SlideShare a Scribd company logo
OSS Metrics for Market Readiness
The OW2 OSCAR Framework
Cédric Thomas, OW2
Paris Open Source Sumit
Paris 16-17 November, 2016
Nov 16, 2016 22016, Cedric Thomas
Agenda OSS Projects and the Value Chain
Market Readiness Observations
Evaluating Readiness and Maturity
Evaluating Open Source Maturity
OW2 OSCAR Approach
Nov 16, 2016 32016, Cedric Thomas
Project categories
Code to product
Supporting market readiness
OSS projects and
the value chain
Nov 16, 2016 42016, Cedric Thomas
Community projects
Nov 16, 2016 52016, Cedric Thomas
Enterprise projects
Nov 16, 2016 62016, Cedric Thomas
Collaborative projects
Nov 16, 2016 72016, Cedric Thomas
Software is Code
Nov 16, 2016 82016, Cedric Thomas
What is a Software Product?
Developer Customer
* When you want to sell it or do business with it, then it becomes a product
Nov 16, 2016 92016, Cedric Thomas
What makes a Software Product?
Developer Customer
Documentation
Upgrades
Roadmap Training Etc.
Pricing Contracts Support Expertise
Packaging
* It's not just code anymore, it's the whole value proposition
102016, Cedric Thomas
Research &
Development
Code
POCs
Use-cases
Demonstrators
Documentation
Roadmap
Upgrades
Bug-fixing
Training
Support
Packaging
Casestudies
Collateral
Pricing
Contracts
Earlyadopters
Etc.
Predictability
Quality
Trust
Without the code, the rest does not exist,but
it's the rest that gives market value to the
code
Delivery
Challenge
What creates value?
Market Value
112016, Cedric Thomas
Research &
Development
Code
POCs
Use-cases
Demonstrators
Documentation
Roadmap
Upgrades
Bug-fixing
Training
Support
Packaging
Casestudies
Collateral
Pricing
Contracts
Earlyadopters
Etc.
Predictability
Quality
Trust
OW2 is an ecosystem platform that helps
create value with open source projects
Delivery
Challenge
Market Value
Who creates value?
The ecosystem
Contributors
Distrib. Vendors
Open Source Orgs.
Fiduciary Services Users
Systems Integrators
122016, Cedric Thomas
Research &
Development
Code
POCs
Use-cases
Demonstrators
Documentation
Roadmap
Upgrades
Bug-fixing
Training
Support
Packaging
Casestudies
Collateral
Pricing
Contracts
Earlyadopters
Etc.
Predictability
Quality
Trust
OW2 is an ecosystem platform that helps
create value with open source projects
Delivery
ChallengeCollaborative Development Technical Resources
Governance, Projects, Initiatives, Quality Program
Communication, Outreach, Marketplace
OSCAR
Market Value
Supporting market readiness
and value creation
132016, Cedric Thomas
Code in the value chain
Ecosystems delivery
Open source governance
IT industry support
Market Readiness
Observations
142016, Cedric Thomas
Code is only a fraction of
the software value chain
It's the whole value chain that
creates market-ready offerings.
Users want a full business proposal,
not just bare code.
Decision-makers expect market-
ready offerings.
i.e. code complemented by:
packaging, services, training,
maintenance, support, etc.
https://commons.wikimedia.org/wiki/File:Ford_assembly_line_-_1913.jpg
152016, Cedric Thomas
Collaborative
development does not
deliver market-ready
offerings.
Ecosystems are expected to deliver
agreed-upon technologies,
roadmaps, reference
implementations, POCs and
components.
Open source developers natural
bias is to concentrate on core code
functionalities.
Code is the soul of free and open
source projects.
https://en.wikipedia.org/wiki/Eiffel_Tower
162016, Cedric Thomas
Successful collaborative
projects implement
flawless open source
governance.
Open source governance best
practices help build sustainable
communities.
Code complementers more likely to
contribute to trustworthy OSS
projects.
Non-Profit open source
organizations provide neutral support
and sustainability.
https://pixabay.com/en/hammer-court-judge-justice-law-1707729/
172016, Cedric Thomas
Successful open source
projects are supported
by IT companies.
Corporate support ensures
roadmap consistency and long-term
sustainability.
Corporate support develops
industry-grade distributions and
market-ready offerings.
Corporate support helps grow
market outreach, sign-up early
adopters and provide use cases for
mainstream market.
182016, Cedric Thomas
Technology Readiness Level
Market readiness
Open source readiness
Evaluating Readiness
and Maturity
192016, Cedric Thomas
Origin: Technology
Readiness Level
A type of measurement system
used to estimate the maturity level of
a particular technology
In technology, there are usually
nine readiness levels. TRL 1 is the
lowest and TRL 9 is the highest.
A TRL number is obtained once the
description has been achieved.
For example, successfully
achieving TRL 4 does not move the
technology to TRL 5.
Pioneered by NASA in the 80’s.
Adopted by the DOE and DOD for
procurement and management of
complex systems.
Idea
(useless)
Operational
(useful)
202016, Cedric Thomas
NASA/DOD TRL
http://www.frankichamaki.com/wp-content/uploads/2014/01/nasa-trl.jpg
212016, Cedric Thomas
http://www.ndia.org/Divisions/Divisions/ScienceAndEngineeringTechnology/Documents/Coyle%20NDIA.pdf
222016, Cedric Thomas
https://steveblank.files.wordpress.com/2013/11/irl.jpg
