Skip to content

This repository contains the reference material related to the OpenChain Project

License

Notifications You must be signed in to change notification settings

OpenChain-Project/Reference-Material

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Reference-Material

This repository contains reference material both directly related to the OpenChain Project and more generally to matters around license, security and other compliance topics in the open source supply chain.

How This Library Works

The library contains over 1,000 documents. To ensure ease of navigation and our ability to adjust and improve the library structure over time, you will find that navigation is primarily guided by this README file, which acts as the starting point for all navigation.

The intention is that:

  1. You will enter this library at the top level of the archive
  2. You will use this README file as your index
  3. We will update the README as the library evolves

How To Navigate The Library (the Index of Contents)

As of 2025-05-08, the library is structured in the following folders alphabetically:

  1. AI-SBOM-Compliance
  2. Open-Source-Compliance-Support-Material
  3. Open-Source-Policy-Templates
  4. OpenChain-Adoption-Guides
  5. OpenChain-Case-Studies
  6. OpenChain-Explainers-For-Internal-Teams
  7. OpenChain-FAQ
  8. OpenChain-For-Mergers-and-Acquisitions
  9. OpenChain-Maturity-Models
  10. OpenChain-Promotion-Material
  11. OpenChain-Standards-Self-Certification
  12. OpenChain-Supplier-Education
  13. OpenChain-Templates
  14. OpenChain-Training
  15. SBOM-Quality-Management

AI-Compliance

OpenChain has an AI Work Group. This is where you will find our work on AI compliance topics. The current focus is on AI SBOM management in the supply chain, and what type of program process points are required to manage this effectively.

There is a copy of the working document in this folder, and the active version for editing is kept here: https://docs.google.com/document/d/1XHztgMALwnu2D02bmWYyXeW3wE_Jw199/edit?pli=1#heading=h.pzcghykzc46

You are welcome to be part of this work. OpenChain AI Work Group mailing list: https://lists.openchainproject.org/g/ai

Open-Source-Compliance-Support-Material

This folder contains compliance-related material non-specific to OpenChain. You may find these community contributions useful in your work.

Open-Source-Policy-Templates

Having an open source policy is a requirement in our standards. This folder contains some template material to get you started or to help you refine existing policies.

OpenChain-Adoption-Guides

This folder contains guides to adopting the OpenChain standards.

OpenChain-Case-Studies

This folder contains case studies from companies that have adopted OpenChain standards.

OpenChain-Explainers-For-Internal-Teams

Explaining the value of OpenChain approaches to compliance process management is critical to ensure buy-in and support across an organization. We have created a series of quick explainer documents to support this.

OpenChain-FAQ

This folder contains the official OpenChain Project Frequently Asked Questions. These are mirrored on our website.

OpenChain-For-Mergers-and-Acquisitions

This folder contains some material relevant to understanding OpenChain standards in the context of Mergers and Acquisitions.

OpenChain-Maturity-Models

Once an organization has begun to adopt OpenChain standards, the question arises of how to iterate and improve their compliance program. Maturity models or capability models are a tool to assist with this. We have one to share with you as a reference guide.

OpenChain-Promotion-Material

This folder contains infographics, one-pagers and introductory presentations to help organizations understand the OpenChain Project, its standards, its reference material, and the global community supporting its work.

OpenChain-Standards-Self-Certification

This folder contains self-certification checklists and questionnaires to help companies easily adopt our standards. This material can also be used as a "health check" for organizations not currently using our standards.

OpenChain-Supplier-Education

This folder contains a leaflet designed to give suppliers a single file that takes them from "what is open source" through to the importance of license compliance, and the use of OpenChain standards.

OpenChain-Templates

This folder contains templates so that the community can develop new presentations or documents with the OpenChain trademarks, mascots and other images.

OpenChain-Training

This folder contains our reference training slides and also the source code for our online training courses.

SBOM-Quality-Management

OpenChain has an SBOM Study Group. This is where you will find our work on SBOM-related topics. The current focus is on SBOM Quality in the supply chain, and what type of approach is required to manage this effectively.

You are welcome to be part of this work. OpenChain SBOM Study Group mailing list: https://lists.openchainproject.org/g/sbom

Where To Get Help

Our website FAQ page contains resources to get help from our project staff: https://openchainproject.org/resources/faq

How To Participate In Development

We would be delighted to work with you through our Education Work Group. You will find their mailing list here: https://lists.openchainproject.org/g/education

You are encourage to open issues or pull requests online: https://github.com/OpenChain-Project/Reference-Material/issues

Licensing

Most of the material in this repository is available under CC-0 licensing (effectively public domain). You will notice some exceptions with Guides (like the Telco SBOM Guide) and with case studies. These documents are not designed to be freely altered because they provide either guidance developed to consensus in our work groups, or the specific experience of companies in addressing compliance matters.

About

This repository contains the reference material related to the OpenChain Project

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages