Linux Foundation offers open source compliance checklist
IDG News Service - Organizations that are interested in using open source in their own products but are wary of intellectual property issues might want to examine a new, mostly free, assistance program just launched by the non-profit Linux Foundation.
The Open Compliance Program includes an assessment checklist, training programs and software tools to monitor open source software usage.
Especially in the growing field of mobile device and consumer electronics manufacturers, software development often involves use of multiple programs -- many open source -- in a single stack, said Jim Zemlin, executive director of The Linux Foundation.
"You have a really complicated supply chain, where you might get source code coming from lots of different places, whether it is a chipset vendor, a mobile handset provider or embedded software vendor," he said. "Managing open source license compliance is complicated."
Related Blog
Linux Foundation launches major open-source license compliance program
Many companies are unaware of how different software licensing works with open source, or their executives fear being forced to divulge their own software code because it was intermingled with some open source code under the Gnu Public License (GPL). SAP, for instance, has set up an open source office and program specifically to deal with such issues.
"What we were looking for is [a way] to solve this complexity and to prevent needless lawsuits," Zemlin said. "Our community has the exact same goal that the industry has, to make using open source as low-cost and as easy as possible."
The Linux Foundation's program provides a range of tools and services to get such companies up to speed, Zemlin said.
The program includes a self-assessment check-list (available in late 2010), training programs, software tools that check programs for open source licensing or other issues, a community workgroup, a compliance directory of companies using open source software, and a new standard, called the Software Package Data Exchange (SPDX), that can be used to create a packing list of all supporting software components within an application.
All these services, except for the training courses, will be free, Zemlin said.
Organizations such as Adobe, Advanced Micro Devices, Cisco Systems, Google, Hewlett-Packard, IBM, Intel, Motorola, Novell, Samsung, the Software Freedom Law Center and Sony Electronics have endorsed this program.
Joab Jackson covers enterprise software and general technology breaking news for The IDG News Service. Follow Joab on Twitter at @Joab_Jackson. Joab's e-mail address is Joab_Jackson@idg.com



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- ESG: Defining Tier One Storage in the Modern Data Center
- This report defines "tier-1" storage in the modern IT world and in the data centers and services that support it. What was a...
- ESG: Using HP's Converged Storage to Develop/Enhance Business Resiliency in VMware Environments
- In this report, Enterprise Strategy Group reviews how HP's portfolio of hardware, software, and services can provide the foundational support for VMware environments....
- HP 3PAR Storage Systems Designed for Mission Critical High Availability
- In this technical whitepaper, learn how HP 3PAR Storage Systems have been designed to deliver 99.999% and greater availability, bringing new possibilities to...
- Utility Storage - The Ideal Platform for Virtual and Cloud Computing
- Server virtualization has transformed corporate IT -- companies have enjoyed major cost savings and have gained flexibility and efficiency. But this has also...
- ESG Lab Review: Focus on Federated Workload Balancing, Asset Management, and Thin Provisioning
- This ESG Lab review documents hands-on testing of HP 3PAR Peer Motion Software's distributed volume management with a focus on federated workload balancing,... All DRM and Legal Issues White Papers
- The Higher-Bandwidth, Lower-Cost Connection of Choice: 10GBASE-T LAN on Motherboard
- Learn how Expedient, a cloud provider, is using 10 Gigabit Ethernet to boost its services and rein in costs.
- Banish Poor Application Performance
- End User Experience, 30-Min Webinar
Wed. March 21st ~ 11 AM ET
Are you ready to gain the proactive ability to rapidly respond... - Virtualization KnowledgeVault
- Virtualization initiatives are underway at most small and midsize businesses, but some unexpected challenges have prevented many organizations from achieving original goals. This...
- Mobility KnowledgeVault
- How "mobile ready" is your infrastructure? This Mobility Knowledge Vault provides a wide variety of expert advice on how to strike a balance...
- Integrated IT Operations Management in the Cloud
- Join award-winning technology editor Stan Gibson and Andrew White, CMO at BMC, to learn how asset management and service management are converging and... All DRM and Legal Issues Webcasts