<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>2024 on OpenChain KWG</title><link>https://OpenChain-Project.github.io/OpenChain-KWG/en/blog/2024/</link><description>Recent content in 2024 on OpenChain KWG</description><generator>Hugo</generator><language>en</language><atom:link href="https://OpenChain-Project.github.io/OpenChain-KWG/en/blog/2024/index.xml" rel="self" type="application/rss+xml"/><item><title>What the Oracle v. Rimini Street Case Tells Us About the Scope of GPL Derivative Works</title><link>https://OpenChain-Project.github.io/OpenChain-KWG/en/blog/2024/12/23/oracle-rimini/</link><pubDate>Mon, 23 Dec 2024 00:00:00 +0000</pubDate><guid>https://OpenChain-Project.github.io/OpenChain-KWG/en/blog/2024/12/23/oracle-rimini/</guid><description>&lt;h2 id="introduction"&gt;&lt;strong&gt;Introduction&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;In disputes over software intellectual property infringement, the concept of &amp;ldquo;derivative works&amp;rdquo; is critically important. This concept becomes a central issue especially when dealing with open source licenses such as the &lt;a href="https://www.gnu.org/licenses/gpl-3.0.html"&gt;GNU General Public License (GPL)&lt;/a&gt;. The recent litigation between &lt;a href="https://www.oracle.com/"&gt;Oracle&lt;/a&gt; and &lt;a href="https://www.riministreet.com/"&gt;Rimini Street&lt;/a&gt; has drawn renewed attention to the legal interpretation of what counts as a derivative work. This article looks at the background of the case, the key rulings, and the implications for open source licensing.&lt;/p&gt;</description></item><item><title>Key Points of the EU's Three Major Digital Regulations That Korean Software Companies Need to Know</title><link>https://OpenChain-Project.github.io/OpenChain-KWG/en/blog/2024/11/12/eu-regulation/</link><pubDate>Tue, 12 Nov 2024 00:00:00 +0000</pubDate><guid>https://OpenChain-Project.github.io/OpenChain-KWG/en/blog/2024/11/12/eu-regulation/</guid><description>&lt;h2 id="introduction"&gt;Introduction&lt;/h2&gt;
&lt;p&gt;Three major pieces of legislation the European Union (EU) has recently introduced carry very significant implications for Korean companies. The &lt;a href="https://ec.europa.eu/info/business-economy-euro/doing-business-eu/contract-rules/digital-contracts/liability-rules-artificial-intelligence_en"&gt;Product Liability Directive (PLD)&lt;/a&gt;, the &lt;a href="https://digital-strategy.ec.europa.eu/en/library/cyber-resilience-act"&gt;Cyber Resilience Act (CRA)&lt;/a&gt;, and the &lt;a href="https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai"&gt;AI Act&lt;/a&gt; present a comprehensive regulatory framework governing the development, deployment, and use of software and AI systems.&lt;/p&gt;
&lt;p&gt;These pieces of legislation matter to Korean companies for the following reasons:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Access to the EU market&lt;/strong&gt;: The EU is one of the largest single markets in the world, and many Korean companies aim to enter it. Failure to comply with these laws can restrict access to the EU market.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Setting a global standard&lt;/strong&gt;: EU regulation tends to become a de facto global standard. This is the so-called &amp;lsquo;&lt;a href="https://en.wikipedia.org/wiki/Brussels_effect"&gt;Brussels effect&lt;/a&gt;&amp;rsquo;, and other countries are likely to introduce similar regulations.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Expanded corporate liability&lt;/strong&gt;: These laws significantly expand the scope of corporate liability. In particular, the strict liability principle under the PLD could pose a new challenge for Korean companies.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Important perspectives for Korean companies to keep in mind when approaching these laws include the following:&lt;/p&gt;</description></item><item><title>To Mine or Not To Mine: A German Court's Ruling on the Copyright Dilemma of the AI Era</title><link>https://OpenChain-Project.github.io/OpenChain-KWG/en/blog/2024/11/06/germany-ai-lawsuit/</link><pubDate>Wed, 06 Nov 2024 00:00:00 +0000</pubDate><guid>https://OpenChain-Project.github.io/OpenChain-KWG/en/blog/2024/11/06/germany-ai-lawsuit/</guid><description>&lt;p&gt;This post is based on JBB Rechtsanwält:innen&amp;rsquo;s blog post &amp;ldquo;To Mine or Not To Mine&amp;rdquo; (&lt;a href="https://jbb.de/to-mine-or-not-to-mine/"&gt;https://jbb.de/to-mine-or-not-to-mine/&lt;/a&gt;) and is published to explain a recent German court ruling on text and data mining (TDM) and to share related knowledge.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Please note that I am not a legal professional, and this content cannot serve as a legal basis. For specific situations related to license and legal issues, please be sure to seek advice from a legal professional.&lt;/p&gt;</description></item><item><title>A Chinese Copyright Infringement Case: "Since GPL-Based Software Products Already Have an Obligation to Disclose Source Anyway, Isn't It Fine to Copy Them?"</title><link>https://OpenChain-Project.github.io/OpenChain-KWG/en/blog/2024/09/23/gpl-openwrt/</link><pubDate>Mon, 23 Sep 2024 00:00:00 +0000</pubDate><guid>https://OpenChain-Project.github.io/OpenChain-KWG/en/blog/2024/09/23/gpl-openwrt/</guid><description>&lt;p&gt;As the use of open source software has spread widely, the legal issues surrounding it have grown increasingly complex. In particular, the question of copyright over derivative works based on open source projects that use a copyleft license such as GPL (GNU General Public License) is a thorny subject for many companies. A recent software copyright infringement lawsuit in China offers important implications for this issue.&lt;/p&gt;
&lt;h2 id="parties-to-the-lawsuit"&gt;Parties to the Lawsuit&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Plaintiff: Wangjing Technology (Wangjing)&lt;/li&gt;
&lt;li&gt;Defendants:
&lt;ul&gt;
&lt;li&gt;Yibang Communication Technology (Yibang)&lt;/li&gt;
&lt;li&gt;Qi&amp;rsquo;ao Network Technology (Qi&amp;rsquo;ao)&lt;/li&gt;
&lt;li&gt;and three individuals (Liu, Wu, Xie)&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="overview-of-the-case"&gt;Overview of the Case&lt;/h2&gt;
&lt;p&gt;In 2009, Wangjing developed a converged communication smart gateway product called &amp;ldquo;OfficeTen.&amp;rdquo;&lt;/p&gt;</description></item><item><title>Elasticsearch Changes Its License Again: How Should Companies Respond?</title><link>https://OpenChain-Project.github.io/OpenChain-KWG/en/blog/2024/09/06/elastic-agpl/</link><pubDate>Fri, 06 Sep 2024 00:00:00 +0000</pubDate><guid>https://OpenChain-Project.github.io/OpenChain-KWG/en/blog/2024/09/06/elastic-agpl/</guid><description>&lt;h2 id="introduction-the-background-of-the-elasticsearch-license"&gt;Introduction: The Background of the Elasticsearch License&lt;/h2&gt;
&lt;p&gt;Elasticsearch began as an open source project and has since gone through several changes in licensing policy. Initially it was distributed under the Apache 2.0 license, but in 2021 Elastic changed its license to the Elastic License 2.0 and the Server Side Public License. Then, on August 30, 2024, it drew attention again with an announcement (&lt;a href="https://www.elastic.co/blog/elasticsearch-is-open-source-again"&gt;Elasticsearch is Open Source, Again&lt;/a&gt;) adding back the &lt;strong&gt;AGPL-3.0&lt;/strong&gt;.&lt;/p&gt;</description></item><item><title>Introduction to SPDX 3.0 and Enterprise Adoption Strategy</title><link>https://OpenChain-Project.github.io/OpenChain-KWG/en/blog/2024/09/06/spdx-30/</link><pubDate>Fri, 06 Sep 2024 00:00:00 +0000</pubDate><guid>https://OpenChain-Project.github.io/OpenChain-KWG/en/blog/2024/09/06/spdx-30/</guid><description>&lt;h2 id="1-introduction-to-spdx-30"&gt;1. Introduction to SPDX 3.0&lt;/h2&gt;
&lt;p&gt;SPDX (Software Package Data Exchange) is an open standard for communicating software component, license, copyright, and security information in a standardized way. SPDX 3.0 is the latest version of this standard, released in April 2024, and is a major update that significantly improves the transparency and security of the software supply chain[2].&lt;/p&gt;
&lt;p&gt;&lt;img src="https://OpenChain-Project.github.io/OpenChain-KWG/en/blog/2024/09/06/spdx-30/featured_SPDX30.png" alt=""&gt;&lt;/p&gt;
&lt;h3 id="definition-and-purpose-of-spdx"&gt;Definition and Purpose of SPDX&lt;/h3&gt;
&lt;p&gt;SPDX is a Linux Foundation project that provides a standard format for sharing important information related to software packages. Its main purposes are as follows:&lt;/p&gt;</description></item><item><title>French Court Orders Major Telecom Orange to Pay Damages for GPL Violation</title><link>https://OpenChain-Project.github.io/OpenChain-KWG/en/blog/2024/02/19/orange-lasso/</link><pubDate>Mon, 19 Feb 2024 00:00:00 +0000</pubDate><guid>https://OpenChain-Project.github.io/OpenChain-KWG/en/blog/2024/02/19/orange-lasso/</guid><description>&lt;p&gt;Hello.&lt;/p&gt;
&lt;p&gt;Today I want to look at a case in which a French court ordered the telecom company Orange to pay damages for violating the GPL. This case seemed especially worth noting for two main reasons.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;First, the defendant in this case is Orange, a major telecom operator. (Since I work at a telecom operator myself&amp;hellip;)&lt;/li&gt;
&lt;li&gt;Second, while GPL violation lawsuits mostly arise in embedded devices, in this case the open source at issue was used to build a B2B web service. This underscores that open source license compliance matters across every area of software development.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Through these aspects, this case looks set to reaffirm the importance of open source license compliance. It stands as an important example emphasizing that companies must thoroughly understand and comply with license requirements when using open source.&lt;/p&gt;</description></item></channel></rss>