Blog
CISA 2026 SBOM Minimum Elements: What to Prepare and Which Tools Fill the Gaps
Sunday, August 09, 2026 in 2026
An analysis of the revised SBOM minimum elements published on July 29, 2026 by CISA and 17 other agencies. The data fields grew from 7 to 17, and licensing entered the minimum baseline for the first time. Covers what an OSPO must decide before …
What the US AI Executive Order (2026-06-02) Means for Enterprise Open Source Managers
Wednesday, June 10, 2026 in 2026
An analysis of the US AI executive order signed on June 2, 2026, based on primary sources. Covers what the AI Cybersecurity Clearinghouse and the voluntary frontier model framework mean for enterprise open source managers, how they contrast with the …
The EU Open Source Strategy: Institutionalizing Open Source for Tech Sovereignty
Tuesday, June 09, 2026 in 2026
An analysis of the EU Open Source Strategy (COM(2026) 503), published by the European Commission on June 3, 2026, based on primary sources. Covers the four objectives, the seven-year EUR 2 billion mobilization, the governance structure, civil-society …
AI-Generated Code: How Far Should Open-Source Scanning Go?
Monday, June 08, 2026 in 2026
Whether AI-generated code needs snippet-level open-source license scanning — the decision factors, grounded in public sources, and how this differs from security-vulnerability scanning.
EU Cyber Resilience Act (CRA) Vulnerability Reporting Obligations — A Research Report for the 2026-09-11 Compliance Date
Monday, May 18, 2026 in 2026
The EU Cyber Resilience Act (CRA) brings its Article 14 reporting obligations into force on September 11, 2026. This article draws primarily on primary sources to lay out how Korean companies should prepare for the 24-hour, 72-hour, and 14-day …
Rockchip and FFmpeg: A License Dispute Case Study
Friday, February 20, 2026 in 2026

This article was written using Claude Code, and the key facts cited were cross-verified against primary sources. Notice This article reflects the author’s personal analysis and summary, and does not constitute legal advice. The facts cited …
The AVM Lawsuit: Revisiting LGPL-2.1 User Rights and the Obligation to Provide Installation Information
Monday, January 13, 2025 in 2025

This post is based on Ars Technica’s article “German router maker is latest company to inadvertently clarify the LGPL license”. The article covers the details of the lawsuit between AVM and Sebastian Steck and the importance of …
What the Oracle v. Rimini Street Case Tells Us About the Scope of GPL Derivative Works
Monday, December 23, 2024 in 2024

Introduction In disputes over software intellectual property infringement, the concept of “derivative works” is critically important. This concept becomes a central issue especially when dealing with open source licenses such as the GNU …
Key Points of the EU's Three Major Digital Regulations That Korean Software Companies Need to Know
Tuesday, November 12, 2024 in 2024

Introduction Three major pieces of legislation the European Union (EU) has recently introduced carry very significant implications for Korean companies. The Product Liability Directive (PLD), the Cyber Resilience Act (CRA), and the AI Act present a …
To Mine or Not To Mine: A German Court's Ruling on the Copyright Dilemma of the AI Era
Wednesday, November 06, 2024 in 2024

This post is based on JBB Rechtsanwält:innen’s blog post “To Mine or Not To Mine” (https://jbb.de/to-mine-or-not-to-mine/) and is published to explain a recent German court ruling on text and data mining (TDM) and to share related …