This is the multi-page printable view of this section. Click here to print.

Return to the regular view of this page.

NIPA OpenChain Guide

Provides a guide for companies to comply with the OpenChain Specification. (Korean only)

OpenUP conducted research under the supervision of the National Information and Communication Industry Promotion Agency (NIPA) and produced a guidebook explaining detailed methods for companies to comply with the OpenChain Specification. : OpenChain 2.0 Guide for Open Source Governance in the Enterprise

With the permission of NIPA, the contents of the guide are published on GitHub, and anyone can refer to the contents, modify / improve the contents.

References

Language

This page contains only Korean language materials for Korean companies.

1 - I. OpenChain Project๋ž€?

์˜ค๋Š˜๋‚  ์†Œํ”„ํŠธ์›จ์–ด๋Š” ๊ฐˆ์ˆ˜๋ก ๊ทธ ๊ทœ๋ชจ์™€ ๋ณต์žก๋„๊ฐ€ ์ปค์ง€๊ณ  ์žˆ๋‹ค. ํ•˜๋‚˜์˜ ์†Œํ”„ํŠธ์›จ์–ด๋ฅผ ๊ฐœ๋ฐœํ•˜๊ธฐ ์œ„ํ•ด์„œ๋Š” ์ž์ฒด ๊ฐœ๋ฐœํ•˜๋Š” ์†Œํ”„ํŠธ์›จ์–ด๋ฟ ์•„๋‹ˆ๋ผ ์˜คํ”ˆ์†Œ์Šค, 3rd party Software, ๋ฐ˜๋„์ฒด ๋ฒค๋”์˜ SDK ๋“ฑ ์†Œํ”„ํŠธ์›จ์–ด ๊ณต๊ธ‰๋ง์— ๊ฑธ์นœ ๋‹ค์–‘ํ•œ ์†Œํ”„ํŠธ์›จ์–ด๊ฐ€ ์‚ฌ์šฉ๋  ์ˆ˜ ์žˆ๊ธฐ ๋•Œ๋ฌธ์ด๋‹ค.

์ด๋Ÿฌํ•œ ๋ณต์žกํ•œ ์†Œํ”„ํŠธ์›จ์–ด ๊ณต๊ธ‰๋ง์˜ ์กฐ์ง ์ค‘ ํ•œ ๊ณณ์ด๋ผ๋„ ๋ผ์ด์„ ์Šค ์˜๋ฌด๋ฅผ ์ค€์ˆ˜ํ•˜์ง€ ์•Š๊ฑฐ๋‚˜, ์˜ฌ๋ฐ”๋ฅธ ์˜คํ”ˆ์†Œ์Šค ์ •๋ณด๋ฅผ ์ œ๊ณตํ•˜์ง€ ๋ชปํ•œ ๊ฒฝ์šฐ, ์ตœ์ข… ์†Œํ”„ํŠธ์›จ์–ด๋ฅผ ๋ฐฐํฌํ•˜๋Š” ๊ธฐ์—…์€ ๋ผ์ด์„ ์Šค ์ค€์ˆ˜์— ์‹คํŒจํ•˜๊ณ  ์ด๋กœ ์ธํ•ด ์ œํ’ˆ ํŒ๋งค๊ฐ€ ์ค‘๋‹จ๋˜๋Š” ์ƒํ™ฉ์ด ๋ฐœ์ƒํ•  ์ˆ˜ ์žˆ๋‹ค. ์‹ค์ œ๋กœ 2009๋…„ 12์›”, Busybox๋ผ๋Š” ์˜คํ”ˆ์†Œ์Šค ๊ด€๋ จ๋œ ์†Œ์†ก์ด ์žˆ์—ˆ๋‹ค. Busybox๋Š” ์ž„๋ฒ ๋””๋“œ ์‹œ์Šคํ…œ์— ๊ด‘๋ฒ”์œ„ํ•˜๊ฒŒ ์‚ฌ์šฉ๋˜๊ณ  ์žˆ๋Š” GPL-2.0 ๋ผ์ด์„ ์Šค๊ฐ€ ์ ์šฉ๋œ ์˜คํ”ˆ์†Œ์Šค์ธ๋ฐ, ๋‘ ๊ณณ์˜ ๊ตญ๋‚ด ํšŒ์‚ฌ๋ฅผ ํฌํ•จํ•˜์—ฌ ์ด 14๊ฐœ ํšŒ์‚ฌ๊ฐ€ ์†Œ์†ก ๋Œ€์ƒ์ด ๋˜์—ˆ๋‹ค. ์ด ์‚ฌ๋ก€์—์„œ ์ฃผ๋ชฉํ• ๋งŒํ•œ ์ ์€ ์ด ์ค‘์—๋Š” ์ œํ’ˆ์„ ์ง์ ‘ ๊ฐœ๋ฐœํ•˜์ง€ ์•Š๊ณ  ๋ฐฐํฌ๋งŒ ํ•œ ํšŒ์‚ฌ๋„ ์†Œ์†ก์„ ๋‹นํ–ˆ๋‹ค๋Š” ์ ์ด๋‹ค.

์ด์™€ ๊ฐ™์€ ๋ณต์žกํ•œ ์†Œํ”„ํŠธ์›จ์–ด ๊ณต๊ธ‰๋ง ํ™˜๊ฒฝ์—์„œ๋Š” ์–ด๋А ํ•œ ๊ธฐ์—…์ด ์•„๋ฌด๋ฆฌ ํ›Œ๋ฅญํ•œ ํ”„๋กœ์„ธ์Šค๋ฅผ ๊ฐ–์ถ”๊ณ  ์žˆ๋‹ค๊ณ  ํ•ด๋„ ์ž์ฒด์ ์œผ๋กœ ์™„๋ฒฝํ•œ ์˜คํ”ˆ์†Œ์Šค ์ปดํ”Œ๋ผ์ด์–ธ์Šค๋ฅผ ๋‹ฌ์„ฑํ•˜๋Š” ๊ฑด ๋งค์šฐ ์–ด๋ ต๋‹ค. ๊ฒฐ๊ตญ ์†Œํ”„ํŠธ์›จ์–ด๋ฅผ ์ตœ์ข… ๋ฐฐํฌํ•˜๋Š” ๊ธฐ์—…์ด ์˜คํ”ˆ์†Œ์Šค ์ปดํ”Œ๋ผ์ด์–ธ์Šค๋ฅผ ์ œ๋Œ€๋กœ ์ดํ–‰ํ•˜๊ธฐ ์œ„ํ•ด์„œ๋Š” ์†Œํ”„ํŠธ์›จ์–ด ๊ณต๊ธ‰๋ง์˜ ๋ชจ๋“  ๊ตฌ์„ฑ์›์ด ๋ผ์ด์„ ์Šค ์˜๋ฌด๋ฅผ ์ค€์ˆ˜ํ•˜๊ณ  ์˜ฌ๋ฐ”๋ฅธ ์˜คํ”ˆ์†Œ์Šค ์ •๋ณด๋ฅผ ์ œ๊ณตํ•˜์—ฌ ๊ณต๊ธ‰๋ง ์ „์ฒด์— ์‹ ๋ขฐ๊ฐ€ ๊ตฌ์ถ•๋˜์–ด์•ผ ํ•œ๋‹ค.

supplychain.png

< OpenChain Open Source Software License Compliance General Public Guide >

Linux Foundation์˜ OpenChain ํ”„๋กœ์ ํŠธ๋Š” ๊ธฐ์—…์ด ์˜คํ”ˆ์†Œ์Šค ์ปดํ”Œ๋ผ์ด์–ธ์Šค๋ฅผ ์œ„ํ•ด ์ค€์ˆ˜ํ•ด์•ผ ํ•  ํ™œ๋™์„ ๋” ๊ฐ„๋‹จํ•˜๊ณ  ์ผ๊ด€์„ฑ ์žˆ๊ฒŒ ๋งŒ๋“ค์–ด ์†Œํ”„ํŠธ์›จ์–ด ๊ณต๊ธ‰๋ง ์ „์ฒด์— ์‹ ๋ขฐ๋ฅผ ๊ตฌ์ถ•ํ•  ์ˆ˜ ์žˆ๋„๋ก ํ•ด์ค€๋‹ค.

openchainlogo.png

2016๋…„ ์œ ๋Ÿฝ์˜ ํ•œ ์˜คํ”ˆ์†Œ์Šค ์ฝ˜ํผ๋Ÿฐ์Šค์—์„œ ํ€„์ปด์˜ ์˜คํ”ˆ์†Œ์Šค ๋ณ€ํ˜ธ์‚ฌ์ธ ๋ฐ์ด๋ธŒ ๋จธ(Dave Marr)๋Š” ํ•œ ๊ธฐ์—…์˜ ์˜คํ”ˆ์†Œ์Šค ์ปดํ”Œ๋ผ์ด์–ธ์Šค ์ˆ˜์ค€์„ ๋†’์ด๊ธฐ ์œ„ํ•ด์„œ๋Š” ์†Œํ”„ํŠธ์›จ์–ด ๊ณต๊ธ‰๋ง ๋‚ด์˜ ๋ชจ๋“  ๊ตฌ์„ฑ์›์ด ์˜คํ”ˆ์†Œ์Šค ์ปดํ”Œ๋ผ์ด์–ธ์Šค ์ˆ˜์ค€์„ ๋†’์ด๋Š” ๊ฒƒ์ด ์ค‘์š”ํ•จ์„ ๊ฐ•์กฐํ•œ ๋ฐ” ์žˆ๋‹ค. ์•„์šธ๋Ÿฌ ์ด๋ฅผ ์œ„ํ•ด์„œ๋Š” ์˜คํ”ˆ์†Œ์Šค๋ฅผ ์ถฉ๋ถ„ํžˆ ์ดํ•ดํ•˜๊ณ , ์ •์ฑ… ๋ฐ ํ”„๋กœ์„ธ์Šค๋ฅผ ์•ž์„œ ๊ตฌ์ถ•ํ•˜๊ณ  ์žˆ๋Š” ๊ธฐ์—…๋“ค์ด ์ž์‹ ๋“ค์˜ ์ž์‚ฐ๊ณผ ๋…ธํ•˜์šฐ๋ฅผ ๊ณต๊ฐœํ•ด ๋ˆ„๊ตฌ๋‚˜ ์ด๋ฅผ ์ฐธ๊ณ ํ•  ์ˆ˜ ์žˆ๊ฒŒ ํ•ด์•ผ ํ•œ๋‹ค๋Š” ์˜๊ฒฌ์„ ์ œ์‹œํ–ˆ๋‹ค. ์ฝ˜ํผ๋Ÿฐ์Šค ์ฐธ์„์ž๋“ค์€โ€œ์˜คํ”ˆ์†Œ์Šค ์ปดํ”Œ๋ผ์ด์–ธ์Šค๋Š” ๊ธฐ์—…์˜ ์ด์ต์„ ์ฐจ๋ณ„ํ™”ํ•  ์ˆ˜ ์žˆ๋Š” ๋ถ„์•ผ๊ฐ€ ์•„๋‹ˆ๋‹ค. ๊ธฐ์—…์€ ์ตœ์†Œํ•œ์˜ ๋ฆฌ์†Œ์Šค๋ฅผ ํˆฌ์ž…ํ•˜์—ฌ ์ ์ •ํ•œ ์ˆ˜์ค€์˜ ๋ฆฌ์Šคํฌ ๊ด€๋ฆฌ๋ฅผ ์›ํ•˜๊ธฐ ๋•Œ๋ฌธ์— ๊ธฐ์—…๋“ค์ด ๊ฐ€์ง„ ์ž์‚ฐ์„ ๊ณต์œ ํ•˜๋ฉด ํ• ์ˆ˜๋ก ์ ์€ ๋น„์šฉ์œผ๋กœ ๋ชจ๋‘ ํ•จ๊ป˜ ์ปดํ”Œ๋ผ์ด์–ธ์Šค๋ฅผ ๋‹ฌ์„ฑ ํ•  ์ˆ˜ ์žˆ๋‹คโ€๋Š” ์•„์ด๋””์–ด์— ๊ณต๊ฐํ–ˆ๋‹ค. OpenChain ํ”„๋กœ์ ํŠธ(๋‹น์‹œ์—๋Š” Work Group)๋Š” ๊ทธ๋ ‡๊ฒŒ ์‹œ์ž‘๋๊ณ , Qualcomm, Siemens, Wind River, ARM, Adobe ๋“ฑ ๋‹ค์ˆ˜ ๊ธ€๋กœ๋ฒŒ ๊ธฐ์—…๋“ค์ด ์ฐธ์—ฌํ–ˆ๋‹ค.

1.1 - 1. OpenChain Specification

OpenChain ํ”„๋กœ์ ํŠธ๋Š” ๊ณง OpenChain Specification 1.0์„ ์ œ์ž‘ํ•˜์—ฌ ๋ฐฐํฌํ–ˆ๋‹ค. OpenChain Specification์€ ์˜คํ”ˆ์†Œ์Šค ์ปดํ”Œ๋ผ์ด์–ธ์Šค๋ฅผ ์œ„ํ•œ ํ•ต์‹ฌ ์š”๊ตฌ์‚ฌํ•ญ์„ ์ •์˜ํ•œ 12ํŽ˜์ด์ง€ ๋ถ„๋Ÿ‰์˜ ํ‘œ์ค€ ๊ทœ๊ฒฉ์œผ๋กœ, ๊ธฐ์—…์˜ ๊ทœ๋ชจ๋‚˜ ์—…์ข…๊ณผ ๊ด€๊ณ„์—†์ด ๋ชจ๋“  ๋ถ„์•ผ์˜ ํšŒ์‚ฌ์— ์ ํ•ฉํ•˜๋„๋ก ๊ณ ์•ˆ๋˜์—ˆ๋‹ค. 2019๋…„ 4์›”์—๋Š” ๋ฒ„์ „ 2.0์˜ Specification์ด ๋ฐฐํฌ๋์œผ๋ฉฐ, ๊ธฐ์—…์ด ์˜คํ”ˆ์†Œ์Šค ์ปดํ”Œ๋ผ์ด์–ธ์Šค ๋‹ฌ์„ฑ์„ ์œ„ํ•ด ๊ผญ ์ˆ˜ํ–‰ํ•ด์•ผ ํ•  ์—ฌ์„ฏ ๊ฐ€์ง€ ์ฃผ์š” ์š”๊ฑด์— ๋Œ€ํ•œ ์„ค๋ช…๊ณผ ์ด๋ฅผ ์ˆ˜ํ–‰ํ•˜๊ณ  ์žˆ์Œ์„ ์ž…์ฆํ•˜๊ธฐ ์œ„ํ•œ ๊ฒ€์ฆ ์ž๋ฃŒ ๋ชฉ๋ก์„ ์ •์˜ํ•˜๊ณ  ์žˆ๋‹ค.

  1. ์˜คํ”ˆ์†Œ์Šค ์ปดํ”Œ๋ผ์ด์–ธ์Šค๋ฅผ ๊ด€๋ฆฌํ•˜๊ธฐ ์œ„ํ•œ ํ”„๋กœ๊ทธ๋žจ
  2. ํšจ๊ณผ์ ์ธ ๋ฆฌ์†Œ์Šค ์ œ๊ณต์„ ์œ„ํ•œ ์—…๋ฌด ์ •์˜ ๋ฐ ์ง€์›
  3. ์˜คํ”ˆ์†Œ์Šค ๊ฒ€ํ†  ๋ฐ ์Šน์ธ์„ ๊ด€๋ฆฌํ•˜๋Š” ํ”„๋กœ์„ธ์Šค
  4. ์ปดํ”Œ๋ผ์ด์–ธ์Šค ๊ฒฐ๊ณผ๋ฌผ ์ƒ์„ฑ ๋ฐ ์ œ๊ณต์„ ์œ„ํ•œ ํ”„๋กœ์„ธ์Šค
  5. ์˜คํ”ˆ์†Œ์Šค ์ปค๋ฎค๋‹ˆํ‹ฐ ์ฐธ์—ฌ๋ฅผ ์ดํ•ดํ•˜๊ณ  ๊ด€๋ฆฌํ•˜๊ธฐ ์œ„ํ•œ ์ •์ฑ…
  6. OpenChain Specification ์š”๊ฑด ์ค€์ˆ˜

์˜คํ”ˆ์†Œ์Šค ์ปดํ”Œ๋ผ์ด์–ธ์Šค๋ฅผ ์ฒ˜์Œ ์‹œ์ž‘ํ•˜๋Š” ๊ธฐ์—…์ด๋ผ๋ฉด ์ด์™€ ๊ฐ™์€ OpenChain Specification์˜ ์š”๊ฑด์„ ํ•˜๋‚˜์”ฉ ์ถฉ์กฑํ•ด๊ฐ€๋ฉด์„œ ์ˆ˜์ค€์„ ํ–ฅ์ƒ์‹œํ‚ค๋Š” ๊ฒƒ์ด ์ข‹์€ ์ „๋žต์ด๋‹ค.

< https://wiki.linuxfoundation.org/_media/openchain/openchainspec-2.0.pdf >

1.2 - 2. OpenChain Conformance

OpenChain Project๋Š” ๊ธฐ์—…์ด OpenChain Specification์„ ์ถฉ์กฑํ•˜๋Š”์ง€ ์ž์ฒด์ ์œผ๋กœ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋„๋ก ์˜จ๋ผ์ธ ์ž์ฒด ์ธ์ฆ ์›น์‚ฌ์ดํŠธ๋ฅผ ์ œ๊ณตํ•œ๋‹ค.

< https://certification.openchainproject.org/ >

๊ธฐ์—…์˜ ์˜คํ”ˆ์†Œ์Šค ๋‹ด๋‹น์ž๋Š” OpenChain ์ž์ฒด ์ธ์ฆ ์›น์‚ฌ์ดํŠธ์— ๊ฐ€์ž…ํ•ด ์˜จ๋ผ์ธ ์ž์ฒด ์ธ์ฆ์„ ์‹œ์ž‘ํ•  ์ˆ˜ ์žˆ์œผ๋ฉฐ, Yes/No ์งˆ๋ฌธ์— ๋‹ต๋ณ€ํ•˜๋Š” ๋ฐฉ์‹์œผ๋กœ ์ง„ํ–‰๋œ๋‹ค.

< https://certification.openchainproject.org/ >

์ž์ฒด ์ธ์ฆ์„ ํ†ตํ•ด ๋ถ€์กฑํ•œ ๋ถ€๋ถ„์ด ๋ฌด์—‡์ธ์ง€, ์ถ”๊ฐ€๋กœ ํ•„์š”ํ•œ ํ™œ๋™์ด ๋ฌด์—‡์ธ์ง€ ํŒ๋‹จํ•  ์ˆ˜ ์žˆ๋‹ค.

๋งŒ์•ฝ, ์˜คํ”ˆ์†Œ์Šค ์ปดํ”Œ๋ผ์ด์–ธ์Šค ์ฒด๊ณ„๊ฐ€ ์ž˜ ๊ตฌ์ถ•๋œ ๊ธฐ์—…์ด OpenChain ์ž์ฒด ์ธ์ฆ ์งˆ๋ฌธ์ง€์˜ ๋ชจ๋“  ํ•ญ๋ชฉ์„ Yes๋กœ ๋Œ€๋‹ตํ•  ์ˆ˜ ์žˆ๋‹ค๋ฉด ์ด ๊ฒฐ๊ณผ๋ฅผ ์›น์‚ฌ์ดํŠธ์ƒ์— ์ œ์ถœํ•  ์ˆ˜ ์žˆ๋‹ค(Conforming Submission). ๊ทธ๋Ÿฌ๋ฉด OpenChain ์ค€์ˆ˜(Conformant) ๊ธฐ์—…์œผ๋กœ ์ธ์ •๋จ๊ณผ ๋™์‹œ์—, OpenChain ํ”„๋กœ์ ํŠธ์˜ ์›น์‚ฌ์ดํŠธ์—์„œ OpenChain ์ค€์ˆ˜ ํ”„๋กœ๊ทธ๋žจ์„ ๊ฐ–์ถ˜ ๊ธฐ์—… ๋ชฉ๋ก์— ๊ธฐ์—…์˜ ๋กœ๊ณ ๋ฅผ ๋“ฑ๋กํ•  ์ˆ˜ ์žˆ๊ฒŒ ๋œ๋‹ค.

< Organizations with a publicly announced OpenChain Conformant Program >

OpenChain ์ค€์ˆ˜ ๊ธฐ์—…์—๊ฒŒ๋Š” OpenChain ๋กœ๊ณ ๋ฅผ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋Š” ์ž๊ฒฉ์ด ์ฃผ์–ด์ง„๋‹ค. ์ด๋ ‡๊ฒŒ OpenChain ์ค€์ˆ˜ ํ”„๋กœ๊ทธ๋žจ์„ ๊ฐ–์ท„๋‹ค๊ณ  ์ธ์ •๋ฐ›์€ ๊ธฐ์—…์€ ์†Œํ”„ํŠธ์›จ์–ด ๊ณต๊ธ‰๋ง ๋‚ด์—์„œ ์˜คํ”ˆ์†Œ์Šค ์ปดํ”Œ๋ผ์ด์–ธ์Šค๋ฅผ ์ถฉ์‹คํ•˜๊ฒŒ ์ˆ˜ํ–‰ํ•˜๊ณ  ์žˆ์Œ์„ ๋ณด์—ฌ์ค„ ์ˆ˜ ์žˆ๋‹ค.

< https://www.openchainproject.org/ >

1.3 - 3. OpenChain Curriculum

OpenChain ํ”„๋กœ์ ํŠธ์—์„œ๋Š” ๊ธฐ์—…์ด ์ปดํ”Œ๋ผ์ด์–ธ์Šค ํ”„๋กœ๊ทธ๋žจ์„ ๊ตฌ์ถ•ํ•˜๋Š”๋ฐ ํ•„์š”ํ•œ ์ •์ฑ… ๋ฌธ์„œ ํ…œํ”Œ๋ฆฟ, ๊ต์œก ์ž๋ฃŒ ๋“ฑ ๋‹ค์–‘ํ•œ ์ฐธ๊ณ ์ž๋ฃŒ๋ฅผ ์ œ๊ณตํ•œ๋‹ค. ์ด ์ž๋ฃŒ๋“ค์€ OpenChain Specification ๋ฐ ์ผ๋ฐ˜์ ์ธ ์˜คํ”ˆ์†Œ์Šค ์ปดํ”Œ๋ผ์ด์–ธ์Šค ํ™œ๋™์„ ์ง€์›ํ•˜๊ธฐ ์œ„ํ•ด ๊ณ ์•ˆ๋์œผ๋ฉฐ, ๋ˆ„๊ตฌ๋‚˜ ์ž์œ ๋กญ๊ฒŒ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋„๋ก Public Domain์œผ๋กœ ์ œ๊ณต๋œ๋‹ค.

< https://www.openchainproject.org/resources >

2 - II. OpenChain Specification ์ค€์ˆ˜ ๋ฐฉ๋ฒ•

OpenChain Specifiation์—์„œ๋Š” ์˜คํ”ˆ์†Œ์Šค ์ปดํ”Œ๋ผ์ด์–ธ์Šค๋ฅผ ์œ„ํ•œ ํ•ต์‹ฌ ์š”๊ตฌ ์‚ฌํ•ญ์„ ์ •์˜ํ•œ๋‹ค. OpenChain Specification์„ ์ค€์ˆ˜ํ•œ๋‹ค๊ณ  ์ธ์ •๋ฐ›์€ ๊ธฐ์—…์€ ์†Œํ”„ํŠธ์›จ์–ด ์†”๋ฃจ์…˜์„ ๋ฐฐํฌํ•˜๋Š” ์กฐ์ง๊ฐ„์— ์‹ ๋ขฐ๋ฅผ ์ œ๊ณตํ•  ์ˆ˜ ์žˆ๊ฒŒ ๋œ๋‹ค. ์—ฌ๊ธฐ์—์„œ๋Š” ๊ธฐ์—…๋“ค์ด OpenChain Specification์„ ์ค€์ˆ˜ํ•˜๊ธฐ ์œ„ํ•ด ์ถฉ์กฑํ•ด์•ผ ํ•˜๋Š” ์—ฌ์„ฏ๊ฐ€์ง€ ์ฃผ์š” ์š”๊ฑด๊ณผ ๊ทธ ๋ฐฉ๋ฒ•์„ ์„ธ๋ถ€์ ์œผ๋กœ ์„ค๋ช…ํ•œ๋‹ค.

2.1 - 1. ํ”„๋กœ๊ทธ๋žจ ์„ฑ๋ฆฝ

1.1 ์ •์ฑ… (Policy)

์˜คํ”ˆ์†Œ์Šค๋ฅผ ์ด์šฉํ•˜์—ฌ ์†Œํ”„ํŠธ์›จ์–ด๋ฅผ ๊ฐœ๋ฐœํ•˜๊ณ  ๋ฐฐํฌํ•˜๋Š” ๊ธฐ์—…์ด๋ผ๋ฉด ์˜คํ”ˆ์†Œ์Šค๋ฅผ ๊ด€๋ฆฌํ•˜๊ธฐ ์œ„ํ•œ ์ •์ฑ…๊ณผ ํ”„๋กœ์„ธ์Šค๋ฅผ ๊ตฌ์ถ•ํ•˜๊ณ , ์ด๋ฅผ ์œ„ํ•œ ์ธ๋ ฅ๊ณผ ์ž์›์„ ํ• ๋‹นํ•ด์•ผ ํ•œ๋‹ค. OpenChain์—์„œ๋Š” ์ด๋Ÿฌํ•œ ์ผ๋ จ์˜ ํ™œ๋™์„ ๊ด€๋ฆฌํ•˜๋Š” ์ฒด๊ณ„๋ฅผ ์˜คํ”ˆ์†Œ์Šค ํ”„๋กœ๊ทธ๋žจ์ด๋ผ๊ณ  ๋ถ€๋ฅด๊ณ , OpenChain Specification์„ ์ค€์ˆ˜ํ•˜๊ธฐ ์œ„ํ•œ ์ฒซ๋ฒˆ์งธ ์š”๊ฑด์€ ๋ฐ”๋กœ ์ด ํ”„๋กœ๊ทธ๋žจ์„ ์„ค๋ฆฝํ•ด์•ผ ํ•˜๋Š”๊ฒƒ์ด๋‹ค. ์—ฌ๊ธฐ์„œ ์˜คํ”ˆ์†Œ์Šค ํ”„๋กœ๊ทธ๋žจ์ด๋ž€ ์ •์ฑ…, ํ”„๋กœ์„ธ์Šค, ์ธ์› ๋“ฑ ๊ธฐ์—…์ด ์˜คํ”ˆ์†Œ์Šค ์ปดํ”Œ๋ผ์ด์–ธ์Šค ํ™œ๋™์„ ์ˆ˜ํ–‰ํ•˜๊ธฐ ์œ„ํ•œ ์ผ๋ จ์˜ ๊ด€๋ฆฌ ์ฒด๊ณ„๋ฅผ ์˜๋ฏธํ•œ๋‹ค. OpenChain Specification์—์„œ๋Š” ์ด๋ฅผ ์ž…์ฆํ•˜๊ธฐ ์œ„ํ•œ ์ž๋ฃŒ๋กœ ์šฐ์„  ๋ฌธ์„œํ™”๋œ ์˜คํ”ˆ์†Œ์Šค ์ •์ฑ…์„ ์š”๊ตฌํ•œ๋‹ค. ์ด ์•ˆ๋‚ด์„œ์—์„œ๋Š” ์ฐธ๊ณ ๋ฅผ ์œ„ํ•ด OpenChain Specification์˜ ์š”๊ฑด์„ ์ถฉ์กฑํ•˜๋Š” ์˜คํ”ˆ์†Œ์Šค ์ •์ฑ… ๋ฌธ์„œ ์˜ˆ์‹œ๋ฅผ โ€œ[๋ถ€๋ก 01] ์ƒ˜ํ”Œ ์˜คํ”ˆ์†Œ์Šค ์ •์ฑ…โ€์—์„œ ์ œ๊ณตํ•œ๋‹ค.

OpenChain Specification์€ ์ด์–ด์ง€๋Š” ์žฅ์—์„œ ์˜คํ”ˆ์†Œ์Šค ํ”„๋กœ๊ทธ๋žจ์ด ๊ฐ–์ถฐ์•ผํ•  ์š”๊ฑด๋“ค์„ ์„ค๋ช…ํ•˜๊ณ  ์žˆ๋‹ค.

OpenChain Specification 2.0


1.1 ์ •์ฑ…

๊ณต๊ธ‰ ๋Œ€์ƒ ์†Œํ”„ํŠธ์›จ์–ด์˜ ์˜คํ”ˆ์†Œ์Šค ๋ผ์ด์„ ์Šค ์ปดํ”Œ๋ผ์ด์–ธ์Šค๋ฅผ ๊ด€๋ฆฌํ•˜๋Š” ๋ฌธ์„œํ™” ๋œ ์˜คํ”ˆ์†Œ์Šค ์ •์ฑ…์ด ์กด์žฌํ•œ๋‹ค. ์ •์ฑ…์€ ๋‚ด๋ถ€์ ์œผ๋กœ ์ „๋‹ฌ๋˜์–ด์•ผ ํ•œ๋‹ค.

์ž…์ฆ ์ž๋ฃŒ:

1.1.1 ๋ฌธ์„œํ™” ๋œ ์˜คํ”ˆ์†Œ์Šค ์ •์ฑ…
1.1.2 ์†Œํ”„ํŠธ์›จ์–ด ๊ณต๊ธ‰ ๋‹ด๋‹น์ž๊ฐ€ ์˜คํ”ˆ์†Œ์Šค ์ •์ฑ…์˜ ์กด์žฌ๋ฅผ ์ธ์‹ํ•˜๋„๋ก ํ•˜๋Š” ๋ฌธ์„œํ™” ๋œ ์ ˆ์ฐจ (๊ต์œก, ๋‚ด๋ถ€ ์œ„ํ‚ค, ํ˜น์€ ๊ธฐํƒ€ ์‹ค์งˆ์ ์ธ ์˜์‚ฌ์†Œํ†ต ๋ฐฉ๋ฒ• ๋“ฑ)


1.1 Policy

A written Open Source policy exists that governs Open Source license compliance of the Supplied Software. The policy must be internally communicated.

Verification Material(s):

1.1.1 A documented Open Source policy
1.1.2 A documented procedure that makes Software Staff aware of the existence of the Open Source policy (e.g., via training, internal wiki, or other practical communication method)

์˜คํ”ˆ์†Œ์Šค ํ”„๋กœ๊ทธ๋žจ์€ ์†Œํ”„ํŠธ์›จ์–ด ๊ณต๊ธ‰๋‹ด๋‹น์ž๊ฐ€ ์ด ์˜คํ”ˆ์†Œ์Šค ์ •์ฑ… ๋ฌธ์„œ์˜ ์กด์žฌ๋ฅผ ์•Œ๊ณ , ํ•„์š”ํ•œ ํ™œ๋™์„ ํ•  ์ˆ˜ ์žˆ๋„๋ก ๊ต์œก, ๋‚ด๋ถ€ ์œ„ํ‚ค ๋“ฑ ์‹ค์งˆ์ ์ธ ์ˆ˜๋‹จ์„ ์ œ๊ณตํ•ด์•ผ ํ•œ๋‹ค. ์—ฌ๊ธฐ์„œ ์†Œํ”„ํŠธ์›จ์–ด ๊ณต๊ธ‰๋‹ด๋‹น์ž(Software Staff)๋ž€ ๊ธฐ์—…์ด ์†Œํ”„ํŠธ์›จ์–ด๋ฅผ ๊ฐœ๋ฐœํ•˜๊ณ  ๋ฐฐํฌ, ๊ธฐ์—ฌํ•˜๋Š”๋ฐ ๊ด€์—ฌํ•˜๋Š” ๋ชจ๋“  ์ง์›์„ ์˜๋ฏธํ•˜๋ฉฐ, ์†Œํ”„ํŠธ์›จ์–ด ๊ฐœ๋ฐœ์ž, ๋ฐฐํฌ ์—”์ง€๋‹ˆ์–ด, ํ’ˆ์งˆ ์—”์ง€๋‹ˆ์–ด ๋“ฑ์„ ํฌํ•จํ•œ๋‹ค.

๋งŽ์€ ๊ธฐ์—…๋“ค์€ ์˜คํ”ˆ์†Œ์Šค ์ •์ฑ… ๋ฌธ์„œ๋ฅผ ์‚ฌ๋‚ด ์œ„ํ‚ค ์‚ฌ์ดํŠธ๋ฅผ ํ†ตํ•ด ๊ณต๊ฐœํ•˜์—ฌ ์ง์› ๋ˆ„๊ตฌ๋‚˜ ํ•„์š”ํ•œ ์‚ฌํ•ญ์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ๊ฒŒ ํ•œ๋‹ค. ๋˜ํ•œ, ์‹ ๊ทœ ์ฑ„์šฉ์ธ์›์˜ ์ž…์‚ฌ ์—ฐ์ˆ˜ ์‹œ ์˜คํ”ˆ์†Œ์Šค ์ •์ฑ…์— ๋Œ€ํ•œ ๊ต์œก์„ ์˜๋ฌดํ™”ํ•˜๊ณ , ์†Œํ”„ํŠธ์›จ์–ด ๊ณต๊ธ‰๋‹ด๋‹น์ž๋ฅผ ๋Œ€์ƒ์œผ๋กœ ๋งค๋…„ ํ˜น์€ 2๋…„์— ํ•œ๋ฒˆ์”ฉ ์ฃผ๊ธฐ์ ์ธ ๊ต์œก์„ ์ œ๊ณตํ•จ์œผ๋กœ ๋ชจ๋“  ์†Œํ”„ํŠธ์›จ์–ด ๊ณต๊ธ‰๋‹ด๋‹น์ž๊ฐ€ ์˜คํ”ˆ์†Œ์Šค ์ •์ฑ…์˜ ์กด์žฌ๋ฅผ ์ธ์‹ํ•˜๋„๋ก ํ•  ์ˆ˜ ์žˆ๋‹ค. ์ด๋Ÿฌํ•œ ๋ฐฉ๋ฒ•๋“ค์„ ์˜คํ”ˆ์†Œ์Šค ์ •์ฑ… ๋ฌธ์„œ์— ๊ตฌ์ฒดํ™”ํ•˜์—ฌ ํฌํ•จํ•ด์•ผ ํ•œ๋‹ค.

1.2 ์—ญ๋Ÿ‰ (Competence)

OpenChain Specification 2.0


1.2 ์—ญ๋Ÿ‰

์กฐ์ง์€ ๋‹ค์Œ ์‚ฌํ•ญ์„ ์ˆ˜ํ–‰ํ•ด์•ผ ํ•œ๋‹ค: (The organization shall: )

  • ํ”„๋กœ๊ทธ๋žจ์˜ ์„ฑ๋Šฅ ๋ฐ ํšจ๊ณผ์— ์˜ํ–ฅ์„ ๋ฏธ์น˜๋Š” ์—ญํ• ๊ณผ ํ•ด๋‹น ์—ญํ• ์— ๋Œ€ํ•œ ์ฑ…์ž„์„ ํ™•์ธํ•œ๋‹ค;
  • ๊ฐ ์—ญํ• ์„ ์ˆ˜ํ–‰ํ•˜๋Š” ์ธ์›์˜ ํ•„์š”ํ•œ ์—ญ๋Ÿ‰์„ ํŒŒ์•…ํ•œ๋‹ค;
  • ํ•ด๋‹น ์ธ์›์ด ์ ์ ˆํ•œ ๊ต์œก, ํ›ˆ๋ จ ๋ฐ ๊ฒฝํ—˜์„ ๋ฐ”ํƒ•์œผ๋กœ ์ž๊ฒฉ์„ ๊ฐ–์ถ˜ ์ž์ž„์„ ๋ณด์žฅํ•œ๋‹ค;
  • ํ•ด๋‹น๋˜๋Š” ๊ฒฝ์šฐ, ํ•„์š”ํ•œ ์—ญ๋Ÿ‰์„ ํ™•๋ณดํ•˜๊ธฐ ์œ„ํ•œ ์กฐ์น˜๋ฅผ ์ทจํ•œ๋‹ค;
  • ์ ์ ˆํžˆ ๋ฌธ์„œํ™”๋œ ์ •๋ณด๋ฅผ ์—ญ๋Ÿ‰์˜ ์ฆ๊ฑฐ๋กœ ๋ณด์œ ํ•œ๋‹ค.

์ž…์ฆ ์ž๋ฃŒ:

1.2.1 ํ”„๋กœ๊ทธ๋žจ ๋‚ด ์—ฌ๋Ÿฌ ์ฐธ์—ฌ์ž์— ๋Œ€ํ•œ ๋ฌธ์„œํ™”๋œ ์ฑ…์ž„๊ณผ ์—ญํ•  ๋ชฉ๋ก
1.2.2 ๊ฐ ์—ญํ• ์— ๋Œ€ํ•œ ์—ญ๋Ÿ‰์„ ํ™•์ธํ•˜๋Š” ๋ฌธ์„œ
1.2.3 ๊ฐ ํ”„๋กœ๊ทธ๋žจ ์ฐธ์—ฌ์ž์— ๋Œ€ํ•ด ์—ญ๋Ÿ‰์„ ํ‰๊ฐ€ํ•œ ๋ฌธ์„œํ™”๋œ ์ฆ๊ฑฐ


1.2 Competence

The organization shall:

  • Identify the roles and the corresponding responsibilities of those roles that affects the performance and effectiveness of the Program;
  • Determine the necessary competence of person(s) fulfilling each role
  • Ensure that these persons are competent on the basis of appropriate education, training, and/or experience;
  • Where applicable, take actions to acquire the necessary competence; and - Retain appropriate documented information as evidence of competence.

Verification Material(s):

1.2.1 A documented list of roles with corresponding responsibilities for the different participants in the Program.
1.2.2 A document that identifies the competencies for each role.
1.2.3 Documented evidence of assessed competence for each Program participant.

์˜คํ”ˆ์†Œ์Šค ํ”„๋กœ๊ทธ๋žจ์ด ์˜ฌ๋ฐ”๋ฅด๊ฒŒ ๊ตฌ์ถ•๋˜๊ณ  ์šด์˜๋  ์ˆ˜ ์žˆ๋„๋ก ์—ญํ• ๊ณผ ์ฑ…์ž„(R&R)์„ ์ •์˜ํ•ด์•ผ ํ•œ๋‹ค. ๊ฐ ์—ญํ• ์„ ์ˆ˜ํ–‰ํ•  ๋‹ด๋‹น์ž๊ฐ€ ๊ฐ–์ถฐ์•ผ ํ•  ์—ญ๋Ÿ‰์„ ์ •์˜ํ•˜๊ณ , ์ง€์ •๋œ ๋‹ด๋‹น์ž๊ฐ€ ํ•ด๋‹น ์—ญํ• ์„ ์ˆ˜ํ–‰ํ•  ์ˆ˜ ์žˆ๋Š” ์—ญ๋Ÿ‰์„ ๊ฐ–์ถ”์—ˆ๋Š”์ง€ ํŒŒ์•…ํ•ด์•ผ ํ•œ๋‹ค. ํ•ด๋‹น ์ธ์›์ด ๊ต์œก, ํ›ˆ๋ จ ๋ฐ ๊ฒฝํ—˜์„ ๋ฐ”ํƒ•์œผ๋กœ ๋งก์€ ์—ญํ• ์„ ์ˆ˜ํ–‰ํ•  ์ˆ˜ ์žˆ๋Š” ์ž๊ฒฉ์„ ๊ฐ–์ถ”์—ˆ์Œ์„ ๋ณด์žฅํ•ด์•ผ ํ•œ๋‹ค. ์ด๋ฅผ ์œ„ํ•ด ๊ฐ ์ธ์›์ด ํ•„์š”ํ•œ ์—ญ๋Ÿ‰์„ ๊ฐ–์ถœ ์ˆ˜ ์žˆ๋„๋ก ๊ต์œก์„ ์ œ๊ณตํ•œ๋‹ค.

์ด๋ฅผ ์ž…์ฆํ•˜๊ธฐ ์œ„ํ•ด ๊ธฐ์—…์€ ํ”„๋กœ๊ทธ๋žจ ๋‚ด ์—ฌ๋Ÿฌ ์ฐธ์—ฌ์ž์— ๋Œ€ํ•œ ์ฑ…์ž„ ๋ฐ ์—ญํ•  ๋ชฉ๋ก๊ณผ ๊ฐ ์—ญํ• ์„ ์ˆ˜ํ–‰ํ•˜๋Š” ๋‹ด๋‹น์ž๊ฐ€ ๊ฐ–์ถฐ์•ผํ•  ์—ญ๋Ÿ‰์„ ์ •์˜ํ•˜์—ฌ ๋ฌธ์„œํ™” ํ•œ๋‹ค. ์ด ์•ˆ๋‚ด์„œ์—์„œ๋Š” ์ฐธ๊ณ ๋ฅผ ์œ„ํ•ด ์˜คํ”ˆ์†Œ์Šค ํ”„๋กœ๊ทธ๋žจ์˜ ๊ฐ ์ฐธ์—ฌ์ž์˜ ์—ญํ• ๊ณผ ์ฑ…์ž„ ๋ฐ ํ•„์š”ํ•œ ์—ญ๋Ÿ‰์„ ์ •์˜ํ•œ ์ƒ˜ํ”Œ ๋ฌธ์„œ๋ฅผ โ€œ[๋ถ€๋ก 01] ์˜คํ”ˆ์†Œ์Šค ์ •์ฑ… for OpenChain 2.0(์˜ˆ)์˜ 4. ์—ญํ• , ์ฑ…์ž„ ๋ฐ ์—ญ๋Ÿ‰โ€์—์„œ ์ œ๊ณตํ•œ๋‹ค.

๊ทธ๋ฆฌ๊ณ , ๊ธฐ์—…์€ ๊ฐ ์ฐธ์—ฌ์ž๊ฐ€ ์—ญ๋Ÿ‰์„ ๊ฐ–์ถ”๊ณ  ์žˆ๋Š”์ง€ ํ‰๊ฐ€ํ•˜๊ณ , ์ด๋ฅผ ๋ณด๊ด€ํ•œ๋‹ค. ์ด๋ฅผ ์œ„ํ•ด ๊ธฐ์—…์€ ๊ฐ ์ฐธ์—ฌ์ž๊ฐ€ ํ•„์š”ํ•œ ์—ญ๋Ÿ‰์„ ๋ณด์œ ํ•  ์ˆ˜ ์žˆ๋„๋ก ๊ต์œก์„ ์ œ๊ณตํ•œ๋‹ค. ๊ต์œก ๋‚ด์šฉ์„ ๊ธฐ๋ฐ˜์œผ๋กœ ํ‰๊ฐ€ํ•˜๊ณ , ๊ทธ ๊ฒฐ๊ณผ๋Š” ๊ธฐ์—…์˜ ๊ต์œก ์‹œ์Šคํ…œ ํ˜น์€ HR ๋ถ€์„œ์—์„œ ๋ณด๊ด€ํ•ด์•ผ ํ•œ๋‹ค. ์†Œํ”„ํŠธ์›จ์–ด ๊ณต๊ธ‰๋‹ด๋‹น์ž๊ฐ€ ์ˆ˜์ฒœ๋ช… ์ด์ƒ์ด์–ด์„œ ๊ต์œก ์ œ๊ณต์ด ์‰ฝ์ง€ ์•Š์„ ๊ฒฝ์šฐ, ๊ธฐ์—…์˜ ์˜จ๋ผ์ธ ๊ต์œก๊ณผ ํ‰๊ฐ€ ์‹œ์Šคํ…œ์„ ์ด์šฉํ•˜๋Š” ๊ฒƒ๋„ ์ข‹์€ ๋ฐฉ๋ฒ•์ด๋‹ค.

1.3 ์ธ์ง€๋„ (Awareness)

OpenChain Specification 2.0


1.3 ์ธ์ง€๋„

์กฐ์ง์€ ํ”„๋กœ๊ทธ๋žจ ์ฐธ์—ฌ์ž๊ฐ€ ๋‹ค์Œ ์‚ฌํ•ญ์„ ์•Œ๊ณ  ์žˆ์Œ์„ ๋ณด์žฅํ•ด์•ผ ํ•œ๋‹ค:
a) ์˜คํ”ˆ์†Œ์Šค ์ •์ฑ…;
b) ์˜คํ”ˆ์†Œ์Šค ๊ด€๋ จ ๋ชฉํ‘œ;
c) ํ”„๋กœ๊ทธ๋žจ์˜ ํšจ๊ณผ์— ๋Œ€ํ•œ ๊ธฐ์—ฌ;
d) ํ”„๋กœ๊ทธ๋žจ์˜ ์š”๊ฑด ๋ฏธ์ค€์ˆ˜์˜ ์˜๋ฏธ.

์ž…์ฆ ์ž๋ฃŒ:

1.3.1 ๊ฐ ํ”„๋กœ๊ทธ๋žจ ๋‹ด๋‹น์ž์— ๋Œ€ํ•ด ํ”„๋กœ๊ทธ๋žจ์˜ ๋ชฉํ‘œ, ํ”„๋กœ๊ทธ๋žจ์— ๊ธฐ์—ฌ, ๊ทธ๋ฆฌ๊ณ  ํ”„๋กœ๊ทธ๋žจ ๋ฏธ์ค€์ˆ˜์˜ ์˜๋ฏธ๋ฅผ ํฌํ•จํ•˜๋Š” ์ธ์ง€๋„๋ฅผ ํ‰๊ฐ€ํ•œ ๋ฌธ์„œํ™”๋œ ์ฆ๊ฑฐ.


1.3 Awareness

The organization shall ensure that Program participants are aware of:
a) The Open Source policy;
b) Relevant Open Source objectives;
c) Their contribution to the effectiveness of the Program; and
d) The implications of not following the Programโ€™s requirements.

Verification Material(s):

1.3.1 Documented evidence of assessed awareness for each Program personnel including the Programโ€™s objectives, ones contribution within the Program, and implications of Program non-conformance.

ํ”„๋กœ๊ทธ๋žจ ์ฐธ์—ฌ์ž๊ฐ€ ์˜คํ”ˆ์†Œ์Šค ์ •์ฑ…, ๊ธฐ์—…์˜ ์˜คํ”ˆ์†Œ์Šค ๊ด€๋ จ ๋ชฉํ‘œ, ์˜คํ”ˆ์†Œ์Šค ํ”„๋กœ๊ทธ๋žจ์ด ํšจ๊ณผ์ ์ผ ์ˆ˜ ์žˆ๋„๋ก ์ฐธ์—ฌ์ž์˜ ๊ธฐ์—ฌ ๋ฐฉ๋ฒ•, ๊ทธ๋ฆฌ๊ณ  ํ”„๋กœ๊ทธ๋žจ ์š”๊ฑด์„ ์ค€์ˆ˜ํ•˜์ง€ ์•Š์•˜์„ ๋•Œ์˜ ๋ฐœ์ƒํ•  ์ˆ˜ ์žˆ๋Š” ์œ„ํ—˜์— ๋Œ€ํ•ด ์ธ์‹ํ•˜๋„๋ก ํ•œ๋‹ค.

์ด๋ฅผ ์œ„ํ•ด ์˜คํ”ˆ์†Œ์Šค ์ •์ฑ…์€ ํ”„๋กœ๊ทธ๋žจ ์ฐธ์—ฌ์ž๊ฐ€ ์˜คํ”ˆ์†Œ์Šค ์ •์ฑ… ๋“ฑ์˜ ์ฃผ์š” ๋‚ด์šฉ์„ ์ธ์‹ํ•  ์ˆ˜ ์žˆ๋„๋ก ๋‹ค์Œ์˜ ๋‚ด์šฉ์„ ํฌํ•จํ•ด์•ผ ํ•œ๋‹ค.

  • ๋จผ์ €, ์˜คํ”ˆ์†Œ์Šค๋ฅผ ์‚ฌ์šฉ, ๋ฐฐํฌ, ๊ธฐ์—ฌํ•˜๋Š” ์ผ๋ จ์˜ ํ™œ๋™์„ ์ˆ˜ํ–‰ํ•˜๋Š” ๋ชฉํ‘œ๋ฅผ ํฌํ•จํ•œ๋‹ค. ์˜ˆ๋ฅผ ๋“ค์–ด,โ€œ์˜คํ”ˆ์†Œ์Šค๋ฅผ ์ด์šฉํ•˜์—ฌ ์ œํ’ˆ์„ ๋งŒ๋“ค๋•Œ ์˜คํ”ˆ์†Œ์Šค ์ปดํ”Œ๋ผ์ด์–ธ์Šค ๋ฆฌ์Šคํฌ๋ฅผ ์ตœ์†Œํ™”ํ•˜๊ณ , ์˜คํ”ˆ์†Œ์Šค ์ปค๋ฎค๋‹ˆํ‹ฐ์— ์ฐธ์—ฌํ•˜๊ณ  ๊ธฐ์—ฌํ•จ์œผ๋กœ ์ตœ๊ณ ์˜ ๊ฐ€์น˜๋ฅผ ์ฐฝ์ถœํ•œ๋‹คโ€์™€ ๊ฐ™์€ ํ˜•ํƒœ๋กœ ๋ชฉํ‘œ๋ฅผ ์ˆ˜๋ฆฝํ•  ์ˆ˜ ์žˆ๋‹ค.
  • ๊ทธ๋ฆฌ๊ณ , ํ”„๋กœ๊ทธ๋žจ ์ฐธ์—ฌ์ž๊ฐ€ ์ž์‹ ์˜ ์—ญํ• ์— ๋Œ€ํ•œ ์ฑ…์ž„์„ ์™„์ˆ˜ํ•จ์œผ๋กœ์จ ์˜คํ”ˆ์†Œ์Šค ํ”„๋กœ๊ทธ๋žจ์˜ ํšจ๊ณผ๊ฐ€ ์ฆ๋Œ€๋  ์ˆ˜ ์žˆ์Œ์„ ์•Œ๋ฆฐ๋‹ค.
  • ๋˜ํ•œ, ์˜คํ”ˆ์†Œ์Šค ํ”„๋กœ๊ทธ๋žจ์˜ ์š”๊ฑด๋“ค์„ ์ค€์ˆ˜ํ•˜์ง€ ์•Š์•˜์„ ๋•Œ ์–ด๋– ํ•œ ์œ„ํ—˜์ด ๋ฐœ์ƒํ•˜๋Š”์ง€์— ๋Œ€ํ•ด์„œ๋„ ์•Œ๋ฆฐ๋‹ค.

๋Œ€ํ‘œ์ ์ธ ์œ„ํ—˜ ์š”์†Œ๋Š” ๋‹ค์Œ๊ณผ ๊ฐ™๋‹ค.

  • ์‚ฌ์šฉํ•œ ์ฝ”๋“œ์˜ ์ €์ž‘๊ถŒ์ž๋กœ๋ถ€ํ„ฐ ๋ฒ•์  ํด๋ ˆ์ž„
  • ์˜๋„ํ•˜์ง€ ์•Š์€ ๊ธฐ์—… ๋…์  ์ฝ”๋“œ์˜ ๊ณต๊ฐœ
  • ๋ผ์ด์„ ์Šค ์˜๋ฌด ์œ„๋ฐ˜์œผ๋กœ ์ธํ•œ ๋ฒŒ๊ธˆ
  • ํ‰ํŒ ์†์‹ค
  • ์ˆ˜์ต ์†์‹ค
  • ๊ณต๊ธ‰์—…์ฒด ๋ฐ ๊ณ ๊ฐ๊ณผ์˜ ๊ณ„์•ฝ ์œ„๋ฐ˜

๊ฐ ํ”„๋กœ๊ทธ๋žจ ๋‹ด๋‹น์ž๊ฐ€ ํ”„๋กœ๊ทธ๋žจ์˜ ๋ชฉํ‘œ, ํ”„๋กœ๊ทธ๋žจ์— ๊ธฐ์—ฌ ๋ฐฉ๋ฒ•, ํ”„๋กœ๊ทธ๋žจ ๋ฏธ์ค€์ˆ˜์˜ ์˜๋ฏธ์— ๋Œ€ํ•ด ์˜ฌ๋ฐ”๋ฅด๊ฒŒ ์ธ์‹ํ•  ์ˆ˜ ์žˆ๋„๋ก ๊ต์œก์„ ์ œ๊ณตํ•˜๊ณ , ์ด๋ฅผ ํ‰๊ฐ€ํ•œ๋‹ค. ํ‰๊ฐ€ํ•œ ๊ฒฐ๊ณผ๋Š” ๋ฌธ์„œํ™”ํ•˜์—ฌ ๋ณด๊ด€ํ•œ๋‹ค. 1.2์žฅ์—์„œ ์–ธ๊ธ‰ํ•œ ๊ต์œก ๋ฐ ํ‰๊ฐ€ ์‹œ ์ด์— ๋Œ€ํ•œ ๋‚ด์šฉ์„ ํฌํ•จํ•˜๋ฉด ๋  ๊ฒƒ์ด๋‹ค.

1.4 ํ”„๋กœ๊ทธ๋žจ ์ ์šฉ ๋ฒ”์œ„ (Program Scope)

OpenChain Specification 2.0


1.4 ํ”„๋กœ๊ทธ๋žจ ์ ์šฉ ๋ฒ”์œ„

์„œ๋กœ ๋‹ค๋ฅธ ํ”„๋กœ๊ทธ๋žจ๋“ค์€ ์„œ๋กœ ๋‹ค๋ฅธ ์ˆ˜์ค€์˜ ๋ฒ”์œ„๊นŒ์ง€ ์ ์šฉ๋  ์ˆ˜ ์žˆ๋‹ค. ์˜ˆ๋ฅผ ๋“ค์–ด, ํ•˜๋‚˜์˜ ํ”„๋กœ๊ทธ๋žจ์ด ํ•˜๋‚˜์˜ ์ œํ’ˆ ๋ผ์ธ, ์ „์ฒด ๋ถ€์„œ ๋˜๋Š” ์ „์ฒด ์กฐ์ง์„ ๊ด€๋ฆฌํ•  ์ˆ˜ ์žˆ๋‹ค. ๊ฐ ํ”„๋กœ๊ทธ๋žจ๋ณ„๋กœ ๋ฒ”์œ„ ์ง€์ •์ด ์ด๋ฃจ์–ด์งˆ ํ•„์š”๊ฐ€ ์žˆ๋‹ค.

์ž…์ฆ ์ž๋ฃŒ:

1.4.1 ํ”„๋กœ๊ทธ๋žจ์˜ ์ ์šฉ ๋ฒ”์œ„์™€ ํ•œ๊ณ„๋ฅผ ๋ช…ํ™•ํ•˜๊ฒŒ ์ •์˜ํ•œ ๋ฌธ์„œํ™”๋œ ์ง„์ˆ .


1.4 Program Scope

Different Programs may be governed by different levels of scope. For example, a program could govern a single product line, an entire department or an entire organization. The scope designation needs to be declared for each Program.

Verification Material(s):

1.4.1 A written statement that clearly defines the scope and limits of the Program.

์˜คํ”ˆ์†Œ์Šค ํ”„๋กœ๊ทธ๋žจ์€ ๋ฐ˜๋“œ์‹œ ๊ธฐ์—… ์ „์ฒด์— ์ ์šฉํ•ด์•ผ ํ•˜๋Š” ๊ฒƒ์€ ์•„๋‹ˆ๋‹ค. ๊ธฐ์—… ๋‚ด ๊ฐ ์กฐ์ง์˜ ํŠน์„ฑ์— ๋”ฐ๋ผ ํ”„๋กœ๊ทธ๋žจ์˜ ์ ์šฉ ๋ฒ”์œ„๋ฅผ ๋‹ฌ๋ฆฌ ํ•  ์ˆ˜ ์žˆ๋‹ค. ์˜ˆ๋ฅผ ๋“ค์–ด, ์†Œํ”„ํŠธ์›จ์–ด๋ฅผ ์ „ํ˜€ ๋ฐฐํฌํ•˜์ง€ ์•Š๋Š” ์กฐ์ง์ด๋ผ๋ฉด ์˜คํ”ˆ์†Œ์Šค ํ”„๋กœ๊ทธ๋žจ์˜ ์ ์šฉ ๋ฒ”์œ„์— ํ•ด๋‹นํ•˜์ง€ ์•Š์„ ์ˆ˜ ์žˆ๋‹ค. ๋”ฐ๋ผ์„œ, ๊ธฐ์—…์˜ ์˜คํ”ˆ์†Œ์Šค ์ •์ฑ…์€ ์˜คํ”ˆ์†Œ์Šค ํ”„๋กœ๊ทธ๋žจ์˜ ์ ์šฉ ๋ฒ”์œ„์™€ ํ•œ๊ณ„๋ฅผ ๋ช…ํ™•ํžˆ ์ •์˜ํ•ด์•ผ ํ•œ๋‹ค.

์˜ˆ๋ฅผ ๋“ค์–ด, โ€œ์ด ์˜คํ”ˆ์†Œ์Šค ์ •์ฑ…์€ ํšŒ์‚ฌ๊ฐ€ ์™ธ๋ถ€์— ๋ฐฐํฌํ•˜๋Š” ๋ชจ๋“  ์ œํ’ˆ์— ์ ์šฉํ•œ๋‹ค. ํ–ฅํ›„ ๋ฐฐํฌํ•˜๋Š” ์ œํ’ˆ์˜ ํ˜•ํƒœ์— ๋”ฐ๋ผ ํ”„๋กœ๊ทธ๋žจ์˜ ๊ตฌ์„ฑ๊ณผ ์ ์šฉ ๋ฒ”์œ„๊ฐ€ ๋‹ฌ๋ผ์งˆ ์ˆ˜ ์žˆ์œผ๋ฉฐ, ์ด์— ๋Œ€ํ•ด์„œ๋Š” ์˜คํ”ˆ์†Œ์Šค ํŒ€์ด OSRB์™€์˜ ํ˜‘์˜๋ฅผ ํ†ตํ•ด ๊ฒฐ์ •ํ•œ๋‹ค.โ€์™€ ๊ฐ™์€ ํ˜•ํƒœ๋กœ ํ”„๋กœ๊ทธ๋žจ ์ ์šฉ ๋ฒ”์œ„๋ฅผ ์ •์˜ํ•  ์ˆ˜ ์žˆ๋‹ค.

1.5 ๋ผ์ด์„ ์Šค ์˜๋ฌด (License Obligations)

OpenChain Specification 2.0


1.5 ๋ผ์ด์„ ์Šค ์˜๋ฌด

๊ฐ ๋ผ์ด์„ ์Šค์— ์˜ํ•ด ๋ถ€์—ฌ๋œ ์˜๋ฌด, ์ œํ•œ ๋ฐ ๊ถŒ๋ฆฌ๋ฅผ ๊ฒฐ์ •ํ•˜๊ธฐ ์œ„ํ•ด ์‹๋ณ„๋œ ๋ผ์ด์„ ์Šค๋ฅผ ๊ฒ€ํ† ํ•˜๋Š” ํ”„๋กœ์„ธ์Šค๊ฐ€ ์กด์žฌํ•œ๋‹ค.

์ž…์ฆ ์ž๋ฃŒ:

1.5.1 ๊ฐ ์‹๋ณ„๋œ ๋ผ์ด์„ ์Šค์— ์˜ํ•ด ๋ถ€๊ณผ๋˜๋Š” ์˜๋ฌด, ์ œํ•œ ๋ฐ ๊ถŒ๋ฆฌ๋ฅผ ๊ฒ€ํ† ํ•˜๊ณ  ๋ฌธ์„œํ™”ํ•˜๊ธฐ ์œ„ํ•œ ๋ฌธ์„œํ™”๋œ ์ ˆ์ฐจ.


1.5 License Obligations

A process exists for reviewing the Identified Licenses to determine the obligations, restrictions and rights granted by each license.

Verification Material(s):

1.5.1 A written statement that clearly defines the scope and limits of the Program.

์˜คํ”ˆ์†Œ์Šค์˜ ์‚ฌ์šฉ ๊ฐ€๋Šฅ ์—ฌ๋ถ€๋ฅผ ํŒ๋‹จํ•˜๊ธฐ ์œ„ํ•ด์„œ๋Š” ๋จผ์ € ์˜คํ”ˆ์†Œ์Šค์˜ ๋ผ์ด์„ ์Šค๊ฐ€ ๋ฌด์—‡์ธ์ง€ ์‹๋ณ„ํ•˜๊ณ , ๋ผ์ด์„ ์Šค๊ฐ€ ์š”๊ตฌํ•˜๋Š” ์˜๋ฌด์‚ฌํ•ญ์„ ๊ฒ€ํ† ํ•˜๊ณ  ํ™•์ธํ•ด์•ผ ํ•œ๋‹ค. ์˜คํ”ˆ์†Œ์Šค ํ”„๋กœ๊ทธ๋žจ์€ ์†Œํ”„ํŠธ์›จ์–ด ๊ฐœ๋ฐœํŒ€์—์„œ ์˜คํ”ˆ์†Œ์Šค ๋ผ์ด์„ ์Šค๊ฐ€ ๋ถ€์—ฌํ•˜๋Š” ์˜๋ฌด, ์ œํ•œ ๋ฐ ๊ถŒ๋ฆฌ๋ฅผ ๊ฒ€ํ† ํ•  ์ˆ˜ ์žˆ๋„๋ก ์˜คํ”ˆ์†Œ์Šค ๋ผ์ด์„ ์Šค ์˜๋ฌด ์š”์•ฝ ์ž๋ฃŒ๋ฅผ ์ œ๊ณตํ•˜๋Š” ๊ฒƒ์ด ์ข‹๋‹ค. ๊ณต๊ฐœSW ๋ผ์ด์„ ์Šค(https://www.oss.kr/oss_license )์—์„œ๋Š” ์ฃผ์š” ์˜คํ”ˆ์†Œ์Šค ๋ผ์ด์„ ์Šค์˜ ์˜๋ฌด, ์ œํ•œ ๋ฐ ๊ถŒ๋ฆฌ๋ฅผ ์ž์„ธํžˆ ์„ค๋ช…ํ•œ๋‹ค.

์˜คํ”ˆ์†Œ์Šค๋ฅผ ์‚ฌ์šฉํ•˜๊ธฐ์— ์•ž์„œ ๋ผ์ด์„ ์Šค ๊ฒ€ํ† ํ•˜๊ณ  ์ด๋ฅผ ๋ฌธ์„œํ™”ํ•˜๋Š” ์ ˆ์ฐจ๋Š”โ€œ[๋ถ€๋ก 02] ์˜คํ”ˆ์†Œ์Šค ์ปดํ”Œ๋ผ์ด์–ธ์Šค ํ”„๋กœ์„ธ์Šค (์˜ˆ์‹œ)โ€์ ˆ์ฐจ์˜ ์˜คํ”ˆ์†Œ์Šค ์‹๋ณ„ ๋‹จ๊ณ„์— ํ•ด๋‹นํ•œ๋‹ค.

2.2 - 2. ๊ด€๋ จ ์—…๋ฌด ์ •์˜ ๋ฐ ์ง€์›

2.1 ์ ‘๊ทผ์„ฑ (Access)

OpenChain Specification 2.0


2.1 ์ ‘๊ทผ์„ฑ

์™ธ๋ถ€ ์˜คํ”ˆ์†Œ์Šค ๋ฌธ์˜์— ํšจ๊ณผ์ ์œผ๋กœ ๋Œ€์‘ํ•  ์ˆ˜ ์žˆ๋Š” ํ”„๋กœ์„ธ์Šค๋ฅผ ์œ ์ง€ํ•œ๋‹ค. ์ œ 3์ž๊ฐ€ ์˜คํ”ˆ์†Œ์Šค ์ปดํ”Œ๋ผ์ด์–ธ์Šค ๋ฌธ์˜๋ฅผ ํ•  ์ˆ˜ ์žˆ๋Š” ๋ฐฉ๋ฒ•์„ ๊ณต๊ฐœ์ ์œผ๋กœ ๋ฐํžŒ๋‹ค.

์ž…์ฆ ์ž๋ฃŒ:

2.1.1 ์ œ 3์ž๊ฐ€ ์˜คํ”ˆ์†Œ์Šค ์ปดํ”Œ๋ผ์ด์–ธ์Šค ๋ฌธ์˜๋ฅผ ํ•  ์ˆ˜ ์žˆ๊ฒŒ ๊ณต๊ฐœ์ ์œผ๋กœ ์•Œ๋ ค์ง„ ๋ฐฉ๋ฒ• (๊ณต๊ฐœ๋œ ์—ฐ๋ฝ์ฒ˜ ์ด๋ฉ”์ผ ์ฃผ์†Œ, ๋˜๋Š” Linux Foundation์˜ Open Compliance Directory ๋“ฑ).
2.1.2 ์ œ 3์ž์˜ ์˜คํ”ˆ์†Œ์Šค ๋ผ์ด์„ ์Šค ์ปดํ”Œ๋ผ์ด์–ธ์Šค ๋ฌธ์˜์— ๋Œ€์‘ํ•˜๊ธฐ ์œ„ํ•œ ๋‚ด๋ถ€์˜ ๋ฌธ์„œํ™”๋œ ์ ˆ์ฐจ.


2.1 Access

Maintain a process to effectively respond to external Open Source inquiries. Publicly identify a means by which a third party can make an Open Source compliance inquiry.

Verification Material(s):

2.1.1 Publicly visible method that allows any third party to make an Open Source license compliance inquiry (e.g., via a published contact email address, or the Linux Foundation’s Open Compliance Directory).
2.1.2 An internal documented procedure for responding to third party Open Source license compliance inquiries.

