Talk
Beginner
First Talk

Early Risk Indication tool for OSS Compliance

Rejected

Session Description

This presentation showcases an innovative utility developed inhouse to identify early risk components using open-source tools and libraries. It addresses the challenges of OSS license compliance and security risks, offering practical solutions to mitigate these issues early in the build phase.

 In today's software landscape, commercial products heavily rely on open-source components. However, developers often lack detailed knowledge of the associated license obligations. Our utility addresses this by identifying third-party libraries early in the build phase, enabling timely decisions to mitigate license and security risks. 

Benefits to the Ecosystem 

Attendees will gain a deeper understanding of the challenges associated with open-source license compliance and security risks. They will learn about practical solutions and tools that can be integrated into their development workflows to mitigate these risks early in the build phase.

 Scope

  • Utilize internal and third-party tools such as:
    Maven-scanner, Node-scanner, Gradle-scanner, Go-scanner, Deb-scanner, Container-scanner, NuGet-scanner, PyPI-scanner, Trivy

  • Analyze components defined in package managers.

  • Generate structured reports in Excel format.

Business Impact:
By providing developers with early risk assessment of their codebase before consulting FOSS experts, we enable proactive decision-making regarding package integration. This preventive approach reduces the need for late-stage modifications and expert consultations, resulting in an estimated 10-20% cost reduction in development and compliance processes.

Future Scope

The utility is planned for release as an open-source solution, enabling community collaboration and continuous improvement through public contributions.

Key Takeaways

  • Introduce different package manager tools

  • Visualize license risks, security risks and End of life components from the scanned code

  • Realtime decision making and mitigation measures.

References

Session Categories

Technology / FOSS licenses, policy
Which track are you applying for?
Main track

Speakers

Kiran Kumar Reddy Aluka
License/OSS Management Professional SIemens Technology and Services Ltd
linkedin.com/in/kiranaluka
Kiran Kumar Reddy Aluka
Sudhakar M S
License/OSS Management Professional SIemens Technology and Services Ltd
linkedin.com/in/sudhakar-m-s-bab776b5
Sudhakar M S

Reviews

0 %
Approvability
0
Approvals
3
Rejections
0
Not Sure

The utility is planned for release as an open-source solution, enabling community collaboration and continuous improvement through public contributions

Reviewer #1
Rejected

We can only accept a talk about a FOSS project. The proposal does not mention when exactly is this going to be open sourced

Reviewer #2
Rejected

Your proposal is not about a FOSS project, as the tool you are presenting is currently in-house and does not have a confirmed open-source release date.

For future submissions, we recommend that you submit your proposal once the tool has been released as a FOSS project. This will allow the program committee to better evaluate your contribution to the FOSS ecosystem and ensure that your talk is a better fit for the conference.

Reviewer #3
Rejected