<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>2026 on OpenChain KWG</title><link>https://OpenChain-Project.github.io/OpenChain-KWG/en/blog/2026/</link><description>Recent content in 2026 on OpenChain KWG</description><generator>Hugo</generator><language>en</language><atom:link href="https://OpenChain-Project.github.io/OpenChain-KWG/en/blog/2026/index.xml" rel="self" type="application/rss+xml"/><item><title>CISA 2026 SBOM Minimum Elements: What to Prepare and Which Tools Fill the Gaps</title><link>https://OpenChain-Project.github.io/OpenChain-KWG/en/blog/2026/08/09/cisa-sbom-minimum-elements/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://OpenChain-Project.github.io/OpenChain-KWG/en/blog/2026/08/09/cisa-sbom-minimum-elements/</guid><description>&lt;div class="alert alert-info" role="alert"&gt;
&lt;p&gt;This article was written with Claude Code, and the key facts cited here were cross-checked against primary sources.&lt;/p&gt;
&lt;/div&gt;
&lt;h2 id="summary"&gt;Summary&lt;/h2&gt;
&lt;p&gt;On July 29, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) and 17 other agencies published a revised set of minimum elements for a Software Bill of Materials (SBOM)&lt;a id="a2-ref-1"&gt;&lt;/a&gt;&lt;a href="https://OpenChain-Project.github.io/OpenChain-KWG/en/blog/2026/08/09/cisa-sbom-minimum-elements/#a2"&gt;A2&lt;/a&gt;. The document states plainly that it replaces, rather than amends, the baseline established in 2021 by the National Telecommunications and Information Administration (NTIA).&lt;/p&gt;</description></item><item><title>What the US AI Executive Order (2026-06-02) Means for Enterprise Open Source Managers</title><link>https://OpenChain-Project.github.io/OpenChain-KWG/en/blog/2026/06/10/us-ai-eo-ospo/</link><pubDate>Wed, 10 Jun 2026 00:00:00 +0000</pubDate><guid>https://OpenChain-Project.github.io/OpenChain-KWG/en/blog/2026/06/10/us-ai-eo-ospo/</guid><description>&lt;div class="alert alert-info" role="alert"&gt;
&lt;p&gt;This article was written with Claude Code, and the key facts cited here were cross-checked against primary sources.&lt;/p&gt;
&lt;/div&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Summary&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The executive order &amp;ldquo;Promoting Advanced Artificial Intelligence Innovation and Security,&amp;rdquo; signed on June 2, 2026, imposes no obligations on enterprises. Its substance is the Treasury Department-led AI Cybersecurity Clearinghouse (a relay body that pools, verifies, and distributes vulnerability information, to be established within 30 days) and a voluntary pre-disclosure framework for frontier models (to be designed within 60 days); mandatory licensing and pre-approval are explicitly excluded &lt;a id="a1-ref-1"&gt;&lt;/a&gt;&lt;a href="https://OpenChain-Project.github.io/OpenChain-KWG/en/blog/2026/06/10/us-ai-eo-ospo/#a1"&gt;A1&lt;/a&gt;. No provision applies directly to enterprise open source managers either. Still, there is a reason to read this order: the context behind it. AI finding open source vulnerabilities faster than humans do has already become reality. Ahead of the executive order, an unreleased Anthropic model found 6,202 high- or critical-severity vulnerabilities in open source projects over two months, and patching has not kept pace &lt;a id="a6-ref-1"&gt;&lt;/a&gt;&lt;a href="https://OpenChain-Project.github.io/OpenChain-KWG/en/blog/2026/06/10/us-ai-eo-ospo/#a6"&gt;A6&lt;/a&gt;·&lt;a id="c1-ref-1"&gt;&lt;/a&gt;&lt;a href="https://OpenChain-Project.github.io/OpenChain-KWG/en/blog/2026/06/10/us-ai-eo-ospo/#c1"&gt;C1&lt;/a&gt;. What open source managers need to prepare is not compliance with the executive order, but a response system that can handle a check of patch-processing capacity, cleanup of end-of-life (EOL) components, and the EU Cyber Resilience Act reporting obligation taking effect September 11, 2026, all at once.&lt;/p&gt;</description></item><item><title>The EU Open Source Strategy: Institutionalizing Open Source for Tech Sovereignty</title><link>https://OpenChain-Project.github.io/OpenChain-KWG/en/blog/2026/06/09/eu-oss-strategy/</link><pubDate>Tue, 09 Jun 2026 00:00:00 +0000</pubDate><guid>https://OpenChain-Project.github.io/OpenChain-KWG/en/blog/2026/06/09/eu-oss-strategy/</guid><description>&lt;div class="alert alert-info" role="alert"&gt;
&lt;p&gt;This article was written with Claude Code, and the key facts cited here were cross-checked against primary sources.&lt;/p&gt;
&lt;/div&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Summary&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The European Commission&amp;rsquo;s &amp;ldquo;Communication on European Tech Sovereignty&amp;rdquo; (COM(2026) 503 final), published on June 3, 2026, comes with an EU Open Source Strategy attached. It is the first time open source has been placed at the center of EU digital policy. The strategy sets four objectives — leveraging open source for sovereignty, strengthening the ecosystem, opening up public administration, and reinforcing standards and international cooperation — and calls for roughly EUR 2 billion in public and private funding to be mobilized for open-source-related measures over the next seven years. The aim is to reduce the EU&amp;rsquo;s dependence on US proprietary IT, on which it spends an estimated EUR 264 billion annually. Civil society (FSFE) and policy analysts have welcomed the direction while flagging limits: whether the funding is sufficient, how open standards relate to open source, the light treatment of open hardware, and the practitioner skills gap. For Korean public-sector and enterprise practitioners, the points worth watching directly are the opening of EU procurement, the open-source steward regulation, and the open-source default for the EUDI Wallet.&lt;/p&gt;</description></item><item><title>AI-Generated Code: How Far Should Open-Source Scanning Go?</title><link>https://OpenChain-Project.github.io/OpenChain-KWG/en/blog/2026/06/08/ai-snippet-scan/</link><pubDate>Mon, 08 Jun 2026 00:00:00 +0000</pubDate><guid>https://OpenChain-Project.github.io/OpenChain-KWG/en/blog/2026/06/08/ai-snippet-scan/</guid><description>&lt;div class="alert alert-info" role="alert"&gt;&lt;div class="h4 alert-heading" role="heading"&gt;About this article&lt;/div&gt;
&lt;p&gt;This article was written with the help of Claude Code, and its key facts were cross-checked against public sources.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="alert alert-warning" role="alert"&gt;&lt;div class="h4 alert-heading" role="heading"&gt;Disclaimer&lt;/div&gt;
&lt;p&gt;This article reflects the author&amp;rsquo;s personal analysis and is not legal advice. The cited facts were verified against public sources, but for any specific situation please consult a qualified professional such as an attorney.&lt;/p&gt;
&lt;/div&gt;
&lt;h2 id="first-one-thing-to-get-straight"&gt;First, one thing to get straight&lt;/h2&gt;
&lt;p&gt;There is no quick yes-or-no answer to this question, because the deciding factor is not AI itself — as we will see. AI coding raises the rate at which code fragments enter a codebase without being declared as packages, but it does not change the conditions under which a license obligation arises. So instead of asking &amp;ldquo;does scanning still matter in the AI era,&amp;rdquo; it helps to ask &amp;ldquo;under what conditions does snippet-level scanning matter more, and under what conditions less.&amp;rdquo;&lt;/p&gt;</description></item><item><title>EU Cyber Resilience Act (CRA) Vulnerability Reporting Obligations — A Research Report for the 2026-09-11 Compliance Date</title><link>https://OpenChain-Project.github.io/OpenChain-KWG/en/blog/2026/05/18/eu-cra/</link><pubDate>Mon, 18 May 2026 00:00:00 +0000</pubDate><guid>https://OpenChain-Project.github.io/OpenChain-KWG/en/blog/2026/05/18/eu-cra/</guid><description>&lt;div class="alert alert-info" role="alert"&gt;
&lt;p&gt;This article was written with Claude Code, and the key facts cited here were cross-checked against primary sources.&lt;/p&gt;
&lt;/div&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Summary&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The EU Cyber Resilience Act (Cyber Resilience Act, CRA — Regulation (EU) 2024/2847) is the EU&amp;rsquo;s first comprehensive product security regulation, imposing horizontal cybersecurity obligations on every &amp;ldquo;product with digital elements&amp;rdquo; (PDE) placed on the EU market. The regulation entered into force on December 10, 2024, and applies in phases. From September 11, 2026, the Article 14 reporting obligations take effect, requiring manufacturers, importers, and distributors to notify ENISA (the European Union Agency for Cybersecurity) and Member State CSIRTs of actively exploited vulnerabilities and severe incidents within a staged 24-hour, 72-hour, and 14-day window. Companies that have not stood up a reporting workflow by this date face fines of up to €15 million or 2.5% of worldwide annual turnover, and Korean companies that place products on the EU market are subject to the obligation immediately. &lt;a id="a1-ref-1"&gt;&lt;/a&gt;&lt;a href="https://OpenChain-Project.github.io/OpenChain-KWG/en/blog/2026/05/18/eu-cra/#a1"&gt;A1&lt;/a&gt;, &lt;a id="b1-ref-1"&gt;&lt;/a&gt;&lt;a href="https://OpenChain-Project.github.io/OpenChain-KWG/en/blog/2026/05/18/eu-cra/#b1"&gt;B1&lt;/a&gt;, &lt;a id="e1-ref-1"&gt;&lt;/a&gt;&lt;a href="https://OpenChain-Project.github.io/OpenChain-KWG/en/blog/2026/05/18/eu-cra/#e1"&gt;E1&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Rockchip and FFmpeg: A License Dispute Case Study</title><link>https://OpenChain-Project.github.io/OpenChain-KWG/en/blog/2026/02/20/ffmpeg/</link><pubDate>Fri, 20 Feb 2026 00:00:00 +0000</pubDate><guid>https://OpenChain-Project.github.io/OpenChain-KWG/en/blog/2026/02/20/ffmpeg/</guid><description>&lt;div class="alert alert-info" role="alert"&gt;
&lt;p&gt;This article was written using Claude Code, and the key facts cited were cross-verified against primary sources.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="alert alert-warning" role="alert"&gt;&lt;div class="h4 alert-heading" role="heading"&gt;Notice&lt;/div&gt;
&lt;p&gt;This article reflects the author&amp;rsquo;s personal analysis and summary, and does not constitute legal advice. The facts cited have been verified based on publicly available sources, but legal determinations such as whether infringement has occurred are matters that can be disputed, so please have specific matters reviewed by an attorney or other expert.&lt;/p&gt;</description></item></channel></rss>