Investment Readiness
Level
232016, Cedric Thomas
QualiPSo
OW2 SQuAT
CII Badge Program
Evaluating Open
Source Maturity
242016, Cedric Thomas
Measuring Open Source Data collection and dashboards
OpenHub on GitHub, RISCOSS
Analyser on GitHub
Bitergia
License and IP analysis:
Black Duck Software, Palamida,
DejaCode, TripleCheck
Analysis models
NASA Reuse Readiness Levels
Core Infrastructure Initiative Badge
program
OSS Watch Software Sustainability
Maturity Model
252016, Cedric Thomas
2007: QualiPSo European project
48 months (2007-2010)
22 organisations from 9 countries
(3 continents)
It is all about TRUST
Trust cannot be claimed without
being proved!!!
QualiPSo aimed at standardising
the way OSS systems are built,
offered and consumed.
262016, Cedric Thomas
272016, Cedric Thomas
2010: OW2 SQuAT
Software Quality
Assurance and
Trustworthiness
IP verification: FOSSology
Applied on all OW2 mature
projects
Code verification: Antelink
Provides traceability of external
libraries
Static analysis: Sonar
Set of OW2 Sonar rules
Code quality: Trustie
TSRR installation on OW2
Maturity analysis: Qualipso
OMM applied to OW2 projects
282016, Cedric Thomas
PDOC STD QTP LCS ENV DFCT MST CM PP REQM RDMP STK
0
1
2
3
4
3.22
3.75
3.43
4
3.83
3.71 3.75
4
3
4
3
3.89
OMM Basic level
Trustworthy elements assessment
Trustworthy elements
Assessedvalue
PDOC STD QTP LCS ENV DFCT MST CM PP REQM RDMP STK
0
1
2
3
4
5
6
7
8
9
10
56%
75% 43%
100%
83%
86%
75%
100%
0%
100%
33%
100%
22%
25%
57%
0%
17%
0%
25%
0%
100% 0%
33%
11%
0%
0%
0%
0%
14%
0%
0%
0%
0%
33%
0%
11%
0%
0%
0%
0%
0%
0%
0%
0%
0%
0%
0%
OMM Basic level
Practices assessment value
4 3 2 1
Trustworthy elements
Assessmentvalueofpractices
OW2 Implementation of
the QualiPSo OMM
292016, Cedric Thomas
2012: RISCOSS
Commercial
Products/Services
???
Antepedia
Business Users Integrators
Open source as a public
resource freely accessible
But OSS come from very
different backgrounds
Exploring and mapping the
open source landscape
Need to identify, measure,
evaluate existing software
Many tools and online
services available
302016, Cedric Thomas
2015: CII Badge Program
(Linux Foundation)
Core Infrastructure Initiative (CII)
Launched after the Heartbleed
failure
Organized by The Linux Foundation
Supported by Amazon Web
Services, Adobe, Bloomberg, Cisco,
Dell, Facebook, Fujitsu, Google,
Hitachi, HP, Huawei, IBM, Intel,
Microsoft, NetApp, NEC, Qualcomm,
RackSpace, salesforce.com, and
VMware
https://www.coreinfrastructure.org/
David A. Wheeler at OW2con'16
312016, Cedric Thomas
CII BADGE PROGRAM Checklist:
Basics Project website
Project website content
FLOSS License
Documentation
Other
Change control Public version-controlled source repository
Version numbering
Release notes (ChangeLog)
Reporting Bug reporting process
Vulnerability reporting process
Quality Working build system
Automated test suite
New functionality testing
Warning flags
Security Secure development knowledge
Good cryptographic practices
Secured delivery mechanism
Publicly-known vulnerabilities fixed
Analysis Static code analysis
Dynamic analysis
322016, Cedric Thomas
More than just TRL
Market readiness
Promotes best practices
OW2 OSCAR Approach
332016, Cedric Thomas
OSCAR
Open Source Capability
Assessment Radar
Based on SQuAT
Increase the Quality and
Trustworthiness of OW2 projects
To facilitate decision making and
adoption of OW2 projects
Through:
Quality assessment tools
A check-list of best practices to
reach market maturity
OSCAR is SQuAT second
generation
342016, Cedric Thomas
OSCAR
An assessment
method and a
platform
Requirements
Metrics
Visual Reporting
Risk analysis
OMMForm
Metrics / Scorecards
Documentation
Privacy / GDPR
Standards
Licenses and IP
Fossology
SonarQube
Static code analysis
Code / Commits / Bugs
Testing / CI / Release
Cloud Deployment
OMMForm
Governance Engineering
More to come:
- Accessibility
- Deployability
- Marketing
- Funding
Nov 16, 2016 352016, Cedric Thomas
OMM
Assessment
Web Form
Nov 16, 2016 362016, Cedric Thomas
OMM
Assessment
+ CII input
Nov 16, 2016 372016, Cedric Thomas
FOSSology
License analysis
Nov 16, 2016 382016, Cedric Thomas
SonarQube
Static code
analysis
Nov 16, 2016 392016, Cedric Thomas
Activeness
Risk Drivers
Nov 16, 2016 402016, Cedric Thomas
Risk Models
Nov 16, 2016 412016, Cedric Thomas
OSCAR
Market Readiness
Scorecard
422016, Cedric Thomas
Summary
2016, Cedric Thomas
Summary Open source software come in
different value chains
Software value chain and the open
source delivery challenge
Readiness scaling helps make
decision
Experience in open source market
readiness analysis
OSCAR, the OW2 OSS market
readiness assessment approach
2016, Cedric Thomas
Open source is a vehicle for collaborative innovation
Software value chain and the open source delivery challenge
Readiness scaling helps make decision
Experience in open source market readiness analysis
OSCAR, the OW2 open source market readiness approach
45
www.ow2.org
For more details please contact Cedric Thomas, OW2 CEO, cedric.thomas@ow2.org
And now let's talk
Q&A
Disagreements
Complements
Feedback
etc.
Thank You

More Related Content

PDF
China SDN NFV Industry Alliance_ONF_Rick Bauer_To Act and Not Lay Claim FINAL
PPTX
QA Fest 2019. Ирина Бондарук. Breaking into information security
PDF
DevSecOps: The Open Source Way
PPTX
José Vila - ¿Otro parche más? No, por favor. [rooted2018]
PPTX
#Fstoco - Monitoring and Instrumentation, why Tracing is Key
PDF
MISRA C – Recent developments and a road map to the future
PPTX
Javier Hijas & Ori Kuyumgiski - Security at the speed of DevOps [rooted2018]
PDF
MISRA C in an ISO 26262 context
China SDN NFV Industry Alliance_ONF_Rick Bauer_To Act and Not Lay Claim FINAL
QA Fest 2019. Ирина Бондарук. Breaking into information security
DevSecOps: The Open Source Way
José Vila - ¿Otro parche más? No, por favor. [rooted2018]
#Fstoco - Monitoring and Instrumentation, why Tracing is Key
MISRA C – Recent developments and a road map to the future
Javier Hijas & Ori Kuyumgiski - Security at the speed of DevOps [rooted2018]
MISRA C in an ISO 26262 context

Viewers also liked (20)

PDF
Business plan creation presentation final 112013
PDF
PR Campaign Case Study 수강후기
PDF
Analyze of Tumblr.com
PDF
Kalimucho Research Project, OW2con11, Nov 24-25, Paris
 
PDF
SpagoBi Real Time Business Intelligence, OW2con11, Nov 24-25, Paris
 
PDF
JOnAS Addons, OW2con 2011, Nov 24-25, Paris
 
PDF
Open Source PLM, OW2con11, Nov 24-25, Paris
 
PPSX
6 october 09.20_am_hejnowski_ver pl
PDF
Manage Traceability with Apache Atlas flexible metadata repository.
 
