-
Notifications
You must be signed in to change notification settings - Fork 137
Update 06-chapter.md #593
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Update 06-chapter.md #593
Changes from 4 commits
Commits
Show all changes
7 commits
Select commit
Hold shift + click to select a range
f2684d6
Update 06-chapter.md
harmonyelendu cd21283
Update ospo-book/content/en/06-chapter.md
alice-sowerby 0b10c28
Update ospo-book/content/en/06-chapter.md
alice-sowerby 80cac9d
Update ospo-book/content/en/06-chapter.md
alice-sowerby 579f105
Update ospo-book/content/en/06-chapter.md
alice-sowerby f6bd868
Update ospo-book/content/en/06-chapter.md
alice-sowerby b141675
Update ospo-book/content/en/06-chapter.md
alice-sowerby File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -135,14 +135,14 @@ | |
|
|
||
| **Commentary** | ||
|
|
||
| Engagement with open source communities includes working in the upstream to effectively use OSS in organizational products. In this, there is a need to monitor the intake of OSS for infosec, legal, and engineering reasons. Companies can establish software intake processes, working with teams to either technically track or socially consider issues related to open source intake. Organization impact can also include working downstream with projects and companies that rely on your organizational products. This can include working to gain a clearer picture of the open source that is in your shipped products. Organizations can work in securing and regulating their own internal open source processes in an effort to improve product development activities. | ||
| Engagement with open source communities includes working in the upstream to effectively use OSS in organizational products. In this, there is a need to monitor the intake of OSS for infosec, legal, and engineering reasons. Companies can establish software intake processes, working with teams to either technically track or socially consider issues related to open source intake. Organizational impact can also include working downstream with projects and companies that rely on your organizational products. This can include working to gain a clearer picture of the open source that is in your shipped products. Organizations can work in securing and regulating their own internal open source processes in an effort to improve product development activities. | ||
|
|
||
| **Questions** | ||
|
|
||
| * What characteristics does an organization inspect related to inbound OSS? | ||
| * What product-level software and infrastructure contains OSS dependencies? | ||
| * How is OSPO strategy aligned with organizational strategy and departmental objectives? | ||
| * How often is OPSO strategy used to guide business decision making processes? | ||
| * How often is OSPO strategy used to guide business decision making processes? | ||
| * How does the use of open source influence organizational value? | ||
|
|
||
| **Metrics** | ||
|
|
@@ -176,8 +176,7 @@ | |
| * The life cycle stage of the project (for example early stage vs. mature). | ||
| * Its complexity (how big and technically demanding it is). | ||
| * The governance model (how decisions are made and who makes them). | ||
|
|
||
| The strategic value the project holds for the organization | ||
| * The strategic value the project holds for the organization | ||
|
|
||
| When comparing open source projects, OSPOs should group and assess projects with similar characteristics. Comparing very different types of projects can lead to misleading results [^3]. | ||
|
|
||
|
|
@@ -211,7 +210,7 @@ | |
|
|
||
| #### Monitoring Projects Already in Use | ||
|
|
||
| The company also needed a way to track OSS projects already integrated into their systems. Because these projects often have many dependencies, manual checks weren't practical. | ||
| The company also needed a way to track OSS projects already integrated into their systems. Because these projects often have many dependencies, manual checks were not practical. | ||
|
|
||
| Their proposed solution: | ||
|
|
||
|
|
@@ -242,7 +241,7 @@ | |
| * Integrate health checks into existing workflows. | ||
| * Support the process with training, tools, and regular team discussions. | ||
|
|
||
| By identifying problems early and responding quickly, organizations can reduce risks and make sure their open source software stays secure, stable, and sustainable. | ||
| By identifying problems early and responding quickly, organizations can reduce risks and make sure their open source software remains secure, stable, and sustainable. | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. I don't know why this change is suggested. It makes little difference. |
||
|
|
||
| Resources like the CHAOSS Project and the OpenSSF Scorecard can help OSPOs get started or strengthen their approach. | ||
|
|
||
|
|
@@ -256,11 +255,11 @@ | |
|
|
||
| ### Footnotes | ||
|
|
||
| [^1]: CHAOSS Practitioner Guides: https://chaoss.community/about-chaoss-practitioner-guides/ | ||
| [^1]: CHAOSS Practitioner Guides: https://chaoss.community/about-chaoss-practitioner-guides. | ||
|
|
||
| [^2]: Linåker, J., Papatheocharous, E., & Olsson, T. (2022). How to characterize the health of an Open Source Software project? A snowball literature review of an emerging practice. In the 18th International Symposium on Open Collaboration. DOI. https://doi.org/10.1145/3555051.3555067 | ||
| [^2]: Linåker, J., Papatheocharous, E., & Olsson, T. (2022). How to Characterize the health of an Open Source Software project? A snowball literature review of an emerging practice. In the 18th International Symposium on Open Collaboration. DOI. https://doi.org/10.1145/3555051.3555067 | ||
|
|
||
| [^3]: Lumbard, K., Germonprez, M., and Goggins, S. (2023). An Empirical Investigation of Social Comparison and Open Source Community Health, Information Systems Journal, 34(2), 499-532. https://onlinelibrary.wiley.com/doi/abs/10.1111/isj.12485 | ||
| [^3]: Lumbard, K., Germonprez, M., & Goggins, S. (2023). An Empirical Investigation of Social Comparison and Open Source Community Health, Information Systems Journal, 34(2), 499-532. https://onlinelibrary.wiley.com/doi/abs/10.1111/isj.12485 | ||
|
|
||
| [^4]: Linåker, J., Olsson, T., & Papatheocharous, E. (2024). How to Assess the Health of Open Source Software dependencies in an Organization’s Intake Process: Insights from an Interview-survey and Case Study. | ||
| [^4]: Linåker, J., Olsson, T., & Papatheocharous, E. (2024). How to Assess the Health of Open Source Software dependencies in an Organization’s Intake Process: Insights from an Interview Survey and Case Study. | ||
|
alice-sowerby marked this conversation as resolved.
Outdated
|
||
| https://opensym.org/wp-content/uploads/2023/03/os22-paper-A11-linaker.pdf | ||
|
alice-sowerby marked this conversation as resolved.
Outdated
|
||
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.