Blog
CISA 2026 SBOM Minimum Elements: What to Prepare and Which Tools Fill the Gaps
Sunday, August 09, 2026 in 2026
Categories:
This article was written with Claude Code, and the key facts cited here were cross-checked against primary sources. Summary On July 29, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) and 17 other agencies published a revised set …
What the US AI Executive Order (2026-06-02) Means for Enterprise Open Source Managers
Wednesday, June 10, 2026 in 2026
Categories:
This article was written with Claude Code, and the key facts cited here were cross-checked against primary sources. Summary The executive order “Promoting Advanced Artificial Intelligence Innovation and Security,” signed on June 2, 2026, …
The EU Open Source Strategy: Institutionalizing Open Source for Tech Sovereignty
Tuesday, June 09, 2026 in 2026
Categories:
This article was written with Claude Code, and the key facts cited here were cross-checked against primary sources. Summary The European Commission’s “Communication on European Tech Sovereignty” (COM(2026) 503 final), published on …
AI-Generated Code: How Far Should Open-Source Scanning Go?
Monday, June 08, 2026 in 2026
Categories:
About this article This article was written with the help of Claude Code, and its key facts were cross-checked against public sources. Disclaimer This article reflects the author’s personal analysis and is not legal advice. The cited facts were …
EU Cyber Resilience Act (CRA) Vulnerability Reporting Obligations — A Research Report for the 2026-09-11 Compliance Date
Monday, May 18, 2026 in 2026
Categories:
This article was written with Claude Code, and the key facts cited here were cross-checked against primary sources. Summary The EU Cyber Resilience Act (Cyber Resilience Act, CRA — Regulation (EU) 2024/2847) is the EU’s first comprehensive …
Rockchip and FFmpeg: A License Dispute Case Study
Friday, February 20, 2026 in 2026
Categories:

This article was written using Claude Code, and the key facts cited were cross-verified against primary sources. Notice This article reflects the author’s personal analysis and summary, and does not constitute legal advice. The facts cited …
The AVM Lawsuit: Revisiting LGPL-2.1 User Rights and the Obligation to Provide Installation Information
Monday, January 13, 2025 in 2025
Categories:

This post is based on Ars Technica’s article “German router maker is latest company to inadvertently clarify the LGPL license”. The article covers the details of the lawsuit between AVM and Sebastian Steck and the importance of …
What the Oracle v. Rimini Street Case Tells Us About the Scope of GPL Derivative Works
Monday, December 23, 2024 in 2024
Categories:

Introduction In disputes over software intellectual property infringement, the concept of “derivative works” is critically important. This concept becomes a central issue especially when dealing with open source licenses such as the GNU …
Key Points of the EU's Three Major Digital Regulations That Korean Software Companies Need to Know
Tuesday, November 12, 2024 in 2024
Categories:

Introduction Three major pieces of legislation the European Union (EU) has recently introduced carry very significant implications for Korean companies. The Product Liability Directive (PLD), the Cyber Resilience Act (CRA), and the AI Act present a …
To Mine or Not To Mine: A German Court's Ruling on the Copyright Dilemma of the AI Era
Wednesday, November 06, 2024 in 2024
Categories:

This post is based on JBB Rechtsanwält:innen’s blog post “To Mine or Not To Mine” (https://jbb.de/to-mine-or-not-to-mine/) and is published to explain a recent German court ruling on text and data mining (TDM) and to share related …