PDF
Capstone Project Final Presentation
PDF
Sofa2 Q-im ress-ow2-conference-nov10
 
PPTX
Palacio Gobierno del Ecuador
PDF
Migration Novaforge OW2 Conference Nov10
 
PDF
OW2con'16 Keynote address: Kubernetes, the rising tide of systems administrat...
 
PDF
OSGi & JOnAS, OW2con11, Nov 24-25, Paris
 
PDF
OS Approach for Industrializing Research Tools, OW2con11
 
PDF
ACCEDE WEB, LES GUIDES D’ACCESSIBILITE POUR PROJETS WEB
 
PPT
Ppt ch 16
PPT
Big data - Cassandra
PDF
Discovering Tolerance.pptx
Business plan creation presentation final 112013
PR Campaign Case Study 수강후기
Analyze of Tumblr.com
Kalimucho Research Project, OW2con11, Nov 24-25, Paris
 
SpagoBi Real Time Business Intelligence, OW2con11, Nov 24-25, Paris
 
JOnAS Addons, OW2con 2011, Nov 24-25, Paris
 
Open Source PLM, OW2con11, Nov 24-25, Paris
 
6 october 09.20_am_hejnowski_ver pl
Manage Traceability with Apache Atlas flexible metadata repository.
 
Capstone Project Final Presentation
Sofa2 Q-im ress-ow2-conference-nov10
 
Palacio Gobierno del Ecuador
Migration Novaforge OW2 Conference Nov10
 
OW2con'16 Keynote address: Kubernetes, the rising tide of systems administrat...
 
OSGi & JOnAS, OW2con11, Nov 24-25, Paris
 
OS Approach for Industrializing Research Tools, OW2con11
 
ACCEDE WEB, LES GUIDES D’ACCESSIBILITE POUR PROJETS WEB
 
Ppt ch 16
Big data - Cassandra
Discovering Tolerance.pptx
Ad

Similar to OSS Metrics for Market Readiness (20)

PDF
From TRL to MRL: Assessing Open Source Project Market Readiness, Cédric Thoma...
 
PDF
From OSCAR to the OW2 Market Readiness Index, Cédric Thomas, Stéphane Laurièr...
 
PDF
POSS2016Nov16-The Open Source Software Value Chain
 
PDF
OW2 in the Open Source Value Chain, WOW2con'16, Paris.
 
PDF
SFScon 2020 - Cedric Thomas - Open Source ecosystem sustainability bring the ...
PDF
Cédric Thomas, OW2 CEO presentation at Net Futures 2016
 
PDF
OW2 Open Source Good Governance Initiative, OW2online'20, June 2020
 
PDF
OW2 Open Source Community Corporate Presentation (update January 2020)
 
PDF
Adding value to Projects : the OW2 Process, Paris Open Source Summit 2017
 
PDF
EvalOSS : A Framework to Evaluate Open Source Software
PDF
Progress Reports on OW2’s Market Readiness Index, OW2con'18, June 7-8, Paris
 
PDF
Creating a level playing field for open source software options in IT selecti...
PDF
SFScon'20 Bringing the User into the Equation
 
PPT
Engaging With Open Source in a procurement process
PDF
Health and Sustainability of Open Source Software from a Public Sector Perspe...
PDF
WSO2CON 2024 - Does Open Source Still Matter?
PDF
OSSF 2018 - Greg Olson of Open Source Sense - Building Mission- and Business-...
PDF
AppHub OW2con'15 - Peter Deussen Presentation
PDF
AppHub project presentation at MICAS 2015
PDF
2109 apb-micas-2015
From TRL to MRL: Assessing Open Source Project Market Readiness, Cédric Thoma...
 
From OSCAR to the OW2 Market Readiness Index, Cédric Thomas, Stéphane Laurièr...
 
POSS2016Nov16-The Open Source Software Value Chain
 
OW2 in the Open Source Value Chain, WOW2con'16, Paris.
 
