Effective Open Source Management Practices for Companies (2): OpenChain Korea Work Group

In the previous post, I introduced the OpenChain Project for global collaboration as an effective open source management practice for companies. This time, I would like to introduce the OpenChain Korea Work Group, a collaborative community for Korean companies to effectively manage open source.

OpenChain Korea Work Group

The OpenChain Korea Work Group (KWG) is a subgroup of the Linux Foundation’s OpenChain Project. This group is a gathering where, through the open source spirit of collaboration and sharing, everyone thinks about and shares ways to succeed at effective open source management. Open source managers from Korea’s major ICT companies participate in the KWG.

featured_kwg

OpenChain KWG Regular Meetings

Even large companies that have already established policies and processes for open source management find it difficult to escape open source license or security vulnerability risks, given today’s massive and complex software supply chains. Ultimately, it is important to raise the level of open source management across all companies in the software supply chain. To achieve this, companies with a high level of understanding of open source management practices need to first share their know-how and act as a guide so that other companies can easily participate.

Even if a company shares its open source management assets with competitors, this does not negatively affect revenue. Conversely, even if a company learns a competitor’s open source management policy, it cannot connect this to its own profit. If companies share open source management best practices with each other, each company can achieve significant results with less cost and fewer resources invested. Resonating with this idea, the first OpenChain KWG meeting, attended by open source managers from LG Electronics, SK telecom, Kakao, Hyundai Motor, and Samsung Electronics, was held in January 2019.

17th Meeting (In-Person)

The meetings are held every quarter, and were held online during the COVID-19 period. Then, on March 28, 2023, an in-person meeting was held for the first time in 3 years. About 50 open source managers from 19 companies/organizations attended. This in-person meeting was organized by LINE Plus. Thank you to LINE Plus’s open source managers Seoyeon Lee and Donghyuk Kim for providing a comfortable venue, refreshments, and souvenirs! ^^

Untitled

In the first part of this meeting, there were presentations on the latest domestic and international trends in the OpenChain Project and the security assurance specification, as well as a presentation on legal issues and case studies related to AI technology. In the second part, there was a session presenting open source tools developed and shared by companies for open source management. I will cover the details of each presentation below.

Part 1: Session Presentations

OpenChain Global Update (Linux Foundation, Shane Coughlan)

Shane Coughlan, General Manager of the Linux Foundation’s OpenChain Project, attended in person and introduced the Global Trend of the OpenChain Project.

Untitled

In addition to ISO/IEC 5230, the standard for open source compliance, ISO/IEC DIS 18974, a standard for security, is also under development. This standard is expected to soon be registered as an official ISO standard, and a Self-Checklist that companies must comply with has also been published. Companies can use these materials to carry out efficient open source risk management.

Shane also brought souvenirs for KWG members, which received a great response. (Thank you, Shane.)

Untitled

Introduction to the OpenChain Security Standard (SK telecom, Haksung Jang)

ISO/IEC 5230 is the international standard for open source compliance. This standard was registered with ISO in 2020, and many companies around the world comply with this standard to carry out open source compliance management well. The reason companies need to manage open source is not only license compliance but also the risk of security vulnerabilities. The OpenChain Project has created a standard for security vulnerability management, ISO/IEC DIS 18974, the OpenChain security assurance specification. I gave a brief summary introduction of what this standard consists of.

Untitled

This security standard is organized in the same format as ISO/IEC 5230. Instead of license compliance, it defines the requirements that must be fulfilled for security vulnerability management. In addition to license compliance, companies must establish policies and processes for security vulnerability management. They must also establish procedures to respond to discovered security vulnerabilities.

Untitled

Jungsuk Park of ETRI analyzed the recently filed Stable Diffusion-related lawsuit and introduced AI legal issues. The presentation materials can be found here.

Untitled

Jungsuk Park analyzed the current status of AI-related legislation, and based on this, explored and shared ways to respond to AI-related open source compliance issues.

Untitled

Part 2: Mini Summit - Open Source Management Automation Tools

In Part 2, there were session presentations sharing each company’s best practices for automating open source management.

Dependency Analysis Methods by Tool (Kakao, Hyunji Lim)

Hyunji Lim of Kakao presented a comparative analysis of the dependency analysis methods of open source analysis tools. The presentation materials can be found here.

Untitled

She identified and shared the dependency analysis methods of the representative open source analysis tools FOSSA, FOSSLight, ORT (OSS Review Toolkit), and OLIVE Platform.

Untitled

OSORI (LG Electronics, Soim Kim)

Soim Kim of LG Electronics gave a session presentation introducing the OSORI project.

Untitled

OSORI is an open source project that discloses open source information data so that anyone can easily check open source information and comply with the necessary obligations. It defined a schema for building a database of the key information, license types, and related key compliance and restriction requirements for open source projects held by LG Electronics, Samsung Electronics, and Kakao, organized as tables by item, and introduced a roadmap for future data refinement, establishing operating policy, and building a guide page.

Untitled

FOSSLight Roadmap (LG Electronics, Kyungae Kim)

FOSSLight is an integrated open source management system developed in-house by LG Electronics, which was open-sourced in 2021 for anyone to use. Kyungae Kim of LG Electronics introduced the 2023 FOSSLight Roadmap.

Untitled

The FOSSLight Project has a roadmap for 2023 that includes improving security vulnerability features, strengthening SBOM functionality, and improving UX.

Untitled

Have You Tried OLIVE Lately? (Kakao, Eunkyung Hwang)

OLIVE Platform is an open source license verification service developed by Kakao, which anyone can use for free with just a Kakao account. Eunkyung Hwang of Kakao introduced the key features of the OLIVE Platform.

Untitled

The OLIVE Platform added the OLIVE CLI feature, which can be used safely even when there are concerns about source code exposure, allowing it to be adopted even in the security-sensitive financial sector.

Untitled

onot Has Gotten Pretty Usable! (Kakao, Hyeonmin Han)

onot is an open source project jointly developed by SK telecom and Kakao. It is a tool that automatically converts an SBOM written in the SPDX format into an open source notice. Hyeonmin Han of Kakao introduced the new features recently added to onot. The presentation materials can be found here.

Untitled

onot can now extract file information in addition to package information, and now also supports multi-license notation. It can generate open source notices from SPDX documents in RDF/XML format as well, and now supports a more convenient user environment, such as a GUI on Windows PCs.

Untitled

Closing

The in-person meeting, held for the first time in about 3 years, was so packed with content that the short time felt like too little. Thank you again to Seoyeon Lee and Donghyuk Kim of LINE Plus for preparing a wonderful venue, souvenirs, and even raffle prizes.

Untitled

Companies face similar difficulties in open source management work, and sharing how they overcame and streamlined these challenges is of great help to one another. The OpenChain Korea Work Group is a gathering that anyone who shares this sentiment can voluntarily join. Anyone in charge of open source management at a company or organization can participate in the OpenChain Korea Work Group: How to Join

Lastly, the OpenChain KWG holds regular meetings every quarter. The next meeting is expected to be held at Kakao.

Until then, happy days to everyone!

Last modified August 9, 2026: 전체 콘텐츠 영어판 추가 (608dd718)