31st Meeting
Software Supply Chain Security and Open Source Governance
We look at the state of open source governance at CJ Group, how an open source management framework runs from an operations team's perspective, and tools for software supply chain security.
Directions Google Maps Naver Map Kakao Map
Registration and the detailed program are announced via the OpenChain KWG mailing list. Subscribe to receive the sign-up link.
- OpenChain
- EU CRA
- OSS Governance
- Supply Chain Security
- SBOM
Who Should Attend
- Practitioners preparing for ISO 5230 or ISO 18974 self-certification, or working out the scope of their EU Cyber Resilience Act (CRA) response
- Organizations looking to streamline open source management and cut operational load with tooling
- Teams starting on software supply chain security or needing to verify SBOMs received from suppliers
- Anyone who wants to hear other companies’ cases and expand their practitioner network
Sponsor

Agenda
CJ Group's open source governance framework, told through three core topics: certification status across the group, data contributions to the OSSORI project, and the response to the EU Cyber Resilience Act (CRA).
Experience running OSS Governance across CJ Group's many organizations and affiliates, and how it grew into a framework that carries on even when the people change.
An introduction to Trusted OSS, an initiative that began in the KWG community, and BomLens, released by SK telecom. The talk covers what tools can take over: producing ISO 5230 and ISO 18974 self-certification artifacts (Trusted OSS Agents), running a self-hosted software composition analysis portal (TRUSCA), and generating and checking supplier SBOMs (BomLens).
Slides (PDF)Session titles and times may change as preparation continues. Confirmed details will be published on this page and announced via the mailing list.
Speakers

Leads OpenChain Project standards and the global community.

Open source and patent management for CJ Group.

Runs the open source management system for CJ Group.

Open Source Program Manager at SK telecom and OpenChain Ambassador.
OpenChain Updates: Global Highlights
Highlights Mary Wang shared during the OpenChain Updates segment.
- The OpenChain Community Day, OSPOlogy, and the OSPO Summit were all successfully completed.
- RC1 of the OpenChain CRA Requirement & Checklist has been released for review, with Version 1.0 targeted for September 11. Many companies and OpenChain partners have shown strong interest and would like to collaborate. (GitHub)
- The SBOM Quality Guide has received several PRs after the public review comment period, and Kobotasan and the community continue to work on it.
- The Automotive SBOM framework 1.1 is open for public review, with a PR release planned for October.
Group Discussion Topics
Common topics for the 15:10–15:55 group discussion. Each group may pick one or two topics of most interest and go deeper.
Topic A. AI Licensing and Open Source Governance in the AI Era
- How do you actually review the licensing obligations for the weights and datasets of open models (e.g., Llama)?
- How does your organization handle the copyright, licensing, and security risks of code generated by AI coding assistants?
- What does an AI-era governance framework (policy, review, evidence) look like, and how does it differ from existing open source governance?
Topic B. Internal Open Source Compliance Process and Certification
- What’s the next step for organizations just starting a process versus those maturing one? How do you divide roles and responsibilities (R&R) across teams?
- What are the key checkpoints for ISO/IEC 5230 (OpenChain) certification prep, or for audit response in finance and other regulated industries?
- How do you handle review quality dropping under release-schedule pressure, or cases where license identification is hard (no LICENSE file, mismatched notices across headers/package metadata/individual sources, or confusion over whether a dual license is “or” or “and”)?
Topic C. SBOM, Vulnerability Management, and Tooling Automation
- How far is your open source review pipeline automated, and where does manual work still remain?
- What’s your criterion for identifying which items in an SBOM actually require notice? How do you compensate for the difficulty of finding reference cases for risk response?
- What’s your approach to vulnerability management, and how did you get past the barriers to tool adoption (false positives, performance, operational overhead)?
Dinner After the Meeting
A dinner gathering follows the regular meeting. Attendance is optional, and details will be announced via the mailing list.
![[2026 September] OpenChain Korea Work Group in CJ](https://live.staticflickr.com/65535/55516924083_4b364c5ce4_b.jpg)