg
 
WSO2CON 2024 - Freedom First—Unleashing Developer Potential with Open Source
WSO2CON 2024 - Freedom First—Unleashing Developer Potential with Open SourceWSO2CON 2024 - Freedom First—Unleashing Developer Potential with Open Source
WSO2CON 2024 - Freedom First—Unleashing Developer Potential with Open Source
 
Abortion Pill Prices Tembisa [(+27832195400*)] 🏥 Women's Abortion Clinic in T...
Abortion Pill Prices Tembisa [(+27832195400*)] 🏥 Women's Abortion Clinic in T...Abortion Pill Prices Tembisa [(+27832195400*)] 🏥 Women's Abortion Clinic in T...
Abortion Pill Prices Tembisa [(+27832195400*)] 🏥 Women's Abortion Clinic in T...
 
%in Midrand+277-882-255-28 abortion pills for sale in midrand
%in Midrand+277-882-255-28 abortion pills for sale in midrand%in Midrand+277-882-255-28 abortion pills for sale in midrand
%in Midrand+277-882-255-28 abortion pills for sale in midrand
 
%in Benoni+277-882-255-28 abortion pills for sale in Benoni
%in Benoni+277-882-255-28 abortion pills for sale in Benoni%in Benoni+277-882-255-28 abortion pills for sale in Benoni
%in Benoni+277-882-255-28 abortion pills for sale in Benoni
 
%in Hazyview+277-882-255-28 abortion pills for sale in Hazyview
%in Hazyview+277-882-255-28 abortion pills for sale in Hazyview%in Hazyview+277-882-255-28 abortion pills for sale in Hazyview
%in Hazyview+277-882-255-28 abortion pills for sale in Hazyview
 
%in Stilfontein+277-882-255-28 abortion pills for sale in Stilfontein
%in Stilfontein+277-882-255-28 abortion pills for sale in Stilfontein%in Stilfontein+277-882-255-28 abortion pills for sale in Stilfontein
%in Stilfontein+277-882-255-28 abortion pills for sale in Stilfontein
 
VTU technical seminar 8Th Sem on Scikit-learn
VTU technical seminar 8Th Sem on Scikit-learnVTU technical seminar 8Th Sem on Scikit-learn
VTU technical seminar 8Th Sem on Scikit-learn
 