๋ฐฐํฌํ•œ ์ œํ’ˆ์— ์‚ฌ์šฉ๋œ ์˜คํ”ˆ์†Œ์Šค์— ๋Œ€ํ•ด ๊ณ ๊ฐ ๋ฐ ์˜คํ”ˆ์†Œ์Šค ์ €์ž‘๊ถŒ์ž๊ฐ€ ๊ธฐ์—…์—๊ฒŒ ์˜คํ”ˆ์†Œ์Šค ๊ด€๋ จ ๋ฌธ์˜, ์š”์ฒญ ๋ฐ ํด๋ ˆ์ž„์„ ์ œ๊ธฐํ•˜๋Š” ๊ฒฝ์šฐ๊ฐ€ ์žˆ๋‹ค. ์†Œ์†ก๊นŒ์ง€ ๋‹นํ•˜์ง€ ์•Š๊ธฐ ์œ„ํ•ด์„œ๋Š” ์ด๋Ÿฌํ•œ ์™ธ๋ถ€ ๋ฌธ์˜์— ๊ฐ€๋Šฅํ•œ ๋น ๋ฅด๊ณ  ์ •ํ™•ํ•˜๊ฒŒ ๋Œ€์‘ํ•˜๋Š” ๊ฒƒ์ด ์ค‘์š”ํ•˜๋‹ค. ๋”ฐ๋ผ์„œ ๊ธฐ์—…์€ ์™ธ๋ถ€์—์„œ ๊ธฐ์—…์—๊ฒŒ ์˜คํ”ˆ์†Œ์Šค ๊ด€๋ จ ๋ฌธ์˜๋ฅผ ํ•  ์ˆ˜ ์žˆ๋Š” ์—ฐ๋ฝ ๋ฐฉ๋ฒ•์„ ๊ณต๊ฐœ์ ์œผ๋กœ ๋ฐํžˆ๊ณ , ์™ธ๋ถ€ ์˜คํ”ˆ์†Œ์Šค ๋ฌธ์˜๋ฅผ ์ ‘์ˆ˜ํ•˜์˜€์„ ๋•Œ ๋น ๋ฅด๊ณ  ํšจ๊ณผ์ ์œผ๋กœ ๋Œ€์‘ ํ•  ์ˆ˜ ์žˆ๋Š” ํ”„๋กœ์„ธ์Šค๋ฅผ ๊ฐ–์ถ”๊ณ  ์žˆ์–ด์•ผ ํ•œ๋‹ค.

์™ธ๋ถ€์—์„œ ๊ธฐ์—…์—๊ฒŒ ์˜คํ”ˆ์†Œ์Šค ๊ด€๋ จ ๋ฌธ์˜๋ฅผ ํ•  ์ˆ˜ ์žˆ๋Š” ์—ฐ๋ฝ ๋ฐฉ๋ฒ•์€ ํšŒ์‚ฌ์˜ ์˜คํ”ˆ์†Œ์Šค ๋‹ด๋‹น์ž์˜ ์ด๋ฉ”์ผ ์ฃผ์†Œ๋ฅผ ๊ณต๊ฐœํ•˜๊ฑฐ๋‚˜, Linux Foundation์˜ Open Compliance Directory๋ฅผ ์ด์šฉํ•˜๋Š” ๊ฒƒ์ด๋‹ค.

์˜คํ”ˆ์†Œ์Šค ๊ฐœ๋ฐœ์ž๋“ค์ด ๊ธฐ์—…์˜ ์˜คํ”ˆ์†Œ์Šค ์ปดํ”Œ๋ผ์ด์–ธ์Šค ๊ด€๋ จ ์ด์Šˆ๋ฅผ ๋…ผ์˜ํ•˜๊ธฐ ์œ„ํ•ด ๊ธฐ์—… ๋‹ด๋‹น์ž์—๊ฒŒ ์—ฐ๋ฝํ•˜๊ณ  ์‹ถ์–ด๋„ ์—ฐ๋ฝ ๋ฐฉ๋ฒ•์„ ์ฐพ์ง€ ๋ชปํ•˜๋‹ค๊ฐ€ ๊ฒฐ๊ตญ ๋ฒ•์  ํด๋ ˆ์ž„๊นŒ์ง€ ์ œ๊ธฐํ•˜๋Š” ๊ฒฝ์šฐ๊ฐ€ ์žˆ๋‹ค. Linux Foundation์€ ์ด๋Ÿฌํ•œ ๊ฒฝ์šฐ๋ฅผ ์ตœ์†Œํ™” ํ•˜๊ธฐ ์œ„ํ•ด ๊ธฐ์—…๋“ค์—๊ฒŒ ์˜คํ”ˆ์†Œ์Šค ๊ด€๋ จ ๋ฌธ์˜๋ฅผ ๋ฐ›์„ ์ˆ˜ ์žˆ๋Š” ์—ฐ๋ฝ์ฒ˜๋ฅผ ๊ณต๊ฐœํ•  ์ˆ˜ ์žˆ๋„๋ก Open Compliance Directory๋ผ๋Š” ๊ณต๊ฐ„์„ ๋งˆ๋ จํ•˜์˜€๋‹ค.

directory.png

< https://compliance.linuxfoundation.org/references/open-compliance-directory/ >


์ด๋ฅผ ํ†ตํ•ด ์˜คํ”ˆ์†Œ์Šค ๊ฐœ๋ฐœ์ž๋“ค์€ ์›ํ•˜๋Š” ๊ธฐ์—…์˜ ์ปจํƒ ํฌ์ธํŠธ ์ •๋ณด๋ฅผ ์‰ฝ๊ฒŒ ํ™•์ธํ•  ์ˆ˜ ์žˆ๊ณ , ๋ฒ•์  ํด๋ ˆ์ž„๊นŒ์ง€ ์ œ๊ธฐํ•˜๊ธฐ ์ด์ „์— ๊ธฐ์—…์˜ ์˜คํ”ˆ์†Œ์Šค ๋‹ด๋‹น์ž์™€ ์˜คํ”ˆ์†Œ์Šค ์ปดํ”Œ๋ผ์ด์–ธ์Šค ์ด์Šˆ๋ฅผ ๋…ผ์˜ํ•˜์—ฌ ๋ฌธ์ œ๋ฅผ ํ•ด๊ฒฐํ•  ์ˆ˜ ์žˆ๋‹ค. ๊ธฐ์—…์˜ ์˜คํ”ˆ์†Œ์Šค ๋‹ด๋‹น์ž๋Š” Open Compliance Directory์— ๊ธฐ์—… ์ •๋ณด ๋ฐ ์—ฐ๋ฝ ๋ฐฉ๋ฒ•์„ ๋“ฑ๋กํ•˜๋Š” ๊ฒƒ์ด ์†Œ์†ก ๋ฆฌ์Šคํฌ๋ฅผ ์ค„์ผ ์ˆ˜ ์žˆ๋Š” ๋ฐฉ๋ฒ• ์ค‘ ํ•˜๋‚˜์ด๋‹ค.

addrequest.png

< https://www.linuxsources.org/content/open-compliance-directory-add-organization-request >


์™ธ๋ถ€ ๋ฌธ์˜ ๋ฐ ์š”์ฒญ์˜ ์ฃผ๋œ ๋‚ด์šฉ์€ ๋‹ค์Œ๊ณผ ๊ฐ™๋‹ค.

  • ํŠน์ • ์˜คํ”ˆ์†Œ์Šค๊ฐ€ ์ œํ’ˆ ๋ฐ ์„œ๋น„์Šค์— ์‚ฌ์šฉ๋˜์—ˆ๋Š”์ง€ ํ™•์ธ ์š”์ฒญ
  • Written Offer์—์„œ ์–ธ๊ธ‰๋œ GPL, LGPL ๋“ฑ์˜ ๋ผ์ด์„ ์Šค ํ•˜์˜ ์†Œ์Šค ์ฝ”๋“œ ์ œ๊ณต ์š”์ฒญ
  • ์˜คํ”ˆ์†Œ์Šค ๊ณ ์ง€๋ฌธ์— ๋ช…์‹œ๋˜์ง€ ์•Š์•˜์ง€๋งŒ ์ œํ’ˆ์—์„œ ๋ฐœ๊ฒฌ๋œ ์˜คํ”ˆ์†Œ์Šค์— ๋Œ€ํ•œ ํ•ด๋ช… ๋ฐ ์†Œ์Šค ์ฝ”๋“œ ๊ณต๊ฐœ ์š”์ฒญ
  • GPL, LGPL ๋“ฑ์˜ ์˜๋ฌด๋กœ ๊ณต๊ฐœ๋œ ์†Œ์Šค ์ฝ”๋“œ์— ๋ˆ„๋ฝ๋œ ํŒŒ์ผ ์ œ๊ณต ์š”์ฒญ
  • Copyright ํ‘œ์‹œ ์š”์ฒญ

์™ธ๋ถ€๋กœ๋ถ€ํ„ฐ์˜ ์ด๋Ÿฌํ•œ ์˜คํ”ˆ์†Œ์Šค ์ปดํ”Œ๋ผ์ด์–ธ์Šค ๋ฌธ์˜์— ์‹ ์†ํ•˜๊ณ  ์ •ํ™•ํ•˜๊ฒŒ ๋Œ€์‘ํ•œ๋‹ค๋ฉด ์†Œ์†ก๊นŒ์ง€ ์ง„ํ–‰๋˜๋Š” ์œ„ํ—˜์„ ํฌ๊ฒŒ ์ค„์ผ ์ˆ˜ ์žˆ๋‹ค. ๋”ฐ๋ผ์„œ, ๊ธฐ์—…์€ ์™ธ๋ถ€์˜ ์˜คํ”ˆ์†Œ์Šค ์ปดํ”Œ๋ผ์ด์–ธ์Šค ๋ฌธ์˜์— ๋Œ€์‘ํ•˜๊ธฐ ์œ„ํ•œ ์ ˆ์ฐจ๋ฅผ ๊ฐ–๊ณ  ์žˆ์–ด์•ผ ํ•œ๋‹ค. ์ปดํ”Œ๋ผ์ด์–ธ์Šค ๋ฌธ์˜๋ฅผ ๋Œ€์‘ํ•˜๊ธฐ ์œ„ํ•œ ์ผ๋ฐ˜์ ์ธ ์ ˆ์ฐจ๋Š” ๋‹ค์Œ๊ณผ ๊ฐ™๋‹ค.

process.png

< https://www.linuxsources.org/content/open-compliance-directory-add-organization-request >

  1. ์ ‘์ˆ˜ ํ™•์ธ (Acknowledge) ๋ฌธ์˜๋ฅผ ๋ฐ›์œผ๋ฉด ์ฆ‰์‹œ ์‘๋‹ตํ•˜์—ฌ, ๋ฌธ์˜๊ฐ€ ์ œ๋Œ€๋กœ ์ ‘์ˆ˜๋˜์—ˆ์Œ์„ ์•Œ๋ฆฐ๋‹ค. ์ด๋•Œ ์กฐ์น˜ ์˜ˆ์ •์ผ์„ ํ•จ๊ป˜ ์•Œ๋ฆฐ๋‹ค. ์š”์ฒญ์ž์˜ ์˜๋„๊ฐ€ ๋ฌด์—‡์ธ์ง€ ์ •ํ™•ํžˆ ํŒŒ์•…ํ•˜๋Š” ๊ฒƒ์ด ์ค‘์š”ํ•˜๊ธฐ ๋•Œ๋ฌธ์— ๋ฌธ์˜๊ฐ€ ๋ถˆ๋ช…ํ™•ํ•œ ๊ฒฝ์šฐ ์ถ”๊ฐ€ ์„ค๋ช…์„ ์š”์ฒญํ•œ๋‹ค.
  2. ์š”์ฒญ์ž์—๊ฒŒ ์•Œ๋ฆผ (Inform) ์š”์ฒญ์ž์—๊ฒŒ ์˜คํ”ˆ์†Œ์Šค ์ปดํ”Œ๋ผ์ด์–ธ์Šค๋ฅผ ์ถฉ์‹คํžˆ ์ˆ˜ํ–‰ํ•˜๊ณ  ์žˆ์Œ๊ณผ ์š”์ฒญ์ž์˜ ๋ฌธ์˜์— ๋Œ€ํ•ด ์กฐ์‚ฌํ•˜๊ณ  ์žˆ์Œ์„ ์•Œ๋ฆฐ๋‹ค. ๋‚ด๋ถ€ ์กฐ์‚ฌ ์ง„ํ–‰์‚ฌํ•ญ์ด ์—…๋ฐ์ดํŠธ๋˜๋ฉด ์•Œ๋ฆฌ๋Š” ๊ฒƒ์ด ์ข‹๋‹ค.
  3. ๋‚ด๋ถ€ ์กฐ์‚ฌ (Investigate) ๋ฌธ์˜์— ๋Œ€ํ•ด ๋‚ด๋ถ€ ์กฐ์‚ฌ๋ฅผ ์ง„ํ–‰ํ•œ๋‹ค. ๋ฌธ์ œ๊ฐ€ ๋œ ์ œํ’ˆ์˜ ๋ฒ„์ „์— ๋Œ€ํ•˜์—ฌ ์ปดํ”Œ๋ผ์ด์–ธ์Šค ํ”„๋กœ์„ธ์Šค๊ฐ€ ์ ์ ˆํ•˜๊ฒŒ ์ˆ˜ํ–‰๋˜์—ˆ๋Š”์ง€ BOM ๋ฐ ๋ฌธ์„œํ™” ๋œ ๊ฒ€ํ†  ์ด๋ ฅ์„ ํ†ตํ•ด ํ™•์ธํ•œ๋‹ค.
  4. ์š”์ฒญ์ž์—๊ฒŒ ๋ณด๊ณ  (Report) ์š”์ฒญ์ž์—๊ฒŒ ํ†ต๋ณดํ–ˆ๋˜ ์กฐ์น˜ ์˜ˆ์ •์ผ ๋‚ด์— ๋‚ด๋ถ€ ์กฐ์‚ฌ๋ฅผ ๋งˆ์น˜๊ณ , ์ด์— ๋Œ€ํ•œ ๋‚ด๋ถ€ ๊ธฐ๋ก์„ ๋‚จ๊ธด ํ›„ ์š”์ฒญ์ž์—๊ฒŒ ๊ฒฐ๊ณผ๋ฅผ ์•Œ๋ฆฐ๋‹ค.
  5. ์ฒ˜๋ฆฌ ์ข…๋ฃŒ (Close Inquiry) ์š”์ฒญ์ž์˜ ๋ฌธ์˜๊ฐ€ ์˜คํ•ด๋กœ ์ธํ•œ ์ž˜๋ชป๋œ ์ง€์ ์ด๋‚˜ ์š”์ฒญ์ด์—ˆ๋‹ค๋ฉด ์ถ”๊ฐ€ ์กฐ์น˜ ์—†์ด ์š”์ฒญ์ž์—๊ฒŒ ์ด๋ฅผ ์•Œ๋ฆฌ๊ณ  ์ฒ˜๋ฆฌ๋ฅผ ์ข…๋ฃŒํ•œ๋‹ค.
  6. ๋ฌธ์ œ ๋ณด์™„ (Rectify) ๋‚ด๋ถ€์กฐ์‚ฌ์—์„œ ์‹ค์ œ ์ปดํ”Œ๋ผ์ด์–ธ์Šค ๋ฌธ์ œ๊ฐ€ ๋ฐœ๊ฒฌ๋˜๋ฉด ํ•ด๋‹น ์กฐ์ง์€ ์ œํ’ˆ ๋˜๋Š” ์„œ๋น„์Šค์˜ ์ปดํ”Œ๋ผ์ด์–ธ์Šค ๋ฌธ์ œ๋ฅผ ํ•ด๊ฒฐํ•˜๊ธฐ ์œ„ํ•ด ํ•„์š”ํ•œ ๋ชจ๋“  ์ ˆ์ฐจ๋ฅผ ์ˆ˜ํ–‰ํ•œ๋‹ค. ์˜ˆ์ƒ๋˜๋Š” ์™„๋ฃŒ ์ผ์ž๋ฅผ ์š”์ฒญ์ž์—๊ฒŒ ๋‹ค์‹œ ํ•œ๋ฒˆ ์•Œ๋ฆฐ๋‹ค. ์ฆ‰, ํ•ด๋‹น ์˜คํ”ˆ์†Œ์Šค ๋ผ์ด์„ ์Šค์˜ ์˜๋ฌด๋ฅผ ์ดํ–‰ํ•˜๊ธฐ ์œ„ํ•œ ์ •ํ™•ํ•œ ๋ฐฉ๋ฒ•๊ณผ ์‹œ๊ธฐ๋ฅผ ์•Œ๋ ค์•ผ ํ•œ๋‹ค. ๋ฌธ์ œ๋ฅผ ํ•ด๊ฒฐํ•œ ํ›„์—๋Š” ์ฆ‰์‹œ ์š”์ฒญ์ž์—๊ฒŒ ์•Œ๋ฆฌ๊ณ  ๋ฌธ์ œ๊ฐ€ ํ•ด๊ฒฐ๋˜์—ˆ์Œ์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋Š” ์ตœ์„ ์˜ ๋ฐฉ๋ฒ•์„ ์ œ๊ณตํ•œ๋‹ค.
  7. ํ”„๋กœ์„ธ์Šค ๊ฐœ์„  (Improve) ์ปดํ”Œ๋ผ์ด์–ธ์Šค ๋ฌธ์ œ๊ฐ€ ์žˆ์—ˆ๋˜ ๊ฒฝ์šฐ, OSRB ๋ฏธํŒ…์„ ํ†ตํ•ด ์‚ฌ๋ก€๋ฅผ ๊ฒ€ํ† ํ•˜๊ณ , ๋ฌธ์ œ๊ฐ€ ๋ฐœ์ƒํ•œ ๊ฒฝ์œ„๋ฅผ ํŒŒ์•…ํ•˜์—ฌ, ๋ฌธ์ œ๊ฐ€ ์žฌ๋ฐœํ•˜์ง€ ์•Š์„ ์ˆ˜ ์žˆ๋„๋ก ํ”„๋กœ์„ธ์Šค๋ฅผ ๊ฐœ์„ ํ•œ๋‹ค.

2.2 ํšจ๊ณผ์ ์ธ ๋ฆฌ์†Œ์Šค ์ œ๊ณต (Effectively Resourced)

OpenChain Specification 2.0


2.2 ํšจ๊ณผ์ ์ธ ๋ฆฌ์†Œ์Šค ์ œ๊ณต

ํ”„๋กœ๊ทธ๋žจ ์—…๋ฌด๋ฅผ ํ™•์ธํ•˜๊ณ  ๋ฆฌ์†Œ์Šค๋ฅผ ์ œ๊ณตํ•˜๋ผ:

  • ํ”„๋กœ๊ทธ๋žจ ์—…๋ฌด๋ฅผ ์„ฑ๊ณต์ ์œผ๋กœ ์ˆ˜ํ–‰ํ•  ์ˆ˜ ์žˆ๋„๋ก ์ฑ…์ž„์„ ํ• ๋‹นํ•˜๋ผ.
  • ํ”„๋กœ๊ทธ๋žจ ์—…๋ฌด๋ฅผ ์œ„ํ•ด ์ถฉ๋ถ„ํ•œ ๋ฆฌ์†Œ์Šค๊ฐ€ ์ œ๊ณต๋œ๋‹ค:
    โ€ข ์—…๋ฌด๋ฅผ ์ˆ˜ํ–‰ํ•  ์‹œ๊ฐ„์ด ํ• ๋‹น๋˜์—ˆ๋‹ค;
    โ€ข ์ ์ ˆํ•œ ์ž๊ธˆ์ด ํ• ๋‹น๋˜์—ˆ๋‹ค.
  • ์ •์ฑ… ๋ฐ ์ง€์› ์—…๋ฌด๋ฅผ ๊ฒ€ํ† ํ•˜๊ณ  ์—…๋ฐ์ดํŠธํ•˜๋Š” ํ”„๋กœ์„ธ์Šค๊ฐ€ ์กด์žฌํ•œ๋‹ค;
  • ์˜คํ”ˆ์†Œ์Šค ๋ผ์ด์„ ์Šค ์ปดํ”Œ๋ผ์ด์–ธ์Šค์™€ ๊ด€๋ จ๋œ ๋ฒ•๋ฅ  ๊ฐ€์ด๋“œ๋ฅผ ํ•„์š”๋กœ ํ•˜๋Š” ์ธ์›์ด ๋ฒ•๋ฅ  ์ „๋ฌธ ์ง€์‹์„ ์ด์šฉํ•  ์ˆ˜ ์žˆ๋‹ค;
  • ์˜คํ”ˆ์†Œ์Šค ๋ผ์ด์„ ์Šค ์ปดํ”Œ๋ผ์ด์–ธ์Šค ๋ฌธ์ œ๋ฅผ ํ•ด๊ฒฐํ•˜๊ธฐ ์œ„ํ•œ ํ”„๋กœ์„ธ์Šค๊ฐ€ ์กด์žฌํ•œ๋‹ค.

์ž…์ฆ ์ž๋ฃŒ:

2.2.1 ํ™•์ธ๋œ ํ”„๋กœ๊ทธ๋žจ ์—ญํ• ์˜ ๋‹ด๋‹น์ž ์ด๋ฆ„, ๊ทธ๋ฃน ๋˜๋Š” ๊ธฐ๋Šฅ์ด ๊ธฐ์žฌ๋œ ๋ฌธ์„œ
2.2.2 ํ™•์ธ๋œ ํ”„๋กœ๊ทธ๋žจ ์—ญํ• ์ด ์ ์ ˆํ•˜๊ฒŒ ์ถฉ์›๋˜์—ˆ๊ณ  ์ ํ•ฉํ•˜๊ฒŒ ์ž๊ธˆ์ด ์ œ๊ณต๋˜์—ˆ๋‹ค
2.2.3 ์˜คํ”ˆ์†Œ์Šค ๋ผ์ด์„ ์Šค ์ปดํ”Œ๋ผ์ด์–ธ์Šค ๋ฌธ์ œ๋ฅผ ํ•ด๊ฒฐํ•˜๊ธฐ ์œ„ํ•ด ๋‚ด๋ถ€ ๋˜๋Š” ์™ธ๋ถ€์˜ ์ „๋ฌธ ๋ฒ•๋ฅ  ์ง€์‹์„ ์ด์šฉํ•  ์ˆ˜ ์žˆ๋Š” ๋ฐฉ๋ฒ•์˜ ํ™•์ธ.
2.2.4 ์˜คํ”ˆ์†Œ์Šค ์ปดํ”Œ๋ผ์ด์–ธ์Šค์— ๋Œ€ํ•œ ๋‚ด๋ถ€ ์ฑ…์ž„์„ ํ• ๋‹นํ•˜๋Š” ๋ฌธ์„œํ™”๋œ ์ ˆ์ฐจ 2.2.5 ๋ฏธ์ค€์ˆ˜ ์‚ฌ๋ก€์˜ ๊ฒ€ํ†  ๋ฐ ์‹œ์ •์„ ๊ทœ์ •ํ•˜๋Š” ๋ฌธ์„œํ™”๋œ ์ ˆ์ฐจ


2.2 Effectively Resourced

Identify and Resource Program Task(s):

  • Assign accountability to ensure the successful execution of Program tasks.
  • Program tasks are sufficiently resourced:
    โ€ข Time to perform the tasks have been allocated; and
    โ€ข Adequate funding has been allocated.
  • A process exists for reviewing and updating the policy and supporting tasks;
  • Legal expertise pertaining to Open Source license compliance is accessible to those who may need such guidance; and
  • A process exists for the resolution of Open Source license compliance issues.

Verification Material(s):

2.2.1 Document with name of persons, group or function in Program role(s) identified.
2.2.2 The identified Program roles have been properly staffed and adequate funding provided.
2.2.3 Identification of legal expertise available to address Open Source license compliance matters which could be internal or external.
2.2.4 A documented procedure that assigns internal responsibilities for Open Source compliance.
2.2.5 A documented procedure for handling the review and remediation of non-compliant cases.

๊ธฐ์—…์€ ์˜คํ”ˆ์†Œ์Šค ํ”„๋กœ๊ทธ๋žจ์ด ์›ํ™œํ•˜๊ฒŒ ๊ธฐ๋Šฅ์„ ์ˆ˜ํ–‰ํ•  ์ˆ˜ ์žˆ๋„๋ก ๋ฆฌ์†Œ์Šค๋ฅผ ์ถฉ๋ถ„ํ•˜๊ฒŒ ์ œ๊ณตํ•ด์•ผ ํ•œ๋‹ค.

  • ํ”„๋กœ๊ทธ๋žจ ์ฐธ์—ฌ์ž๋“ค์ด ์—…๋ฌด๋ฅผ ์ˆ˜ํ–‰ํ•  ์ˆ˜ ์žˆ๋Š” ์‹œ๊ฐ„๊ณผ ์ž๊ธˆ์„ ํ• ๋‹นํ•˜๊ณ , ์ฃผ๊ธฐ์ ์œผ๋กœ ์˜คํ”ˆ์†Œ์Šค ์ •์ฑ…์„ ๊ฒ€ํ† ํ•˜์—ฌ ๊ธฐ์—…์˜ ์†Œํ”„ํŠธ์›จ์–ด ์ „๋žต์— ๋งž์ถ”์–ด ์—…๋ฐ์ดํŠธํ•ด์•ผ ํ•œ๋‹ค.
  • ํ”„๋กœ๊ทธ๋žจ ์ฐธ์—ฌ์ž๋“ค์ด ์ปดํ”Œ๋ผ์ด์–ธ์Šค ์ด์Šˆ ํ•ด๊ฒฐ์„ ์œ„ํ•œ ํ”„๋กœ์„ธ์Šค๊ฐ€ ๊ตฌ์ถ•๋˜์–ด์•ผ ํ•˜๊ณ , ์ด์Šˆ ํ•ด๊ฒฐ์„ ์œ„ํ•ด ๋ฒ•์ ์ธ ๊ฒ€ํ† ๊ฐ€ ํ•„์š”ํ•  ๊ฒฝ์šฐ ๋ฒ•๋ฌด ์ž๋ฌธ์„ ์š”์ฒญํ•  ์ˆ˜ ์žˆ๋Š” ๋ฐฉ๋ฒ•์ด ์ œ๊ณต๋˜์–ด์•ผ ํ•œ๋‹ค.

์˜คํ”ˆ์†Œ์Šค ํ”„๋กœ๊ทธ๋žจ์ด ๊ธฐ๋Šฅ์„ ์ˆ˜ํ–‰ํ•˜๊ธฐ ์œ„ํ•ด์„œ๋Š” ๊ฐ ์—ญํ•  ๋ณ„ ๋‹ด๋‹น์ž๊ฐ€ ์ง€์ •๋˜์–ด์•ผ ํ•œ๋‹ค.

  • ๊ฐ ์—ญํ•  ๋ณ„ ๋‹ด๋‹น์ž ํ˜น์€ ๋‹ด๋‹น ์กฐ์ง์„ ์ง€์ •ํ•˜๊ณ , ๋ˆ„๊ตฌ๋‚˜ ์ด๋ฅผ ์ฐธ๊ณ ํ•  ์ˆ˜ ์žˆ๋„๋ก ๋ฌธ์„œํ™”ํ•˜์—ฌ ๊ณต์œ ํ•œ๋‹ค.
  • ๊ฐ ์กฐ์ง์˜ ์ฑ…์ž„์ž๋Š” ํ”„๋กœ๊ทธ๋žจ ๋‚ด์˜ ๊ฐ ์—ญํ• ๋ณ„ ๋‹ด๋‹น์ž๊ฐ€ ์ ์ ˆํžˆ ์ถฉ์›๋˜์—ˆ๋Š”์ง€, ์—…๋ฌด๋ฅผ ์ˆ˜ํ–‰ํ•˜๋Š”๋ฐ ํ•„์š”ํ•œ ์ž๊ธˆ์ด ์ ์ ˆํ•˜๊ฒŒ ์ œ๊ณต๋˜์—ˆ๋Š”์ง€๋ฅผ ํ™•์ธํ•œ๋‹ค.

๋งŒ์•ฝ, ํ”„๋กœ๊ทธ๋žจ ์ฐธ์—ฌ์ž๊ฐ€ ์ž์‹ ์˜ ์—ญํ• ์„ ์ˆ˜ํ–‰ํ•˜๋Š”๋ฐ ๋ฆฌ์†Œ์Šค๋‚˜ ์ž๊ธˆ ์ง€์›์ด ๋ถ€์กฑํ•˜๋‹ค๊ณ  ํŒ๋‹จํ•œ๋‹ค๋ฉด, ๋ฐ˜๋“œ์‹œ ๊ธฐ์—…์˜ ์˜คํ”ˆ์†Œ์Šค ์ฑ…์ž„์ž์—๊ฒŒ ๋ฌธ์ œ๋ฅผ ์ œ๊ธฐํ•˜์—ฌ ํ•ด๊ฒฐํ•ด์•ผ ํ•œ๋‹ค. ๋ฌธ์ œ๊ฐ€ ํšจ๊ณผ์ ์œผ๋กœ ํ•ด๊ฒฐ๋˜์ง€ ์•Š์„ ๊ฒฝ์šฐ, ์˜คํ”ˆ์†Œ์Šค ์ด์‚ฌํšŒ์— ๋ณด๊ณ ํ•˜๊ณ , ์ด์‚ฌํšŒ๋Š” ํ•„์š”ํ•œ ์˜์‚ฌ๊ฒฐ์ •์„ ์ˆ˜ํ–‰ํ•˜์—ฌ ์ ์ ˆํ•œ ์ž์›์ด ํ• ๋‹น ๋  ์ˆ˜ ์žˆ๋„๋ก ํ•ด์•ผ ํ•œ๋‹ค.

๊ธฐ์—…์€ ํ”„๋กœ๊ทธ๋žจ ์ฐธ์—ฌ์ž๊ฐ€ ์ด์Šˆ ํ•ด๊ฒฐ์„ ์œ„ํ•ด ๋ฒ•๋ฅ ์ ์ธ ๊ฒ€ํ† ๊ฐ€ ํ•„์š”ํ•  ๊ฒฝ์šฐ, ์ด์— ๋Œ€ํ•ด ๋ฒ•๋ฅ  ์ž๋ฌธ์„ ์š”์ฒญํ•  ์ˆ˜ ์žˆ๋Š” ๋ฐฉ๋ฒ•์„ ์ œ๊ณตํ•ด์•ผ ํ•œ๋‹ค. ํšŒ์‚ฌ ๋‚ด์˜ ๋ฒ•๋ฌดํŒ€์„ ํ†ตํ•ด ์šฐ์„  ์ œ๊ณตํ•˜๊ณ , ์ด์Šˆ๊ฐ€ ์ฒจ์˜ˆํ•œ ๊ฒฝ์šฐ, ์˜คํ”ˆ์†Œ์Šค ์ „๋ฌธ ๋ณ€ํ˜ธ์‚ฌ๋ฅผ ๋ณด์œ ํ•œ ์™ธ๋ถ€ ๋ฒ•๋ฌด ๋ฒ•์ธ์„ ์ด์šฉํ•  ์ˆ˜ ์žˆ๋‹ค. OpenChain Project์—์„œ๋Š” ํŒŒํŠธ๋„ˆ ํ”„๋กœ๊ทธ๋žจ์„ ํ†ตํ•ด ์˜คํ”ˆ์†Œ์Šค ๊ด€๋ จ ์ž๋ฌธ์„ ์ œ๊ณตํ•˜๋Š” ๊ธ€๋กœ๋ฒŒ ๋ฒ•๋ฌด๋ฒ•์ธ ๋ฆฌ์ŠคํŠธ๋ฅผ ์ œ๊ณตํ•œ๋‹ค.

partners.png

< https://www.openchainproject.org/partners >

OpenChain ํŒŒํŠธ๋„ˆ๋กœ ๋“ฑ๋ก๋œ ๋ฒ•๋ฌด๋ฒ•์ธ์€ OpenChain Project์—์„œ ์š”๊ตฌํ•˜๋Š” ์š”๊ฑด์„ ์ถฉ์กฑํ•œ ๊ณณ๋“ค์ด๋ฉฐ, ๋Œ€ํ•œ๋ฏผ๊ตญ์—์„œ๋Š” ๋ฒ•๋ฌด๋ฒ•์ธ ํƒœํ‰์–‘์ด ๋“ฑ๋ก๋˜์–ด ์žˆ๋‹ค.

์˜คํ”ˆ์†Œ์Šค ์ฑ…์ž„์ž๋Š” ๊ธฐ์—…์˜ ์˜คํ”ˆ์†Œ์Šค ์ปดํ”Œ๋ผ์ด์–ธ์Šค ํ™œ๋™์„ ์œ„ํ•œ ๊ธฐ์—… ๋‚ด๋ถ€์˜ ์—ญํ• ๊ณผ ์ฑ…์ž„์„ ํ• ๋‹นํ•ด์•ผ ํ•œ๋‹ค. ์˜คํ”ˆ์†Œ์Šค ์ •์ฑ… ๋ฌธ์„œ์—๋Š” ์˜คํ”ˆ์†Œ์Šค ์ฑ…์ž„์ž๊ฐ€ ์˜คํ”ˆ์†Œ์Šค ์ปดํ”Œ๋ผ์ด์–ธ์Šค ์ด์Šˆ ํ•ด๊ฒฐ์„ ์œ„ํ•ด ๋‹ด๋‹นํ•ด์•ผ ํ•  ์—ญํ• ์— ๋Œ€ํ•ด ๊ธฐ์ˆ ํ•œ๋‹ค.

์ปดํ”Œ๋ผ์ด์–ธ์Šค ๋ฏธ์ค€์ˆ˜ ์ด์Šˆ๊ฐ€ ์ œ๊ธฐ๋œ ๊ฒฝ์šฐ, ๊ธฐ์—…์€ ์ด๋ฅผ ์‹ ์†ํžˆ ๊ฒ€ํ† ํ•˜๊ณ  ๋Œ€์‘ํ•˜๊ธฐ ์œ„ํ•œ ์ ˆ์ฐจ๋ฅผ ๋ฌธ์„œํ™”ํ•ด์•ผ ํ•œ๋‹ค. ์ด์— ๋Œ€ํ•œ ์ž์„ธํ•œ ๋‚ด์šฉ์€ 2.1์žฅ์—์„œ ์™ธ๋ถ€ ๋ฌธ์˜ ๋Œ€์‘์— ๋Œ€ํ•œ ํ”„๋กœ์„ธ์Šค ์„ค๋ช… ๋ถ€๋ถ„์„ ์ฐธ๊ณ ํ•  ์ˆ˜ ์žˆ๋‹ค.

