<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>TRUSCA on OpenChain KWG</title><link>https://OpenChain-Project.github.io/OpenChain-KWG/en/tags/trusca/</link><description>Recent content in TRUSCA on OpenChain KWG</description><generator>Hugo</generator><language>en</language><atom:link href="https://OpenChain-Project.github.io/OpenChain-KWG/en/tags/trusca/index.xml" rel="self" type="application/rss+xml"/><item><title>TRUSCA</title><link>https://OpenChain-Project.github.io/OpenChain-KWG/en/guide/tools/11-trusca/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://OpenChain-Project.github.io/OpenChain-KWG/en/guide/tools/11-trusca/</guid><description>&lt;p&gt;Managing the vulnerabilities and licenses of open source components calls for an SCA (Software Composition Analysis) tool. Several commercial products exist, but some organizations look for an open source tool they can install and run on their own infrastructure.&lt;/p&gt;&#10;&lt;p&gt;TRUSCA is a self-hosted SCA portal published for that purpose. Released under Apache 2.0, it brings vulnerabilities (CVE), license compliance, and SBOM management into a single screen. It is developed by &lt;a href="https://OpenChain-Project.github.io/OpenChain-KWG/en/guide/trustedoss/"&gt;TrustedOSS&lt;/a&gt;, a project that grew out of KWG community work.&lt;/p&gt;</description></item><item><title>TrustedOSS</title><link>https://OpenChain-Project.github.io/OpenChain-KWG/en/guide/trustedoss/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://OpenChain-Project.github.io/OpenChain-KWG/en/guide/trustedoss/</guid><description>&lt;div class="pageinfo pageinfo-primary"&gt;&#10;&lt;p&gt;TrustedOSS grew out of KWG community work and was published by the author of this guide.&#10;Its documentation is released under CC BY 4.0 and its code under MIT and Apache 2.0.&lt;/p&gt;&#10;&lt;p&gt;&lt;strong&gt;Site: &lt;a href="https://trustedoss.github.io/en/"&gt;https://trustedoss.github.io/en/&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;&#10;&#10;&lt;/div&gt;&#10;&#10;&lt;p&gt;TrustedOSS covers four areas.&lt;/p&gt;&#10;&lt;h2 id="generating-self-certification-deliverables"&gt;Generating self-certification deliverables&lt;/h2&gt;&#10;&lt;p&gt;It produces the documents required for ISO/IEC 5230 and ISO/IEC 18974 self-certification&#10;through a conversation with an AI agent: organizational setup, policy, processes, SBOM&#10;analysis, vulnerability reports, training curricula, and a draft conformance statement.&#10;It follows the same six steps described in the&#10;&lt;a href="https://OpenChain-Project.github.io/OpenChain-KWG/en/guide/opensource_for_enterprise/"&gt;open source management guide&lt;/a&gt;.&lt;/p&gt;</description></item></channel></rss>