OpenChain Tooling Work Group Meeting #2 - Agenda Slides

  • 1. 2nd meeting open source tooling for open source compliance work group Cpoyright © the open source tooling group 2019
  • 2. Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt Agenda Top Name Actors 1. News All 2. Introduction of the existing work All 3. Areas to focus on Oliver 4. Next steps All
  • 3. Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt News • We have a logo • First version of the website is online https://oss-compliance-tooling.org/ • Presentation template available in impress format: https://github.com/Open-Source-Compliance/Sharing- creates-value/tree/master/Templates • New contribution from Michael Picht Vulas and CLA assistant were added to the tools – Thank you Michael • Events • Past Events • OSS Summit NA • Upcoming Events • OSS working team meeting of BITKOM • OSS Summit Europe in Lyon
  • 4. Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt Agenda Top Name Actors 1. News All 2. Introduction of the existing work All 3. Areas to focus on Oliver 4. Next steps All
  • 5. Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt Integrated, automated – end to end OSS compliance toolchain made with OSS To build an integrated end to end compliance toolchain is not about to build a monolithic monster, it is about to use current available Open Source tools and define and implement the needed APIs/Data structures they need to provide, in order to plug them into the current set up CI/CD workflow and to enable them to trigger other Open Source compliance tools in a way that they seamlessly interact which each other and potential external data sources. The already existing projects remain independent projects We are making turn-key Open Source tooling for Open Source Compliance
  • 6. Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt Big Picture – Integrated Compliance Toolchain CI / CD Infrastructure License & Copyright Scanner Component Analysis Service Compliance artifact consistency Component inventory (Metadata Repository) Dependency resolver Source package downloader Container content resolver License Obligations Database Policy checker (Compliance Checker) Obligation fulfillment Build Tools Continous IntegrationArtifact Repository Source Code Repo outbound software & compliance artifacts FOSS Compliance Bundle generator Binary analyser Inbound software Public compliance artifact repos contributions Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data)
  • 7. Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt Integrated, automated – end to end OSS compliance toolchain made with OSS We are making turn-key Open Source tooling for Open Source Compliance • Identify the functional blocks required • Identify the workflows • Identify the required data and data flows • Implement provide the needed APIs (as contributions) • Provide the glue Code • Provide easy to deploy building blocks • Documentation • Spread the word
  • 8. Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt UML Big Picture View https://github.com/Open-Source-Compliance/Sharing- creates-value/blob/master/Tooling- Landscape/Unanimous- Understanding/OSS_Tooling_Landscape_UML_Deploy.pl antuml Glossary https://github.com/Open-Source-Compliance/Sharing- creates-value/blob/master/Tooling- Landscape/Unanimous-Understanding/OSS-Tooling- Landscape-Glossary.md Introduction of the existing work
  • 9. Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt Introduction of the existing work Process flows: https://github.com/Open-Source- Compliance/Sharing-creates- value/tree/master/Tooling-Landscape/Unanimous- Understanding/Process%20Flows
  • 10. Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt Data Model: https://github.com/Open-Source- Compliance/Sharing-creates- value/tree/master/Tooling-Landscape/Unanimous- Understanding/Data%20Structures Introduction of the existing work
  • 11. Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt Agenda Top Name Actors 1. News All 2. Introduction of the existing work All 3. Areas to focus on Oliver 4. Next steps All
  • 12. Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt Areas to focus on
  • 13. Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt Big Picture – Integrated Compliance Toolchain CI / CD Infrastructure License & Copyright Scanner Component Analysis Service Compliance artifact consistency Component inventory (Metadata Repository) Dependency resolver Source package downloader Container content resolver License Obligations Database Policy checker (Compliance Checker) Obligation fulfillment Build Tools Continous IntegrationArtifact Repository Source Code Repo outbound software & compliance artifacts FOSS Compliance Bundle generator Binary analyser Inbound software Public compliance artifact repos contributions Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) License: CC-BY-SA-4.0
  • 14. Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt Big Picture – Integrated Compliance Toolchain Instance CI / CD Infrastructure Component Analysis Service Compliance artifact consistency Build Tools Continous IntegrationArtifact Repository Source Code Repo outbound software & compliance artifacts BANG Inbound software contributions Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) Integration layer (API/Data) ScanCode Dependency resolver Binary analyserContainer content resolver Source package downloader Component inventory License & Copyright Scanner Policy checker Obligation fulfillment FOSS Compliance Bundle generator License Obligations Database License Classifier Public compliance artifact repos
  • 15. Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt Next steps
  • 16. Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt Restructuring of the repo sharing-creates-value Move to OSS-compliance-work- results a new repo of the group Open-Source-Compliance Update and move content to OSS-compliance-work-results a new repo of the group Open- Source-Compliance Preparing a slide deck with an overview of the tooling working group – that can be used when someone wants to give a presentation about the tooling working group
  • 17. 2019 Licensed under CC-BY-SA-4.0 Oliver Fendt User stories We are making turn-key Open Source tooling for Open Source Compliance • As a Software developer I … • As a compliance officer I … • As a product owner I … • As a legal assessor I … • As a compliance assistant I … • ….
  • 18. Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt Next Meeting Date: 18th of Sept
  • 19. Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt Links / Communication Github: https://github.com/Open-Source-Compliance/Sharing-creates-value Slack: https://join.slack.com/t/ossbasedcompl- bhx9742/shared_invite/enQtNzA5OTc3OTAwMjExLWNhYWVkZDk2Y2RlNDI4ODI2N zQyNDU5ZWE4ODRmZWI1ZmM1MzA4ZTc2MTdkZGFhMzc2NmUyODRhNDZjNWI 5Njc Mailing List: Subscription page: https://groups.io/g/oss-based-compliance-tooling Email address: oss-based-compliance-tooling@groups.io Where to communicate what?
  • 20. Copyright 2019 The tooling working group Licensed under CC-BY-SA-4.0 Oliver Fendt Credits Picture by Splitshireon https//pixabay.com license: pixabay license