This is the multi-page printable view of this section. Click here to print.
2023
Checklist for Preparing an In-Person Meeting
Hello. Last March 28 was a time everyone will remember. It was our first in-person meeting in three years, since before COVID. Having gone so long without one, I learned that hosting a venue takes more miscellaneous preparation than I expected.
We’ll hold another in-person meeting like this at some point, so drawing on this experience, I put together a checklist for preparing one. (The next host might end up being me again… oops, better not jinx it!)

Before the Meeting
A list of tasks worth doing before the meeting. It includes work the Planning Sub-group should handle.
- Set the date and time of the meeting
- Recruit speakers
- Collect advance registrations — a Google Form is recommended (to gauge how large a venue you’ll need and to collect information needed for building access)
- Check the visitor access procedure and pre-register visitors if required
- Check visitor parking arrangements
- Check whether visitors may bring electronic devices
- Check what wireless internet is available to visitors
- Prepare name badges for attendees (so names and affiliations are easy to recognize)
- Prepare venue guidance slides
- Send a guidance email about visiting the venue
- Check the venue and confirm equipment (desks, chairs, speaker laptop, microphone, sound system, projector, laser pointer, etc.)
- Prepare a budget for refreshments and giveaways if needed
Day of the Meeting
A list of tasks to complete on the day of the meeting, before it starts.
- Put up event signage (to guide other employees nearby)
- Check the microphone, sound system, and projector setup and connections
- Prepare the presentation laptop
- Set up the venue, adding chairs if needed
- Post Wi-Fi instructions (print them out and place them in the venue)
- Set up a table for handing out name badges
- Prepare refreshments if needed
- Have company introduction materials on hand if needed
- Guide attendees in and direct them to their seats
After the Event
A list of tasks to complete after the event ends.
- Guide attendees out (returning visitor badges, settling parking)
- Take down event signage
- Tidy up the venue
That covers the memorable points I’ve drawn on to put together this checklist. I hope it helps with preparing future events. If I learn anything new from a future event, I’ll update the list again.
Thank you.
Effective Open Source Management Practices for Companies (2): OpenChain Korea Work Group
In the previous post, I introduced the OpenChain Project for global collaboration as an effective open source management practice for companies. This time, I would like to introduce the OpenChain Korea Work Group, a collaborative community for Korean companies to effectively manage open source.
OpenChain Korea Work Group
The OpenChain Korea Work Group (KWG) is a subgroup of the Linux Foundation’s OpenChain Project. This group is a gathering where, through the open source spirit of collaboration and sharing, everyone thinks about and shares ways to succeed at effective open source management. Open source managers from Korea’s major ICT companies participate in the KWG.

OpenChain KWG Regular Meetings
Even large companies that have already established policies and processes for open source management find it difficult to escape open source license or security vulnerability risks, given today’s massive and complex software supply chains. Ultimately, it is important to raise the level of open source management across all companies in the software supply chain. To achieve this, companies with a high level of understanding of open source management practices need to first share their know-how and act as a guide so that other companies can easily participate.
Even if a company shares its open source management assets with competitors, this does not negatively affect revenue. Conversely, even if a company learns a competitor’s open source management policy, it cannot connect this to its own profit. If companies share open source management best practices with each other, each company can achieve significant results with less cost and fewer resources invested. Resonating with this idea, the first OpenChain KWG meeting, attended by open source managers from LG Electronics, SK telecom, Kakao, Hyundai Motor, and Samsung Electronics, was held in January 2019.
17th Meeting (In-Person)
The meetings are held every quarter, and were held online during the COVID-19 period. Then, on March 28, 2023, an in-person meeting was held for the first time in 3 years. About 50 open source managers from 19 companies/organizations attended. This in-person meeting was organized by LINE Plus. Thank you to LINE Plus’s open source managers Seoyeon Lee and Donghyuk Kim for providing a comfortable venue, refreshments, and souvenirs! ^^

In the first part of this meeting, there were presentations on the latest domestic and international trends in the OpenChain Project and the security assurance specification, as well as a presentation on legal issues and case studies related to AI technology. In the second part, there was a session presenting open source tools developed and shared by companies for open source management. I will cover the details of each presentation below.
Part 1: Session Presentations
OpenChain Global Update (Linux Foundation, Shane Coughlan)
Shane Coughlan, General Manager of the Linux Foundation’s OpenChain Project, attended in person and introduced the Global Trend of the OpenChain Project.

In addition to ISO/IEC 5230, the standard for open source compliance, ISO/IEC 18974, a standard for security, is also under development. This standard is expected to soon be registered as an official ISO standard, and a Self-Checklist that companies must comply with has also been published. Companies can use these materials to carry out efficient open source risk management.
Shane also brought souvenirs for KWG members, which received a great response. (Thank you, Shane.)

Introduction to the OpenChain Security Standard (SK telecom, Haksung Jang)
ISO/IEC 5230 is the international standard for open source compliance. This standard was registered with ISO in 2020, and many companies around the world comply with this standard to carry out open source compliance management well. The reason companies need to manage open source is not only license compliance but also the risk of security vulnerabilities. The OpenChain Project has created a standard for security vulnerability management, ISO/IEC 18974, the OpenChain security assurance specification. I gave a brief summary introduction of what this standard consists of.

This security standard is organized in the same format as ISO/IEC 5230. Instead of license compliance, it defines the requirements that must be fulfilled for security vulnerability management. In addition to license compliance, companies must establish policies and processes for security vulnerability management. They must also establish procedures to respond to discovered security vulnerabilities.
Legal Issues of AI Technologies / Case Study: Getty Images v. Stability AI (ETRI, Jungsuk Park)

Jungsuk Park of ETRI analyzed the recently filed Stable Diffusion-related lawsuit and introduced AI legal issues. The presentation materials can be found here.

Jungsuk Park analyzed the current status of AI-related legislation, and based on this, explored and shared ways to respond to AI-related open source compliance issues.

Part 2: Mini Summit - Open Source Management Automation Tools
In Part 2, there were session presentations sharing each company’s best practices for automating open source management.
Dependency Analysis Methods by Tool (Kakao, Hyunji Lim)
Hyunji Lim of Kakao presented a comparative analysis of the dependency analysis methods of open source analysis tools. The presentation materials can be found here.

She identified and shared the dependency analysis methods of the representative open source analysis tools FOSSA, FOSSLight, ORT (OSS Review Toolkit), and OLIVE Platform.

OSORI (LG Electronics, Soim Kim)
Soim Kim of LG Electronics gave a session presentation introducing the OSORI project.

OSORI is an open source project that discloses open source information data so that anyone can easily check open source information and comply with the necessary obligations. It defined a schema for building a database of the key information, license types, and related key compliance and restriction requirements for open source projects held by LG Electronics, Samsung Electronics, and Kakao, organized as tables by item, and introduced a roadmap for future data refinement, establishing operating policy, and building a guide page.

FOSSLight Roadmap (LG Electronics, Kyungae Kim)
FOSSLight is an integrated open source management system developed in-house by LG Electronics, which was open-sourced in 2021 for anyone to use. Kyungae Kim of LG Electronics introduced the 2023 FOSSLight Roadmap.

The FOSSLight Project has a roadmap for 2023 that includes improving security vulnerability features, strengthening SBOM functionality, and improving UX.

Have You Tried OLIVE Lately? (Kakao, Eunkyung Hwang)
OLIVE Platform is an open source license verification service developed by Kakao, which anyone can use for free with just a Kakao account, or a GitHub, Google, or Facebook account.
Eunkyung Hwang of Kakao introduced the key features of the OLIVE Platform.

The OLIVE Platform added the OLIVE CLI feature, which can be used safely even when there are concerns about source code exposure, allowing it to be adopted even in the security-sensitive financial sector.

onot Has Gotten Pretty Usable! (Kakao, Hyeonmin Han)
onot is an open source project jointly developed by SK telecom and Kakao. It is a tool that automatically converts an SBOM written in the SPDX format into an open source notice. Hyeonmin Han of Kakao introduced the new features recently added to onot. The presentation materials can be found here.

onot can now extract file information in addition to package information, and now also supports multi-license notation. It can generate open source notices from SPDX documents in RDF/XML format as well, and now supports a more convenient user environment, such as a GUI on Windows PCs.

Closing
The in-person meeting, held for the first time in about 3 years, was so packed with content that the short time felt like too little. Thank you again to Seoyeon Lee and Donghyuk Kim of LINE Plus for preparing a wonderful venue, souvenirs, and even raffle prizes.

Companies face similar difficulties in open source management work, and sharing how they overcame and streamlined these challenges is of great help to one another. The OpenChain Korea Work Group is a gathering that anyone who shares this sentiment can voluntarily join. Anyone in charge of open source management at a company or organization can participate in the OpenChain Korea Work Group: How to Join
Lastly, the OpenChain KWG holds regular meetings every quarter. The next meeting is expected to be held at Kakao.
Until then, happy days to everyone!
Effective Corporate Open Source Management (1): The OpenChain Project for Global Collaboration
Using open source has become almost essential to modern software development, to the point that it is said over 93% of the software products companies develop use open source. Yet there are reports that 53% of the open source used has license compliance issues, and 81% has security vulnerabilities. Given the complexity of modern software development environments and the vast software supply chain, companies developing products with open source need open source management efforts to minimize license compliance and security vulnerability risks. The Linux Foundation’s OpenChain Project is a project for carrying out these efforts at the community level, with multiple companies sharing and collaborating together.
On March 27, 2023, Shane Coughlan, General Manager of the OpenChain Project, visited SK telecom for a session explaining the OpenChain Project’s major activities, international standards related to open source, and global trends.

Members of SK telecom’s OSRB and the SK Group open source council (SK Planet, SK Shieldus, SK Inc., the Supex Council, and others) took part and exchanged various opinions.

On this day, Shane introduced the OpenChain Project and explained how it jointly resolves open source management issues in the software supply chain through global collaboration. This article introduces the main points.
OpenChain Project Global Community
Multiple global companies collaborate through the OpenChain Project to manage software supply chain issues: https://www.openchainproject.org/community
Platinum Members

Community Structure
The OpenChain Project has numerous Work Groups, and each Work Group develops standards for open source management and jointly builds automation tools. There are also Work Groups organized by country.

OpenChain Standard
ISO/IEC 5230:2020, ISO/IEC 18974
The most visible outcome is the development of the first international standard for open source management. In December 2020, ISO/IEC 5230 was registered as the sole international standard for open source compliance. ISO/IEC 18974 is the de facto standard for open source security assurance compliance, and is scheduled to be formally registered as an ISO standard in the second half of 2023.
These standards define the core requirements companies need to manage open source. By complying with the requirements of these standards, a company can transparently demonstrate that open source management is taking place within its software supply chain.

Self-Certification
The OpenChain Project also provides a checklist for Self-Certification. Companies can raise their level of open source management by working through the checklist items one by one.

Adoption of OpenChain ISO/IEC 5230:2020
A company that complies with every item on the checklist can declare itself compliant with ISO/IEC 5230. The list of companies that have declared adoption of ISO/IEC 5230 includes several Korean companies as well, such as LG Electronics, Kakao, Samsung Electronics, Naver, SK telecom, NCSOFT, and Hyundai Motor Group.

Other Interesting Items
Online Webinar
The OpenChain Project continues to hold online webinars on open source management.

Training Courses
A free training course for open source license compliance is provided, and a badge can also be earned upon completion.

This training course is put to various uses, such as companies requiring their employees or suppliers to complete it.

Update on China and Japan
China
Collaboration with the OpenChain Project is also active in China. In particular, discussions on collaboration are underway with Chinese government bodies such as CAICT and CESI.
Companies such as Huawei, Honor, and OPPO also actively participate in the OpenChain China Work Group, which has around 250 members.
Starting in the second quarter of 2023, a quarterly event co-hosted by OpenChain and CAICT is planned, and the Asian Legal Network (ALN) together with OIN is also said to be restarting.
Japan
The OpenChain Japan Work Group has around 190 participating members. Fujitsu, Hitachi, NEC, Panasonic, Sony, Toshiba, and Toyota provide ongoing support, and community events are held every other month.
In collaboration with TODO Group, OSPO events are also held every two weeks.
Korea Market: Challenges and Opportunities
Current Situation
The OpenChain Korea Work Group is an excellent Work Group that ranks second in the world in scale and enthusiasm, after Japan. Major companies such as SK telecom, LG Electronics, Samsung Electronics, and Hyundai Motor participate, and NIPA is also involved through sponsorship and other means.
That said, Korea is not immune to the risk posed by the global economic downturn. It is also a shame that there is no Korean corporate member on the OpenChain Board.
Opportunities
If the OpenChain Korea Work Group continues its community meetings and activities as it has so far, opportunities will keep coming. If possible, it would be good to work toward including the OpenChain standard in government open source policy, as Japan and China have done, and to encourage the participation of government bodies for this purpose.
Lastly, if a Korean company joins the OpenChain Board, it would increase the strategic diversity of the OpenChain Project and help grow its influence in the global supply chain.
Closing
The OpenChain Project is a community for applying the open source approach of sharing and collaboration to the field of corporate open source management itself, so that everyone can together achieve a high level of risk management practice with lower cost and fewer resources. The OpenChain Korea Work Group is where companies that share this purpose gather. Nearly 100 open source managers from various companies have joined the OpenChain Korea Work Group’s mailing list and are active there. As it happens, an offline meetup was held on March 28, the first in three years since COVID. I will cover this in detail in the next article.
After the meeting session with Shane, we enjoyed a nice lunch sponsored by SK telecom’s Tech HR team. (Thank you, Sangki~ ^^)

Thank you.
Buy Anaconda If You Use It. If Not, Use conda-forge!
Hello.
Do you often use Anaconda when setting up a Python development environment? Python is widely used for everything from simple task automation to data analysis, AI training, and modeling, and running multiple Python projects can create the inconvenience of package version conflicts. Anaconda has the advantage of providing a virtual environment for each development project to prevent version conflicts, and it is widely used because it can be easily downloaded and installed from the homepage.

But you need to buy Anaconda to use it.
In September 2020, Anaconda changed its Terms of Service to require payment when a company or government organization with 200 or more employees uses the Anaconda Repository.
Therefore, if you are a developer working at a company with 200 or more employees, you must purchase a Pro or higher license on the Anaconda website.

https://www.anaconda.com/pricing
Let’s look a bit more closely. To install Anaconda, you can typically download the Anaconda Distribution for free from the Anaconda homepage.

https://www.anaconda.com/products/distribution
Installing it sets up a development environment easily, since the conda package manager, Python, and about 150 packages are installed together.
Anaconda Inc. hosts the Anaconda Repository, providing over 8,000 open source packages, and users can reliably install and manage these packages with the conda install PACKAGENAME command.

The Terms of Service for this very Anaconda Repository is what changed in September 2020, and free use of the Anaconda Repository is no longer possible for commercial activity.
Many developers easily download and use the Anaconda Distribution, but in doing so they end up using the Anaconda Repository. For a developer at a company with 200 or more employees, this results in “unintentionally” violating Anaconda’s Terms of Service, and to avoid this you must purchase Anaconda Pro or higher.
For reference, Miniconda is, like Anaconda, a software package that installs the conda package manager, Python, and minimal dependencies. Using Miniconda also accesses the Anaconda Repository to download packages, so it can be considered subject to the same paid-purchase requirement as Anaconda.

https://docs.conda.io/en/latest/miniconda.html
In the end, even if a developer at a company with 200 or more employees downloads and uses the Anaconda Distribution for free, they won’t immediately be charged or have features blocked. Still, for the stable development of Anaconda, it would be good for developers at companies with 200 or more employees to voluntarily purchase and use it. (Of course, a license violation notice and invoice could show up at the company at some point. ^^)
There is an alternative: ‘conda-forge’
Anaconda Inc. publishes and maintains the package manager conda as open source. conda itself is open source released under the BSD-3-Clause license, so there is no problem with companies using it for free.

https://github.com/conda/conda
conda needs a repository location to find packages to install and manage, and this is called a channel. The default channel is the Anaconda Repository. However, there is also a community-based repository: conda-forge.

You can install conda and add conda-forge as a channel.
conda config --add channels conda-forge
conda config --set channel_priority strict
This way, since you are not using the Anaconda Repository, you can use conda without violating the Terms of Service described above.
Peter Wang, CEO of Anaconda Inc., has stated directly that downloading Miniconda and changing the conda config to conda-forge allows free use.

https://www.reddit.com/r/Python/comments/iqsk3y/comment/g4xuabr/
Removing the defaults channel, which points to the Anaconda Repository, entirely can more reliably restrict use of the Anaconda Repository.
conda config --remove channels defaults
You can check whether the channel has changed as intended with the command below.
### Before the change
% conda config --show channels
channels:
- defaults
### After the change
% conda config --show channels
channels:
- conda-forge
Miniforge adds conda-forge to the channel at installation.
Going a step further, Miniforge is an open source project that provides a minimal installer for conda, and it adds conda-forge to the channel by default at installation. Miniforge is also known to support various CPU architectures, including Apple M1.

https://github.com/conda-forge/miniforge
Therefore, if you install Miniforge instead of Anaconda, it appears you can relatively easily set up a development environment with the conda package manager without violating the license.
One interesting point is that operating conda-forge requires substantial hosting costs, which Anaconda Inc. pays. Anaconda Inc. explains that it needed the revenue from changing the Anaconda Repository’s Terms of Service in order to keep conda-forge free.
Considering development convenience and stability, it would be good to purchase and use Anaconda Pro where possible. Until then, to avoid license issues, you might consider the Miniconda + conda-forge combination, or Miniforge, as alternatives.
Please let me know if there is anything incorrect. ^^
Thank you.