Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Formal statement format for project with no OSS BOM #9

Open
dineshr93 opened this issue Jul 26, 2021 · 1 comment
Open

Formal statement format for project with no OSS BOM #9

dineshr93 opened this issue Jul 26, 2021 · 1 comment

Comments

@dineshr93
Copy link
Contributor

Hi all,

Is there a formal statement to give to customers for the projects which has no OSS components.?

we cannot give confirmation that no OSS is being used because we cannot ensure 100% accuracy since there is always limitations to the tools. So we need come up with a statement which sets the tools limitations in place & also state that no OSS evidence has been found after performing the so & so scan.

I wanted to know does there are any statements already in place in Open chain. I searched here https://github.com/OpenChain-Project/Reference-Material
but I did not find anything related to it.

Thanks

@shanecoughlan
Copy link
Contributor

We do not provide a single "source of truth" statement for such a matter. It is really up to the in-house procurement and legal times.

Conceptually, it might be something like this:
The supplier confirms that the provided software has been audited and confirms that it contains no components under open source licenses."

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants