We're sorry but this page doesn't work properly without JavaScript enabled. Please enable it to continue.
Feedback

Build license management into your pipelines

Formale Metadaten

Titel
Build license management into your pipelines
Serientitel
Anzahl der Teile
38
Autor
Lizenz
CC-Namensnennung 3.0 Unported:
Sie dürfen das Werk bzw. den Inhalt zu jedem legalen Zweck nutzen, verändern und in unveränderter oder veränderter Form vervielfältigen, verbreiten und öffentlich zugänglich machen, sofern Sie den Namen des Autors/Rechteinhabers in der von ihm festgelegten Weise nennen.
Identifikatoren
Herausgeber
Erscheinungsjahr
Sprache

Inhaltliche Metadaten

Fachgebiet
Genre
Abstract
We’re all moving fast and in order to do so we’re relying on a lot of dependencies to give us that commercial edge. In doing so we’re trusting the work of strangers on the internet, and also that of vendors who may change their mind on who can benefit from their software. The 2022 OSSRA (Open Source Security and Risk) report, examines the results of more than 2,400 audits of commercial codebases, of which 97% contained open source. Four of the 17 industry sectors represented in the report—Computer Hardware and Semiconductors, Cybersecurity, Energy and Clean Tech, and IoT—contained open source in 100% of their audited codebases. If you install Electron and have to add 87 packages — that means 87 license dependencies. Every single package is likely to have its own dependencies, and therefore, another license you need to comply with. As you can imagine license management can’t be done manually and when done incorrectly can create a technical debt. License litigation may end up forcing you to release your code under the same license as the package dependency you used. Other potential problems include being sued for financial liability by the creator of the component, and/or losing reputation and getting negative press coverage. Find out how to do a software composition analysis to create an SBOM (Software Bill of Materials), and how to monitor changes in your components’ licenses every time you deploy.