SlideShare a Scribd company logo
FOSSLight
Open Source Project
2021. 7. 6.
Kyoungae Kim
OpenChain Webinar
1 / 29
Contents
1. What is FOSSLight?
2. Why FOSSLight System?
3. FOSSLight Open Source Project
What is FOSSLight?
3 / 29
LGE OSC Process
WE NEED A TOOL & SYSTEM
4 / 29
OSPO
SW development
team
LGE OSC Process & FOSSLight
Step1.
Identification
Step 4.
Distribution
Step 2.
Approval
Step 3.
Notice &
Verification
Analyze
open source
Request for
analysis review
Create
OSS Package
OSS
Package
Distribute
OSS distribution site
Notice
OSS Notice &
OSS Package
Notice
OSS
Notice
Review
OSS Package
Review
analysis result
BOM
OSS BOM
& Obligation
OSS
report
FOSSLight
report
FOSSLight Scanner
FOSSLight
FOSSLight Open Source Project
Software
5 / 29
FOSSLight Scanner
Dependency Binary
Source
Code
Source
Scanner
Dependency
Scanner
Binary
Scanner
Android Yocto
Platform
specific
npm pip maven
gradle pods ∙∙∙
ScanCode
6 / 29
OSS
License
Vulnera
bility
3rd
Party
Project
Self
check Rest
API CI/CD
FOSSLight System
 All-in-one Open Source Compliance & Vulnerability
Project
OSC Process
License / OSS
Vulnerability
3rd Party Project
3rd Party OSS
Management
Self-Check
Check OSS, License,
Vulnerability
without OSPO Review
7 / 29
FOSSLight Source Scanner
 Detect Copyright & License text
 String Search
 Use ScanCode
 Cannot find OSS Name
 https://github.com/fosslight/fosslight_source_scanner
8 / 29
FOSSLight Dependency Scanner
 Print OSS information based on dependencies.
 Available Package Manager
 Gradle (Java/Android)
 Maven (Java)
 NPM (Node.js)
 Pypi (Python)
 Pub (Dart with flutter)
 Cocoapods (Swift/Obj-C)
 Direct Dependency & Transitive Dependency
 https://github.com/fosslight/fosslight_dependency_scanner
9 / 29
FOSSLight Release soon..
 FOSSLight Binary Scanner
 Doesn’t scan binary itself.
 Just calculate checksum(same) and TLSH(similar)
 Compare with Binary DB Information and extract OSS Information
 FOSSLight REUSE
 Reuse (https://github.com/fsfe/reuse-tool)
 Check Copyright/License writing rules in Source Code
Why FOSSLight System ?
11 / 29
Project Dashboard
12 / 29
BOM Management (1/2)
https://linuxfoundation.org/blog/what-is-an-sbom/
13 / 29
BOM Management (2/2)
14 / 29
BOM Compare
15 / 29
Same OSS (Nickname)
16 / 29
Same OSS (Nickname)
17 / 29
Same License (Nickname)
18 / 29
Support Various OSS Notice Format
19 / 29
Communication
20 / 29
OpenChain Conformance
FOSSLight Open Source Project
22 / 29
FOSSLight Open Source Project
FOSS (Free and Open Source Software) + Light
23 / 29
FOSSLight
 https://FOSSLight.org
 https://demo.FOSSLight.org
 https://FOSSLight.org/fosslight-guide
24 / 29
FOSSLight Press Release
25 / 29
Github Star
26 / 29
FOSSLight Roadmap
FOSSLight
Source
Scanner
FOSSLight
System
FOSSLight
Binary
Scanner
FOSSLight
Reuse
FOSSLight
Dependency
Scanner
2021
1Q
2021
2Q
2021
3Q
27 / 29
FOSSLight Contribution Items
 Identification Input : SPDX, other scanner result
 Distribution Implementation
 Integration with Open Database (ex. Software Heritage)
 Test Automation
28 / 29
Your attention, please.
Thank YOU !!
29 / 29
Appendix. FOSSLight Sticker Image Candidates

More Related Content

PDF
SBOM, Is It 42?
PDF
Pen-Testing with Metasploit
PPTX
Cyber Threat Intelligence.pptx
PPTX
DAST, SAST, Hybrid, Hybrid 2.0 & IAST - Methodology & Limitations
PPTX
Presentation on 'Understanding and Utilising Threat Intelligence in Cybersecu...
PPTX
Detection Rules Coverage
PPTX
VAPT - Vulnerability Assessment & Penetration Testing
PPTX
Dragos S4x20: How to Build an OT Security Operations Center
SBOM, Is It 42?
Pen-Testing with Metasploit
Cyber Threat Intelligence.pptx
DAST, SAST, Hybrid, Hybrid 2.0 & IAST - Methodology & Limitations
Presentation on 'Understanding and Utilising Threat Intelligence in Cybersecu...
Detection Rules Coverage
VAPT - Vulnerability Assessment & Penetration Testing
Dragos S4x20: How to Build an OT Security Operations Center

What's hot (20)

PPTX
Vapt pci dss methodology ppt v1.0
PDF
Final Project Report-SIEM
PDF
F5 Web Application Security
PPTX
Threat Hunting with Splunk Hands-on
PDF
Accelerating Hyper-Converged Enterprise Virtualization using Proxmox and Ceph
PDF
Threat Hunting with Splunk
PDF
Threat Hunting
PPTX
VAPT PRESENTATION full.pptx
PPTX
F5 - BigIP ASM introduction
PDF
Patch and Vulnerability Management
PDF
Edge architecture ieee international conference on cloud engineering
PPT
Introduction to Web Application Penetration Testing
PDF
Super Easy Memory Forensics
 
ODP
OWASP Secure Coding
PDF
Threat Intelligence 101 - Steve Lodin - Submitted
PPTX
Security Champions - Introduce them in your Organisation
PDF
IBM QRadar Security Intelligence Overview
PPTX
Cyber Defense Matrix: Revolutions
PDF
Cyber Kill Chain Deck for General Audience
PPTX
Bsides 2019 - Intelligent Threat Hunting
Vapt pci dss methodology ppt v1.0
Final Project Report-SIEM
F5 Web Application Security
Threat Hunting with Splunk Hands-on
Accelerating Hyper-Converged Enterprise Virtualization using Proxmox and Ceph
Threat Hunting with Splunk
Threat Hunting
VAPT PRESENTATION full.pptx
F5 - BigIP ASM introduction
Patch and Vulnerability Management
Edge architecture ieee international conference on cloud engineering
Introduction to Web Application Penetration Testing
Super Easy Memory Forensics
 
OWASP Secure Coding
Threat Intelligence 101 - Steve Lodin - Submitted
Security Champions - Introduce them in your Organisation
IBM QRadar Security Intelligence Overview
Cyber Defense Matrix: Revolutions
Cyber Kill Chain Deck for General Audience
Bsides 2019 - Intelligent Threat Hunting
Ad

Similar to FOSSLight Open Source Project (20)

PDF
Fedora Modularity
PPTX
Open Source Software Concepts
PPTX
2nd
PPTX
2nd
PDF
Introduction to FOSS
PDF
Intro to FOSS
PDF
Cape Cod Web Technology Meetup - 3
KEY
Using Open Source for Enterprise
PDF
An Overview of the IHK/McKernel Multi-kernel Operating System
ODP
Fos sintro pres-dav
ODP
Introduction to Free and Open Source Software (FOSS)
PDF
GoOpen 2010: Sandro D'Elia
PPT
Asf icfoss-mentoring
ODP
Gup2011| open source
ODP
Open Source Selection
PDF
An Open Source Workshop
PDF
Build OTB with the SuperBuild
 
ODP
Foss Presentation
PPTX
Hacktoberfest 2020 - Open source for beginners
DOC
Report presentation
Fedora Modularity
Open Source Software Concepts
2nd
2nd
Introduction to FOSS
Intro to FOSS
Cape Cod Web Technology Meetup - 3
Using Open Source for Enterprise
An Overview of the IHK/McKernel Multi-kernel Operating System
Fos sintro pres-dav
Introduction to Free and Open Source Software (FOSS)
GoOpen 2010: Sandro D'Elia
Asf icfoss-mentoring
Gup2011| open source
Open Source Selection
An Open Source Workshop
Build OTB with the SuperBuild
 
Foss Presentation
Hacktoberfest 2020 - Open source for beginners
Report presentation
Ad

More from Shane Coughlan (20)

PPTX
Operations Profile SPDX_Update_20250711_Example_05_03.pptx
PDF
The 3rd OSPO Summit - China (Beijing - 2025-06-12)
PPTX
OpenChain Korea Work Group Meeting - 2025-06-16
PPTX
OpenChain Tooling Work Group - 2025-07-02
PPTX
OpenChain @ OSS NA - In From the Cold: Open Source as Part of Mainstream Soft...
PPTX
In From the Cold: Open Source as Part of Mainstream Software Asset Management
PPTX
Empowering Asian Contributions: The Rise of Regional User Groups in Open Sour...
PDF
Open Chain Q2 Steering Committee Meeting - 2025-06-25
PDF
OpenChain Webinar - AboutCode - Practical Compliance in One Stack – Licensing...
PPTX
OpenChain China Work Group – Regular Meeting 3 – 2024-11-29 @ 14:00 to 17:30
PPTX
OpenChain @ InnerSource Summit 2024 - 2024-11-20
PPTX
OpenChain Korea Work Group Meeting #24 - 2024-11-26
PDF
Compliance and Integrity in the Software Supply Chain with Software Heritage:...
PDF
Fujitsu’s OSS standards conformance and AI Management System Standardization ...
PPTX
OpenChain China Work Group Presentation @ OSCAR 2024
PPTX
OpenChain Japan Community Day - 2024-10-17
PPTX
ETRI EOST2024 Seoul Keynote - 2024-10-15
PDF
OpenChain Webinar- The Role of Data in the Supply Chain of AI - 2024-10-10
PDF
SBOM Implementation Reality - From Crawl to Walk, the SPDX Lite Profile for t...
PPTX
OpenChain Webinar - AI Legal Landscape - Slides
Operations Profile SPDX_Update_20250711_Example_05_03.pptx
The 3rd OSPO Summit - China (Beijing - 2025-06-12)
OpenChain Korea Work Group Meeting - 2025-06-16
OpenChain Tooling Work Group - 2025-07-02
OpenChain @ OSS NA - In From the Cold: Open Source as Part of Mainstream Soft...
In From the Cold: Open Source as Part of Mainstream Software Asset Management
Empowering Asian Contributions: The Rise of Regional User Groups in Open Sour...
Open Chain Q2 Steering Committee Meeting - 2025-06-25
OpenChain Webinar - AboutCode - Practical Compliance in One Stack – Licensing...
OpenChain China Work Group – Regular Meeting 3 – 2024-11-29 @ 14:00 to 17:30
OpenChain @ InnerSource Summit 2024 - 2024-11-20
OpenChain Korea Work Group Meeting #24 - 2024-11-26
Compliance and Integrity in the Software Supply Chain with Software Heritage:...
Fujitsu’s OSS standards conformance and AI Management System Standardization ...
OpenChain China Work Group Presentation @ OSCAR 2024
OpenChain Japan Community Day - 2024-10-17
ETRI EOST2024 Seoul Keynote - 2024-10-15
OpenChain Webinar- The Role of Data in the Supply Chain of AI - 2024-10-10
SBOM Implementation Reality - From Crawl to Walk, the SPDX Lite Profile for t...
OpenChain Webinar - AI Legal Landscape - Slides

Recently uploaded (20)

PDF
How Tridens DevSecOps Ensures Compliance, Security, and Agility
PDF
iTop VPN Crack Latest Version Full Key 2025
PDF
wealthsignaloriginal-com-DS-text-... (1).pdf
PPTX
Computer Software and OS of computer science of grade 11.pptx
PPTX
Trending Python Topics for Data Visualization in 2025
PPTX
AMADEUS TRAVEL AGENT SOFTWARE | AMADEUS TICKETING SYSTEM
PPTX
WiFi Honeypot Detecscfddssdffsedfseztor.pptx
PPTX
Custom Software Development Services.pptx.pptx
PDF
Top 10 Software Development Trends to Watch in 2025 🚀.pdf
PDF
Designing Intelligence for the Shop Floor.pdf
DOCX
Greta — No-Code AI for Building Full-Stack Web & Mobile Apps
PPTX
assetexplorer- product-overview - presentation
PPTX
Weekly report ppt - harsh dattuprasad patel.pptx
PDF
Autodesk AutoCAD Crack Free Download 2025
PDF
EaseUS PDF Editor Pro 6.2.0.2 Crack with License Key 2025
PPTX
"Secure File Sharing Solutions on AWS".pptx
DOCX
How to Use SharePoint as an ISO-Compliant Document Management System
PDF
Topaz Photo AI Crack New Download (Latest 2025)
PPTX
Monitoring Stack: Grafana, Loki & Promtail
PPTX
Oracle Fusion HCM Cloud Demo for Beginners
How Tridens DevSecOps Ensures Compliance, Security, and Agility
iTop VPN Crack Latest Version Full Key 2025
wealthsignaloriginal-com-DS-text-... (1).pdf
Computer Software and OS of computer science of grade 11.pptx
Trending Python Topics for Data Visualization in 2025
AMADEUS TRAVEL AGENT SOFTWARE | AMADEUS TICKETING SYSTEM
WiFi Honeypot Detecscfddssdffsedfseztor.pptx
Custom Software Development Services.pptx.pptx
Top 10 Software Development Trends to Watch in 2025 🚀.pdf
Designing Intelligence for the Shop Floor.pdf
Greta — No-Code AI for Building Full-Stack Web & Mobile Apps
assetexplorer- product-overview - presentation
Weekly report ppt - harsh dattuprasad patel.pptx
Autodesk AutoCAD Crack Free Download 2025
EaseUS PDF Editor Pro 6.2.0.2 Crack with License Key 2025
"Secure File Sharing Solutions on AWS".pptx
How to Use SharePoint as an ISO-Compliant Document Management System
Topaz Photo AI Crack New Download (Latest 2025)
Monitoring Stack: Grafana, Loki & Promtail
Oracle Fusion HCM Cloud Demo for Beginners

FOSSLight Open Source Project

  • 1. FOSSLight Open Source Project 2021. 7. 6. Kyoungae Kim OpenChain Webinar
  • 2. 1 / 29 Contents 1. What is FOSSLight? 2. Why FOSSLight System? 3. FOSSLight Open Source Project
  • 4. 3 / 29 LGE OSC Process WE NEED A TOOL & SYSTEM
  • 5. 4 / 29 OSPO SW development team LGE OSC Process & FOSSLight Step1. Identification Step 4. Distribution Step 2. Approval Step 3. Notice & Verification Analyze open source Request for analysis review Create OSS Package OSS Package Distribute OSS distribution site Notice OSS Notice & OSS Package Notice OSS Notice Review OSS Package Review analysis result BOM OSS BOM & Obligation OSS report FOSSLight report FOSSLight Scanner FOSSLight FOSSLight Open Source Project Software
  • 6. 5 / 29 FOSSLight Scanner Dependency Binary Source Code Source Scanner Dependency Scanner Binary Scanner Android Yocto Platform specific npm pip maven gradle pods ∙∙∙ ScanCode
  • 7. 6 / 29 OSS License Vulnera bility 3rd Party Project Self check Rest API CI/CD FOSSLight System  All-in-one Open Source Compliance & Vulnerability Project OSC Process License / OSS Vulnerability 3rd Party Project 3rd Party OSS Management Self-Check Check OSS, License, Vulnerability without OSPO Review
  • 8. 7 / 29 FOSSLight Source Scanner  Detect Copyright & License text  String Search  Use ScanCode  Cannot find OSS Name  https://github.com/fosslight/fosslight_source_scanner
  • 9. 8 / 29 FOSSLight Dependency Scanner  Print OSS information based on dependencies.  Available Package Manager  Gradle (Java/Android)  Maven (Java)  NPM (Node.js)  Pypi (Python)  Pub (Dart with flutter)  Cocoapods (Swift/Obj-C)  Direct Dependency & Transitive Dependency  https://github.com/fosslight/fosslight_dependency_scanner
  • 10. 9 / 29 FOSSLight Release soon..  FOSSLight Binary Scanner  Doesn’t scan binary itself.  Just calculate checksum(same) and TLSH(similar)  Compare with Binary DB Information and extract OSS Information  FOSSLight REUSE  Reuse (https://github.com/fsfe/reuse-tool)  Check Copyright/License writing rules in Source Code
  • 12. 11 / 29 Project Dashboard
  • 13. 12 / 29 BOM Management (1/2) https://linuxfoundation.org/blog/what-is-an-sbom/
  • 14. 13 / 29 BOM Management (2/2)
  • 15. 14 / 29 BOM Compare
  • 16. 15 / 29 Same OSS (Nickname)
  • 17. 16 / 29 Same OSS (Nickname)
  • 18. 17 / 29 Same License (Nickname)
  • 19. 18 / 29 Support Various OSS Notice Format
  • 21. 20 / 29 OpenChain Conformance
  • 23. 22 / 29 FOSSLight Open Source Project FOSS (Free and Open Source Software) + Light
  • 24. 23 / 29 FOSSLight  https://FOSSLight.org  https://demo.FOSSLight.org  https://FOSSLight.org/fosslight-guide
  • 25. 24 / 29 FOSSLight Press Release
  • 27. 26 / 29 FOSSLight Roadmap FOSSLight Source Scanner FOSSLight System FOSSLight Binary Scanner FOSSLight Reuse FOSSLight Dependency Scanner 2021 1Q 2021 2Q 2021 3Q
  • 28. 27 / 29 FOSSLight Contribution Items  Identification Input : SPDX, other scanner result  Distribution Implementation  Integration with Open Database (ex. Software Heritage)  Test Automation
  • 29. 28 / 29 Your attention, please. Thank YOU !!
  • 30. 29 / 29 Appendix. FOSSLight Sticker Image Candidates