2.3 - 3. ์˜คํ”ˆ์†Œ์Šค ์ฝ˜ํ…์ธ  ๊ฒ€ํ†  ๋ฐ ์Šน์ธ

3.1 BOM (Bill of Materials)

OpenChain Specification 2.0


3.1 BOM

๊ณต๊ธ‰ ๋Œ€์ƒ ์†Œํ”„ํŠธ์›จ์–ด๋ฅผ ๊ตฌ์„ฑํ•˜๋Š” ๊ฐ ์˜คํ”ˆ์†Œ์Šค ์ปดํฌ๋„ŒํŠธ(๋ฐ ์‹๋ณ„๋œ ๋ผ์ด์„ ์Šค)๋ฅผ ํฌํ•จํ•˜๋Š” BOM์„ ์ž‘์„ฑํ•˜๊ณ  ๊ด€๋ฆฌํ•˜๋Š” ํ”„๋กœ์„ธ์Šค๊ฐ€ ์žˆ๋‹ค.

์ž…์ฆ ์ž๋ฃŒ:

3.1.1 ๊ณต๊ธ‰ ๋Œ€์ƒ ์†Œํ”„ํŠธ์›จ์–ด๋ฅผ ๊ตฌ์„ฑํ•˜๋Š” ์˜คํ”ˆ์†Œ์Šค ์ปดํฌ๋„ŒํŠธ ๋ชจ์Œ์— ๋Œ€ํ•œ ์ •๋ณด๋ฅผ ์‹๋ณ„, ์ถ”์ , ๊ฒ€ํ† , ์Šน์ธ ๋ฐ ๋ณด๊ด€ํ•˜๋Š” ๋ฌธ์„œํ™”๋œ ์ ˆ์ฐจ
3.1.2 ๊ณต๊ธ‰ ๋Œ€์ƒ ์†Œํ”„ํŠธ์›จ์–ด์— ๋Œ€ํ•ด ๋ฌธ์„œํ™”๋œ ์ ˆ์ฐจ๊ฐ€ ์ ์ ˆํžˆ ์ค€์ˆ˜๋˜์—ˆ์Œ์„ ์ž…์ฆํ•˜๋Š” ์˜คํ”ˆ์†Œ์Šค ์ปดํฌ๋„ŒํŠธ ๊ธฐ๋ก.


3.1 Bill of Materials

A process exists for creating and managing a bill of materials that includes each Open Source component (and its Identified Licenses) from which the Supplied Software is comprised.

Verification Material(s):

3.1.1 A documented procedure for identifying, tracking, reviewing, approving, and archiving information about the collection of Open Source components from which the Supplied Software is comprised.
3.1.2 Open Source component records for the Supplied Software that demonstrates the documented procedure was properly followed.

์˜คํ”ˆ์†Œ์Šค ์ปดํ”Œ๋ผ์ด์–ธ์Šค ํ™œ๋™์˜ ๊ฐ€์žฅ ๊ธฐ๋ณธ์€ ๋ฐ”๋กœ ๊ณต๊ธ‰ ๋Œ€์ƒ ์†Œํ”„ํŠธ์›จ์–ด์— ํฌํ•จ๋œ ์˜คํ”ˆ์†Œ์Šค ํ˜„ํ™ฉ์„ ํŒŒ์•…ํ•˜๋Š” ๊ฒƒ์ด๋‹ค. ๊ณต๊ธ‰ ๋Œ€์ƒ ์†Œํ”„ํŠธ์›จ์–ด์— ํฌํ•จ๋œ ์˜คํ”ˆ์†Œ์Šค์™€ ๊ทธ ๋ผ์ด์„ ์Šค๋ฅผ ์‹๋ณ„ํ•˜์—ฌ ๊ทธ ์ •๋ณด๋ฅผ ๋‹ด๊ณ ์žˆ๋Š” BOM์„ ์ž‘์„ฑํ•˜๊ณ  ๊ด€๋ฆฌํ•˜๋Š” ํ”„๋กœ์„ธ์Šค๋ฅผ ๊ตฌ์ถ•ํ•ด์•ผ ํ•œ๋‹ค. ๊ณต๊ธ‰ ๋Œ€์ƒ ์†Œํ”„ํŠธ์›จ์–ด๋งˆ๋‹ค ์–ด๋–ค ์˜คํ”ˆ์†Œ์Šค๊ฐ€ ํฌํ•จ๋˜์–ด ์žˆ๋Š”์ง€ ์•Œ๊ณ  ์žˆ์–ด์•ผ ์†Œํ”„ํŠธ์›จ์–ด๋ฅผ ๋ฐฐํฌํ•  ๋•Œ ๊ฐ ๋ผ์ด์„ ์Šค๊ฐ€ ์š”๊ตฌํ•˜๋Š” ์˜๋ฌด ์‚ฌํ•ญ์„ ์ค€์ˆ˜ํ•  ์ˆ˜ ์žˆ๊ธฐ ๋•Œ๋ฌธ์ด๋‹ค. ๋ชจ๋“  ์˜คํ”ˆ์†Œ์Šค๋Š” ๋ฐฐํฌ ๋Œ€์ƒ ์†Œํ”„ํŠธ์›จ์–ด์— ํ†ตํ•ฉํ•˜๊ธฐ ์ „์— ๊ฒ€ํ†  ๋ฐ ์Šน์ธ๋˜์–ด์•ผ ํ•œ๋‹ค. ์˜คํ”ˆ์†Œ์Šค์˜ ๊ธฐ๋Šฅ, ํ’ˆ์งˆ ๋ฟ๋งŒ ์•„๋‹ˆ๋ผ ์ถœ์ฒ˜, ๋ผ์ด์„ ์Šค ์š”๊ฑด์„ ์ถฉ์กฑํ•˜๋Š”์ง€ ๊ฒ€ํ† ๊ฐ€ ๋˜์•ผ ํ•œ๋‹ค. ์ด๋ฅผ ์œ„ํ•ด ๊ฒ€ํ†  ์š”์ฒญ โ†’ ๋ฆฌ๋ทฐ โ†’ ์Šน์ธ ๊ณผ์ •์ด ํ•„์š”ํ•˜๋‹ค. [๋ถ€๋ก 02]์—์„œ๋Š” ๊ธฐ์—…์˜ ์˜คํ”ˆ์†Œ์Šค ์ปดํ”Œ๋ผ์ด์–ธ์Šค๋ฅผ ์œ„ํ•œ ํ”„๋กœ์„ธ์Šค ์ „๊ณผ์ •์— ๋Œ€ํ•ด ์„ค๋ช…ํ•˜๊ณ  ์žˆ๋‹ค. ์‹๋ณ„๋ถ€ํ„ฐ ๋“ฑ๋ก๊นŒ์ง€์˜ ๊ณผ์ •์„ ํ†ตํ•ด BOM์„ ์ž‘์„ฑํ•˜๊ณ  ๊ด€๋ฆฌํ•˜๊ฒŒ ๋œ๋‹ค.

{% page-ref page="../../appendix/process.md" %}

๊ณต๊ธ‰ ๋Œ€์ƒ ์†Œํ”„ํŠธ์›จ์–ด์— ํฌํ•จ๋œ ์˜คํ”ˆ์†Œ์Šค ๋ชฉ๋ก์€ ๋ฌธ์„œํ™”ํ•˜์—ฌ ๋ณด๊ด€ํ•ด์•ผ ํ•œ๋‹ค. Eclipse ์žฌ๋‹จ์—์„œ ํ›„์›ํ•˜๋Š” ์˜คํ”ˆ์†Œ์Šค ํ”„๋กœ์ ํŠธ์ธ SW360(https://projects.eclipse.org/proposals/ sw360)์€ ๊ณต๊ธ‰ ๋Œ€์ƒ ์†Œํ”„ํŠธ์›จ์–ด๋ณ„๋กœ ํฌํ•จํ•˜๊ณ  ์žˆ๋Š” ์˜คํ”ˆ์†Œ์Šค ๋ชฉ๋ก์„ ํŠธ๋ž˜ํ‚นํ•  ์ˆ˜ ์žˆ๋Š” ๊ธฐ๋Šฅ์„ ์ œ๊ณตํ•œ๋‹ค. SW360 ์‚ฌ์šฉ ๋ฐฉ๋ฒ•์€ [๋ถ€๋ก 03]์„ ์ฐธ๊ณ ํ•  ์ˆ˜ ์žˆ๋‹ค.

์˜คํ”ˆ์†Œ์Šค ์ปดํ”Œ๋ผ์ด์–ธ์Šค ํ”„๋กœ์„ธ์Šค์˜ ๋ชจ๋“  ๊ณผ์ •๊ณผ ๊ฒฐ๊ณผ๋Š” ๋ฌธ์„œํ™”๊ฐ€ ๋˜์–ด์•ผ ํ•œ๋‹ค. ์ด๋ฉ”์ผ์„ ์‚ฌ์šฉํ•˜๋Š” ๊ฒƒ ๋ณด๋‹ค๋Š” Jira, Bugzilla ๋“ฑ์˜ ์ด์Šˆ ํŠธ๋ž˜ํ‚น ์‹œ์Šคํ…œ์„ ์ด์šฉํ•˜๋Š” ๊ฒƒ์ด ์ด๋Ÿฌํ•œ ๊ณผ์ •์„ ํšจ์œจ์ ์œผ๋กœ ๋ฌธ์„œํ™” ํ•  ์ˆ˜ ์žˆ๋‹ค.

3.2 ๋ผ์ด์„ ์Šค ์ปดํ”Œ๋ผ์ด์–ธ์Šค

OpenChain Specification 2.0


3.2 ๋ผ์ด์„ ์Šค ์ปดํ”Œ๋ผ์ด์–ธ์Šค

ํ”„๋กœ๊ทธ๋žจ์€ ๊ณต๊ธ‰ ๋Œ€์ƒ ์†Œํ”„ํŠธ์›จ์–ด์— ๋Œ€ํ•ด ์†Œํ”„ํŠธ์›จ์–ด ๊ณต๊ธ‰ ๋‹ด๋‹น์ž๊ฐ€ ์ ‘ํ•˜๊ฒŒ ๋˜๋Š” ์ผ๋ฐ˜์ ์ธ ์˜คํ”ˆ์†Œ์Šค ์‚ฌ์šฉ ์‚ฌ๋ก€๋ฅผ ๊ด€๋ฆฌํ•  ์ˆ˜ ์žˆ์–ด์•ผ ํ•˜๋ฉฐ, ๋‹ค์Œ๊ณผ ๊ฐ™์€ ์‚ฌ๋ก€๊ฐ€ ํฌํ•จ๋  ์ˆ˜ ์žˆ๋‹ค(์ด ๋ชฉ๋ก์ด ์™„์ „ํ•œ ๊ฒƒ์€ ์•„๋‹ˆ๋ฉฐ, ๋ชจ๋“  ์‚ฌ์šฉ ์‚ฌ๋ก€๊ฐ€ ์ ์šฉ๋˜์–ด์•ผ ํ•˜๋Š” ๊ฒƒ์€ ์•„๋‹ˆ๋‹ค).:

  • ๋ฐ”์ด๋„ˆ๋ฆฌ ํ˜•ํƒœ๋กœ ๋ฐฐํฌ;
  • ์†Œ์Šค ํ˜•ํƒœ๋กœ ๋ฐฐํฌ;
  • Copyleft ์˜๋ฌด๋ฅผ ๋ฐœ์ƒ์‹œํ‚ฌ ์ˆ˜ ์žˆ๋Š” ๋‹ค๋ฅธ ์˜คํ”ˆ์†Œ์Šค์™€ ํ†ตํ•ฉ;
  • ์ˆ˜์ •ํ•œ ์˜คํ”ˆ์†Œ์Šค๋ฅผ ํฌํ•จ;
  • ๊ณต๊ธ‰ ๋Œ€์ƒ ์†Œํ”„ํŠธ์›จ์–ด ๋‚ด์—์„œ ์ƒํ˜ธ ์ž‘์šฉํ•˜๋Š” ๋‹ค๋ฅธ ์ปดํฌ๋„ŒํŠธ์™€ ํ˜ธํ™˜๋˜์ง€ ์•Š๋Š” ๋ผ์ด์„ ์Šค ํ•˜์˜ ์˜คํ”ˆ์†Œ์Šค ๋˜๋Š” ๊ธฐํƒ€ ์†Œํ”„ํŠธ์›จ์–ด๋ฅผ ํฌํ•จ; - ์ €์ž‘์ž ํ‘œ์‹œ ์š”๊ฑด์ด ์žˆ๋Š” ์˜คํ”ˆ์†Œ์Šค๋ฅผ ํฌํ•จ.

์ž…์ฆ ์ž๋ฃŒ:

3.2.1 ๊ณต๊ธ‰ ๋Œ€์ƒ ์†Œํ”„ํŠธ์›จ์–ด์˜ ์˜คํ”ˆ์†Œ์Šค ์ปดํฌ๋„ŒํŠธ์— ๋Œ€ํ•ด ์ผ๋ฐ˜์ ์ธ ์˜คํ”ˆ์†Œ์Šค ๋ผ์ด์„ ์Šค ์‚ฌ์šฉ ์‚ฌ๋ก€๋ฅผ ์ฒ˜๋ฆฌํ•˜๊ธฐ ์œ„ํ•œ ๋ฌธ์„œํ™”๋œ ์ ˆ์ฐจ.


3.2 License Compliance

The Program must be capable of managing common Open Source license use cases encountered by Software Staff for Supplied Software, which may include the following use cases (note that the list is neither exhaustive, nor may all of the use cases apply):

  • distributed in binary form;
  • distributed in source form;
  • integrated with other Open Source such that it may trigger copyleft obligations;
  • contains modified Open Source;
  • contains Open Source or other software under an incompatible license interacting with other components within the Supplied Software; and/or - contains Open Source with attribution requirements.

Verification Material(s):

A documented procedure for handling the common Open Source license use cases for the Open Source components of the Supplied Software.

์˜คํ”ˆ์†Œ์Šค ๋ผ์ด์„ ์Šค๋ฅผ ์ œ๋Œ€๋กœ ์ค€์ˆ˜ํ•˜๊ธฐ ์œ„ํ•ด์„œ๋Š” ์˜คํ”ˆ์†Œ์Šค ๋ผ์ด์„ ์Šค ๋ณ„๋กœ ์š”๊ตฌํ•˜๋Š” ์‚ฌํ•ญ์— ๋Œ€ํ•ด ์ •ํ™•ํžˆ ์•Œ๊ณ  ์žˆ์–ด์•ผ ํ•œ๋‹ค. ๊ฐœ๋ณ„ ์†Œํ”„ํŠธ์›จ์–ด ๊ฐœ๋ฐœ์ž๊ฐ€ ์ด๋ฅผ ์ผ์ผ์ด ํŒŒ์•…ํ•˜๋Š” ๊ฒƒ์€ ์–ด๋ ต๊ธฐ ๋•Œ๋ฌธ์— ์˜คํ”ˆ์†Œ์Šค ์ฑ…์ž„์ž๋Š” ์ž์ฃผ ์‚ฌ์šฉ๋˜๋Š” ์˜คํ”ˆ์†Œ์Šค ๋ผ์ด์„ ์Šค ๋“ค์— ๋Œ€ํ•ด ์ผ๋ฐ˜์ ์ธ ์‚ฌ์šฉ ์‚ฌ๋ก€๋ณ„ ์š”๊ตฌ์‚ฌํ•ญ/์ฃผ์˜์‚ฌํ•ญ์„ ์ •๋ฆฌํ•˜์—ฌ ํšŒ์‚ฌ ๋‚ด๋ถ€์— ๊ณต์œ ํ•˜๋Š” ๊ฒƒ์ด ์ข‹๋‹ค. ์˜คํ”ˆ์†Œ์Šค ์ฑ…์ž„์ž๋Š” ์ž์ฃผ ์‚ฌ์šฉ๋˜๋Š” ์˜คํ”ˆ์†Œ์Šค ๋ผ์ด์„ ์Šค๋ณ„๋กœ ์ผ๋ฐ˜์ ์ธ ์‚ฌ์šฉ ์‚ฌ๋ก€์— ๋Œ€ํ•œ ์˜๋ฌด ์š”์•ฝ ์ž๋ฃŒ๋ฅผ ์ œ๊ณตํ•œ๋‹ค. ์˜คํ”ˆ์†Œ์Šค ๋ผ์ด์„ ์Šค์— ๋Œ€ํ•œ ์ผ๋ฐ˜์ ์ธ ๊ฐ€์ด๋“œ์™€ ๋ผ์ด์„ ์Šค ์˜๋ฌด ์š”์•ฝ ์ž๋ฃŒ๋Š” NIPA์—์„œ ์ œ๊ณตํ•˜๋Š”โ€œ๊ณต๊ฐœSW ๋ผ์ด์„ ์Šค ๊ฐ€์ด๋“œโ€๋ฅผ ์ฐธ๊ณ ํ•  ์ˆ˜ ์žˆ๋‹ค. (https://www.oss.kr/oss_license)

[๋ถ€๋ก 2] ์˜คํ”ˆ์†Œ์Šค ์ปดํ”Œ๋ผ์ด์–ธ์Šค ํ”„๋กœ์„ธ์Šค (์˜ˆ์‹œ)์˜ ์˜คํ”ˆ์†Œ์Šค ์ปดํ”Œ๋ผ์ด์–ธ์Šค ํ”„๋กœ์„ธ์Šค์˜ ์‹๋ณ„, ๊ฒ€์‚ฌ, ๋ฌธ์ œํ•ด๊ฒฐ, ๋ฆฌ๋ทฐ, ์Šน์ธ ๋‹จ๊ณ„๋ฅผ ํ†ตํ•ด ๊ณต๊ธ‰ ๋Œ€์ƒ ์†Œํ”„ํŠธ์›จ์–ด์˜ ์˜คํ”ˆ์†Œ์Šค ์ปดํฌ๋„ŒํŠธ์— ๋Œ€ํ•ด ์ผ๋ฐ˜์ ์ธ ์˜คํ”ˆ์†Œ์Šค ๋ผ์ด์„ ์Šค ์‚ฌ์šฉ ์‚ฌ๋ก€๋ฅผ ์ฒ˜๋ฆฌํ•  ์ˆ˜ ์žˆ๋‹ค.

์‹๋ณ„ ๋ฐ ๊ฒ€์‚ฌ ๋‹จ๊ณ„์—์„œ๋Š” ์†Œ์Šค์ฝ”๋“œ ์Šค์บ” ๋„๊ตฌ๋ฅผ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋‹ค. ์†Œ์Šค์ฝ”๋“œ ์Šค์บ” ๋„๊ตฌ๋Š” ๋ฌด๋ฃŒ๋กœ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋Š” ์˜คํ”ˆ์†Œ์Šค ๊ธฐ๋ฐ˜ ๋„๊ตฌ๋ถ€ํ„ฐ ์ƒ์šฉ ๋„๊ตฌ๊นŒ์ง€ ๋‹ค์–‘ํ•˜๊ฒŒ ์žˆ๋‹ค. ๊ฐ ๋„๊ตฌ๋“ค์€ ํŠน์žฅ์  ๋“ค์ด ์žˆ์ง€๋งŒ ์–ด๋–ค ํ•˜๋‚˜๋„ ๋ชจ๋“  ๋ฌธ์ œ๋ฅผ ํ•ด๊ฒฐํ•  ์ˆ˜ ์žˆ๋Š” ์™„๋ฒฝํ•œ ๊ธฐ๋Šฅ์„ ์ œ๊ณตํ•˜์ง€ ์•Š๋Š”๋‹ค. ๋”ฐ๋ผ์„œ ๊ธฐ์—…์€ ์ œํ’ˆ์˜ ํŠน์„ฑ๊ณผ ์š”๊ตฌ์‚ฌํ•ญ์— ๋งž๋Š” ์ ํ•ฉํ•œ ๋„๊ตฌ๋ฅผ ์„ ํƒํ•ด์•ผ ํ•œ๋‹ค. ๋งŽ์€ ๊ธฐ์—…๋“ค์ด ์ด๋Ÿฌํ•œ ์ž๋™ํ™”๋œ ์†Œ์Šค ์ฝ”๋“œ ์Šค์บ” ๋„๊ตฌ์™€ ์ˆ˜๋™ ๊ฒ€ํ† ๋ฅผ ๋ณ‘ํ–‰ํ•˜์—ฌ ์ด์šฉํ•œ๋‹ค. Linux Foundation์˜ FOSSology Project๋Š” ์˜คํ”ˆ์†Œ์Šค๋กœ ๊ณต๊ฐœ๋œ ์†Œ์Šค ์ฝ”๋“œ ์Šค์บ” ๋„๊ตฌ๋กœ์„œ ๊ธฐ์—…๋“ค์ด ์†์‰ฝ๊ฒŒ ๋ฌด๋ฃŒ๋กœ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋‹ค. ์‚ฌ์šฉ ๋ฐฉ๋ฒ•์€ [๋ถ€๋ก 03] ์˜คํ”ˆ์†Œ์Šค๋„๊ตฌ (FOSSology, SW360)์„ ์ฐธ๊ณ ํ•  ์ˆ˜ ์žˆ๋‹ค.

2.4 - 4. ์ปดํ”Œ๋ผ์ด์–ธ์Šค ๊ฒฐ๊ณผ๋ฌผ ์ƒ์„ฑ ๋ฐ ์ „๋‹ฌ

OpenChain Specification 2.0


4.1 ์ปดํ”Œ๋ผ์ด์–ธ์Šค ๊ฒฐ๊ณผ๋ฌผ

๊ณต๊ธ‰ ๋Œ€์ƒ ์†Œํ”„ํŠธ์›จ์–ด์— ๋Œ€ํ•œ ์ปดํ”Œ๋ผ์ด์–ธ์Šค ๊ฒฐ๊ณผ๋ฌผ ์„ธํŠธ๋ฅผ ์ƒ์„ฑํ•˜๋Š” ํ”„๋กœ์„ธ์Šค๊ฐ€์กด์žฌํ•œ๋‹ค.

์ž…์ฆ ์ž๋ฃŒ:

4.1.1 ์‹๋ณ„๋œ ๋ผ์ด์„ ์Šค์—์„œ ์š”๊ตฌํ•˜๋Š” ๋Œ€๋กœ ์ปดํ”Œ๋ผ์ด์–ธ์Šค ๊ฒฐ๊ณผ๋ฌผ์„ ์ค€๋น„ํ•˜๊ณ  ๊ณต๊ธ‰ ๋Œ€์ƒ ์†Œํ”„ํŠธ์›จ์–ด์™€ ํ•จ๊ป˜ ๋ฐฐํฌํ•˜๊ธฐ ์œ„ํ•œ ํ”„๋กœ์„ธ์Šค๋ฅผ ์„ค๋ช…ํ•˜๋Š” ๋ฌธ์„œํ™”๋œ ์ ˆ์ฐจ.
4.1.2 ๊ณต๊ธ‰ ๋Œ€์ƒ ์†Œํ”„ํŠธ์›จ์–ด์˜ ์ปดํ”Œ๋ผ์ด์–ธ์Šค ๊ฒฐ๊ณผ๋ฌผ ์‚ฌ๋ณธ์„ ๋ณด๊ด€ํ•˜๊ธฐ ์œ„ํ•œ ๋ฌธ์„œํ™”๋œ ์ ˆ์ฐจ - ๋ณด๊ด€ ํŒŒ์ผ์€ ๊ณต๊ธ‰ ๋Œ€์ƒ ์†Œํ”„ํŠธ์›จ์–ด์˜ ๋งˆ์ง€๋ง‰ ์ œ๊ณต ์ดํ›„ ์ ์ ˆํ•œ ๊ธฐ๊ฐ„(ํ˜น์€ ์‹๋ณ„๋œ ๋ผ์ด์„ ์Šค๊ฐ€ ์š”๊ตฌํ•˜๋Š” ๊ธฐ๊ฐ„ (๋‘˜ ์ค‘ ๋” ๊ธด ์‹œ๊ฐ„)) ๋™์•ˆ ๋ณด๊ด€๋˜์–ด์•ผ ํ•œ๋‹ค. ์ ˆ์ฐจ๊ฐ€ ์˜ฌ๋ฐ”๋ฅด๊ฒŒ ์ง€์ผœ์กŒ์Œ์„ ์ž…์ฆํ•˜๋Š” ๊ธฐ๋ก์ด ์กด์žฌํ•œ๋‹ค.


4.1 Compliance Artifacts

A process exists for creating the set of Compliance Artifacts for the Supplied Software.

Verification Materials(s):

4.1.1 A documented procedure that describes the process under which the Compliance Artifacts are prepared and distributed with the Supplied Software as required by the Identified Licenses.
4.1.2 A documented procedure for archiving copies of the Compliance Artifacts of the Supplied Software - where the archive is planned to exist for a reasonable period of time since the last offer of the Supplied Software; or as required by the Identified Licenses (whichever is longer). Records exist that demonstrate the procedure has been properly followed.

3.1์žฅ์—์„œ ์˜คํ”ˆ์†Œ์Šค ์ปดํ”Œ๋ผ์ด์–ธ์Šค ํ™œ๋™์˜ ๊ฐ€์žฅ ๊ธฐ๋ณธ์€ ๊ณต๊ธ‰ ๋Œ€์ƒ ์†Œํ”„ํŠธ์›จ์–ด์— ํฌํ•จ๋œ ์˜คํ”ˆ์†Œ์Šค ํ˜„ํ™ฉ์„ ํŒŒ์•…ํ•˜๋Š” ๊ฒƒ์ด๋ผ๊ณ  ํ•˜์˜€๋‹ค. ์ด๋Š” ๋ฐ”๋กœ ์˜คํ”ˆ์†Œ์Šค ์ปดํ”Œ๋ผ์ด์–ธ์Šค์˜ ํ•ต์‹ฌ์ธ ์˜คํ”ˆ์†Œ์Šค ๋ผ์ด์„ ์Šค์˜ ์˜๋ฌด๋ฅผ ํŒŒ์•…ํ•˜์—ฌ ์š”๊ฑด๋“ค์„ ์ถฉ์กฑํ•˜๊ธฐ ์œ„ํ•ด์„œ์ด๋‹ค. ์ฆ‰, ๊ณต๊ธ‰ ๋Œ€์ƒ ์†Œํ”„ํŠธ์›จ์–ด์— ํฌํ•จ๋œ ๊ฒƒ์œผ๋กœ ์‹๋ณ„ํ•œ ์˜คํ”ˆ์†Œ์Šค์— ๋Œ€ํ•œ ์ปดํ”Œ๋ผ์ด์–ธ์Šค ๊ฒฐ๊ณผ๋ฌผ ์„ธํŠธ๋ฅผ ์ƒ์„ฑํ•˜๋Š” ํ”„๋กœ์„ธ์Šค๊ฐ€ ๊ตฌ์ถ•๋˜์–ด์•ผ ํ•œ๋‹ค.

์ปดํ”Œ๋ผ์ด์–ธ์Šค ๊ฒฐ๊ณผ๋ฌผ์€ ํฌ๊ฒŒ ๋‘๊ฐ€์ง€๋กœ ๊ตฌ๋ถ„๋œ๋‹ค.

  1. ์˜คํ”ˆ์†Œ์Šค ๊ณ ์ง€๋ฌธ : ์˜คํ”ˆ์†Œ์Šค ๋ผ์ด์„ ์Šค ์ „๋ฌธ๊ณผ Copyright ์ •๋ณด ์ œ๊ณต์„ ์œ„ํ•œ ๋ฌธ์„œ
  2. ๊ณต๊ฐœํ•  ์†Œ์Šค์ฝ”๋“œ ํŒจํ‚ค์ง€ : GPL, LGPL ๋“ฑ ์†Œ์Šค ์ฝ”๋“œ ์ œ๊ณต์„ ์š”๊ตฌํ•˜๋Š” ์˜คํ”ˆ์†Œ์Šค ๋ผ์ด์„ ์Šค ์˜๋ฌด ์ดํ–‰์„ ์œ„ํ•ด ๊ณต๊ฐœํ•  ์†Œ์Šค์ฝ”๋“œ๋ฅผ ์ทจํ•ฉํ•œ ํŒจํ‚ค์ง€

์ปดํ”Œ๋ผ์ด์–ธ์Šค ๊ฒฐ๊ณผ๋ฌผ์€ ๊ณต๊ธ‰ ๋Œ€์ƒ ์†Œํ”„ํŠธ์›จ์–ด๋ฅผ ๋ฐฐํฌํ•  ๋•Œ ํ•จ๊ป˜ ์ œ๊ณตํ•ด์•ผ ํ•œ๋‹ค.โ€œ[๋ถ€๋ก 02] ์˜คํ”ˆ์†Œ์Šค ์ปดํ”Œ๋ผ์ด์–ธ์Šค ํ”„๋กœ์„ธ์Šค(์˜ˆ์‹œ)โ€์˜ ๊ณ ์ง€, ํ™•์ธ, ๋ฐฐํฌ ๋‹จ๊ณ„๋ฅผ ํ†ตํ•ด ์ปดํ”Œ๋ผ์ด์–ธ์Šค ๊ฒฐ๊ณผ๋ฌผ์„ ์ƒ์„ฑํ•˜์—ฌ ๋ฐฐํฌํ•œ๋‹ค.

๊ณต๊ธ‰ ๋Œ€์ƒ ์†Œํ”„ํŠธ์›จ์–ด๋ฅผ ๋ฐฐํฌ ์‹œ, ๊ณต๊ฐœํ•  ์†Œ์Šค์ฝ”๋“œ ํŒจํ‚ค์ง€๋ฅผ ๋™๋ด‰ํ•˜๋Š” ๊ฒƒ์ด ๊ณค๋ž€ํ•  ๊ฒฝ์šฐ, ์ตœ์†Œ 3๋…„๊ฐ„ ์†Œ์Šค์ฝ”๋“œ๋ฅผ ์ œ๊ณตํ•˜๊ฒ ๋‹ค๋Š” ์„œ๋ฉด ์•ฝ์ •์„œ(Written Offer)๋ฅผ ์ œ๊ณตํ•˜๋Š” ๊ฒƒ์œผ๋กœ ๋Œ€์‹ ํ•  ์ˆ˜ ์žˆ๋‹ค. ์ผ๋ฐ˜์ ์œผ๋กœ ์„œ๋ฉด ์•ฝ์ •์„œ๋Š” ์ œํ’ˆ์˜ ์‚ฌ์šฉ์ž ๋งค๋‰ด์–ผ์„ ํ†ตํ•ด ์ œ๊ณตํ•˜๋ฉฐ, ์˜ˆ์‹œ๋Š” ๋‹ค์Œ๊ณผ ๊ฐ™๋‹ค.

The software included in this product contains copyrighted software that is licensed under the GPL. A copy of that license is included in this document on page X. You may obtain the complete Corresponding Source code from us for a period of three years after our last shipment of this product, which will be no earlier than 2011-08- 01, by sending a money order or check for $5 to:

GPL Compliance Division
Our Company
Any Town, US 99999

Please writeโ€œsource for product Yโ€ in the memo line of your payment.
You may also find a copy of the source at http://www.example.com/sources/Y/.
This offer is valid to anyone in receipt of this information.

< https://www.softwarefreedom.org/resources/2014/SFLC-Guide_to_GPL_Compliance_2d_ed.html >

๋”ฐ๋ผ์„œ, ์ปดํ”Œ๋ผ์ด์–ธ์Šค ๊ฒฐ๊ณผ๋ฌผ์€ 3๋…„ ์ด์ƒ ๋ณด๊ด€ํ•ด์•ผ ํ•˜๋ฉฐ ์ด๋ฅผ ์œ„ํ•œ ํ”„๋กœ์„ธ์Šค๊ฐ€ ๊ตฌ์ถ•๋˜์–ด์•ผ ํ•œ๋‹ค. ๊ธฐ์—…๋“ค์€ ์ž์ฒด์ ์ธ ์›น์‚ฌ์ดํŠธ(์˜ˆ: http://opensource.lge.com/) ๊ตฌ์ถ•ํ•˜์—ฌ ์™ธ๋ถ€ ๊ณ ๊ฐ๋“ค์ด ๊ณต๊ธ‰ ๋Œ€์ƒ ์†Œํ”„ํŠธ์›จ์–ด์— ๋Œ€ํ•œ ์˜คํ”ˆ์†Œ์Šค ๊ณ ์ง€๋ฌธ๊ณผ ๊ณต๊ฐœํ•  ์†Œ์Šค์ฝ”๋“œ ํŒจํ‚ค์ง€๋ฅผ ์–ธ์ œ๋“ ์ง€ ๋‹ค์šด๋ฐ›์„ ์ˆ˜ ์žˆ๋„๋ก ํŽธ์˜๋ฅผ ์ œ๊ณตํ•œ๋‹ค.

2.5 - 5. ์˜คํ”ˆ์†Œ์Šค ์ปค๋ฎค๋‹ˆํ‹ฐ ์ฐธ์—ฌ์— ๋Œ€ํ•œ ์ดํ•ด

5.1 ๊ธฐ์—ฌ (Contributions)

OpenChain Specification 2.0


5.1 ๊ธฐ์—ฌ

์กฐ์ง์ด ์˜คํ”ˆ์†Œ์Šค ํ”„๋กœ์ ํŠธ์— ๊ธฐ์—ฌ๋ฅผ ๊ณ ๋ คํ•œ๋‹ค๋ฉด

  • ์˜คํ”ˆ์†Œ์Šค ํ”„๋กœ์ ํŠธ์— ๋Œ€ํ•œ ๊ธฐ์—ฌ๋ฅผ ๊ด€๋ฆฌํ•˜๋Š” ๋ฌธ์„œํ™”๋œ ์ •์ฑ…์ด ์กด์žฌํ•œ๋‹ค;
  • ์ด ์ •์ฑ…์ด ๋‚ด๋ถ€์ ์œผ๋กœ ์ „๋‹ฌ๋˜์–ด์•ผ ํ•œ๋‹ค;
  • ์ •์ฑ…์„ ๊ตฌํ˜„ํ•˜๋Š” ํ”„๋กœ์„ธ์Šค๊ฐ€ ์กด์žฌํ•œ๋‹ค.

์ž…์ฆ ์ž๋ฃŒ:

์กฐ์ง์ด ์˜คํ”ˆ์†Œ์Šค ํ”„๋กœ์ ํŠธ์— ๋Œ€ํ•œ ๊ธฐ์—ฌ๋ฅผ ํ—ˆ์šฉํ•œ๋‹ค๋ฉด ๋‹ค์Œ์ด ์กด์žฌํ•ด์•ผ ํ•œ๋‹ค:
5.1.1 ๋ฌธ์„œํ™”๋œ ์˜คํ”ˆ์†Œ์Šค ๊ธฐ์—ฌ ์ •์ฑ…;
5.1.2 ์˜คํ”ˆ์†Œ์Šค ๊ธฐ์—ฌ๋ฅผ ๊ด€๋ฆฌํ•˜๋Š” ๋ฌธ์„œํ™”๋œ ์ ˆ์ฐจ;
5.1.3 ๋ชจ๋“  ์†Œํ”„ํŠธ์›จ์–ด ๊ณต๊ธ‰ ๋‹ด๋‹น์ž๊ฐ€ ์˜คํ”ˆ์†Œ์Šค ๊ธฐ์—ฌ ์ •์ฑ…์˜ ์กด์žฌ๋ฅผ ์ธ์‹ํ•˜๋„๋ก ํ•˜๋Š” ๋ฌธ์„œํ™”๋œ ์ ˆ์ฐจ (๊ต์œก, ๋‚ด๋ถ€ ์œ„ํ‚ค, ๋˜๋Š” ๊ธฐํƒ€ ์‹ค์งˆ์ ์ธ ์˜์‚ฌ์†Œํ†ต ๋ฐฉ๋ฒ• ๋“ฑ).


5.1 Contributions

If an organization considers contributions to Open Source projects then

  • a written policy exists that governs contributions to Open Source projects;
  • the policy must be internally communicated; and
  • a process exists that implements the policy

Verification Materials(s):

If an organization permits contributions to Open Source projects then the following must exist:

  • 5.1.1 a documented Open Source contribution policy;
  • 5.1.2 a documented procedure that governs Open Source contributions; and
  • 5.1.3 a documented procedure that makes all Software Staff aware of the existence of the Open Source contribution policy (e.g., via training, internal wiki, or other practical communication method).

๊ธ€๋กœ๋ฒŒ ์†Œํ”„ํŠธ์›จ์–ด ๊ธฐ์—…๋“ค์€ ์˜คํ”ˆ์†Œ์Šค๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์ œํ’ˆ์„ ๋งŒ๋“ค๊ณ  ์„œ๋น„์Šค๋ฅผ ํ•˜๋Š” ๊ฒƒ ๋ฟ๋งŒ ์•„๋‹ˆ๋ผ ์˜คํ”ˆ์†Œ์Šค ํ”„๋กœ์ ํŠธ์— ๊ธฐ์—ฌํ•˜๋ฉฐ ์–ป์„ ์ˆ˜ ์žˆ๋Š” ์ „๋žต์  ๊ฐ€์น˜๋„ ์ค‘์š”ํ•˜๊ฒŒ ์—ฌ๊ธด๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ ์˜คํ”ˆ์†Œ์Šค ํ”„๋กœ์ ํŠธ ์ƒํƒœ๊ณ„์™€ ์ปค๋ฎค๋‹ˆํ‹ฐ ์šด์˜๋ฐฉ์‹์— ๋Œ€ํ•œ ์ถฉ๋ถ„ํ•œ ์ดํ•ด์™€ ์ „๋žต ์—†์ด ์ ‘๊ทผํ•œ๋‹ค๋ฉด ์˜ˆ๊ธฐ์น˜ ์•Š๊ฒŒ ํšŒ์‚ฌ์˜ ๋ช…์„ฑ์ด ์†์ƒ๋˜๊ณ  ๋ฒ•์  ์œ„ํ—˜์ด ๋ฐœ์ƒํ•  ์ˆ˜ ์žˆ๋‹ค. ๋”ฐ๋ผ์„œ ๊ธฐ์—…์€ ์˜คํ”ˆ์†Œ์Šค ํ”„๋กœ์ ํŠธ๋กœ์˜ ์ฐธ์—ฌ ๋ฐ ๊ธฐ์—ฌ๋ฅผ ์œ„ํ•œ ์ „๋žต๊ณผ ์ •์ฑ…์„ ๋งŒ๋“œ๋Š” ๊ฒƒ์ด ์ค‘์š”ํ•˜๋‹ค.

[๋ถ€๋ก 01] ์˜คํ”ˆ์†Œ์Šค ์ •์ฑ… for OpenChain 2.0(์˜ˆ์‹œ)์˜ 8์žฅ ์˜คํ”ˆ์†Œ์Šค ๊ธฐ์—ฌ ์ •์ฑ…์„ ์ฐธ๊ณ ํ•  ์ˆ˜ ์žˆ๋‹ค.

2.6 - 6. ์„ค๋ช…์„œ ์š”๊ฑด ์ค€์ˆ˜

6.1 ์ค€์ˆ˜ (Conformance)

OpenChain Specification 2.0


6.1 ์ค€์ˆ˜

ํ”„๋กœ๊ทธ๋žจ์ด OpenChain์„ ์ค€์ˆ˜ํ•œ๋‹ค๊ณ  ๊ฐ„์ฃผ๋˜๋ ค๋ฉด ์กฐ์ง์€ ํ”„๋กœ๊ทธ๋žจ์ด ์ด ์„ค๋ช…์„œ์— ์ œ์‹œ๋œ ์š”๊ฑด์„ ์ถฉ์กฑํ•˜๋Š”์ง€ ํ™•์ธํ•ด์•ผ ํ•œ๋‹ค.

์ž…์ฆ ์ž๋ฃŒ:

6.1.1 ์š”๊ฑด 1.4์— ๋ช…์‹œ๋œ ํ”„๋กœ๊ทธ๋žจ์„ ํ™•์ธํ•˜๋Š” ๋ฌธ์„œ๋Š” ์ด ์„ค๋ช…์„œ์˜ ๋ชจ๋“  ์š”๊ฑด์„ ์ถฉ์กฑํ•œ๋‹ค.

6.1 Conformance

In order for a Program to be deemed OpenChain Conformant, the organization must affirm that the program satisfies the requirements presented in this specification.

Verification Materials(s):

6.1.1 A document affirming the Program specified in requirement 1.4 satisfies all the requirements of this specification.

๊ธฐ์—…์ด OpenChain์„ ์ค€์ˆ˜ํ•˜๋Š” ์˜คํ”ˆ์†Œ์Šค ํ”„๋กœ๊ทธ๋žจ์„ ๊ฐ€์ง€๊ณ  ์žˆ๋‹ค๊ณ  ์„ ์–ธํ•œ๋‹ค๋Š” ๊ฒƒ์€ OpenChain Specification์˜ ๋ชจ๋“  ์š”๊ฑด์„ ์ถฉ์กฑํ•œ๋‹ค๋Š” ๊ฒƒ์ด๋‹ค. ์–ด๋А ํ•˜๋‚˜์˜ ์š”๊ฑด์ด๋ผ๋„ ์ถฉ์กฑํ•˜์ง€ ๋ชปํ•œ๋‹ค๋ฉด OpenChain์„ ์ค€์ˆ˜ํ•œ๋‹ค๊ณ  ํ•  ์ˆ˜ ์—†๋‹ค.

OpenChain Specification์˜ ๋ชจ๋“  ์š”๊ฑด์„ ์ถฉ์กฑํ•œ๋‹ค๋ฉด, [๋ถ€๋ก 01] ์˜คํ”ˆ์†Œ์Šค ์ •์ฑ… for OpenChain 2.0(์˜ˆ์‹œ)์˜ 9์žฅ์—์„œ์™€ ๊ฐ™์ด OpenChain์„ ์ถฉ์กฑํ•˜๊ณ  ์žˆ์Œ์„ ๋ฌธ์„œ์ƒ์— ๋ช…์‹œํ•  ์ˆ˜ ์žˆ๋‹ค.

6.2 ๊ธฐ๊ฐ„ (Duration)

OpenChain Specification 2.0


6.2 ๊ธฐ๊ฐ„

์ด ์„ค๋ช…์„œ ๋ฒ„์ „์— ๋Œ€ํ•œ OpenChain ์ค€์ˆ˜ ํ”„๋กœ๊ทธ๋žจ์€ ์ค€์ˆ˜ํ•œ๋‹ค๊ณ  ํ™•์ธ์ด ์ด๋ฃจ์–ด์ง„ ๋‚ ๋กœ๋ถ€ํ„ฐ 18๊ฐœ์›”๋™์•ˆ ์ง€์†๋œ๋‹ค. ์ค€์ˆ˜ ํ™•์ธ ๋“ฑ๋ก ์ ˆ์ฐจ๋Š” OpenChain ํ”„๋กœ์ ํŠธ์˜ ์›น์‚ฌ์ดํŠธ์—์„œ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค.

์ž…์ฆ ์ž๋ฃŒ:

6.2.1 ์ค€์ˆ˜ํ•œ๋‹ค๋Š” ํ™•์ธ์ด ์ด๋ฃจ์–ด์ง„ ํ›„ 18๊ฐœ์›” ์ด๋‚ด์— ์ด ์„ค๋ช…์„œ ๋ฒ„์ „(2.0)์˜ ๋ชจ๋“  ์š”๊ฑด์„ ์ถฉ์กฑํ•˜๋Š” ๊ฒƒ์„ ํ™•์ธํ•˜๋Š” ๋ฌธ์„œ.


6.2 Duration

A Program that is OpenChain Conformant with this version of the specification will last 18 months from the date conformance validation was obtained. The conformance validation registration procedure can be found on the OpenChain projectโ€™s website.

Verification Materials(s):

6.2.1 A document affirming the Program meets all the requirements of this version of the specification (version 2.0), within the past 18 months of obtaining conformance validation.

์˜คํ”ˆ์†Œ์Šค ํ”„๋กœ๊ทธ๋žจ์ด OpenChain์„ ์ค€์ˆ˜ํ•œ๋‹ค๊ณ  ์„ ์–ธํ•œ ์ดํ›„์—๋„ ๊ณ„์†ํ•ด์„œ ์ค€์ˆ˜ํ•˜๋Š” ํ™œ๋™์„ ์œ ์ง€ํ•˜๋Š” ๊ฒƒ์ด ์ค‘์š”ํ•˜๋‹ค. OpenChain Specification 2.0์˜ 6.2.1์กฐ์—์„œ๋Š” OpenChain์„ ์ค€์ˆ˜ํ•œ๋‹ค๊ณ  ์„ ์–ธํ•œ ์ดํ›„์—๋„ ์ตœ์†Œ 18๊ฐœ์›” ์ด์ƒ์€ ๋ณ€ํ•จ์—†์ด OpenChain Specification 2.0์˜ ๋ชจ๋“  ์š”๊ฑด์„ ์ค€์ˆ˜ํ•˜๊ณ  ์žˆ์–ด์•ผ ํ•จ์„ ์š”๊ตฌํ•œ๋‹ค.

๊ธฐ์—…์€ ์˜คํ”ˆ์†Œ์Šค ํ”„๋กœ๊ทธ๋žจ์ด OpenChain์„ ์ค€์ˆ˜ํ•จ์„ ์„ ์–ธํ•œ ์ดํ›„ ์ ์–ด๋„ 18๊ฐœ์›” ์ด์ƒ ๊ณ„์†ํ•ด์„œ ์ค€์ˆ˜ํ•˜๋Š” ์ƒํƒœ๋ฅผ ์œ ์ง€ํ•˜์—ฌ์•ผ ํ•˜๋ฉฐ, ๊ทธ๋ ‡๊ฒŒ ํ•˜๊ณ  ์žˆ๋‹ค๋ฉด, [๋ถ€๋ก 01] ์˜คํ”ˆ์†Œ์Šค ์ •์ฑ… for OpenChain 2.0 (์˜ˆ์‹œ)์˜ 9์žฅ์—์„œ์™€ ๊ฐ™์ด OpenChain์„ 18๊ฐœ์›” ์ด์ƒ ๊ณ„์†ํ•˜์—ฌ ์ถฉ์กฑํ•˜๊ณ  ์žˆ์Œ์„ ๋ฌธ์„œ์ƒ์— ๋ช…์‹œํ•  ์ˆ˜ ์žˆ๋‹ค.

3 - ๋ถ€๋ก

3.1 - 1. ์ƒ˜ํ”Œ ์˜คํ”ˆ์†Œ์Šค ์ •์ฑ… for OpenChain 2.1

OOํšŒ์‚ฌ ์˜คํ”ˆ์†Œ์Šค ์ •์ฑ…

1. ๋ชฉ์ 

์ด ์ •์ฑ…์€ ์˜คํ”ˆ์†Œ์Šค๋ฅผ ์‚ฌ์šฉํ•˜๋Š” ์กฐ์ง ์ „์ฒด๊ฐ€ ์˜คํ”ˆ์†Œ์Šค ์ปดํ”Œ๋ผ์ด์–ธ์Šค ํ™œ๋™์„ ์ˆ˜ํ–‰ํ•˜๋„๋ก ์ˆ˜๋ฆฝ๋˜์—ˆ๋‹ค. ๋˜ํ•œ ์ด ์ •์ฑ…์€ ์ง์›๋“ค์ด ์˜คํ”ˆ์†Œ์Šค์˜ ๊ฐ€์น˜๋ฅผ ์ดํ•ดํ•˜๊ฒŒ ํ•˜๊ณ , ์˜คํ”ˆ์†Œ์Šค ์ปค๋ฎค๋‹ˆํ‹ฐ์— ๊ธฐ์—ฌํ•˜๊ธฐ ์œ„ํ•œ ๋ฐฉ๋ฒ•์„ ์ œ๊ณตํ•œ๋‹ค.

<OOํšŒ์‚ฌ>์˜ ์ง์›์€ ์ด ์ •์ฑ…์˜ ๊ทผ๊ฑฐ์™€ ๋‚ด์šฉ์„ ์ดํ•ดํ•˜๊ณ  ํ•„์š”ํ•œ ํ™œ๋™์„ ์ถฉ์‹คํžˆ ์ˆ˜ํ–‰ํ•จ์œผ๋กœ์จ ์ •์ฑ…์˜ ํšจ๊ณผ ๋ฐ ํšŒ์‚ฌ์˜ ์ปดํ”Œ๋ผ์ด์–ธ์Šค ์ˆ˜์ค€ ํ–ฅ์ƒ์— ๊ธฐ์—ฌํ•œ๋‹ค.

์ด ์ •์ฑ…์„ ์ค€์ˆ˜ํ•˜๋Š” ๊ฒƒ์€ ์ค‘์š”ํ•˜๋‹ค. ์ค€์ˆ˜ํ•˜์ง€ ์•Š์„ ๊ฒฝ์šฐ ๋‹ค์Œ๊ณผ ๊ฐ™์€ ์ƒํ™ฉ์„ ์ดˆ๋ž˜ํ•  ์ˆ˜ ์žˆ๋‹ค.

  • ์‚ฌ์šฉ ์ค‘์ธ ์ฝ”๋“œ์— ๋Œ€ํ•œ ์ €์ž‘๊ถŒ ๋˜๋Š” ๊ธฐํƒ€ ์ง€์‹์žฌ์‚ฐ๊ถŒ ๋ณด์œ ์ž์˜ ๋ฒ•์  ํด๋ ˆ์ž„
  • ๊ณ ๊ฐ์œผ๋กœ๋ถ€ํ„ฐ์˜ ํด๋ ˆ์ž„
  • ํšŒ์‚ฌ ๋…์  ์ฝ”๋“œ์˜ ์˜๋„์น˜ ์•Š์€ ๊ณต๊ฐœ
  • ๋ผ์ด์„ ์Šค ์˜๋ฌด ์œ„๋ฐ˜์œผ๋กœ ์ธํ•œ ๋ฒŒ๊ธˆ ๋ถ€๊ณผ
  • ํ‰ํŒ ์†์‹ค
  • ์ˆ˜์ต ์†์‹ค
  • ๊ณต๊ธ‰์—…์ฒด ๋ฐ ๊ณ ๊ฐ๊ณผ์˜ ๊ณ„์•ฝ ์œ„๋ฐ˜

์ด๋Ÿฌํ•œ ์ด์œ ๋กœ ํšŒ์‚ฌ๋Š” ์ฝ”๋“œ ์นจํ•ด๋ฅผ ์‹ฌ๊ฐํ•˜๊ฒŒ ๊ฐ„์ฃผํ•˜๋ฉฐ, ์ฝ”๋“œ๋ฅผ ์นจํ•ดํ•˜๋Š” ๊ฐœ์ธ์€ ํšŒ์‚ฌ์˜ ์ง•๊ณ„ ์ ˆ์ฐจ์— ์ฒ˜ํ•ด์งˆ ์ˆ˜ ์žˆ๋‹ค.

2. ์ ์šฉ

์ด ์˜คํ”ˆ์†Œ์Šค ์ •์ฑ…์€ [ํšŒ์‚ฌ๊ฐ€ ์™ธ๋ถ€๋กœ ์ œ๊ณตํ•˜๊ฑฐ๋‚˜ ๋ฐฐํฌํ•˜๋Š” ๋ชจ๋“  ์ œํ’ˆ]์— ์ ์šฉ๋œ๋‹ค. ์˜คํ”ˆ์†Œ์Šค๋ฅผ ๋‚ด๋ถ€ ์‚ฌ์šฉ ๋ชฉ์ ์œผ๋กœ๋งŒ ์‚ฌ์šฉํ•˜๋Š” ๊ฒƒ์€ ์ด ์ •์ฑ…์˜ ๋ฒ”์œ„์— ํฌํ•จ๋˜์ง€ ์•Š๋Š”๋‹ค.

๋˜ํ•œ ์ด ์ •์ฑ…์€ <OOํšŒ์‚ฌ>์˜ ์ง์›์ด ์˜คํ”ˆ์†Œ์Šค ํ”„๋กœ์ ํŠธ์— ๊ธฐ์—ฌํ•˜๊ฑฐ๋‚˜ <OOํšŒ์‚ฌ>์˜ ์ฝ”๋“œ๋ฅผ ์˜คํ”ˆ์†Œ์Šค๋กœ ๊ณต๊ฐœํ• ๋•Œ ์ ์šฉํ•œ๋‹ค.

<OOํšŒ์‚ฌ>์˜ ์˜คํ”ˆ์†Œ์Šค ์ •์ฑ…์€ [LINK]์—์„œ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค.

3. ์šฉ์–ด

โ€œ์˜คํ”ˆ์†Œ์Šคโ€ - Open Source Initiative(OpenSource.org)์—์„œ ๋ฐœํ‘œํ•œ Open Source Definition ํ˜น์€ Free Software Foundation์—์„œ ๋ฐœํ‘œํ•œ Free Software Definition์„ ์ถฉ์กฑํ•˜๋Š” ๋ผ์ด์„ ์Šค, ํ˜น์€ ์œ ์‚ฌํ•œ ๋ผ์ด์„ ์Šค๊ฐ€ ํ•˜๋‚˜ ์ด์ƒ ์ ์šฉ๋œ ์†Œํ”„ํŠธ์›จ์–ด.

“๊ณต๊ธ‰ ๋Œ€์ƒ ์†Œํ”„ํŠธ์›จ์–ด” - ํšŒ์‚ฌ๊ฐ€ ์ œ3์ž (๋‹ค๋ฅธ ์กฐ์ง ๋˜๋Š” ๊ฐœ์ธ)์—๊ฒŒ ๋ฐฐํฌํ•˜๋Š” ์†Œํ”„ํŠธ์›จ์–ด

4. ์—ญํ• , ์ฑ…์ž„ ๋ฐ ์—ญ๋Ÿ‰

์ด ์ •์ฑ…์˜ ํšจ๊ณผ์ ์ธ ์ˆ˜ํ–‰์„ ๋ณด์žฅํ•˜๊ธฐ ์œ„ํ•ด ๋‹ค์Œ๊ณผ ๊ฐ™์ด ํ•„์š”ํ•œ ์—ญํ•  ๋ฐ ์ฑ…์ž„๊ณผ ๊ฐ ์—ญํ• ์˜ ๋‹ด๋‹น์ž๊ฐ€ ๊ฐ–์ถ”์–ด์•ผ ํ•  ์—ญ๋Ÿ‰์„ ์ •์˜ํ•œ๋‹ค.

<OOํšŒ์‚ฌ>์˜ ์†Œํ”„ํŠธ์›จ์–ด ๊ฐœ๋ฐœ ๋ฐ ๋ฐฐํฌ๋ฅผ ๋‹ด๋‹นํ•˜๋Š” ์ตœ๊ณ  ์ž„์›์€ ๊ฐ ์—ญํ•  ๋ฐ ์ฑ…์ž„์„ ์œ„ํ•œ ๋‹ด๋‹น์ž๊ฐ€ ์ง€์ •๋˜๊ณ , ์—ญํ• ์„ ์ˆ˜ํ–‰ํ•  ์ ์ ˆํ•œ ์ž๊ธˆ๊ณผ ์‹œ๊ฐ„์ด ํ• ๋‹น๋˜๋„๋ก ๋ณด์žฅํ•ด์•ผ ํ•œ๋‹ค.

๊ฐ ์—ญํ• ์˜ ๋‹ด๋‹น์ž๋Š” ์ž์‹ ์˜ ์—ญํ• ์— ๋Œ€ํ•ด ์ ์ ˆํ•˜๊ฒŒ ์ง€์›์ด ๋˜์ง€ ์•Š๋Š”๋‹ค๋ฉด ๋ฐ˜๋“œ์‹œ ์˜คํ”ˆ์†Œ์Šค ์ฑ…์ž„์ž๋ฅผ ํ†ตํ•ด ๋ฌธ์ œ๋ฅผ ํ•ด๊ฒฐํ•ด์•ผ ํ•œ๋‹ค. ์ ์ ˆํ•˜๊ฒŒ ํ•ด๊ฒฐ๋˜์ง€ ์•Š๋Š”๋‹ค๋ฉด, ์˜คํ”ˆ์†Œ์Šค ์šด์˜์œ„์›ํšŒ๋ฅผ ํ†ตํ•ด ๋ฌธ์ œ๋ฅผ ์ œ๊ธฐํ•  ์ˆ˜ ์žˆ๋‹ค.

๊ฐ€) ์˜คํ”ˆ์†Œ์Šค ์ฑ…์ž„์ž

์˜คํ”ˆ์†Œ์Šค ์ฑ…์ž„์ž๋Š” ์˜คํ”ˆ์†Œ์Šค๊ฐ€ ์‚ฌ์šฉ๋œ <OOํšŒ์‚ฌ> ์ œํ’ˆ์˜ ์ปดํ”Œ๋ผ์ด์–ธ์Šค๋ฅผ ๋ณด์žฅํ•  ์ฑ…์ž„๊ณผ ํ•จ๊ป˜ ๋‹ค์Œ ์‚ฌํ•ญ์— ๋Œ€ํ•œ ์ฑ…์ž„์ด ์žˆ๋‹ค.

  • ์˜คํ”ˆ์†Œ์Šค ์ •์ฑ…์„ ๊ฒ€ํ† , ๊ฐœ์„  ๋ฐ ์ „ํŒŒํ•œ๋‹ค.
  • ํšจ์œจ์ ์ธ ์˜คํ”ˆ์†Œ์Šค ์ •์ฑ… ์ˆ˜ํ–‰์„ ์œ„ํ•ด ํšŒ์‚ฌ ๋‚ด๋ถ€์˜ ์—ญํ•  ๋ฐ ์ฑ…์ž„์„ ๊ฒ€ํ† ํ•˜๊ณ  ํ• ๋‹นํ•œ๋‹ค.
  • ์˜คํ”ˆ์†Œ์Šค ์ปดํ”Œ๋ผ์ด์–ธ์Šค ๊ด€๋ จ ์ด์Šˆ์— ๋Œ€ํ•œ ๊ต์œก๊ณผ ํ‰๊ฐ€๋ฅผ ๊ฒ€ํ† ํ•˜๊ณ  ๊ตฌํ˜„ํ•œ๋‹ค.
  • ์˜คํ”ˆ์†Œ์Šค ์šด์˜์œ„์›ํšŒ์˜ ์˜์žฅ์„ ๋งก์•„์„œ ํ™œ๋™์„ ์ง€ํœ˜ํ•œ๋‹ค.
  • ์†Œํ”„ํŠธ์›จ์–ด ๊ฐœ๋ฐœํŒ€์ด ์˜คํ”ˆ์†Œ์Šค ์ •์ฑ…๊ณผ ํ”„๋กœ์„ธ์Šค๋ฅผ ์ดํ•ดํ•˜๊ณ  ์ค€์ˆ˜ํ•˜๋„๋ก ์•ˆ๋‚ดํ•˜๋Š” ์—ญํ• ์„ ํ•˜๊ณ , ํ•„์š”ํ•  ๊ฒฝ์šฐ ๊ฒฝ์˜์ง„์—๊ฒŒ ๋ฌธ์ œ๋ฅผ ์ œ๊ธฐํ•œ๋‹ค.
  • ์™ธ๋ถ€๋กœ๋ถ€ํ„ฐ์˜ ์˜คํ”ˆ์†Œ์Šค ์‚ฌ์šฉ ๋ฐ ์ปดํ”Œ๋ผ์ด์–ธ์Šค์— ๋Œ€ํ•œ ๋ฌธ์˜์— ๋‹ต๋ณ€ํ•œ๋‹ค.

์˜คํ”ˆ์†Œ์Šค ์ฑ…์ž„์ž๋Š” ์—…๋ฌด ์ˆ˜ํ–‰์„ ์œ„ํ•ด ์˜คํ”ˆ์†Œ์Šค ๊ด€๋ จ IP ๋ฆฌ์Šคํฌ, ๊ฐœ๋ฐœ ํ”„๋กœ์„ธ์Šค๋ฅผ ์ดํ•ดํ•˜๊ณ , ์ปค๋ฎค๋‹ˆ์ผ€์ด์…˜ ์Šคํ‚ฌ์— ๋Œ€ํ•œ ์—ญ๋Ÿ‰์„ ๊ฐ–์ถฐ์•ผ ํ•œ๋‹ค.

2020๋…„ 1์›” ํ˜„์žฌ OOOํŒ€์˜ OOO๊ฐ€ ์˜คํ”ˆ์†Œ์Šค ์ฑ…์ž„์ž ์—ญํ• ์„ ๋‹ด๋‹นํ•œ๋‹ค.

๋‚˜) ์˜คํ”ˆ์†Œ์Šค ์„ผํ„ฐ

์˜คํ”ˆ์†Œ์Šค ์„ผํ„ฐ๋Š” ์˜คํ”ˆ์†Œ์Šค ์ปดํ”Œ๋ผ์ด์–ธ์Šค๋ฅผ ์œ„ํ•œ ์ „๋ฌธ ์„ผํ„ฐ์ด๋ฉฐ, ์ปดํ”Œ๋ผ์ด์–ธ์Šค๋ฅผ ํšจ๊ณผ์ ์œผ๋กœ๋‹ฌ์„ฑํ•˜๊ธฐ์œ„ํ•œํ”„๋กœ์„ธ์Šค๋ฅผ์ •์˜ํ•œ๋‹ค. ์˜คํ”ˆ์†Œ์Šค์ฑ…์ž„์ž๊ฐ€๋ฆฌ๋”์—ญํ• ์„์ˆ˜ํ–‰ ํ•˜๊ณ , ์„ผํ„ฐ์˜ ๊ตฌ์„ฑ์›๋“ค์€ ์˜คํ”ˆ์†Œ์Šค ์ฑ…์ž„์ž๊ฐ€ ์›ํ™œํ•˜๊ฒŒ ์ฑ…์ž„์„ ์ˆ˜ํ–‰ํ•  ์ˆ˜ ์žˆ๋„๋ก ๋•๋Š” ์—ญํ• ์„ ๋งก๋Š”๋‹ค. ์˜คํ”ˆ์†Œ์Šค ์„ผํ„ฐ๋Š” ๋‹ค์Œ๊ณผ ๊ฐ™์€ ์—ญํ• ์„ ์ˆ˜ํ–‰ํ•œ๋‹ค.

  • ์ปดํ”Œ๋ผ์ด์–ธ์Šค ์‹ค๋ฌด ๊ต์œก์„ ๊ฐœ๋ฐœ ๋ฐ ์ œ๊ณตํ•œ๋‹ค.
  • ์ปดํ”Œ๋ผ์ด์–ธ์Šค ๋„๊ตฌ๋ฅผ ์„ ํƒ / ๊ฐœ๋ฐœ ๋ฐ ๋ฐฐํฌํ•œ๋‹ค.
  • ์ฝ”๋“œ ๊ฒ€์‚ฌ ๋ฐ ์ž๋™ ์Šค์บ”์„ ์ˆ˜ํ–‰ํ•˜์—ฌ <OOํšŒ์‚ฌ> ์ œํ’ˆ ๋‚ด ์˜คํ”ˆ์†Œ์Šค ํฌํ•จ ์—ฌ๋ถ€๋ฅผ ์‹๋ณ„ํ•œ๋‹ค.
  • ์˜คํ”ˆ์†Œ์Šค ์‚ฌ์šฉ ์š”์ฒญ์„ ๊ฒ€ํ† ํ•˜๊ณ  ์Šน์ธํ•œ๋‹ค.
  • ์˜คํ”ˆ์†Œ์Šค ์‚ฌ์šฉ ๋ชฉ๋ก์— ๊ด€ํ•œ ๊ธฐ๋ก์„ ์œ ์ง€ํ•œ๋‹ค.
  • ์˜คํ”ˆ์†Œ์Šค ๊ณ ์ง€ ๋ฐ ์†Œ์Šค์ฝ”๋“œ ๊ณต๊ฐœ๋ฅผ ์œ„ํ•œ ์›น ์‚ฌ์ดํŠธ๋ฅผ ๊ฐœ๋ฐœํ•˜๊ณ  ์œ ์ง€ ๊ด€๋ฆฌํ•œ๋‹ค.

๋‹ค) ์†Œํ”„ํŠธ์›จ์–ด ๊ฐœ๋ฐœํŒ€

์†Œํ”„ํŠธ์›จ์–ด ๊ฐœ๋ฐœํŒ€์€ ์†Œํ”„ํŠธ์›จ์–ด ๊ฐœ๋ฐœ์— ์‚ฌ์šฉํ•  ์˜คํ”ˆ์†Œ์Šค๋ฅผ ์‹๋ณ„ํ•˜๊ณ  ์˜คํ”ˆ์†Œ์Šค ์„ผํ„ฐ์— ์˜คํ”ˆ์†Œ์Šค ์‚ฌ์šฉ ์Šน์ธ ์š”์ฒญ์„ ์ œ์ถœํ•œ๋‹ค.

์†Œํ”„ํŠธ์›จ์–ด ๊ฐœ๋ฐœํŒ€์€ ์†Œํ”„ํŠธ์›จ์–ด ๊ฐœ๋ฐœ์— ์‚ฌ์šฉํ•œ ์˜คํ”ˆ์†Œ์Šค์— ์ ์šฉ๋˜๋Š” ์˜คํ”ˆ์†Œ์Šค ๋ผ์ด์„ ์Šค์˜ ์˜๋ฌด๋ฅผ ์ดํ–‰ํ•  ์ฑ…์ž„์ด ์žˆ๋‹ค.

์†Œํ”„ํŠธ์›จ์–ด ๊ฐœ๋ฐœํŒ€์€ ์˜คํ”ˆ์†Œ์Šค ์ •์ฑ… ๋ฐ ํ”„๋กœ์„ธ์Šค์™€ ์†Œํ”„ํŠธ์›จ์–ด ์•„ํ‚คํ…์ณ๋ฅผ ์ดํ•ดํ•œ๋‹ค.

๋ผ) ๋ฒ•๋ฌดํŒ€

๋ฒ•๋ฌดํŒ€์€ ์˜คํ”ˆ์†Œ์Šค ๋ผ์ด์„ ์Šค์™€ ์˜๋ฌด๋ฅผ ํ•ด์„ํ•œ๋‹ค. ์ด๋Ÿฌํ•œ ์˜๋ฌด๋ฅผ ์ดํ–‰ํ•˜๊ธฐ ์œ„ํ•œ ๊ฐ€์ด๋“œ๋ฅผ ์†Œํ”„ํŠธ์›จ์–ด ๊ฐœ๋ฐœํŒ€์— ์ œ๊ณตํ•œ๋‹ค. ํ˜ธํ™˜๋˜์ง€ ์•Š๋Š” ์˜คํ”ˆ์†Œ์Šค ๋ผ์ด์„ ์Šค๋กœ ์ธํ•œ ์ถฉ๋Œ์„ ํฌํ•จํ•˜์—ฌ ๋ผ์ด์„ ์Šค ๋ฐ ์ง€์‹์žฌ์‚ฐ๊ถŒ ๋ฌธ์ œ์— ๋Œ€ํ•ด ์ž๋ฌธ์„ ์ œ๊ณตํ•œ๋‹ค. ํ•„์š”ํ•  ๊ฒฝ์šฐ ์˜คํ”ˆ์†Œ์Šค ์‚ฌ์šฉ ๊ฒ€ํ†  ๋ฐ ์Šน์ธ ๊ฒฐ์ •์— ์ฐธ์—ฌํ•œ๋‹ค.

์˜คํ”ˆ์†Œ์Šค ํ”„๋กœ์ ํŠธ๋กœ์˜ ๊ธฐ์—ฌ๋ฅผ ์œ„ํ•œ ๊ฒ€ํ†  ์š”์ฒญ์— ์˜๊ฒฌ์„ ์ œ๊ณตํ•œ๋‹ค.

5. ๊ต์œก ๋ฐ ํ‰๊ฐ€

์†Œํ”„ํŠธ์›จ์–ด ๋ฐฐํฌ์— ๊ด€์—ฌํ•˜๋Š” <OOํšŒ์‚ฌ>์˜ ๋ชจ๋“  ์ง์›์€ ๊ต์œก ๋ฐ ํ‰๊ฐ€๋ฅผ ํ†ตํ•ด ์˜คํ”ˆ์†Œ์Šค ์ •์ฑ…์„ ์ˆ™์ง€ํ•œ๋‹ค.

์ด ์ •์ฑ…์„ ์ˆ˜ํ–‰ํ•˜๋Š” ๋ชจ๋“  ๋Œ€์ƒ์ž๋Š” ์ž์‹ ์˜ ์—ญํ• ์— ํ•„์š”ํ•œ ์—ญ๋Ÿ‰์„ ๋‹ค๋ฃจ๋Š” ์ตœ์†Œํ•œ์˜ ๊ธฐ๋ณธ ๊ต์œก์„ ์ˆ˜๊ฐ•ํ•˜๊ณ  ํ‰๊ฐ€๋ฅผ ๋ฐ›๋Š”๋‹ค.

๊ต์œก ๋ฐ ํ‰๊ฐ€ ํ”„๋กœ๊ทธ๋žจ์€ <OOํšŒ์‚ฌ> ์˜คํ”ˆ์†Œ์Šค์ •์ฑ…์˜ ๋ชฉํ‘œ, ์ปดํ”Œ๋ผ์ด์–ธ์Šค ์ˆ˜์ค€ ํ–ฅ์ƒ์— ๊ธฐ์—ฌ ํ•˜๊ธฐ ์œ„ํ•œ ์ฐธ์—ฌ์ž์˜ ์—ญํ•  ๋ฐ ์ปดํ”Œ๋ผ์ด์–ธ์Šค ๋ฏธ์ค€์ˆ˜ ์‹œ ํšŒ์‚ฌ ๋ฐ ๊ฐœ์ธ์— ๋ฏธ์น˜๋Š” ์˜ํ–ฅ ๋“ฑ์— ๋Œ€ํ•ด ๋‹ค๋ฃฌ๋‹ค.

ํ‰๊ฐ€ ๊ธฐ๋ก์€ ์ตœ์†Œ 3๋…„๋™์•ˆ ์œ ์ง€ํ•œ๋‹ค.

6. ์˜คํ”ˆ์†Œ์Šค ์‚ฌ์šฉ ์ •์ฑ…

์˜คํ”ˆ์†Œ์Šค๋ฅผ ์‚ฌ์šฉํ•˜๊ธฐ ์œ„ํ•ด์„œ๋Š” ๋จผ์ € ์˜คํ”ˆ์†Œ์Šค ๋ผ์ด์„ ์Šค๊ฐ€ ๋ฌด์—‡์ธ์ง€ ์‹๋ณ„ํ•˜๊ณ , ๋ผ์ด์„ ์Šค๊ฐ€ ์š”๊ตฌํ•˜๋Š” ์˜๋ฌด ์‚ฌํ•ญ์„ ๊ฒ€ํ† ํ•˜๊ณ  ํ™•์ธํ•œ๋‹ค. ๊ทธ๋ ‡๊ฒŒ ๊ณต๊ธ‰ ๋Œ€์ƒ ์†Œํ”„ํŠธ์›จ์–ด์— ํฌํ•จ๋œ ์˜คํ”ˆ์†Œ์Šค์™€ ๋ผ์ด์„ ์Šค ์˜๋ฌด์‚ฌํ•ญ์„ ์‹๋ณ„ํ•˜๊ณ , ์†Œํ”„ํŠธ์›จ์–ด๋ฅผ ๋ฐฐํฌ ์‹œ ๋ผ์ด์„ ์Šค ์˜๋ฌด์‚ฌํ•ญ์„ ์ค€์ˆ˜ํ•˜๊ธฐ ์œ„ํ•œ ํ™œ๋™์„ ํ•œ๋‹ค.

์ด๋ฅผ ํšจ๊ณผ์ ์œผ๋กœ ์ˆ˜ํ–‰ํ•˜๊ธฐ ์œ„ํ•ด <OOํšŒ์‚ฌ> ์˜คํ”ˆ์†Œ์Šค ์ปดํ”Œ๋ผ์ด์–ธ์Šค ํ”„๋กœ์„ธ์Šค๋ฅผ ์ค€์ˆ˜ํ•œ๋‹ค.

์˜คํ”ˆ์†Œ์Šค ๋ผ์ด์„ ์Šค ์ค€์ˆ˜๋ฅผ ์œ„ํ•œ ๊ณผ์ •์—์„œ ์˜๋ฌธ์‚ฌํ•ญ์ด ์žˆ๋Š” ๊ฒฝ์šฐ [์˜คํ”ˆ์†Œ์Šค ์ฑ…์ž„์ž]๋Š” ๋ฒ•๋ฌดํŒ€์—๊ฒŒ ๋ฌธ์˜ ํ•  ์ˆ˜ ์žˆ๋‹ค.

์˜คํ”ˆ์†Œ์Šค ์‚ฌ์šฉ ๊ฒฐ์ • ๊ฒฐ๊ณผ ๋ฐ ๊ด€๋ จ ๊ทผ๊ฑฐ๋Š” ์˜คํ”ˆ์†Œ์Šค ์ด์Šˆ ์ถ”์  ์‹œ์Šคํ…œ์— ๊ธฐ๋กํ•œ๋‹ค.

7. ์™ธ๋ถ€ ๋ฌธ์˜ ๋Œ€์‘ ์ •์ฑ…

<OOํšŒ์‚ฌ>์—์„œ ๋ฐฐํฌํ•œ ์†Œํ”„ํŠธ์›จ์–ด์— ๋Œ€ํ•ด ์™ธ๋ถ€์—์„œ ์˜คํ”ˆ์†Œ์Šค ๊ด€๋ จํ•œ ๋ฌธ์˜ ๋ฐ ์š”์ฒญ์„ ํ•  ์ˆ˜ ์žˆ๋„๋ก ๊ณต๊ฐœ๋œ ์—ฐ๋ฝ์ฒ˜๋ฅผ ์ œ๊ณตํ•œ๋‹ค. ์ด๋ฅผ ์œ„ํ•ด ์†Œํ”„ํŠธ์›จ์–ด ๋ฐฐํฌ ์‹œ ์˜คํ”ˆ์†Œ์Šค ์„ผํ„ฐ์˜ ์ด๋ฉ”์ผ ์ฃผ์†Œ๋ฅผ ์ œ๊ณตํ•˜๊ณ ,
Linux Foundation์˜ Open Compliance Directory (https://compliance. linuxfoundation.org/ references/open-compliance-directory/)์— <OOํšŒ์‚ฌ>์˜ ์—ฐ๋ฝ์ฒ˜๋ฅผ ๋“ฑ๋กํ•œ๋‹ค.

์™ธ๋ถ€๋กœ๋ถ€ํ„ฐ ์˜คํ”ˆ์†Œ์Šค ๊ด€๋ จ ๋ฌธ์˜๋ฅผ ๋ฐ›์€ ์‚ฌ๋žŒ์€ ๋ˆ„๊ตฌ๋‚˜ ์˜คํ”ˆ์†Œ์Šค ์ฑ…์ž„์ž์—๊ฒŒ ๋ฌธ์˜ํ•œ๋‹ค. ์˜คํ”ˆ์†Œ์Šค ์ฑ…์ž„์ž๋Š” ๋ฌธ์˜๋ฅผ ์ฒ˜๋ฆฌํ•˜๊ณ  ํšŒ์‚ฌ ๋‚ด ์ ์ ˆํ•œ ๊ฐœ์ธ ๋˜๋Š” ์กฐ์ง์— ํ• ๋‹นํ•œ๋‹ค. ์˜คํ”ˆ์†Œ์Šค ์ฑ…์ž„์ž๋Š” ๋ฌธ์˜๋ฅผ ํ• ๋‹นํ•˜๊ณ  ์ฒ˜๋ฆฌํ•˜๋Š” ๊ฒƒ์— ๋Œ€ํ•œ ์ „๋ฐ˜์ ์ธ ์ฑ…์ž„์ด ์žˆ๋‹ค.

<OOํšŒ์‚ฌ>์—์„œ ๋ฐฐํฌํ•œ ์†Œํ”„ํŠธ์›จ์–ด์— ๋Œ€ํ•ด ์™ธ๋ถ€๋กœ๋ถ€ํ„ฐ ์ปดํ”Œ๋ผ์ด์–ธ์Šค ๋ฏธ์ค€์ˆ˜ ์ด์Šˆ๊ฐ€ ์ œ๊ธฐ๋  ๊ฒฝ์šฐ, ์˜คํ”ˆ์†Œ์Šค ์ฑ…์ž„์ž๋Š” ๋‹ค์Œ๊ณผ ๊ฐ™์ด ์ฒ˜๋ฆฌํ•œ๋‹ค.

  1. ์งˆ์˜ ์ ‘์ˆ˜ ์Šน์ธ ๋ฐ ์ ์ ˆํ•œ ํ•ด๊ฒฐ ์‹œ๊ฐ„์„ ๋ช…์‹œํ•œ๋‹ค.
  2. ์งˆ์˜๊ฐ€ ์ง„์งœ ๋ฌธ์ œ์ธ ๊ฒƒ์ธ์ง€๋ฅผ ํ™•์ธํ•œ๋‹ค. (์•„๋‹ˆ๋ผ๋ฉด ์˜์—…์ผ ๊ธฐ์ค€ 3์ผ ์ด๋‚ด์— ์งˆ์˜์ž์—๊ฒŒ ์‘๋‹ตํ•œ๋‹ค.)
  3. ์ด์Šˆ๊ฐ€ ์ง„์งœ ๋ฌธ์ œ๋ผ๋ฉด, 3์ผ ์ด๋‚ด์— ์ ์ ˆํ•œ ๋Œ€์‘ ๋ฐฉ๋ฒ•์„ ๊ฒฐ์ •ํ•˜๊ณ , ์งˆ์˜์ž์—๊ฒŒ ๋Œ€์‘ ๊ณ„ํš์— ๋Œ€ํ•ด ์‘๋‹ตํ•œ๋‹ค.
  4. ๊ฒฐ์ •ํ•œ ๋ฐฉ๋ฒ•์— ๋”ฐ๋ผ 30์ผ ์ด๋‚ด์— ๋Œ€์‘ํ•˜๊ณ , ์งˆ์˜์ž์—๊ฒŒ ๋ฌธ์ œ๊ฐ€ ํ•ด๊ฒฐ๋˜์—ˆ์Œ์„ ์•Œ๋ฆฐ๋‹ค.
  5. ์ด์ƒ์˜ ์‚ฌํ•ญ์„ ์˜คํ”ˆ์†Œ์Šค ์ด์Šˆ ์ถ”์ ์‹œ์Šคํ…œ์— ๊ธฐ๋กํ•œ๋‹ค.

8. ์˜คํ”ˆ์†Œ์Šค ๊ธฐ์—ฌ ์ •์ฑ…

<OOํšŒ์‚ฌ>๋Š” ์˜คํ”ˆ์†Œ์Šค์—์„œ์˜ ๋น„์ฆˆ๋‹ˆ์Šค ๊ฐ€์น˜ ์ฐฝ์ถœ์„ ์œ„ํ•ด ์™ธ๋ถ€ ์˜คํ”ˆ์†Œ์Šค ํ”„๋กœ์ ๋กœ์˜ ์ฐธ์—ฌ์™€ ๊ธฐ์—ฌ๋ฅผ ๊ถŒ์žฅํ•œ๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ ์˜๋„ํ•˜์ง€ ์•Š์€ ์ง€์‹ ์žฌ์‚ฐ์˜ ๋…ธ์ถœ ํ˜น์€ ์นจํ•ด๋ฅผ ์ฃผ์˜ํ•ด์•ผ ํ•œ๋‹ค.

ํšŒ์‚ฌ์˜ ์—…๋ฌด์™€ ๊ด€๋ จ์ด ์žˆ๋Š” ์˜คํ”ˆ์†Œ์Šค ํ”„๋กœ์ ํŠธ์— ๊ธฐ์—ฌํ•˜๊ธฐ ์œ„ํ•ด์„œ๋Š” ๋จผ์ € SW๊ฐœ๋ฐœํŒ€ ๋ฆฌ๋”์—๊ฒŒ ์Šน์ธ์„ ๋ฐ›์•„์•ผ ํ•œ๋‹ค.

๊ทธ๋ฆฌ๊ณ  ์˜คํ”ˆ์†Œ์Šค ํ”„๋กœ์ ํŠธ์˜ ์˜คํ”ˆ์†Œ์Šค ๋ผ์ด์„ ์Šค์™€ ํŠนํ—ˆ ์กฐ๊ฑด์„ ๊ฒ€ํ† ํ•œ๋‹ค. ๋˜ํ•œ ๊ธฐ์—ฌ ํ•˜๊ณ ์ž ํ•˜๋Š” ์˜คํ”ˆ์†Œ์Šค ํ”„๋กœ์ ํŠธ๊ฐ€ ์š”๊ตฌํ•˜๋Š” DCO (Developer Certificate of Origin), CLA (Contributor License Agreement)๋“ฑ์˜ ๋ฌธ์„œ ์„œ๋ช…์— ๋Œ€ํ•ด ๊ฒ€ํ† ํ•ด์•ผ ํ•œ๋‹ค. ํ•„์š”ํ•  ๊ฒฝ์šฐ ๋ฒ•๋ฌดํŒ€์— ๊ฒ€ํ† ๋ฅผ ์š”์ฒญํ•  ์ˆ˜ ์žˆ๋‹ค.

9. OpenChain ์ค€์ˆ˜

<OOํšŒ์‚ฌ>๋Š” ์†Œํ”„ํŠธ์›จ์–ด ๊ณต๊ธ‰๋ง์—์„œ์˜ ์˜คํ”ˆ์†Œ์Šค ์ปดํ”Œ๋ผ์ด์–ธ์Šค ์ˆ˜์ค€ ํ–ฅ์ƒ์„ ์œ„ํ•ด Linux Foundation์˜ OpenChain ํ”„๋กœ์ ํŠธ์˜ ์ •์‹ ์„ ์ง€์ง€ํ•˜๋ฉฐ ์ ๊ทน์ ์œผ๋กœ ์ฐธ์—ฌํ•œ๋‹ค. <OOํšŒ์‚ฌ>์˜ ์˜คํ”ˆ์†Œ์Šค ์ •์ฑ…์€ OpenChain Specification 2.0์„ ์ค€์ˆ˜ํ•˜๋„๋ก ์„ค๊ณ„๋˜์—ˆ๋‹ค.

<OOํšŒ์‚ฌ>๋Š” <OOํšŒ์‚ฌ>์˜ ์˜คํ”ˆ์†Œ์Šค ์ •์ฑ…์„ ํฌํ•จํ•˜๋Š” ์˜คํ”ˆ์†Œ์Šค ํ”„๋กœ๊ทธ๋žจ์ด OpenChain Specification 2.0์˜ ๋ชจ๋“  ์š”๊ฑด์„ ์ค€์ˆ˜ํ•˜๊ณ  ์žˆ์Œ์„ ํ™•์•ฝํ•œ๋‹ค.

<OOํšŒ์‚ฌ>๋Š” <OOํšŒ์‚ฌ>์˜ ์˜คํ”ˆ์†Œ์Šค ์ •์ฑ…์„ ํฌํ•จํ•˜๋Š” ์˜คํ”ˆ์†Œ์Šค ํ”„๋กœ๊ทธ๋žจ์ด OpenChain Specification 2.0์˜ ๋ชจ๋“  ์š”๊ฑด์„ ์ค€์ˆ˜ํ•˜๊ณ  ์žˆ์Œ์„ ํ™•์•ฝํ•œ ์ดํ›„ 18๊ฐœ์›” ๋™์•ˆ ์—ฌ์ „ํžˆ ๋ชจ๋“  ์š”๊ฑด์„ ์ค€์ˆ˜ํ•˜๊ธฐ ์œ„ํ•œ ํ™œ๋™์„ ์ˆ˜ํ–‰ํ•˜๊ณ  ์žˆ์Œ์„ ํ™•์•ฝํ•œ๋‹ค.

3.2 - 2. ์˜คํ”ˆ์†Œ์Šค ์ปดํ”Œ๋ผ์ด์–ธ์Šค ํ”„๋กœ์„ธ์Šค (template)

์˜คํ”ˆ์†Œ์Šค ์ปดํ”Œ๋ผ์ด์–ธ์Šค์˜ ์ฃผ์š” ๋‘๊ฐ€์ง€ ๋ชฉ์ ์€ ๋‹ค์Œ๊ณผ ๊ฐ™๋‹ค.

  1. ์˜๋ฌด ํŒŒ์•… : ๊ณต๊ธ‰ ๋Œ€์ƒ ์†Œํ”„ํŠธ์›จ์–ด๊ฐ€ ํฌํ•จํ•˜๊ณ  ์žˆ๋Š” ์˜คํ”ˆ์†Œ์Šค๋ฅผ ์‹๋ณ„ํ•˜๊ณ  ๊ฐ ์˜คํ”ˆ์†Œ์Šค ๋ผ์ด์„ ์Šค๊ฐ€ ์š”๊ตฌํ•˜๋Š” ์˜๋ฌด๋ฅผ ํŒŒ์•…ํ•œ๋‹ค.
  2. ์˜๋ฌด ์‚ฌํ•ญ ์ดํ–‰ : ์‹๋ณ„ํ•œ ์˜๋ฌด ์‚ฌํ•ญ์„ ์ดํ–‰ํ•œ๋‹ค.

์ด๋ฅผ ์œ„ํ•ด ๊ธฐ์—…์€ ๊ณต๊ธ‰ ๋Œ€์ƒ ์†Œํ”„ํŠธ์›จ์–ด๋ฅผ ๋ฐฐํฌํ•˜๋Š” ์‹œ์ ์— ์˜คํ”ˆ์†Œ์Šค ๋ผ์ด์„ ์Šค ์˜๋ฌด์‚ฌํ•ญ์„ ์ค€์ˆ˜ํ•  ์ˆ˜ ์žˆ๋„๋ก ์˜คํ”ˆ์†Œ์Šค ์ปดํ”Œ๋ผ์ด์–ธ์Šค ํ”„๋กœ์„ธ์Šค๋ฅผ ๊ตฌ์ถ•ํ•ด์•ผ ํ•œ๋‹ค. ์—ฌ๊ธฐ์„œ๋Š” ์ผ๋ฐ˜์ ์ธ ์˜คํ”ˆ์†Œ์Šค ์ปดํ”Œ๋ผ์ด์–ธ์Šค ํ”„๋กœ์„ธ์Šค์˜ ๊ตฌ์„ฑ์š”์†Œ์™€ ๊ฐ๊ฐ์˜ ๊ธฐ๋Šฅ ๋ฐ ์—ญํ• ์„ ํฌํ•จํ•˜๋Š” ํ”„๋กœ์„ธ์Šค(์˜ˆ์‹œ)๋ฅผ ์ œ์•ˆํ•œ๋‹ค.

<OO ํšŒ์‚ฌ> ์˜คํ”ˆ์†Œ์Šค ์ปดํ”Œ๋ผ์ด์–ธ์Šค ํ”„๋กœ์„ธ์Šค (์˜ˆ์‹œ)

<OO ํšŒ์‚ฌ>์˜ ์˜คํ”ˆ์†Œ์Šค ์ •์ฑ…์— ๊ทผ๊ฑฐํ•˜์—ฌ ์˜คํ”ˆ์†Œ์Šค๋ฅผ ์‚ฌ์šฉํ•˜๊ธฐ ์œ„ํ•ด์„œ๋Š” ๋จผ์ € ์˜คํ”ˆ์†Œ์Šค ๋ผ์ด์„ ์Šค๊ฐ€ ๋ฌด์—‡์ธ์ง€ ์‹๋ณ„ํ•˜๊ณ , ๋ผ์ด์„ ์Šค๊ฐ€ ์š”๊ตฌํ•˜๋Š” ์˜๋ฌด ์‚ฌํ•ญ์„ ๊ฒ€ํ† ํ•˜๊ณ  ํ™•์ธํ•ด์•ผ ํ•œ๋‹ค. ๊ทธ๋ ‡๊ฒŒ ๊ณต๊ธ‰ ๋Œ€์ƒ ์†Œํ”„ํŠธ์›จ์–ด์— ํฌํ•จ๋œ ์˜คํ”ˆ์†Œ์Šค์™€ ๋ผ์ด์„ ์Šค ์˜๋ฌด์‚ฌํ•ญ์„ ์‹๋ณ„ํ•˜๊ณ , ์†Œํ”„ํŠธ์›จ์–ด๋ฅผ ๋ฐฐํฌ ์‹œ ๋ผ์ด์„ ์Šค ์˜๋ฌด์‚ฌํ•ญ์„ ์ค€์ˆ˜ํ•˜๊ธฐ ์œ„ํ•œ ์˜คํ”ˆ์†Œ์Šค ์ปดํ”Œ๋ผ์ด์–ธ์Šค ํ™œ๋™์„ ํ•ด์•ผ ํ•œ๋‹ค.

<OOํšŒ์‚ฌ>์˜ ์˜คํ”ˆ์†Œ์Šค ์ปดํ”Œ๋ผ์ด์–ธ์Šค ํ”„๋กœ์„ธ์„œ๋Š” ๊ณต๊ธ‰ ๋Œ€์ƒ ์†Œํ”„ํŠธ์›จ์–ด์— ์‚ฌ์šฉ๋˜๋Š” ์˜คํ”ˆ์†Œ์Šค๋ฅผ ๊ด€๋ฆฌํ•˜๋Š” ์ผ๋ จ์˜ ๊ณผ์ •์„ ์ •์˜ํ•œ๋‹ค. ์ด ๊ณผ์ •์—๋Š” ๋‹ค์Œ ์‚ฌํ•ญ์ด ํฌํ•จ๋œ๋‹ค.

  1. ๊ณต๊ธ‰ ๋Œ€์ƒ ์†Œํ”„ํŠธ์›จ์–ด์— ์‚ฌ์šฉ๋œ ๋ชจ๋“  ์˜คํ”ˆ์†Œ์Šค ์‹๋ณ„
  2. ์‹๋ณ„ํ•œ ์˜คํ”ˆ์†Œ์Šค์— ์˜ํ•ด ๋ฐœ์ƒํ•˜๋Š” ๋ชจ๋“  ์˜๋ฌด๋ฅผ ์‹๋ณ„ํ•˜๊ณ  ์ถ”์ 
  3. ๋ชจ๋“  ์˜๋ฌด๋ฅผ ์ถฉ์กฑํ•˜๊ธฐ ์œ„ํ•œ ํ™œ๋™

์ด๋ฅผ ํšจ๊ณผ์ ์œผ๋กœ ์ˆ˜ํ–‰ํ•˜๊ธฐ ์œ„ํ•ด <OOํšŒ์‚ฌ>์˜ ๋ชจ๋“œ ์†Œํ”„ํŠธ์›จ์–ด ๊ณต๊ธ‰๊ด€๋ฆฌ์ž๋Š” ๋‹ค์Œ 10๋‹จ๊ณ„๋ฅผ ์ˆ˜ํ–‰ํ•œ๋‹ค.

Step 1. ์˜คํ”ˆ์†Œ์Šค ์‹๋ณ„ (Identification of Open Source)

์˜คํ”ˆ์†Œ์Šค ์‹๋ณ„ ๋‹จ๊ณ„๋Š” ์˜คํ”ˆ์†Œ์Šค ์ปดํฌ๋„ŒํŠธ๋ฅผ ์‹๋ณ„ํ•˜๊ธฐ ์œ„ํ•œ ๊ฒ€ํ†  ๋‹จ๊ณ„์ด๋‹ค. ์ž์ฒด ๋…์  ์†Œํ”„ํŠธ์›จ์–ด์ธ์ง€, ์ œ3์ž ์†Œํ”„ํŠธ์›จ์–ด์ธ์ง€ ์—ฌ๋ถ€์— ๊ด€๊ณ„ ์—†์ด ๊ณต๊ธ‰ ๋Œ€์ƒ ์†Œํ”„ํŠธ์›จ์–ด์— ํฌํ•จ๋œ ์˜คํ”ˆ์†Œ์Šค๋ฅผ ๋ชจ๋‹ˆํ„ฐ๋งํ•œ๋‹ค. ์˜คํ”ˆ์†Œ์Šค ์‹๋ณ„ ๋ฐฉ๋ฒ•์€ ๋‹ค์Œ๊ณผ ๊ฐ™๋‹ค.

  • ์˜คํ”ˆ์†Œ์Šค ์‚ฌ์šฉ ์š”์ฒญ ์ ‘์ˆ˜ : SW๊ฐœ๋ฐœ์ž๋Š” ํŠน์ • ์ œํ’ˆ์— ์˜คํ”ˆ์†Œ์Šค๋ฅผ ์‚ฌ์šฉํ•˜๊ณ ์ž ํ•จ์„ ์˜คํ”ˆ์†Œ์Šค ์ฑ…์ž„์ž ๋˜๋Š” ์˜คํ”ˆ์†Œ์Šค ์„ผํ„ฐ์— ์•Œ๋ฆฌ๊ณ , ๊ฒ€ํ†  ๋ฐ ์Šน์ธ์„ ์œ„ํ•œ ์˜คํ”ˆ์†Œ์Šค ํŒจํ‚ค์ง€์˜ ์šฉ๋„์— ๊ด€ํ•œ ์ •๋ณด๋ฅผ ์ œ๊ณตํ•œ๋‹ค.
  • ํšŒ์‚ฌ ๊ฐœ๋ฐœ ์†Œํ”„ํŠธ์›จ์–ด ๊ฒ€์‚ฌ (Auditing) : ๊ฐœ๋ฐœ์ž๊ฐ€ ์˜คํ”ˆ์†Œ์Šค์˜ ์†Œ์Šค์ฝ”๋“œ๋ฅผ ๋ณต์‚ฌํ•ด์„œ ๊ฐ€์ ธ์™€ ์†Œํ”„ํŠธ์›จ์–ด๋ฅผ ๊ฐœ๋ฐœํ•  ์ˆ˜ ์žˆ๊ธฐ ๋•Œ๋ฌธ์— ํšŒ์‚ฌ๊ฐ€ ๊ฐœ๋ฐœํ•œ ์†Œํ”„ํŠธ์›จ์–ด์— ๋Œ€ํ•ด์„œ๋„ ๊ฒ€์‚ฌ๋ฅผ ์ˆ˜ํ–‰ํ•œ๋‹ค.
  • ์ œ3์ž ์†Œํ”„ํŠธ์›จ์–ด ์‹ค์‚ฌ (Due diligence)
์‹๋ณ„ ๋‹จ๊ณ„ ์‹œ์ž‘ ์กฐ๊ฑด์‹๋ณ„ ๋‹จ๊ณ„ ๊ฒฐ๊ณผ
โ€ข ๊ฐœ๋ฐœ์ž๋กœ๋ถ€ํ„ฐ ํŠน์ • ์˜คํ”ˆ์†Œ์Šค ์‚ฌ์šฉ ์š”์ฒญ ์ ‘์ˆ˜
โ€ข ๊ฐœ๋ฐœ ํ”„๋กœ์„ธ์Šค ์ƒ ์†Œํ”„ํŠธ์›จ์–ด ๊ฒ€์‚ฌ ๋‹จ๊ณ„
โ€ข ์ œ3์ž ์†Œํ”„ํŠธ์›จ์–ด ์ž…์ˆ˜ ๋ฐ ๊ฐœ๋ฐœ์†Œํ”„ํŠธ์›จ์–ด๋กœ์˜ ํ†ตํ•ฉ
โ€ข ์˜คํ”ˆ์†Œ์Šค์— ๋Œ€ํ•œ ์ปดํ”Œ๋ผ์ด์–ธ์Šค ๊ธฐ๋ก ์ƒ์„ฑ (Jira ๋“ฑ ํ™œ์šฉ)
โ€ข ์†Œ์Šค์ฝ”๋“œ ์Šค์บ” ๋Œ€์ƒ ์„ ์ • ๋ฐ ์š”์ฒญ

Step 2. ์†Œ์Šค ์ฝ”๋“œ ๊ฒ€์‚ฌ (Auditing Source Code)

์†Œ์Šค ์ฝ”๋“œ ๊ฒ€์‚ฌ ๋‹จ๊ณ„์—์„œ๋Š” ์†Œ์Šค ์ฝ”๋“œ ๋ถ„์„ ๋„๊ตฌ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์†Œ์Šค ์ฝ”๋“œ๋ฅผ ์Šค์บ”ํ•˜์—ฌ ์˜คํ”ˆ์†Œ์Šค๋ฅผ ๋ฐœ๊ฒฌํ•œ๋‹ค. ์†Œ์Šค ์ฝ”๋“œ ์Šค์บ”๋„๊ตฌ๋Š” FOSSology๋ฅผ ์ด์šฉํ•œ๋‹ค. GPL-3.0 ๋“ฑ ์ •์ฑ…์ ์œผ๋กœ ์‚ฌ์šฉํ•  ์ˆ˜ ์—†๋Š” ์˜คํ”ˆ์†Œ์Šค ๋ผ์ด์„ ์Šค๊ฐ€ ์ ์šฉ๋œ ์˜คํ”ˆ์†Œ์Šค ํ˜น์€ ๋ผ์ด์„ ์Šค ์ถฉ๋Œ๋กœ ์–‘๋ฆฝํ•  ์ˆ˜ ์—†๋Š” ์˜คํ”ˆ์†Œ์Šค๊ฐ€ ๋ฐœ๊ฒฌ๋  ๊ฒฝ์šฐ ๋ฌธ์ œ๋กœ ์‹๋ณ„ํ•˜์—ฌ ๊ฐœ๋ฐœํŒ€์— ๋ณด์™„์„ ์š”์ฒญํ•œ๋‹ค.

์‹๋ณ„ ๋‹จ๊ณ„ ์‹œ์ž‘ ์กฐ๊ฑด์‹๋ณ„ ๋‹จ๊ณ„ ๊ฒฐ๊ณผ
โ€ข ๊ฐœ๋ฐœ์ž๋กœ๋ถ€ํ„ฐ ํŠน์ • ์˜คํ”ˆ์†Œ์Šค ์‚ฌ์šฉ ์š”์ฒญ ์ ‘์ˆ˜
โ€ข ๊ฐœ๋ฐœ ํ”„๋กœ์„ธ์Šค ์ƒ ์†Œํ”„ํŠธ์›จ์–ด ๊ฒ€์‚ฌ ๋‹จ๊ณ„
โ€ข ์ œ3์ž ์†Œํ”„ํŠธ์›จ์–ด ์ž…์ˆ˜ ๋ฐ ๊ฐœ๋ฐœ์†Œํ”„ํŠธ์›จ์–ด๋กœ์˜ ํ†ตํ•ฉ
โ€ข ์˜คํ”ˆ์†Œ์Šค์— ๋Œ€ํ•œ ์ปดํ”Œ๋ผ์ด์–ธ์Šค ๊ธฐ๋ก ์ƒ์„ฑ (Jira ๋“ฑ ํ™œ์šฉ)
โ€ข ์†Œ์Šค์ฝ”๋“œ ์Šค์บ” ๋Œ€์ƒ ์„ ์ • ๋ฐ ์š”์ฒญ

Step 3. ๋ฌธ์ œ ํ•ด๊ฒฐ (Resolving Issues)

์†Œ์Šค ์ฝ”๋“œ ๊ฒ€์‚ฌ ๋‹จ๊ณ„์—์„œ ์‹๋ณ„๋œ ๋ชจ๋“  ๋ฌธ์ œ๋ฅผ ํ•ด๊ฒฐํ•œ๋‹ค. ๋ฌธ์ œ ์‚ฌํ•ญ์€ Jira Ticket์œผ๋กœ ์ƒ์„ฑํ•˜์—ฌ ๊ฐœ๋ฐœํŒ€์— ํ• ๋‹น๋˜๊ณ , ์˜คํ”ˆ์†Œ์Šค ์ฑ…์ž„์ž๋Š” ๋ชจ๋“  ๋ฌธ์ œ๊ฐ€ ์ ์ ˆํ•˜๊ฒŒ ํ•ด๊ฒฐ๋˜์—ˆ๋Š”์ง€ ํ™•์ธํ•œ๋‹ค.

๋ฌธ์ œ ํ•ด๊ฒฐ ๋‹จ๊ณ„ ์‹œ์ž‘ ์กฐ๊ฑด๋ฌธ์ œ ํ•ด๊ฒฐ ๋‹จ๊ณ„ ๊ฒฐ
โ€ข ์†Œ์Šค ์ฝ”๋“œ ์Šค์บ” ์™„๋ฃŒ ๋ฐ ๊ฒฐ๊ณผ ์ƒ์„ฑ โ€ข ๋ฌธ์ œ ์‹๋ณ„โ€ข ์‹๋ณ„๋œ ๋ฌธ์ œ๋ฅผ ๋ชจ๋‘ ํ•ด๊ฒฐ

Step 4. ๊ฒ€ํ†  (Reviews)

์‹๋ณ„๋œ ๋ชจ๋“  ๋ฌธ์ œ๊ฐ€ ํ•ด๊ฒฐ๋˜๋ฉด ๊ฒ€ํ†  ๋‹จ๊ณ„๋กœ ์ด๋™ํ•œ๋‹ค. ๊ฒ€ํ†  ๋‹จ๊ณ„์˜ ์ ˆ์ฐจ๋Š” ๋‹ค์Œ๊ณผ ๊ฐ™๋‹ค.

  1. ์†Œํ”„ํŠธ์›จ์–ด PL : ์†Œํ”„ํŠธ์›จ์–ด์— ํฌํ•จ๋œ ์˜คํ”ˆ์†Œ์Šค์— ๋Œ€ํ•œ ์‚ฌ์šฉ ์Šน์ธ ์š”์ฒญ์„œ๋ฅผ ์ œ์ถœํ•œ๋‹ค.
  2. ์˜คํ”ˆ์†Œ์Šค ์ฑ…์ž„์ž : ์‚ฌ์šฉ ์Šน์ธ ์š”์ฒญ์„œ๋ฅผ ์ ‘์ˆ˜ํ•˜๋ฉด ๋ชจ๋“  ์ •๋ณด๊ฐ€ ๋ˆ„๋ฝ์—†์ด ํฌํ•จ ๋˜์—ˆ๋Š”์ง€๋ฅผ ํ™•์ธํ•˜๊ณ , Jira ticket์„ ์ƒ์„ฑํ•˜์—ฌ ๊ฒ€ํ†  ์ ˆ์ฐจ๋ฅผ ์ง„ํ–‰ํ•œ๋‹ค.
  3. ์†Œ์Šค์ฝ”๋“œ ๊ฒ€์‚ฌ ๋‹ด๋‹น์ž: Jira ticket์ด ์ƒ์„ฑ๋˜๋ฉด ์†Œ์Šค์ฝ”๋“œ ๊ฒ€์‚ฌ๋ฅผ ์ˆ˜ํ–‰ํ•˜์—ฌ ๋ฌธ์ œ๊ฐ€ ๋ชจ๋‘ ํ•ด๊ฒฐ๋˜์—ˆ๋Š”์ง€ ํ™•์ธํ•œ๋‹ค.
  4. ๋ฒ•๋ฌดํŒ€ : ๋ผ์ด์„ ์Šค ์ด์Šˆ๋ฅผ ๊ฒ€ํ† ํ•œ๋‹ค.
๊ฒ€ํ†  ๋‹จ๊ณ„ ์‹œ์ž‘ ์กฐ๊ฑด๊ฒ€ํ†  ๋‹จ๊ณ„ ๊ฒฐ๊ณผ
โ€ข ์‹๋ณ„๋œ ๋ชจ๋“  ๋ฌธ์ œ ํ•ด๊ฒฐโ€ข ์˜คํ”ˆ์†Œ์Šค ์ฑ…์ž„์ž, ์†Œ์Šค์ฝ”๋“œ ๊ฒ€์‚ฌ ๋‹ด๋‹น์ž, ๋ฒ•๋ฌดํŒ€ ๋“ฑ์˜ ๊ฒ€ํ† ๋ฅผ ์™„๋ฃŒํ•˜์—ฌ ์Šน์ธ ์ค€๋น„๊ฐ€ ๋œ ์ƒํƒœ

Step 5. ์Šน์ธ (Approval)

๊ฒ€ํ† ๊ฐ€ ์™„๋ฃŒ๋˜๋ฉด Jira ticket์€ ์Šน์ธ ๋‹จ๊ณ„๋กœ ์ด๋™ํ•œ๋‹ค. OSRB๋Š” ์˜คํ”ˆ์†Œ์Šค์˜ ์‚ฌ์šฉ์„ ์Šน์ธํ•˜๊ฑฐ๋‚˜ ๊ฑฐ์ ˆํ•œ๋‹ค. ๊ฑฐ์ ˆ์‹œ์—๋Š” ์ด์œ ์— ๋Œ€ํ•œ ์„ค๋ช…๊ณผ ์ˆ˜์ • ๋ฐฉ๋ฒ•์„ ์ œ์•ˆํ•œ๋‹ค. OSRB๊ฐ€ ์˜คํ”ˆ์†Œ์Šค ๊ตฌ์„ฑ์š”์†Œ์˜ ์‚ฌ์šฉ์„ ์Šน์ธํ•˜๋ฉด ๊ฐœ๋ฐœํŒ€์€ ๋ผ์ด์„ ์Šค ์˜๋ฌด๋ฅผ ์ดํ–‰ํ•˜๊ธฐ ์œ„ํ•œ ์ค€๋น„๋ฅผ ์‹œ์ž‘ํ•œ๋‹ค.

์Šน์ธ ๋‹จ๊ณ„ ์‹œ์ž‘ ์กฐ๊ฑด์Šน์ธ ๋‹จ๊ณ„ ๊ฒฐ๊ณผ
โ€ข ๊ฒ€ํ† ๊ฐ€ ์™„๋ฃŒ๋œ ์ƒํƒœโ€ข OSRB๋Š” ์˜คํ”ˆ์†Œ์Šค์˜ ์‚ฌ์šฉ์„ ์Šน์ธํ•˜๊ฑฐ๋‚˜ ๊ฑฐ์ ˆํ•จ
โ€ข ๊ฑฐ์ ˆ ์‹œ์—๋Š” ์ด์œ ์— ๋Œ€ํ•œ ์„ค๋ช…๊ณผ ์ˆ˜์ • ๋ฐฉ๋ฒ• ์ œ์•ˆ

Step 6. ๋“ฑ๋ก (Registration)

์‚ฌ์šฉ์ด ์Šน์ธ๋œ ์˜คํ”ˆ์†Œ์Šค ๊ตฌ์„ฑ์š”์†Œ๋Š” ์˜คํ”ˆ์†Œ์Šค ์‚ฌ์šฉ์„ ์ถ”์ ํ•˜๋Š” BOM (์†Œํ”„ํŠธ์›จ์–ด ์ธ๋ฒคํ† ๋ฆฌ)์— ์ถ”๊ฐ€ํ•œ๋‹ค. BOM์—๋Š” ์˜คํ”ˆ์†Œ์Šค ๊ตฌ์„ฑ์š”์†Œ ์ด๋ฆ„, ๋ฒ„์ „, ๊ด€๋ฆฌ ๋‹ด๋‹น์ž ์ด๋ฆ„, ์ด๋ฅผ ์‚ฌ์šฉํ•˜๋Š” ์ œํ’ˆ ์ด๋ฆ„, ์ œํ’ˆ ๋ฒ„์ „, ์ œํ’ˆ ๋ฆด๋ฆฌ์ฆˆ ๋ฒˆํ˜ธ ๋“ฑ์˜ ์ •๋ณด๋ฅผ ํฌํ•จํ•œ๋‹ค. BOM์„ ๊ด€๋ฆฌํ•˜๋Š” ๋„๊ตฌ๋Š” SW360์„ ์‚ฌ์šฉํ•œ๋‹ค.

๋“ฑ๋ก ๋‹จ๊ณ„ ์‹œ์ž‘ ์กฐ๊ฑด๋“ฑ๋ก ๋‹จ๊ณ„ ๊ฒฐ๊ณผ
โ€ข OSRB๊ฐ€ ์˜คํ”ˆ์†Œ์Šค ์‚ฌ์šฉ์„ ์Šน์ธโ€ข ์˜คํ”ˆ์†Œ์Šค ๊ตฌ์„ฑ์š”์†Œ๋ฅผ BOM์— ๋“ฑ๋ก

Step 7. ๊ณ ์ง€ (Notices)

์˜คํ”ˆ์†Œ์Šค๋ฅผ ์‚ฌ์šฉํ•  ๋•Œ ์ฃผ์š” ์˜๋ฌด ์ค‘ ํ•˜๋‚˜๋Š” ๊ณ ์ง€ ์˜๋ฌด์ด๋‹ค. ์ด๋ฅผ ์œ„ํ•ด ๋‹ค์Œ ์‚ฌํ•ญ์„ ์ˆ˜ํ–‰ ํ•œ๋‹ค.

  • ์ €์ž‘๊ถŒ, ๋ผ์ด์„ ์Šค ๊ณ ์ง€๋ฅผ ์ œ๊ณตํ•œ๋‹ค.
  • ๋ผ์ด์„ ์Šค ์‚ฌ๋ณธ์„ ์ œ๊ณตํ•œ๋‹ค.
  • (ํ•ด๋‹น๋˜๋Š” ๊ฒฝ์šฐ) ์†Œ์Šค ์ฝ”๋“œ ์‚ฌ๋ณธ์„ ์–ป์„ ์ˆ˜ ์žˆ๋Š” ๋ฐฉ๋ฒ•์„ ์ตœ์ข… ์‚ฌ์šฉ์ž์—๊ฒŒ ์•Œ๋ฆฐ๋‹ค.
๊ณ ์ง€ ๋‹จ๊ณ„ ์‹œ์ž‘ ์กฐ๊ฑด๊ณ ์ง€ ๋‹จ๊ณ„ ๊ฒฐ๊ณผ
์˜คํ”ˆ์†Œ์Šค๋ฅผ BOM์— ๋“ฑ๋ก์ €์ž‘๊ถŒ, ๋ผ์ด์„ ์Šค ๊ณ ์ง€๋ฅผ ์ค€๋น„ํ•˜๊ณ , ์ด๋ฅผ ์ œํ’ˆ์— ํฌํ•จ๋˜๋„๋ก ๊ด€๋ จ ๋ถ€์„œ๋กœ ์ „๋‹ฌ

์ด์™€ ๊ฐ™์€ ์‚ฌํ•ญ์„ ์ œํ’ˆ ๋ฐฐํฌ ์‹œ ํฌํ•จ์‹œํ‚ฌ ์ˆ˜ ์žˆ๋„๋ก ๊ด€๋ จ ๋ถ€์„œ์— ์ „๋‹ฌํ•œ๋‹ค. ํ™”๋ฉด์ด ์žˆ๋Š” ์ œํ’ˆ์ด๋ฉด ์‚ฌ์šฉ์ž๊ฐ€ ๋ฉ”๋‰ด > ์˜คํ”ˆ์†Œ์Šค ๊ณ ์ง€ ์ •๋ณด์—์„œ ์˜คํ”ˆ ์†Œ์Šค ๊ณ ์ง€ ๋‚ด์šฉ์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ๊ฒŒ ํ•œ๋‹ค. ์ œํ’ˆ์— ํ™”๋ฉด์ด ์—†์„ ๊ฒฝ์šฐ, ์‚ฌ์šฉ์ž ๋งค๋‰ด์–ผ์— ์˜คํ”ˆ์†Œ์Šค ๊ณ ์ง€ ๋‚ด์šฉ์„ ํฌํ•จ์‹œํ‚จ๋‹ค.

Step 8. ๋ฐฐํฌ ์ „ ํ™•์ธ (Pre-Distribution Verifications)

์ด ๋‹จ๊ณ„์—์„œ๋Š” ๋‹ค์Œ ์‚ฌํ•ญ์„ ๋ณด์žฅํ•˜๊ธฐ ์œ„ํ•œ ํ™•์ธ์„ ์ˆ˜ํ–‰ํ•œ๋‹ค.

  • ์˜คํ”ˆ์†Œ์Šค ๋ผ์ด์„ ์Šค๊ฐ€ ์š”๊ตฌํ•˜๋Š” ๊ณต๊ฐœํ•  ์†Œ์Šค ์ฝ”๋“œ๋ฅผ ์ทจํ•ฉํ•œ๋‹ค.
  • ์ทจํ•ฉํ•œ ์†Œ์Šค ์ฝ”๋“œ๋Š” ์ œํ’ˆ์— ํƒ‘์žฌ๋œ ๋ฐ”์ด๋„ˆ๋ฆฌ์™€ ๋งค์น˜๋˜์–ด์•ผ ํ•œ๋‹ค.
  • ์†Œ์Šค ์ฝ”๋“œ ๋‚ด ๋ถ€์ ์ ˆํ•œ ์ฃผ์„์„ ์ œ๊ฑฐํ•œ๋‹ค.
  • ์ ์ ˆํ•œ ๊ณ ์ง€๋ฌธ์ด ์ œํ’ˆ์— ํฌํ•จ๋˜์—ˆ๋‹ค. ์—ฌ๊ธฐ์—๋Š” ์ตœ์ข… ์‚ฌ์šฉ์ž๊ฐ€ ์†Œ์Šค ์ฝ”๋“œ๋ฅผ ๋ฐ›์„ ์ˆ˜ ์žˆ๋Š” ๋ฐฉ๋ฒ• (Written Offer)๋„ ํ•จ๊ป˜ ์ œ๊ณตํ•œ๋‹ค.
๋ฐฐํฌ ์ „ ํ™•์ธ ๋‹จ๊ณ„ ์‹œ์ž‘ ์กฐ๊ฑด๋ฐฐํฌ ์ „ ํ™•์ธ ๋‹จ๊ณ„ ๊ฒฐ๊ณผ
โ€ข ๋ชจ๋“  ์˜คํ”ˆ์†Œ์Šค ๊ตฌ์„ฑ์š”์†Œ๊ฐ€ BOM์— ๋“ฑ๋กโ€ข ๊ณ ์ง€ ์˜๋ฌด๋ฅผ ์ดํ–‰ํ•  ์ˆ˜ ์žˆ๋„๋ก ์กฐ์น˜
โ€ข ๊ณต๊ฐœํ•  ์†Œ์Šค ์ฝ”๋“œ ์ทจํ•ฉ
โ€ข ์†Œ์Šค ์ฝ”๋“œ ์ œ๊ณต ๋ฐฉ๋ฒ• ๊ฒฐ์ •
โ€ข ๋ฐฐํฌ ์ „ ํ™•์ธ ์ˆ˜ํ–‰ ์™„๋ฃŒ

Step 9. ๋ฐฐํฌ (Distribution)

๋ฐฐํฌ ์ „ ํ™•์ธ์ด ์™„๋ฃŒ๋˜๋ฉด ๊ณต๊ฐœํ•  ์†Œ์Šค ์ฝ”๋“œ ํŒจํ‚ค์ง€๋ฅผ ์˜คํ”ˆ์†Œ์Šค ๋ฐฐํฌ์‚ฌ์ดํŠธ์— ์—…๋กœ๋“œํ•œ๋‹ค. ์˜คํ”ˆ์†Œ์Šค ๋ฐฐํฌ์‚ฌ์ดํŠธ์—๋Š” ์ œํ’ˆ ๋ฐ ๋ฒ„์ „๋ณ„๋กœ ๋“ฑ๋กํ•  ์ˆ˜ ์žˆ๋‹ค. ์ตœ์ข… ์‚ฌ์šฉ์ž๋Š” ์ž์‹ ์ด ์›ํ•˜๋Š” ์ œํ’ˆ์˜ ๋ฒ„์ „์— ํ•ด๋‹นํ•˜๋Š” ์†Œ์Šค ์ฝ”๋“œ ํŒจํ‚ค์ง€๋ฅผ ์˜คํ”ˆ์†Œ์Šค ๋ฐฐํฌ์‚ฌ์ดํŠธ์—์„œ ๊ฒ€์ƒ‰ํ•˜์—ฌ ๋‹ค์šด๋กœ๋“œ ๋ฐ›์„ ์ˆ˜ ์žˆ๋‹ค.

๋ฐฐํฌ ๋‹จ๊ณ„ ์‹œ์ž‘ ์กฐ๊ฑด๋ฐฐํฌ ๋‹จ๊ณ„ ๊ฒฐ๊ณผ
โ€ข ๋ชจ๋“  ๋ฐฐํฌ ์ „ ํ™•์ธ ์™„๋ฃŒโ€ข ํŠน์ • ์ œํ’ˆ์˜ ๋ฒ„์ „์— ๋Œ€ํ•œ ๊ณต๊ฐœํ•  ์†Œ์Šค ์ฝ”๋“œ ํŒจํ‚ค์ง€๋ฅผ ์˜คํ”ˆ์†Œ์Šค ๋ฐฐํฌ์‚ฌ์ดํŠธ์— ์—…๋กœ๋“œ

Step 10. ์ตœ์ข… ํ™•์ธ (Final Verifications)

๊ณต๊ฐœํ•  ์†Œ์Šค ์ฝ”๋“œ ํŒจํ‚ค์ง€๋ฅผ ์˜คํ”ˆ์†Œ์Šค ๋ฐฐํฌ์‚ฌ์ดํŠธ์— ์—…๋กœ๋“œ ํ›„ ํŒจํ‚ค์ง€๊ฐ€ ์˜ฌ๋ฐ”๋ฅด๊ฒŒ ์—…๋กœ๋“œ ๋˜์—ˆ๊ณ , ์™ธ๋ถ€์—์„œ ์˜ค๋ฅ˜ ์—†์ด ๋‹ค์šด๋กœ๋“œ ๋ฐ ์••์ถ• ํ•ด์ œ๊ฐ€ ๋˜๋Š”์ง€ ํ™•์ธํ•œ๋‹ค. ๋ผ์ด์„ ์Šค์— ๋”ฐ๋ผ ๋นŒ๋“œํ•˜์—ฌ ๋ฐ”์ด๋„ˆ๋ฆฌ ์ƒ์„ฑ๊นŒ์ง€ ๋ณด์žฅ์„ ์š”๊ตฌํ•˜๋Š” ๊ฒฝ์šฐ, ์™ธ๋ถ€์—์„œ ๋‹ค์šด๋ฐ›์€ ์†Œ์Šค ์ฝ”๋“œ๊ฐ€ README์˜ ์•ˆ๋‚ด๋Œ€๋กœ ์˜ค๋ฅ˜ ์—†์ด ๋นŒ๋“œํ•˜์—ฌ ๋ฐ”์ด๋„ˆ๋ฆฌ๊ฐ€ ์ƒ์„ฑ๋˜๋Š”์ง€, ์ƒ์„ฑ๋œ ๋ฐ”์ด๋„ˆ๋ฆฌ๊ฐ€ ์ œํ’ˆ์— ํƒ‘์žฌ๋œ ๋ฐ”์ด๋„ˆ๋ฆฌ์™€ ๋™์ผํ•œ์ง€ ํ™•์ธํ•œ๋‹ค.

์ตœ์ข… ํ™•์ธ ๋‹จ๊ณ„ ์‹œ์ž‘ ์กฐ๊ฑด์ตœ์ข… ํ™•์ธ ๋‹จ๊ณ„ ๊ฒฐ๊ณผ
โ€ข ๊ณต๊ฐœํ•  ์†Œ์Šค ์ฝ”๋“œ๊ฐ€ ์˜คํ”ˆ์†Œ์Šค ๋ฐฐํฌ์‚ฌ์ดํŠธ์— ๊ฒŒ์‹œโ€ข ์™ธ๋ถ€์—์„œ ๋‹ค์šด๋กœ๋“œ๊ฐ€ ์ด์ƒ์—†์ด ์ˆ˜ํ–‰๋˜๋Š”์ง€, ์ œํ’ˆ๊ณผ ๋™์ผํ•œ ๋ฒ„์ „์˜ ๋ฐ”์ด๋„ˆ๋ฆฌ์™€ ๋งค์น˜๊ฐ€ ๋˜๋Š”์ง€ ํ™•์ธ

3.3 - 3. ์˜คํ”ˆ์†Œ์Šค๋„๊ตฌ (FOSSology, SW360)

์˜คํ”ˆ์†Œ์Šค ์ปดํ”Œ๋ผ์ด์–ธ์Šค ํ™œ๋™์„ ์œ„ํ•ด์„œ๋Š” ์ •์ฑ…, ํ”„๋กœ์„ธ์Šค๋‚˜ ๊ต์œก์ž๋ฃŒ๋ฟ๋งŒ ์•„๋‹ˆ๋ผ ์†Œ์Šค์ฝ”๋“œ ์Šค์บ”, Dependency ๋ถ„์„, ์˜คํ”ˆ์†Œ์Šค BOM ๊ด€๋ฆฌ ๋“ฑ์„ ์œ„ํ•œ ๋‹ค์–‘ํ•œ ๋„๊ตฌ์™€ ์‹œ์Šคํ…œ๋„ ์š”๊ตฌ๋œ๋‹ค. ๋•Œ๋ฌธ์— ๋‹ค์ˆ˜์˜ ๊ธฐ์—…์ด ์ด๋Ÿฌํ•œ ๋„๊ตฌ์™€ ์‹œ์Šคํ…œ์„ ๋„์ž…ํ•˜๊ณ  ํ™œ์šฉํ•˜๋Š”๋ฐ ๋งŽ์€ ๋ฆฌ์†Œ์Šค๋ฅผ ํˆฌ์ž…ํ•˜๊ณ  ์žˆ๋‹ค. ํŠนํžˆ ์˜คํ”ˆ์†Œ์Šค ์ปดํ”Œ๋ผ์ด์–ธ์Šค๋ฅผ ์ฒ˜์Œ ์‹œ์ž‘ํ•˜๋Š” ๊ธฐ์—…์€ ํ”„๋กœ์„ธ์Šค๋ฟ ์•„๋‹ˆ๋ผ ๋น„์šฉ ์ธก๋ฉด์—์„œ๋„ ์–ด๋ ค์›€์„ ๊ฒช๊ณ  ์žˆ๋‹ค.

์ด๋Ÿฐ ์–ด๋ ค์›€์„ ํ•ด๊ฒฐํ•˜๊ธฐ ์œ„ํ•ด, 2019๋…„ 6์›”, OpenChain ํ”„๋กœ์ ํŠธ์— ์ฐธ์—ฌํ•˜๊ณ  ์žˆ๋Š” ์ง€๋ฉ˜์Šค, ๋ณด์‰ฌ, ๋„์‹œ๋ฐ”, ํ›„์ง€์“ฐ, ํžˆํƒ€์น˜ ๋“ฑ์˜ ์˜คํ”ˆ์†Œ์Šค ์ปดํ”Œ๋ผ์ด์–ธ์Šค ๋„๊ตฌ ์ „๋ฌธ๊ฐ€๋“ค์„ ์ฃผ์ถ•์œผ๋กœ OpenChain Tooling Work Group์ด ์‹œ์ž‘๋˜์—ˆ๋‹ค.

OpenChain Tooling Work Group์€ ์—ฌ๋Ÿฌ ๊ธฐ์—…์˜ ์˜คํ”ˆ์†Œ์Šค ์ „๋ฌธ๊ฐ€๋“ค์ด ์ด์Šˆ๋ฅผ ํ•จ๊ป˜ ํ•ด๊ฒฐํ•˜๊ณ  ๊ฒฐ๊ณผ๋ฌผ์„ ๊ณต์œ ํ•ด ์˜คํ”ˆ์†Œ์Šค ์ปดํ”Œ๋ผ์ด์–ธ์Šค ๋น„์šฉ์„ ์ ˆ๊ฐํ•˜๊ณ  ์–‘์งˆ์˜ ์ปดํ”Œ๋ผ์ด์–ธ์Šค ๊ฒฐ๊ณผ๋ฌผ์„ ๋งŒ๋“ค์–ด ๋‚ด๊ธฐ ์œ„ํ•ด ๊ตฌ์„ฑ๋˜์—ˆ๋‹ค.

๊ตฌ์ฒด์ ์œผ๋กœ๋Š” FOSSology, SW360, Software Heritage, ClearlyDefined, SPDX ๋“ฑ์˜ ๊ธฐ์กด ์˜คํ”ˆ์†Œ์Šค ํ”„๋กœ์ ํŠธ๋ฅผ ํ™œ์šฉํ•˜์—ฌ ํ†ตํ•ฉ(turn-key) ์˜คํ”ˆ์†Œ์Šค ํˆด ์ฒด์ธ์„ ๋งŒ๋“ค๊ณ , ๋ชจ๋“  ๊ธฐ์—…์ด ์ด๋ฅผ ์ž์œ ๋กญ๊ฒŒ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋„๋ก ํ•˜๋Š” ๊ฒƒ์„ ๋ชฉํ‘œ๋กœ ์‚ผ๊ณ  ์žˆ๋‹ค. (https://groups.io/g/oss-based-compliance-tooling)

์—ฌ๊ธฐ์„œ๋Š” FOSSology์™€ SW360์— ๋Œ€ํ•ด ์†Œ๊ฐœ ๋ฐ ๊ฐ„๋‹จํ•œ ์‚ฌ์šฉ ๋ฐฉ๋ฒ•์— ๋Œ€ํ•ด ์•Œ์•„๋ณธ๋‹ค.

3.3.1 - FOSSology

์˜คํ”ˆ์†Œ์Šค ์ปดํ”Œ๋ผ์ด์–ธ์Šค๋ฅผ ์œ„ํ•ด ์†Œํ”„ํŠธ์›จ์–ด ๋‚ด์— ํฌํ•จ๋œ ์˜คํ”ˆ์†Œ์Šค์™€ ๋ผ์ด์„ ์Šค ์ •๋ณด๋ฅผ ๊ฒ€์ถœํ•˜๊ธฐ ์œ„ํ•ด ์†Œ์Šค์ฝ”๋“œ ์Šค์บ” ๋„๊ตฌ๋ฅผ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋‹ค.

https://www.fossology.org/

< https://www.fossology.org/ >

Linux Foundation์˜ FOSSology ํ”„๋กœ์ ํŠธ๋Š” ์ด๋Ÿฌํ•œ ์Šค์บ” ๋„๊ตฌ๋ฅผ ๊ฐœ๋ฐœํ•˜๊ณ  ์˜คํ”ˆ์†Œ์Šค๋กœ ๊ณต๊ฐœํ•ด ๋ˆ„๊ตฌ๋‚˜ ์ž์œ ๋กญ๊ฒŒ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๊ฒŒ ํ•œ ๋„๊ตฌ์ด๋‹ค.

์ฃผ์š” ํŠน์ง•

FOSSology๋Š” ์›น๊ธฐ๋ฐ˜์˜ ํ”„๋กœ๊ทธ๋žจ์œผ๋กœ ์‚ฌ์šฉ์ž๋Š” ์›น์‚ฌ์ดํŠธ์— ๋กœ๊ทธ์ธํ•˜์—ฌ ๊ฐœ๋ณ„ ํŒŒ์ผ ํ˜น์€ ์†Œํ”„ํŠธ์›จ์–ด ํŒจํ‚ค์ง€๋ฅผ ์—…๋กœ๋“œํ•  ์ˆ˜ ์žˆ๋‹ค. FOSSology๋Š” ์—…๋กœ๋“œ๋œ ํŒŒ์ผ ๋‚ด์— ๋ผ์ด์„ ์Šค ํ…์ŠคํŠธ์™€ Copyright ์ •๋ณด๋ฅผ ๊ฒ€์ถœํ•œ๋‹ค. ๊ฐœ๋ฐœ์ž๋Š” ์‚ฌ์šฉํ•˜๊ณ ์ž ํ•˜๋Š” ์˜คํ”ˆ์†Œ์Šค์˜ ๋ผ์ด์„ ์Šค๊ฐ€ ๋ฌด์—‡์ธ์ง€, Copyright์€ ์–ด๋–ป๊ฒŒ ๋˜๋Š”์ง€์— ๋Œ€ํ•œ ์ •๋ณด๋ฅผ ํ™•์ธํ•˜๊ณ ์ž ํ• ๋•Œ FOSSology๋ฅผ ์ด์šฉํ•˜๋Š” ๊ฒƒ์ด ์ข‹๋‹ค. FOSSology๋Š” ๊ฐœ๋ฐœ์ž๊ฐ€ ์—…๋กœ๋“œํ•œ ์˜คํ”ˆ์†Œ์Šค ํŒจํ‚ค์ง€ ๋‚ด์˜ ๋ชจ๋“  ํŒŒ์ผ์„ ์Šค์บ”ํ•˜์—ฌ ๊ฐ ํŒŒ์ผ ๋‚ด ๋ผ์ด์„ ์Šค ๊ด€๋ จ ํ…์ŠคํŠธ์™€ Copyright ์ •๋ณด๋ฅผ ์ž๋™์œผ๋กœ ๊ฒ€์ถœํ•˜๊ณ , ์ด๋ฅผ ๋ฆฌํฌํŠธ๋กœ ์ƒ์„ฑํ•œ๋‹ค. FOSSology ์ฃผ์š” ํŠน์ง•์— ๋Œ€ํ•œ ์ž์„ธํ•œ ๋‚ด์šฉ์€ ๋‹ค์Œ ํŽ˜์ด์ง€๋ฅผ ์ฐธ๊ณ ํ•  ์ˆ˜ ์žˆ๋‹ค. : https://www.fossology.org/features/

์„ค์น˜

๊ธฐ์—… ๋‚ด์—์„œ FOSSology๋ฅผ ์‚ฌ์šฉํ•˜๊ธฐ ์œ„ํ•ด์„œ๋Š” ์‚ฌ๋‚ด์— FOSSology ์„œ๋ฒ„๋ฅผ ๊ตฌ์ถ•ํ•ด์•ผ ํ•œ๋‹ค. ์ด๋ฅผ ์œ„ํ•ด ๋ฆฌ๋ˆ…์Šค ๊ธฐ๋ฐ˜์˜ ์„œ๋ฒ„ ์‹œ์Šคํ…œ์— FOSSology๋ฅผ ์„ค์น˜ํ•ด์•ผ ํ•œ๋‹ค. FOSSology๋Š” ๋‹ค์Œ ์„ธ ๊ฐ€์ง€ ๋ฐฉ๋ฒ•์œผ๋กœ ์„ค์น˜ํ•  ์ˆ˜ ์žˆ๋‹ค.

  1. Docker ์‚ฌ์šฉ
  2. Vagrant์™€ VirtualBox ์‚ฌ์šฉ
  3. Source buildํ•˜์—ฌ ์„ค์น˜

์—ฌ๊ธฐ์„œ๋Š” ๊ฐ€์žฅ ๊ฐ„ํŽธํ•œ ๋ฐฉ๋ฒ•์ธ Docker๋ฅผ ์‚ฌ์šฉํ•˜๋Š” ๋ฐฉ๋ฒ•์— ๋Œ€ํ•ด ์„ค๋ช…ํ•œ๋‹ค.

FOSSology๋Š” ์ปจํ…Œ์ด๋„ˆํ™” ๋œ Docker ์ด๋ฏธ์ง€๋ฅผ Docker Hub (https://hub.docker.com/)๋ฅผ ํ†ตํ•ด ๊ณต๊ฐœํ•˜๊ณ  ์žˆ๋‹ค. : https://hub.docker.com/r/fossology/fossology

Pre-built ๋œ Docker ์ด๋ฏธ์ง€๋Š” ๋‹ค์Œ ๋ช…๋ น์–ด๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์‹คํ–‰ํ•  ์ˆ˜ ์žˆ๋‹ค.

$ docker run -p 8081:80 fossology/fossology

Docker ์ด๋ฏธ์ง€๋Š” ๋‹ค์Œ URL๊ณผ ๊ณ„์ • ์ •๋ณด๋กœ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋‹ค. : http://[IP_OF_DOCKER_HOST]:8081/repo

  • Username : fossy
  • Passwd : fossy

์„ค์น˜์™€ ๊ด€๋ จํ•œ ์ž์„ธํ•œ ๋‚ด์šฉ์€ ๋‹ค์Œ ํŽ˜์ด์ง€๋ฅผ ์ฐธ๊ณ ํ•  ์ˆ˜ ์žˆ๋‹ค. : https://github.com/fossology/fossology/blob/master/README.md

ํ…Œ์ŠคํŠธ ์„œ๋ฒ„

FOSSology๋ฅผ ์„ค์น˜ํ•  ์ˆ˜ ์žˆ๋Š” ์‹œ์Šคํ…œ ๊ตฌ์ถ•์ด ๊ณค๋ž€ํ•œ ์ƒํ™ฉ์ด๋ผ๋ฉด, FOSSology Project์—์„œ ์ œ๊ณตํ•˜๋Š” ํ…Œ์ŠคํŠธ ์„œ๋ฒ„๋ฅผ ์ด์šฉํ•  ์ˆ˜ ์žˆ๋‹ค. FOSSology ํ”„๋กœ์ ํŠธ์—์„œ๋Š” ํ…Œ์ŠคํŠธ๋ฅผ ์œ„ํ•œ ํ™˜๊ฒฝ์„ ์ œ๊ณตํ•œ๋‹ค. (ํ…Œ์ŠคํŠธ ์„œ๋ฒ„๋Š” ์˜ˆ๊ณ ์—†์ด ์ค‘๋‹จ๋  ์ˆ˜ ์žˆ๋‹ค.)