SFScon 2020 - Cedric Thomas - Open Source ecosystem sustainability bring the ...
Cédric Thomas, OW2 CEO presentation at Net Futures 2016
 
OW2 Open Source Good Governance Initiative, OW2online'20, June 2020
 
OW2 Open Source Community Corporate Presentation (update January 2020)
 
Adding value to Projects : the OW2 Process, Paris Open Source Summit 2017
 
EvalOSS : A Framework to Evaluate Open Source Software
Progress Reports on OW2’s Market Readiness Index, OW2con'18, June 7-8, Paris
 
Creating a level playing field for open source software options in IT selecti...
SFScon'20 Bringing the User into the Equation
 
Engaging With Open Source in a procurement process
Health and Sustainability of Open Source Software from a Public Sector Perspe...
WSO2CON 2024 - Does Open Source Still Matter?
OSSF 2018 - Greg Olson of Open Source Sense - Building Mission- and Business-...
AppHub OW2con'15 - Peter Deussen Presentation
AppHub project presentation at MICAS 2015
2109 apb-micas-2015
Ad

More from OW2 (20)

PDF
OW2 and RIOS teaming up to boost the open source impact, Nov. 2022 in Roma
 
PDF
The Open Source Good Governance Initiative presented at RIOS OS Week, Nov. 20...
 
PDF
GLPi v.10, les fonctionnalités principales et l'offre cloud
 
PDF
Centreon: superviser le Cloud et le Legacy à partir d'une même plateforme, po...
 
PDF
FusionIAM : la gestion des identités et des accés open source
 
PDF
OW2 Association Européenne aux racines grenobloises, transformer l'industrie ...
 
PDF
Towards a sustainable solution to open source sustainability, OW2online20, Ju...
 
PDF
Advanced proactive and polymorphing cloud application adaptation with MORPHEM...
 
PDF
Open Source governance and the Eclipse Foundation, OW2online, June 2020
 
PDF
Open source contribution policies, OW2online, June 2020
 
PDF
Software development at scale, pandemic lockdown and oss ecosystems, OW2onlin...
 
PDF
Overview of the OpenChain Reference Tooling Work Group, OW2online20, June 2020
 
PDF
Open Source Compliance at Orange, OW2online, June 2020
 
PDF
Ideas, methods and tools for OSS Compliance assessment, OW2online, June 2020
 
PDF
Intelligent package management with FASTEN, OW2online, June 2020
 
PDF
DECODER, a Smarter Environment for DevOps Teams , OW2online, June 2020
 
PDF
Enabling DevOps for IoT software development, powered by Open Source, OW2onli...
 
PDF
Upcoming Challenges in Artificial Intelligence Research and Development, OW2o...
 
PDF
Cacti and Big Data at Orange France, OW2online, June 2020
 
PDF
Open Source Geographic Information System at Orange, OW2online, June 2020
 
OW2 and RIOS teaming up to boost the open source impact, Nov. 2022 in Roma
 
The Open Source Good Governance Initiative presented at RIOS OS Week, Nov. 20...
 
GLPi v.10, les fonctionnalités principales et l'offre cloud
 
Centreon: superviser le Cloud et le Legacy à partir d'une même plateforme, po...
 
FusionIAM : la gestion des identités et des accés open source
 
OW2 Association Européenne aux racines grenobloises, transformer l'industrie ...
 
Towards a sustainable solution to open source sustainability, OW2online20, Ju...
 
Advanced proactive and polymorphing cloud application adaptation with MORPHEM...
 
Open Source governance and the Eclipse Foundation, OW2online, June 2020
 
Open source contribution policies, OW2online, June 2020
 
Software development at scale, pandemic lockdown and oss ecosystems, OW2onlin...
 
Overview of the OpenChain Reference Tooling Work Group, OW2online20, June 2020
 
Open Source Compliance at Orange, OW2online, June 2020
 
Ideas, methods and tools for OSS Compliance assessment, OW2online, June 2020
 
Intelligent package management with FASTEN, OW2online, June 2020
 
DECODER, a Smarter Environment for DevOps Teams , OW2online, June 2020
 
Enabling DevOps for IoT software development, powered by Open Source, OW2onli...
 
Upcoming Challenges in Artificial Intelligence Research and Development, OW2o...
 
Cacti and Big Data at Orange France, OW2online, June 2020
 
Open Source Geographic Information System at Orange, OW2online, June 2020
 

Recently uploaded (20)

PPTX
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PDF
Microsoft Solutions Partner Drive Digital Transformation with D365.pdf
PPTX
Tartificialntelligence_presentation.pptx
PDF
Encapsulation theory and applications.pdf
PDF
Enhancing emotion recognition model for a student engagement use case through...
PDF
gpt5_lecture_notes_comprehensive_20250812015547.pdf
PDF
August Patch Tuesday
PDF
NewMind AI Weekly Chronicles - August'25-Week II
PDF
ENT215_Completing-a-large-scale-migration-and-modernization-with-AWS.pdf
PDF
1 - Historical Antecedents, Social Consideration.pdf
PDF
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
PDF
Encapsulation_ Review paper, used for researhc scholars
PPTX
A Presentation on Artificial Intelligence
PDF
Accuracy of neural networks in brain wave diagnosis of schizophrenia
PPTX
Chapter 5: Probability Theory and Statistics
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
PDF
Unlocking AI with Model Context Protocol (MCP)
PDF
Video forgery: An extensive analysis of inter-and intra-frame manipulation al...
PPTX
Programs and apps: productivity, graphics, security and other tools
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
Building Integrated photovoltaic BIPV_UPV.pdf
Microsoft Solutions Partner Drive Digital Transformation with D365.pdf
Tartificialntelligence_presentation.pptx
Encapsulation theory and applications.pdf
Enhancing emotion recognition model for a student engagement use case through...
gpt5_lecture_notes_comprehensive_20250812015547.pdf
August Patch Tuesday
NewMind AI Weekly Chronicles - August'25-Week II
ENT215_Completing-a-large-scale-migration-and-modernization-with-AWS.pdf
1 - Historical Antecedents, Social Consideration.pdf
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
Encapsulation_ Review paper, used for researhc scholars
A Presentation on Artificial Intelligence
Accuracy of neural networks in brain wave diagnosis of schizophrenia
Chapter 5: Probability Theory and Statistics
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
Unlocking AI with Model Context Protocol (MCP)
Video forgery: An extensive analysis of inter-and intra-frame manipulation al...
Programs and apps: productivity, graphics, security and other tools

