TRACED
Get your Assessment
© TRACED 2022

TRACEDTRACED

  • Solutions
    • DevSecOps
    • Open Source
    • Software Supply Chain
    • M&A Due Diligence
  • Services
    • Assess & Review
    • Train & Enable
    • Policy & Governance
    • Managed Service
    • SBOM
  • Company
  • Insights
  • Contact
Get Your Assessment

Using open source software responsibly

Traced
Thursday, 10 November 2022 / Published in Insight

Using open source software responsibly

Why is responsible OSS usage important?

Nowadays, it is difficult to find a software development project that doesn’t rely on OSS to a greater or lesser extent. That includes, but is not limited to, any web client, node.js, Java or .NET software, and UI widgets.

Open source software is a living, breathing ecosystem and, like any ecosystem, we all have a responsibility to keep that ecosystem healthy. Otherwise, everybody suffers. If any of these products fail, it can leave our development project or enterprise software at risk. As we all depend on OSS, we are all vulnerable if it ceases to work as it should, or is compromised in any way. Therefore, we have a collective responsibility to ensure that it fails as rarely as possible.

How can I support the OSS ecosystem?

There are many things that you should include in your DevOps best practice, in order to support and protect the OSS ecosystem and, by extension, everyone involved in it. The first of these is using a SBOM (Software Bill of Materials) to itemise your OSS code and easily identify any vulnerabilities. By identifying and reporting or eliminating bugs, you are not only improving your own project’s chances of success, but also making a positive contribution to the whole OSS ecosystem and community. 

Why is it my responsibility?

The vast majority of people who come into contact with open source software are consumers – those who take advantage of it either to build their own projects, or as end users, without contributing back to the ecosystem. But all open source projects rely on user contribution, not only in the form of bug reports and patches, but also in documentation, community participation and coding.

Another potentially serious issue when using OSS is that of copyright infringement when dealing with proprietary software. As such, it is vital to be aware of the precise terms of any OSS licence, to ensure you are not acting beyond its scope. Failure to do this could see you embroiled in something like the ongoing case involving Nutanix, who have been accused of violating the terms of an OSS licence. 

I’m a company employee, and can’t contribute to OSS

Although you may not be able to directly contribute to OSS in the ways mentioned above, there are things that you can do to ensure the continued health of the OSS ecosystem. OSS does not run for free, so being able to contribute financially to the products you are using is one of the best things you can do to support them . This could be by paying for consulting, training or content, or by becoming a sponsor or patron if the product supports GitHub Sponsors or Patreon.

If you are in any way involved in the OSS ecosystem, click here for your free Agnostic Open-Sourced assessment, which will provide you with an objective and unbiased view of your software landscape.

  • Tweet
Tagged under: open source software

What you can read next

How government can rebuild trust in open source software
Why it’s important to not ignore Log4j
How to start an Open Source Program Office (OSPO)

Recent Posts

  • Telecom Cloud and its Open Source Risks

    According to federal cyber authorities, some ne...
  • Avoid Surprises: Don’t Let Open Source Issues Impact a Transaction

    Open source software (OSS) is becoming increasi...
  • Software Security Checkpoints in the SDLC

    How Widespread Are Software Security Checkpoint...
  • The Balance Between Open Source Software and Monetisation

    Can OSS Be Commercially Viable? It is commonly ...
  • The risks of neglecting open source developers

    Nowadays, it is rare to find a business which d...

Archives

  • March 2023
  • February 2023
  • December 2022
  • November 2022
  • October 2022

Categories

  • Insight
  • Open Source Development
  • Open Source Risk
  • Open Source Security
  • SBOMs
  • Software Supply Chain

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org
Solutions
  • Software Supply Chain
  • Open Source
  • DevSecOps
  • M&A Due Diligence
Services
  • Assess & Review
  • Policy & Governance
  • Managed Service
  • SBOM
Company
  • Quick Assessment
  • Company
  • Contact us

hello@8bf.c5f.myftpupload.com

© 2022 All rights Reserved @Traced

TOP