31st Meeting

Software Supply Chain Security and Open Source Governance

We look at the state of open source governance at CJ Group, how an open source management framework runs from an operations team's perspective, and tools for software supply chain security.

Date 2026-09-08 (Tue) 14:00–17:00 Venue CJ Human Resources Development Center · Jung-gu, Seoul

Directions Google Maps Naver Map Kakao Map

Registration and the detailed program are announced via the OpenChain KWG mailing list. Subscribe to receive the sign-up link.

08 Sep 2026 · Tue
  • OpenChain
  • EU CRA
  • OSS Governance
  • Supply Chain Security
  • SBOM

Who Should Attend

  • Practitioners preparing for ISO 5230 or ISO 18974 self-certification, or working out the scope of their EU Cyber Resilience Act (CRA) response
  • Organizations looking to streamline open source management and cut operational load with tooling
  • Teams starting on software supply chain security or needing to verify SBOMs received from suppliers
  • Anyone who wants to hear other companies’ cases and expand their practitioner network
Sponsored by CJ

Agenda

14:00–14:10
Welcome & Greetings
Seowoo Kim, Managing Director · CJ
14:10–14:30
OpenChain Updates
Mary Wang, Executive Director · Linux Foundation / KWG Steering Committee
KWG Update (PDF)
14:30–14:55
Session 1. The State of Open Source Governance at CJ Group
Kiyoung Sung, Patent Attorney · CJ

CJ Group's open source governance framework, told through three core topics: certification status across the group, data contributions to the OSSORI project, and the response to the EU Cyber Resilience Act (CRA).

14:55–15:10
Break & Networking
Coffee break
15:10–15:55
Group Discussion
All Participants
15:55–16:20
Session 2. OSS Governance That Centers People and Grows with the System
Byeongseok Choi, General Manager · Olive Networks

Experience running OSS Governance across CJ Group's many organizations and affiliates, and how it grew into a framework that carries on even when the people change.

16:20–16:45
Session 3. Open Source Supply Chain Security Tools: Trusted OSS, TRUSCA, and BomLens
Haksung Jang · SK telecom

An introduction to Trusted OSS, an initiative that began in the KWG community, and BomLens, released by SK telecom. The talk covers what tools can take over: producing ISO 5230 and ISO 18974 self-certification artifacts (Trusted OSS Agents), running a self-hosted software composition analysis portal (TRUSCA), and generating and checking supplier SBOMs (BomLens).

Slides (PDF)
16:45–17:00
Closing & Group Photo
KWG Steering Committee

Session titles and times may change as preparation continues. Confirmed details will be published on this page and announced via the mailing list.

Speakers

Mary Wang
Mary Wang, Executive Director
Linux Foundation · OpenChain Updates

Leads OpenChain Project standards and the global community.

Kiyoung Sung
Kiyoung Sung, Patent Attorney
CJ Corporation · Session 1

Open source and patent management for CJ Group.

Byeongseok Choi
Byeongseok Choi, General Manager
CJ OliveNetworks · Session 2

Runs the open source management system for CJ Group.

Haksung Jang
Haksung Jang, Manager
SK telecom · Session 3

Open Source Program Manager at SK telecom and OpenChain Ambassador.

OpenChain Updates: Global Highlights

Highlights Mary Wang shared during the OpenChain Updates segment.

  • The OpenChain Community Day, OSPOlogy, and the OSPO Summit were all successfully completed.
  • RC1 of the OpenChain CRA Requirement & Checklist has been released for review, with Version 1.0 targeted for September 11. Many companies and OpenChain partners have shown strong interest and would like to collaborate. (GitHub)
  • The SBOM Quality Guide has received several PRs after the public review comment period, and Kobotasan and the community continue to work on it.
  • The Automotive SBOM framework 1.1 is open for public review, with a PR release planned for October.

Group Discussion Topics

Common topics for the 15:10–15:55 group discussion. Each group may pick one or two topics of most interest and go deeper.

Topic A. AI Licensing and Open Source Governance in the AI Era

  • How do you actually review the licensing obligations for the weights and datasets of open models (e.g., Llama)?
  • How does your organization handle the copyright, licensing, and security risks of code generated by AI coding assistants?
  • What does an AI-era governance framework (policy, review, evidence) look like, and how does it differ from existing open source governance?

Topic B. Internal Open Source Compliance Process and Certification

  • What’s the next step for organizations just starting a process versus those maturing one? How do you divide roles and responsibilities (R&R) across teams?
  • What are the key checkpoints for ISO/IEC 5230 (OpenChain) certification prep, or for audit response in finance and other regulated industries?
  • How do you handle review quality dropping under release-schedule pressure, or cases where license identification is hard (no LICENSE file, mismatched notices across headers/package metadata/individual sources, or confusion over whether a dual license is “or” or “and”)?

Topic C. SBOM, Vulnerability Management, and Tooling Automation

  • How far is your open source review pipeline automated, and where does manual work still remain?
  • What’s your criterion for identifying which items in an SBOM actually require notice? How do you compensate for the difficulty of finding reference cases for risk response?
  • What’s your approach to vulnerability management, and how did you get past the barriers to tool adoption (false positives, performance, operational overhead)?

Dinner After the Meeting

A dinner gathering follows the regular meeting. Attendance is optional, and details will be announced via the mailing list.

Album

[2026 September] OpenChain Korea Work Group in CJ