ClearlyDefined v2.0 adds support for LicenseRefs

Favorite One of the major focuses of the ClearlyDefined Technical Roadmap is the improvement in the quality of license data. As such, we are excited to announce the release of ClearlyDefined v2.0 which adds over 2,000 new well-known licenses it can identify. You can see the complete list of new non-SPDX licenses in ScanCode LicenseDB.

Read More
Shared by voicesofopensource November 12, 2024

ClearlyDefined at SOSS Fusion 2024: a collaborative solution to Open Source license compliance

Favorite This past month, the Open Source Security Foundation (OpenSSF) hosted SOSS Fusion in Atlanta, an event that brought together a diverse community of leaders and innovators from across the digital security spectrum. The conference, held on October 22-23, explored themes central to today’s technological landscape: AI security, diversity in

Read More
Shared by voicesofopensource November 6, 2024

ClearlyDefined’s Steering and Outreach Committees Defined

Favorite We are excited to announce the newly elected leaders for the ClearlyDefined Steering and Outreach Committees! What is ClearlyDefined? ClearlyDefined is an Open Source project dedicated to improving the clarity and transparency of Open Source licensing and security data. By harvesting, curating, and sharing essential metadata, ClearlyDefined helps developers

Read More
Shared by voicesofopensource October 16, 2024

GUAC adopts license metadata from ClearlyDefined

Favorite The software supply chain just gained some transparency thanks to an integration of the Open Source Initiative (OSI) project, ClearlyDefined, into GUAC (Graph for Understanding Artifact Composition), an OpenSSF project from the Linux Foundation. GUAC provides a comprehensive mapping of software packages, dependencies, vulnerabilities, attestations, and more, allowing organizations

Read More
Shared by voicesofopensource August 6, 2024

Better identifying conda packages with ClearlyDefined

Favorite ClearlyDefined, an Open Source project that helps organizations with supply chain compliance,  now provides a new harvester implementation for conda, a popular package manager with a large collection of pre-built packages for various domains, including data science, machine learning, scientific computing and more. Conda provides package, dependency and environment

Read More
Shared by voicesofopensource July 23, 2024

Beyond SPDX: expanding licenses identified by ClearlyDefined

Favorite ClearlyDefined is an Open Source project that helps organizations with supply chain compliance. Until recently, ClearlyDefined’s tooling only supported licenses that were part of the standardized SPDX license list. Any component identified by a license that was not part of this list resulted in NOASSERTION, which introduced uncertainty about

Read More
Shared by voicesofopensource July 9, 2024

ClearlyDefined at the ORT Community Days

Favorite Once again Bosch’s campus in Berlin received ORT Community Days, the annual event organized by the OSS Review Toolkit (ORT) community. ORT is an Open Source suite of tools to automate software compliance checks. During this two day event, members from startups like Double Open and NexB, as well

Read More
Shared by voicesofopensource March 13, 2024

Three perspectives from FOSS Backstage

Favorite As a community manager, I find FOSS Backstage to be one of my favorite conferences content-wise and community-wise. This is a conference that happens every year in Berlin, usually in early March. It’s a great opportunity to meet community leaders from Europe and across the world with the goal

Read More
Shared by voicesofopensource March 13, 2024