์‚ฌ์šฉ์ž๋Š” ๋‹ค์Œ ๊ณ„์ •์œผ๋กœ FOSSology ํ…Œ์ŠคํŠธ ์„œ๋ฒ„์— ์ ‘์†ํ•˜์—ฌ FOSSology ๊ธฐ๋Šฅ์„ ์‹œํ—˜ํ•ด๋ณผ ์ˆ˜ ์žˆ๋‹ค.

Basic Workflow

FOSSology์˜ ๊ธฐ๋ณธ ์‚ฌ์šฉ ์ ˆ์ฐจ๋Š” ๋‹ค์Œ๊ณผ ๊ฐ™๋‹ค.

  • ์‚ฌ์šฉํ•˜๊ณ ์ž ํ•˜๋Š” ์˜คํ”ˆ์†Œ์Šค์˜ ๋ผ์ด์„ ์Šค์™€ Copyright ์ •๋ณด๋ฅผ ํ™•์ธํ•˜๊ธฐ ์œ„ํ•ด ์˜คํ”ˆ์†Œ์Šค์˜ ์†Œ์Šค ์ฝ”๋“œ๋ฅผ ํ•˜๋‚˜์˜ ํŒŒ์ผ๋กœ ์••์ถ•ํ•˜์—ฌ FOSSology์— ์—…๋กœ๋“œํ•œ๋‹ค.
  • ์ด๋ฅผ ์œ„ํ•ด ๋ฉ”๋‰ด > Upload > From File์„ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค.

  • ์—…๋กœ๋“œํ•  ํŒŒ์ผ์„ ์„ ํƒํ•˜๊ณ  Upload ๋ฒ„ํŠผ์„ ํด๋ฆญํ•œ๋‹ค.
  • ์—…๋กœ๋“œ๊ฐ€ ์™„๋ฃŒ๋˜๋ฉด Job Agent์— ์˜ํ•ด ์ž๋™์œผ๋กœ ๋ถ„์„์„ ์ˆ˜ํ–‰ํ•œ๋‹ค.
  • ๋ฉ”๋‰ด > Jobs > My Recent Jobs์—์„œ ๋ถ„์„ ์ค‘์ธ Status๋ฅผ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค.

  • ๋ถ„์„์ด ์™„๋ฃŒ๋˜๋ฉด ๋ฉ”๋‰ด > Browse์—์„œ ๋ถ„์„ ๊ฒฐ๊ณผ๋ฅผ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค.

  • ๊ฐœ๋ณ„ ํŒŒ์ผ์„ ์„ ํƒํ•˜๋ฉด FOSSology๊ฐ€ ๊ฒ€์ถœํ•œ ๋ผ์ด์„ ์Šค ๊ด€๋ จ ํ…์ŠคํŠธ๊ฐ€ ๋ฌด์—‡์ธ์ง€ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค.

  • ๋ฉ”๋‰ด > Browser > ํŒŒ์ผ ํ˜น์€ ๋””๋ ‰ํ„ฐ๋ฆฌ๋ฅผ ์„ ํƒ > Copyright/Email/Url/Author์—์„œ๋Š” FOSSology๊ฐ€ ๊ฒ€์ถœํ•œ Copyright/Email/Url/Author ์ •๋ณด๋ฅผ ๋ณด์—ฌ๋‹ค.

์‚ฌ์šฉ์ž๋Š” FOSSology๋Š” ์ด๋ ‡๊ฒŒ ๋ถ„์„ํ•œ ๊ฒฐ๊ณผ๊ฐ€ ์œ ํšจํ•œ์ง€ ์—ฌ๋ถ€์— ๋Œ€ํ•ด ํ™•์ธ ํ›„ ์ž˜๋ชป ๊ฒ€์ถœ๋œ ํ•ญ๋ชฉ์— ๋Œ€ํ•ด์„œ๋Š” ๋ถ„์„ ๊ฒฐ๊ณผ์—์„œ ์ œ์™ธ์‹œํ‚ค๋Š” ์ž‘์—…์„ ํ•  ์ˆ˜ ์žˆ๋‹ค. FOSSology๋Š” ์ด๋ฅผ Clearing ๊ณผ์ •์ด๋ผ๊ณ  ์„ค๋ช…ํ•˜๋ฉฐ, ์ž์„ธํ•œ ์‚ฌํ•ญ์€ ๋‹ค์Œ ํŽ˜์ด์ง€๋ฅผ ์ฐธ๊ณ ํ•  ์ˆ˜ ์žˆ๋‹ค. : https://www.fossology.org/get-started/basic-workflow/

์œ„์™€ ๊ฐ™์€ ๋ฐฉ๋ฒ•์œผ๋กœ ์‚ฌ์šฉํ•˜๊ณ ์ž ํ•˜๋Š” ์˜คํ”ˆ์†Œ์Šค์˜ ๋ผ์ด์„ ์Šค๋Š” ๋ฌด์—‡์ธ์ง€, Copyright ์ •๋ณด๋Š” ์–ด๋–ป๊ฒŒ ๋˜๋Š”์ง€๋ฅผ ๊ฐ„๋‹จํžˆ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค.

3.3.2 - SW360

์˜คํ”ˆ์†Œ์Šค๋ฅผ ํฌํ•จํ•˜๋Š” ์ œํ’ˆ์„ ๊ฐœ๋ฐœํ•˜๊ณ  ๋ฐฐํฌํ•˜๋Š” ๊ธฐ์—…์ด๋ผ๋ฉด ๊ฐ ์ œํ’ˆ๊ณผ ๋ฆด๋ฆฌ์Šค ๋ฒ„์ „๋งˆ๋‹ค ์‚ฌ์šฉํ•œ ์˜คํ”ˆ์†Œ์Šค์˜ ๋ฒ„์ „, ๋ผ์ด์„ ์Šค ๋“ฑ์˜ ์ •๋ณด๋ฅผ ์ˆ˜์ง‘ํ•˜๊ณ  ์ถ”์ ํ•ด์•ผ ํ•œ๋‹ค. ์ด๋ฅผ ํ†ตํ•ด ๊ธฐ์—…์€ ์˜ฌ๋ฐ”๋ฅธ ์˜คํ”ˆ์†Œ์Šค ์ปดํ”Œ๋ผ์ด์–ธ์Šค ํ™œ๋™์„ ์ˆ˜ํ–‰ํ•  ์ˆ˜ ์žˆ๋‹ค.

ํŠนํžˆ, NVD (https://nvd.nist.gov/vuln)์—์„œ ํŠน์ • ์˜คํ”ˆ์†Œ์Šค ๋ฒ„์ „์— ๋ณด์•ˆ ์ทจ์•ฝ์ ์ด ๋ณด๊ณ  ๋˜์—ˆ์„๋•Œ, ํ•ด๋‹น ๋ฒ„์ „์„ ์‚ฌ์šฉํ•˜๊ณ  ์žˆ๋Š” ์ œํ’ˆ์ด ๋ฌด์—‡์ธ์ง€ ์ถ”์ ์„ ํ•  ์ˆ˜ ์—†๋‹ค๋ฉด, ๊ทธ ๊ธฐ์—…์€ ์–ด๋А ์ œํ’ˆ์— ๋ณด์•ˆ ํŒจ์น˜๋ฅผ ์ ์šฉํ•ด์•ผ ํ•  ์ง€ ์•Œ ์ˆ˜ ์—†๋Š” ์ƒํ™ฉ์— ์ฒ˜ํ•˜๊ฒŒ ๋˜๊ณ , ๊ทธ ๊ธฐ์—…์˜ ์ œํ’ˆ๋“ค์€ ๋ณด์•ˆ์ทจ์•ฝ์ ์— ๊ทธ๋Œ€๋กœ ๋…ธ์ถœ์ด ๋  ์ˆ˜ ๋ฐ–์— ์—†๋‹ค.

์ด๋ ‡๋“ฏ, ์˜คํ”ˆ์†Œ์Šค ์ •๋ณด๋ฅผ ์ถ”์ ํ•˜๋Š” ํ™œ๋™์€ ๊ผญ ํ•„์š”ํ•˜๋‹ค. ๊ธฐ์—…๋“ค์€ ์ด๋ฅผ ์œ„ํ•ด ์ž์ฒด ์‹œ์Šคํ…œ์„ ๊ตฌ์ถ•ํ•˜๊ฑฐ๋‚˜, ์ƒ์šฉ ์„œ๋น„์Šค๋ฅผ ๊ตฌ๋งคํ•˜์—ฌ ์‚ฌ์šฉํ•˜๊ธฐ๋„ ํ•œ๋‹ค. SW360์€ Eclipse ์žฌ๋‹จ์—์„œ ํ›„์›ํ•˜๋Š” ์˜คํ”ˆ์†Œ์Šค๋กœ์„œ ์†Œํ”„ํŠธ์›จ์–ด BOM์— ๋Œ€ํ•œ ์ •๋ณด๋ฅผ ์ˆ˜์ง‘ ๋ฐ ์ถ”์ ํ•˜๊ธฐ ์œ„ํ•œ ์›น ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ๋ฐ ์ €์žฅ์†Œ๋ฅผ ์ œ๊ณตํ•œ๋‹ค.

https://www.eclipse.org/sw360/

< https://www.eclipse.org/sw360/ >

์ฃผ์š” ํŠน์ง•

SW360์€ ์›น ๊ธฐ๋ฐ˜์˜ UI๋ฅผ ์ œ๊ณตํ•˜๋ฉฐ ์ฃผ์š” ๊ธฐ๋Šฅ์€ ๋‹ค์Œ๊ณผ ๊ฐ™๋‹ค.

  • ์ œํ’ˆ์— ์‚ฌ์šฉ๋œ ์ปดํฌ๋„ŒํŠธ ์ถ”์ 
  • ๋ณด์•ˆ ์ทจ์•ฝ์  ํ‰๊ฐ€
  • ๋ผ์ด์„ ์Šค ์˜๋ฌด ๊ด€๋ฆฌ
  • ๊ณ ์ง€๋ฌธ ๋“ฑ ๋ฒ•์  ๋ฌธ์„œ ์ƒ์„ฑ

https://www.eclipse.org/sw360/

์„ค์น˜

SW360์€ ๋‹ค์Œ๊ณผ ๊ฐ™์ด ๊ตฌ์„ฑ๋œ๋‹ค.

  • Frontend : Liferay-(Tomcat-)based portal application
  • Backend : Tomcat-based thrift service
  • Database : CouchDB

Project ๊ตฌ์กฐ์™€ ์„ค์น˜๋ฅผ ์œ„ํ•ด ์š”๊ตฌ๋˜๋Š” ์†Œํ”„ํŠธ์›จ์–ด ๋“ฑ ์ž์„ธํ•œ ๋‚ด์šฉ์€ README์˜ Required software ๋ถ€๋ถ„์—์„œ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค. : https://github.com/eclipse/sw360/blob/master/README.md

SW360์€ ๋‹ค์Œ ์„ธ ๊ฐ€์ง€์˜ ์„ค์น˜ ๋ฐฉ๋ฒ•์„ ์ œ๊ณตํ•œ๋‹ค. ์‚ฌ์šฉ์ž๋Š” ์ด ์ค‘ ํ•˜๋‚˜๋ฅผ ์„ ํƒํ•˜์—ฌ ์„ค์น˜ํ•  ์ˆ˜ ์žˆ๋‹ค.

  1. Vagrant (https://www.vagrantup.com/) ๊ธฐ๋ฐ˜ ์„ค์น˜ : Vagrant๋Š” ๊ฐ€์ƒํ™” ์ธ์Šคํ„ด์Šค๋ฅผ ๊ด€๋ฆฌํ•˜๋Š” ๋„๊ตฌ๋กœ์„œ sw360vagrant์—์„œ๋Š” SW360์„ ํ•œ ๋ฒˆ์— Deploy ํ•˜๊ธฐ ์œ„ํ•œ ํ™˜๊ฒฝ์„ ์ œ๊ณตํ•œ๋‹ค. : https://github.com/sw360/sw360vagrant
  2. SW360์˜ ๊ตฌ์„ฑ์š”์†Œ๋ฅผ ๊ฐœ๋ณ„์ ์œผ๋กœ ์„ค์น˜ํ•  ์ˆ˜ ์žˆ๋‹ค. : https://github.com/eclipse/sw360
  3. Docker๋ฅผ ํ†ตํ•ด Deploy ํ•  ์ˆ˜ ์žˆ๋‹ค. : https://github.com/sw360/sw360chores

์—ฌ๊ธฐ์„œ๋Š” CentOS 7.6 ์‹œ์Šคํ…œ์— Vagrant ๊ธฐ๋ฐ˜์œผ๋กœ ์„ค์น˜ํ•˜์—ฌ Deployํ•˜๋Š” ๋ฐฉ๋ฒ•์„ ์†Œ๊ฐœํ•œ๋‹ค. ์ž์„ธํ•œ ์‚ฌํ•ญ์€ README๋ฅผ ์ฐธ๊ณ ํ•œ๋‹ค. : https://github.com/sw360/sw360vagrant/blob/master/README.md

1) ์‚ฌ์ „ ์„ค์น˜

vagrant box์— SW360์„ ์„ค์น˜ํ•˜๊ธฐ ์œ„ํ•ด์„œ๋Š” openjdk, VirtualBox ๋ฐ Vagrant๋ฅผ ์„ค์น˜ํ•ด์•ผ ๋‹ค. ๋จผ์ € openjdk 1.8.0์„ ์„ค์น˜ํ•œ๋‹ค.

$ yum install java-1.8.0-openjdk
$ java -version
openjdk version "1.8.0_191"
OpenJDK Runtime Environment (build 1.8.0_191-b12)โ€
OpenJDK 64-Bit Server VM (build 25.191-b12, mixed mode)

VirtualBox๋ฅผ ์„ค์น˜ํ•œ๋‹ค.

$ sudo wget https://download.virtualbox.org/virtualbox/rpm/el/virtualbox.repo -P /etc/yum.repos.d
$ sudo yum install VirtualBox-5.2

CentOS 7์—์„œ VirtualBox ์„ค์น˜ ์‹œ, โ€œkernel module is not loadedโ€™ ์—๋Ÿฌ๊ฐ€ ๋ฐœ์ƒํ•  ๊ฒฝ์šฐ, kernel-devel์„ ์„ค์น˜ํ•˜์—ฌ ํ•ด๊ฒฐํ•œ ํ›„ VirtualBox๋ฅผ ์žฌ์„ค์น˜ํ•œ๋‹ค.

$ sudo yum install https://centos7.iuscommunity.org/ius-release.rpm
$ sudo yum install dkms
$ sudo yum install kernel-devel
# reboot
$ sudo /sbin/vboxconfig
$ systemctl status vboxdrv
โ— vboxdrv.service - VirtualBox Linux kernel module
   Loaded: loaded (/usr/lib/virtualbox/vboxdrv.sh; enabled; vendor preset: disabled)
   Active: active (exited) since Wed 2020-02-19 09:06:02 KST; 20min ago

Vagrant์™€ vagrant-aws plugin์„ ์„ค์น˜ํ•œ๋‹ค.

$ sudo yum install https://releases.hashicorp.com/vagrant/2.2.6/vagrant_2.2.6_x86_64.rpm 
# vagrant-aws plugin ์„ค์น˜
$ vagrant plugin install vagrant-aws

๊ทธ๋ฆฌ๊ณ , sw360vagrant ์ฝ”๋“œ๋ฅผ Clone ํ•œ๋‹ค.

$ git clone https://github.com/sw360/sw360vagrant.git

2) Dependency ๋‹ค์šด๋กœ๋“œ

Vagrant box๋ฅผ ๋นŒ๋“œํ•˜๋Š” ์‹œ๊ฐ„์„ ์ค„์ด๊ธฐ ์œ„ํ•ด Dependency Package๋“ค์„ ๋ฏธ๋ฆฌ ๋‹ค์šด๋กœ๋“œ ๋ฐ›๋Š”๋‹ค.

$ cd sw360vagrant
$ ./download-packages.sh

๊ทธ๋Ÿฌ๋ฉด ๋‹ค์Œ์˜ package๋“ค์ด ./shared/package ํด๋” ์•ˆ์— ๋‹ค์šด๋กœ๋“œ ๋œ๋‹ค.

  • Liferay 7.2.1 CE GA2 with Tomcat (9.0.17)
  • Postgresql-42.2.9 ODBC client for Java as *.jar file
  • SW 360์—์„œ ํ•„์š”ํ•œ 11๊ฐœ์˜ *.jar ํŒŒ์ผ
  • Thrift 0.11
  • A box images from the Ubuntu 16.04 LTS (xenial-server-cloudimg-amd64-vagrant.box)

3) Base box ์ƒ์„ฑ

์ด์ œ ๋‹ค์Œ ๋ช…๋ น์–ด๋กœ Base box๋ฅผ ์ƒ์„ฑํ•œ๋‹ค.

$ cd generate-box
$ ./generate_box.sh

์ด ์ž‘์—…์€ ์ˆ˜์‹ญ ๋ถ„ ์†Œ์š”๋  ์ˆ˜ ์žˆ๋‹ค.

4) Box ์‹คํ–‰

๋‹ค์Œ ๋ช…๋ น์–ด๋กœ Box๋ฅผ ์‹คํ–‰ํ•œ๋‹ค.

# If you have built a vagrant box from this directory earlier, you will have to destroy it first via
$ vagrant destroy
$ cd ../sw360-single
$ vagrant up

Box๋ฅผ ์‹คํ–‰ํ•˜๋ฉด liferay, postgresql ๋ฐ couchdb๊ฐ€ ๊ตฌ์„ฑ๋œ๋‹ค. ์ด์ƒ์—†์ด ์‹คํ–‰์ด ๋  ๊ฒฝ์šฐ, https://localhost:8443/ ๋กœ Liferay ํ™”๋ฉด์— ์ ‘๊ทผํ•  ์ˆ˜ ์žˆ๋‹ค.

5) SW360 Layout Deploy

๋งˆ์ง€๋ง‰ ๋‹จ๊ณ„๋Š” Liferay์—์„œ SW360์˜ Layout์„ Deployํ•˜๋Š” ๊ฒƒ์ด๋‹ค. ์ด ์ž‘์—…์€ ์•„์ง ์ž๋™ํ™”๊ฐ€ ๋˜์ง€ ์•Š์•„ ๊ด€๋ฆฌ์ž๊ฐ€ ์ˆ˜๋™์œผ๋กœ ์ˆ˜ํ–‰ํ•ด์•ผ ๋‹ค. https://localhost:8443/์— ์ ‘๊ทผํ•˜์—ฌ ๋‹ค์Œ ๊ณ„์ •์œผ๋กœ ๋กœ๊ทธ์ธํ•œ๋‹ค.

์ดํ›„์—๋Š” ๋‹ค์Œ ์‚ฌ์ดํŠธ์˜ ์•ˆ๋‚ด์— ๋”ฐ๋ผ Layout deploy๋ฅผ ์ˆ˜ํ–‰ํ•œ๋‹ค. https://github.com/eclipse/sw360/wiki/Deploy-Liferay7

Deploy๊ฐ€ ์™„๋ฃŒ๋˜๋ฉด ๋‹ค์Œ๊ณผ ๊ฐ™์€ ํ™”๋ฉด์„ ๋ณผ ์ˆ˜ ์žˆ๋‹ค.

Basic Workflow

1) License ๋“ฑ๋ก

SW360์„ ์ฒ˜์Œ ์„ค์น˜ํ•˜๋ฉด ๋จผ์ € ์ž์ฃผ ์‚ฌ์šฉํ•˜๋Š” ์˜คํ”ˆ์†Œ์Šค ๋ผ์ด์„ ์Šค ๋“ค์„ ๋“ฑ๋กํ•ด์•ผ ํ•œ๋‹ค. ๋ผ์ด์„ ์Šค ๋‹ค์Œ๊ณผ ๊ฐ™์€ ์ •๋ณด๋ฅผ ํฌํ•จํ•œ๋‹ค.

  • Full Name
  • Short Name
  • License Type
  • GPL-2.0 Compatibility (์˜ˆ: yes, no)
  • License Text

๋ฉ”๋‰ด > Licenses > Add License๋ฅผ ์„ ํƒํ•˜๋ฉด ๋‹ค์Œ๊ณผ ๊ฐ™์ด Create License ํ™”๋ฉด์œผ๋กœ ์ง„์ž…ํ•œ๋‹ค.

์ด์™€ ๊ฐ™์ด ๋ผ์ด์„ ์Šค๋ฅผ ํ•˜๋‚˜์”ฉ ์ˆ˜๋™์œผ๋กœ ๋“ฑ๋กํ•˜๋Š” ์ผ์€ ์ƒ๋‹นํžˆ ์ˆ˜๊ณ ์Šค๋Ÿฌ์šธ ์ˆ˜ ์žˆ๋Š”๋ฐ, ๋‹คํ–‰ํžˆ SW360์€ SPDX License List๋ฅผ ํ•œ ๋ฒˆ์— Import ํ•˜๋Š” ๊ธฐ๋Šฅ์„ ์ œ๊ณตํ•œ๋‹ค. ๋ฉ”๋‰ด > Admin < Import SPDX Information์„ ํด๋ฆญํ•œ๋‹ค.

๊ทธ๋Ÿฌ๋ฉด, ๊ณง SPDX License List๊ฐ€ ์ž๋™์œผ๋กœ ๋“ฑ๋ก๋ฉ๋‹ˆ๋‹ค. ๋ฉ”๋‰ด > Licenses์—์„œ 338๊ฐœ์˜ License๊ฐ€ ๋“ฑ๋ก๋œ ๊ฒƒ์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค.

2) Component ๋ฐ Release ๋“ฑ๋ก

SW360์—์„œ Component๋Š” ํ•˜๋‚˜์˜ ์†Œํ”„ํŠธ์›จ์–ด ๋‹จ์œ„์ด๋‹ค. ์—ฌ๊ธฐ์—๋Š” ๋‹ค์–‘ํ•œ ํ˜•ํƒœ์˜ ์†Œํ”„ํŠธ์›จ์–ด๊ฐ€ ํ•ด๋‹นํ•  ์ˆ˜ ์žˆ์œผ๋ฉฐ, ๊ทธ ์˜ˆ๋Š” ๋‹ค์Œ๊ณผ ๊ฐ™๋‹ค.

  • ์˜คํ”ˆ์†Œ์Šค ์†Œํ”„ํŠธ์›จ์–ด
  • ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ
  • 3rd party ์†Œํ”„ํŠธ์›จ์–ด

Component๋Š” ๋‹ค์Œ๊ณผ ๊ฐ™์€ ์ •๋ณด๋ฅผ ํฌํ•จํ•œ๋‹ค.

  • Component Name
  • Main Licenses
  • Categories (์˜ˆ: Library, Cloud, Mobile, …)
  • Component Type (์˜ˆ: OSS, Internal, InnerSource, Service, Freeware)
  • Default Vendor
  • Homepage URL

Release๋Š” Component์—์„œ ํ•˜๋‚˜์˜ Version์„ ๊ฐ€๋ฆฌํ‚ค๋Š” ๋‹จ์œ„์ด๋‹ค. ๋”ฐ๋ผ์„œ ํ•˜๋‚˜์˜ Component๋Š” ์—ฌ๋Ÿฌ ๊ฐœ์˜ Release๋ฅผ ๊ฐ€์งˆ ์ˆ˜ ์žˆ๋‹ค. Release๋Š” ํ•˜๋‚˜์˜ Component ํ•˜์œ„์— ์ƒ์„ฑ๋˜์–ด ๊ด€๋ฆฌ๋œ๋‹ค.

Release๋Š” ๋‹ค์Œ๊ณผ ๊ฐ™์€ ์ •๋ณด๋“ค์„ ํฌํ•จํ•œ๋‹ค.

  • Component Name
  • Version
  • License
  • Download URL
  • CPE ID (์˜ˆ: cpe:2.3:a:apache:maven:3.0.4)

์˜ˆ๋ฅผ ๋“ค์–ด, zlib-1.2.8์„ ๋“ฑ๋กํ•ด์•ผ ํ•œ๋‹ค๋ฉด, ๋จผ์ € Component์— zlib์„ ๋จผ์ € ๋“ฑ๋กํ•œ ํ›„, Release์— zlib 1.2.8์„ ๋“ฑ๋กํ•œ๋‹ค. Menu > Components > Add Component๋ฅผ ์„ ํƒํ•˜๋ฉด Create Component ํ™”๋ฉด์œผ๋กœ ์ง„์ž…ํ•˜์—ฌ zlib์— ๋Œ€ํ•œ ์ •๋ณด๋ฅผ ๋“ฑ๋กํ•  ์ˆ˜ ์žˆ๋‹ค.

Component๋ฅผ ์ƒ์„ฑํ•˜๋ฉด, Components > Releases > Add Release์—์„œ zlib-1.2.8 version์— ๋Œ€ํ•œ ์ •๋ณด๋ฅผ ๋“ฑ๋กํ•  ์ˆ˜ ์žˆ๋‹ค.

ํ•˜๋‚˜์˜ zlib์ด๋ผ๋Š” Component์— 1.2.8๊ณผ 1.2.11 version์„ ๊ฐ๊ฐ์˜ Release๋กœ ๋“ฑ๋กํ•˜์˜€์„ ๋•Œ, Release Overview ํ™”๋ฉด์—์„œ ๋‹ค์Œ๊ณผ ๊ฐ™์ด 2๊ฐœ์˜ Release๊ฐ€ ์กด์žฌํ•˜๋Š” ๊ฒƒ์„ ๋ณผ ์ˆ˜ ์žˆ๋‹ค.

SW360์€ ๋‹ค์ˆ˜์˜ Component ์ •๋ณด๋ฅผ Import ์‹œํ‚ค๊ธฐ ์œ„ํ•œ ๊ธฐ๋Šฅ์„ ์ œ๊ณตํ•œ๋‹ค. ๋ฉ”๋‰ด > Admin > Import / Export์— CSV template์— ๋“ฑ๋ก์„ ์›ํ•˜๋Š” Component ์ •๋ณด๋ฅผ ์ž…๋ ฅ ํ›„ Import ํ•  ์ˆ˜ ์žˆ๋‹ค.

๋‹จ, ์ด ๊ธฐ๋Šฅ์€ 2020๋…„ 2์›” ๊ธฐ์ค€ ์•„์ง ์•ˆ์ •์ ์œผ๋กœ ๋™์ž‘ํ•˜์ง€ ์•Š์„ ์ˆ˜ ์žˆ๋‹ค.

3) Project ์ƒ์„ฑ

Project๋Š” ํ•˜๋‚˜์˜ ์ œํ’ˆ์„ ๊ฐ€๋ฆฌํ‚จ๋‹ค. ์‚ฌ์—… ์œ ํ˜•์— ๋”ฐ๋ผ ์ œํ’ˆ์ผ์ˆ˜๋„ ์žˆ๊ณ , ์„œ๋น„์Šค ํ˜น์€ ์†Œํ”„ํŠธ์›จ์–ด ์ผ์ˆ˜๋„ ์žˆ๋‹ค. Project์—๋Š” ์ œํ’ˆ์— ์‚ฌ์šฉ๋œ Component/Release๋ฅผ ๋“ฑ๋กํ•˜์—ฌ ๊ด€๋ฆฌํ•œ๋‹ค.

Project ์ƒ์„ฑ ์‹œ์—๋Š” ๋‹ค์Œ๊ณผ ๊ฐ™์€ ์ •๋ณด๋ฅผ ๋“ฑ๋กํ•œ๋‹ค.

  • Project Name
  • Version
  • Project type (์˜ˆ: Product, Customer Project, Service, Internal Project, InnerSource)

๋ฉ”๋‰ด > Projects > Add Project๋ฅผ ํ†ตํ•ด Project๋ฅผ ์ƒ์„ฑํ•  ์ˆ˜ ์žˆ๋‹ค.

Project๋ฅผ ์ƒ์„ฑํ•˜๊ณ  ๋‚˜๋ฉด, ํฌํ•จํ•˜๋Š” Release๋‚˜ ํ•˜์œ„ Project๋ฅผ ๋“ฑ๋กํ•œ๋‹ค. ๋ฉ”๋‰ด > Projects์—์„œ ํ•ด๋‹น Project๋ฅผ ์„ ํƒํ•˜๋ฉด โ€œLinked Releases and Projectsโ€์—์„œ Linked Projects์™€ Linked Releases๋ฅผ ๋“ฑ๋กํ•  ์ˆ˜ ์žˆ๋‹ค.

๋‹ค์Œ์€ SuperCalc๋ผ๋Š” Project์— OpenSSL 1.0.1๊ณผ zlib 1.2.8์„ Linked Releases๋กœ ๋“ฑ๋กํ•œ ์ดํ›„์˜ ํ™”๋ฉด์ด๋‹ค.

4. ๋ณด์•ˆ ์ทจ์•ฝ์  ๊ด€๋ฆฌ

SW360์€ ๋“ฑ๋ก๋œ Release์— ๋Œ€ํ•ด ๋ณด์•ˆ ์ทจ์•ฝ์ ์ด ์žˆ๋Š”์ง€ ์ž๋™์œผ๋กœ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค. ์ด๋ฅผ ์œ„ํ•ด SW360์€ CVE ์ •๋ณด๋ฅผ ์ฃผ๊ธฐ์ ์œผ๋กœ ์ˆ˜์ง‘ํ•˜๋„๋ก ์Šค์ผ€์ฅด๋งํ•˜๋Š” ๊ธฐ๋Šฅ์„ ์ œ๊ณตํ•œ๋‹ค. ๋ฉ”๋‰ด > Admin > Schedule ์—์„œ CVE SEARCH ์ •๋ณด๋ฅผ 24์‹œ๊ฐ„๋งˆ๋‹ค ์ˆ˜์ง‘ํ•˜๋„๋ก ์Šค์ผ€์ฅด๋ง์„ ์„ค์ •ํ•  ์ˆ˜ ์žˆ๋‹ค.

์ด๋ ‡๊ฒŒ ์Šค์ผ€์ฅด๋ง์„ ์„ค์ •ํ•˜๋ฉด SW360์€ ์ •ํ•ด์ง„ ์‹œ๊ฐ„์— CVE Search ์‚ฌ์ดํŠธ(https://cve.circl.lu/)์—์„œ CVE ์ •๋ณด๋ฅผ ์ˆ˜์ง‘ํ•œ๋‹ค. ์ˆ˜์ง‘ํ•œ CVE ์ •๋ณด๋Š” ๋ฉ”๋‰ด > Vulnerabilities์—์„œ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค.

์ด๋ ‡๊ฒŒ Vulnerabilities ์ •๋ณด๊ฐ€ ์ˆ˜์ง‘๋œ ์ดํ›„์—๋Š” ์ƒ์„ฑํ•œ Project์— ๋ณด์•ˆ ์ทจ์•ฝ์ ์ด ์žˆ๋Š”์ง€ ์กฐํšŒํ•  ์ˆ˜ ์žˆ๋‹ค. ์œ„์—์„œ ์ƒ์„ฑํ•œ SuperCalc Project์—์„œ๋Š” 85๊ฐœ์˜ ๋ณด์•ˆ ์ทจ์•ฝ์ ์ด ๋ณด๊ณ ๋œ ๊ฒƒ์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค.

์ด์™€ ๊ฐ™์€ ๋ฐฉ๋ฒ•์œผ๋กœ ๊ธฐ์—…์—์„œ ๊ฐœ๋ฐœ/๋ฐฐํฌํ•˜๋Š” ์†Œํ”„ํŠธ์›จ์–ด๋ฅผ SW360์— ๋“ฑ๋กํ•˜์—ฌ ๊ด€๋ฆฌํ•œ๋‹ค๋ฉด, ์˜คํ”ˆ์†Œ์Šค ์ปดํ”Œ๋ผ์ด์–ธ์Šค๋ฟ๋งŒ ์•„๋‹ˆ๋ผ ๋ณด์•ˆ ์ทจ์•ฝ์ ์— ๋Œ€ํ•ด์„œ๋„ ๋ฆฌ์Šคํฌ๋ฅผ ์ตœ์†Œํ™”ํ•  ์ˆ˜ ์žˆ๋Š” ํ˜•ํƒœ๋กœ ๊ด€๋ฆฌ๊ฐ€ ๊ฐ€๋Šฅํ•˜๋‹ค.

๋˜ํ•œ SW360์€ ์œ„์™€ ๊ฐ™์€ Web Interface ๋ฟ๋งŒ ์•„๋‹ˆ๋ผ ๋Œ€๋ถ€๋ถ„์˜ ๊ธฐ๋Šฅ์„ REST API๋กœ ์ œ๊ณตํ•˜์—ฌ์„œ FOSSology ๋“ฑ์˜ ๋‹ค๋ฅธ ๋„๊ตฌ์™€์˜ ์—ฐ๋™์ด ๊ฐ€๋Šฅํ•˜๋‹ค. : https://github.com/eclipse/sw360/wiki/Dev-REST-API

์ฆ‰, ์†Œ์Šค ์ฝ”๋“œ ์Šค์บ๋‹ ๋„๊ตฌ์˜ ๋ถ„์„ ๊ฒฐ๊ณผ๋ฅผ SW360์— Import ์‹œํ‚ค๋Š” ๋“ฑ์˜ ๋ฐฉ๋ฒ•์œผ๋กœ DevOps์— Integration ์‹œ์ผœ์„œ Project, Release ๋“ฑ๋ก์„ ์ž๋™ํ™”์‹œ์ผœ์„œ ๊ด€๋ฆฌํ•œ๋‹ค๋ฉด ํšจ์œจ์„ฑ์ด ํฌ๊ฒŒ ์ฆ๊ฐ€๋  ๊ฒƒ์ด๋‹ค.