Chapter 1. Introduction
Introduces an overview of the open source audit process in M&A transactions.
This document is a translation of Open Source Audits in Merger and Acquisition Transactions: The Basics You Must Know (by Ibrahim Haddad, Ph.D., 2018), published by the Linux Foundation. The original author has not reviewed this translation. The original can be viewed at the original PDF.
In an era where software sits at the center of every deal, open source due diligence has become standard practice in mergers and acquisitions (M&A). This book covers how open source audits are conducted in M&A transactions, and what the acquirer and the target company each need to prepare.
Introduces an overview of the open source audit process in M&A transactions.
Summarizes the ways open source enters a codebase: incorporation, linking, and modification.
Explains why open source audits are performed, the criteria for deciding whether to commission one, and the inputs and outputs of the audit process.
Explains the code size and characteristics an auditor must understand to produce an audit estimate, and how urgency affects cost.
Explains the procedures and trade-offs of three audit methods: traditional audits, blind audits, and do-it-yourself (DIY) audits.
Notes that final reports may contain a lot of noise, requiring time to filter out real issues, and that SPDX-format reports must be requested to be received.
Explains that vulnerabilities in open source projects are disclosed alongside the fix process, and that although security and version control are not part of compliance due diligence, scan service providers may address them separately.
Covers the options for resolving compliance issues revealed by the audit, and how the cost of each option can be used in valuing the target company.
Covers how a target company can prepare in advance for an open source audit through its regular compliance activities.
Covers the decisions the acquirer must make before commissioning an audit, and the additional obligations after receiving the audit results.
Summarizes development practices that reduce compliance issues, and mistakes that must be avoided.
Summarizes what the target company and the acquirer each need to prepare in order for open source due diligence to proceed smoothly.