LWN.net Logo

Advertisement

GStreamer, Embedded Linux, Android, VoD, Smooth Streaming, DRM, RTSP, HEVC, PulseAudio, OpenGL. Register now to attend.

Advertise here

A SPDX case study

A SPDX case study

Posted Sep 26, 2013 18:48 UTC (Thu) by HIGHGuY (subscriber, #62277)
Parent article: A SPDX case study

Working for another large company that deals with OSS I recognize the problems faced.
Our company also has a large database that one uploads source code into for license review and that aids the process of verification and license obligation compliance.

For our team, using the tool at first generated a lot of work.
Currently we source 2 different Linux distributions and maintaining all of this information throughout regular package updates and other maintenance is quite a burden.
That is why we further automated the process for our team, going from 2-3 manweeks of work per release, down to 2-3 mandays of work per release. Further tuning can probably bring this down to 1-2 mandays.

For any large company dealing with OSS products, such automation is golden.

There are additional benefits to be found in maintaining such a database like providing teams with security alerts or merely forming an internal community around certain packages, promoting reuse and stimulating communication.


(Log in to post comments)

A SPDX case study

Posted Sep 30, 2013 16:05 UTC (Mon) by dps (subscriber, #5725) [Link]

Working for a company that distributes boxes which aggregate OSS and definitely not OSS software the ability to track what licences apply to which bit of which package would be worth a lot.

Sometime we either don't have the source code or can't get it under a licence that would allow us to redistribute the source code. Some of the other code is hazardous to mental health or part of our secret sauce (and sometimes both).

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds