ClearlyDefined at SOSS Fusion 2024: a collaborative solution to Open Source license compliance

Favorite This past month, the Open Source Security Foundation (OpenSSF) hosted SOSS Fusion in Atlanta, an event that brought together a diverse community of leaders and innovators from across the digital security spectrum. The conference, held on October 22-23, explored themes central to today’s technological landscape: AI security, diversity in

Read More
Shared by voicesofopensource November 6, 2024

GUAC adopts license metadata from ClearlyDefined

Favorite The software supply chain just gained some transparency thanks to an integration of the Open Source Initiative (OSI) project, ClearlyDefined, into GUAC (Graph for Understanding Artifact Composition), an OpenSSF project from the Linux Foundation. GUAC provides a comprehensive mapping of software packages, dependencies, vulnerabilities, attestations, and more, allowing organizations

Read More
Shared by voicesofopensource August 6, 2024

Better identifying conda packages with ClearlyDefined

Favorite ClearlyDefined, an Open Source project that helps organizations with supply chain compliance,  now provides a new harvester implementation for conda, a popular package manager with a large collection of pre-built packages for various domains, including data science, machine learning, scientific computing and more. Conda provides package, dependency and environment

Read More
Shared by voicesofopensource July 23, 2024

Beyond SPDX: expanding licenses identified by ClearlyDefined

Favorite ClearlyDefined is an Open Source project that helps organizations with supply chain compliance. Until recently, ClearlyDefined’s tooling only supported licenses that were part of the standardized SPDX license list. Any component identified by a license that was not part of this list resulted in NOASSERTION, which introduced uncertainty about

Read More
Shared by voicesofopensource July 9, 2024

The most popular licenses for each language in 2023

Favorite The 2023 report of the licenses in use by the biggest package managers highlights the need to educate developers on the importance of licensing information. While many developers know that Open Source software forms the backbone of modern development, the data shows that much of their software is shared

Read More
Shared by voicesofopensource December 7, 2023

The Approved Open Source Licenses never looked better

Favorite A license-review project has been underway with the goal of creating a systematic and well-ordered database of all the licenses that have been submitted to OSI for approval since the time of the organization’s founding. Giulia Dellanoce was brought on as an intern to complete this Approval Registry project,

Read More
Shared by voicesofopensource September 7, 2023