Streamlining the compliance process
Streamlining the compliance process
Posted May 6, 2017 13:25 UTC (Sat) by aggelos (subscriber, #41752)In reply to: Streamlining the compliance process by corbet
Parent article: The rise of copyright trolls
LF is doing quite a bit in this area. OpenChain is there to help companies set up their compliance programs. SPDX is a long-running effort to make it easy to document the provenance of the software in any given distribution. There's a whole list of publications, including the book by Armijn and Shane mentioned elsewhere in this conversation. They also offer an online course in "compliance basics" for free.
It's clear the LF is publishing a lot of documents on how to do compliance as a company - I skimmed the book by Armijn et al. and the thing that stood out, other than the erasure of GPLv3 (people don't ship samba in embedded devices?), is the number of LF documents mentioned in Appendix 1. Only LF documents, come to think of it. Almost as if there are no other publications on the subject.
Documenting an arduous process is well and good and will remain necessary. It is however not the same thing as making said process easier (for instance, by pursuing tooling improvements). My question was about the latter aspect.
My own wish is that the LF would do more to address the outright compliance problems in the industry, and I've told them so. If there's anything happening there it's below the radar, but they are doing quite a bit to make things easier for the companies that want to follow the rules.
It is good to hear about preventive work. What more do you think they could be doing to address the ongoing compliance problems?