OSS Metrics for Market Readiness

  • 1. OSS Metrics for Market Readiness The OW2 OSCAR Framework Cédric Thomas, OW2 Paris Open Source Sumit Paris 16-17 November, 2016
  • 2. Nov 16, 2016 22016, Cedric Thomas Agenda OSS Projects and the Value Chain Market Readiness Observations Evaluating Readiness and Maturity Evaluating Open Source Maturity OW2 OSCAR Approach
  • 3. Nov 16, 2016 32016, Cedric Thomas Project categories Code to product Supporting market readiness OSS projects and the value chain
  • 4. Nov 16, 2016 42016, Cedric Thomas Community projects
  • 5. Nov 16, 2016 52016, Cedric Thomas Enterprise projects
  • 6. Nov 16, 2016 62016, Cedric Thomas Collaborative projects
  • 7. Nov 16, 2016 72016, Cedric Thomas Software is Code
  • 8. Nov 16, 2016 82016, Cedric Thomas What is a Software Product? Developer Customer * When you want to sell it or do business with it, then it becomes a product
  • 9. Nov 16, 2016 92016, Cedric Thomas What makes a Software Product? Developer Customer Documentation Upgrades Roadmap Training Etc. Pricing Contracts Support Expertise Packaging * It's not just code anymore, it's the whole value proposition
  • 10. 102016, Cedric Thomas Research & Development Code POCs Use-cases Demonstrators Documentation Roadmap Upgrades Bug-fixing Training Support Packaging Casestudies Collateral Pricing Contracts Earlyadopters Etc. Predictability Quality Trust Without the code, the rest does not exist,but it's the rest that gives market value to the code Delivery Challenge What creates value? Market Value
  • 11. 112016, Cedric Thomas Research & Development Code POCs Use-cases Demonstrators Documentation Roadmap Upgrades Bug-fixing Training Support Packaging Casestudies Collateral Pricing Contracts Earlyadopters Etc. Predictability Quality Trust OW2 is an ecosystem platform that helps create value with open source projects Delivery Challenge Market Value Who creates value? The ecosystem Contributors Distrib. Vendors Open Source Orgs. Fiduciary Services Users Systems Integrators
  • 12. 122016, Cedric Thomas Research & Development Code POCs Use-cases Demonstrators Documentation Roadmap Upgrades Bug-fixing Training Support Packaging Casestudies Collateral Pricing Contracts Earlyadopters Etc. Predictability Quality Trust OW2 is an ecosystem platform that helps create value with open source projects Delivery ChallengeCollaborative Development Technical Resources Governance, Projects, Initiatives, Quality Program Communication, Outreach, Marketplace OSCAR Market Value Supporting market readiness and value creation
  • 13. 132016, Cedric Thomas Code in the value chain Ecosystems delivery Open source governance IT industry support Market Readiness Observations
  • 14. 142016, Cedric Thomas Code is only a fraction of the software value chain It's the whole value chain that creates market-ready offerings. Users want a full business proposal, not just bare code. Decision-makers expect market- ready offerings. i.e. code complemented by: packaging, services, training, maintenance, support, etc. https://commons.wikimedia.org/wiki/File:Ford_assembly_line_-_1913.jpg
  • 15. 152016, Cedric Thomas Collaborative development does not deliver market-ready offerings. Ecosystems are expected to deliver agreed-upon technologies, roadmaps, reference implementations, POCs and components. Open source developers natural bias is to concentrate on core code functionalities. Code is the soul of free and open source projects. https://en.wikipedia.org/wiki/Eiffel_Tower
  • 16. 162016, Cedric Thomas Successful collaborative projects implement flawless open source governance. Open source governance best practices help build sustainable communities. Code complementers more likely to contribute to trustworthy OSS projects. Non-Profit open source organizations provide neutral support and sustainability. https://pixabay.com/en/hammer-court-judge-justice-law-1707729/
  • 17. 172016, Cedric Thomas Successful open source projects are supported by IT companies. Corporate support ensures roadmap consistency and long-term sustainability. Corporate support develops industry-grade distributions and market-ready offerings. Corporate support helps grow market outreach, sign-up early adopters and provide use cases for mainstream market.
  • 18. 182016, Cedric Thomas Technology Readiness Level Market readiness Open source readiness Evaluating Readiness and Maturity
  • 19. 192016, Cedric Thomas Origin: Technology Readiness Level A type of measurement system used to estimate the maturity level of a particular technology In technology, there are usually nine readiness levels. TRL 1 is the lowest and TRL 9 is the highest. A TRL number is obtained once the description has been achieved. For example, successfully achieving TRL 4 does not move the technology to TRL 5. Pioneered by NASA in the 80’s. Adopted by the DOE and DOD for procurement and management of complex systems. Idea (useless) Operational (useful)
  • 20. 202016, Cedric Thomas NASA/DOD TRL http://www.frankichamaki.com/wp-content/uploads/2014/01/nasa-trl.jpg
  • 23. 232016, Cedric Thomas QualiPSo OW2 SQuAT CII Badge Program Evaluating Open Source Maturity
  • 24. 242016, Cedric Thomas Measuring Open Source Data collection and dashboards OpenHub on GitHub, RISCOSS Analyser on GitHub Bitergia License and IP analysis: Black Duck Software, Palamida, DejaCode, TripleCheck Analysis models NASA Reuse Readiness Levels Core Infrastructure Initiative Badge program OSS Watch Software Sustainability Maturity Model
  • 25. 252016, Cedric Thomas 2007: QualiPSo European project 48 months (2007-2010) 22 organisations from 9 countries (3 continents) It is all about TRUST Trust cannot be claimed without being proved!!! QualiPSo aimed at standardising the way OSS systems are built, offered and consumed.
  • 27. 272016, Cedric Thomas 2010: OW2 SQuAT Software Quality Assurance and Trustworthiness IP verification: FOSSology Applied on all OW2 mature projects Code verification: Antelink Provides traceability of external libraries Static analysis: Sonar Set of OW2 Sonar rules Code quality: Trustie TSRR installation on OW2 Maturity analysis: Qualipso OMM applied to OW2 projects
  • 28. 282016, Cedric Thomas PDOC STD QTP LCS ENV DFCT MST CM PP REQM RDMP STK 0 1 2 3 4 3.22 3.75 3.43 4 3.83 3.71 3.75 4 3 4 3 3.89 OMM Basic level Trustworthy elements assessment Trustworthy elements Assessedvalue PDOC STD QTP LCS ENV DFCT MST CM PP REQM RDMP STK 0 1 2 3 4 5 6 7 8 9 10 56% 75% 43% 100% 83% 86% 75% 100% 0% 100% 33% 100% 22% 25% 57% 0% 17% 0% 25% 0% 100% 0% 33% 11% 0% 0% 0% 0% 14% 0% 0% 0% 0% 33% 0% 11% 0% 0% 0% 0% 0% 0% 0% 0% 0% 0% 0% OMM Basic level Practices assessment value 4 3 2 1 Trustworthy elements Assessmentvalueofpractices OW2 Implementation of the QualiPSo OMM
  • 29. 292016, Cedric Thomas 2012: RISCOSS Commercial Products/Services ??? Antepedia Business Users Integrators Open source as a public resource freely accessible But OSS come from very different backgrounds Exploring and mapping the open source landscape Need to identify, measure, evaluate existing software Many tools and online services available
  • 30. 302016, Cedric Thomas 2015: CII Badge Program (Linux Foundation) Core Infrastructure Initiative (CII) Launched after the Heartbleed failure Organized by The Linux Foundation Supported by Amazon Web Services, Adobe, Bloomberg, Cisco, Dell, Facebook, Fujitsu, Google, Hitachi, HP, Huawei, IBM, Intel, Microsoft, NetApp, NEC, Qualcomm, RackSpace, salesforce.com, and VMware https://www.coreinfrastructure.org/ David A. Wheeler at OW2con'16
  • 31. 312016, Cedric Thomas CII BADGE PROGRAM Checklist: Basics Project website Project website content FLOSS License Documentation Other Change control Public version-controlled source repository Version numbering Release notes (ChangeLog) Reporting Bug reporting process Vulnerability reporting process Quality Working build system Automated test suite New functionality testing Warning flags Security Secure development knowledge Good cryptographic practices Secured delivery mechanism Publicly-known vulnerabilities fixed Analysis Static code analysis Dynamic analysis
  • 32. 322016, Cedric Thomas More than just TRL Market readiness Promotes best practices OW2 OSCAR Approach
  • 33. 332016, Cedric Thomas OSCAR Open Source Capability Assessment Radar Based on SQuAT Increase the Quality and Trustworthiness of OW2 projects To facilitate decision making and adoption of OW2 projects Through: Quality assessment tools A check-list of best practices to reach market maturity OSCAR is SQuAT second generation
  • 34. 342016, Cedric Thomas OSCAR An assessment method and a platform Requirements Metrics Visual Reporting Risk analysis OMMForm Metrics / Scorecards Documentation Privacy / GDPR Standards Licenses and IP Fossology SonarQube Static code analysis Code / Commits / Bugs Testing / CI / Release Cloud Deployment OMMForm Governance Engineering More to come: - Accessibility - Deployability - Marketing - Funding
  • 35. Nov 16, 2016 352016, Cedric Thomas OMM Assessment Web Form
  • 36. Nov 16, 2016 362016, Cedric Thomas OMM Assessment + CII input
  • 37. Nov 16, 2016 372016, Cedric Thomas FOSSology License analysis
  • 38. Nov 16, 2016 382016, Cedric Thomas SonarQube Static code analysis
  • 39. Nov 16, 2016 392016, Cedric Thomas Activeness Risk Drivers
  • 40. Nov 16, 2016 402016, Cedric Thomas Risk Models
  • 41. Nov 16, 2016 412016, Cedric Thomas OSCAR Market Readiness Scorecard
  • 43. 2016, Cedric Thomas Summary Open source software come in different value chains Software value chain and the open source delivery challenge Readiness scaling helps make decision Experience in open source market readiness analysis OSCAR, the OW2 OSS market readiness assessment approach
  • 44. 2016, Cedric Thomas Open source is a vehicle for collaborative innovation Software value chain and the open source delivery challenge Readiness scaling helps make decision Experience in open source market readiness analysis OSCAR, the OW2 open source market readiness approach
  • 45. 45 www.ow2.org For more details please contact Cedric Thomas, OW2 CEO, cedric.thomas@ow2.org And now let's talk Q&A Disagreements Complements Feedback etc. Thank You