FOSSA

FOSSA is the world’s first Modern Open Source Management platform. Designed for development and legal Effortlessly comply with open source licenses.

The Lawyer’s Guide to OSS License Compliance Tools, Featuring Heather Meeker 11/22/2022

How do you get Engineering buy-in on OSS license compliance? You conduct compliance in the way that is most efficient.

Here are a few tips:
1. Compliance tooling is as only effective as the engineers that use it.
2. Use a broad coverage of popular programming languages.
3. Use tools that integrate with Engineering’s preferred workflows and development environments.

Learn more here: https://bit.ly/3UUH3zd

The Lawyer’s Guide to OSS License Compliance Tools, Featuring Heather Meeker Given the large volume of open source software in modern applications, it can be quite difficult to manage OSS license compliance obligations with manual processes alone. But picking the right compliance tool — and then realizing value from it on an ongoing basis — can be easier said than done, ...

How to Get Value from SBOMs Throughout the SDLC 11/17/2022

Join us on December 1st to learn how to operationalize an !

It requires buy-in from the right stakeholders, building the right SBOM-related workflows, and using the right tools — and this can be easier said than done.

FOSSA's Head of Product Kenaz Kwa will discuss best practices for generating SBOMs that can be used throughout the SDLC: http://ow.ly/MSkx50LEh3V

How to Get Value from SBOMs Throughout the SDLC For all of the attention paid to SBOMs (software bill of materials) in recent years, there’s been little conversation about a mission-critical supply chain security use case: integrating SBOMs throughout the software development lifecycle. Instead, SBOMs are generated as a check-box item, placed i...

How UiPath Reduced Open Source Risk Through Team Collaboration - FOSSA 11/16/2022

"Shifting left" refers to the idea that it’s best to identify and fix issues as early as possible in the SDLC.

In the context of open source license compliance and vulnerability management, teams should seek to conduct license compliance and vulnerability analysis integrated directly into existing engineering workflows and as a key component of the CI/CD pipeline.

The security team at UiPath shares, “We’ve seen that it’s a better experience at the CI/CD pipeline level than doing it as a git integration (the code level)."

Learn more on how leveraging FOSSA's CLI helped them reduce open source risk: http://ow.ly/sZF550LGqo3

How UiPath Reduced Open Source Risk Through Team Collaboration - FOSSA Experts from UiPath share best practices to help teams collaborate to reduce risk in their use of open source software.

11/15/2022

Companies like Slack generate Software of Bills ( ) with FOSSA in just minutes.

Learn how to upload your own project in FOSSA's platform integration and how to create a compliance report in accordance with the Cybersecurity Executive Order.

Timeline photos 11/14/2022

software is hugely changing IP risk in the software supply chain.

With the U.S. Supreme Court poised to consider what one lawyer calls the “copyright war of the century” and disputes related to continuing to arise, the space appears to pose increasing legal and reputational risks for businesses.

In partnership with Above the Law, we created a whitepaper for companies to navigate and understand this new landscape:

1. How open-source software became so widespread
2. Why IP risks proliferate in the software supply chain
3. The perils of litigating open source issues

Read more: https://bit.ly/3g2d5Ke

11/10/2022

Why are SBOMs top of mind for in-house counsel at tech companies?

“Number one: security concerns. provide the roadmap in what’s inside your technology. It helps address issues, including compliance, if software offerings are compliant, and for sales.

Customers are wanting more of these—the Biden Executive Order makes it clear that the government is focusing and moving more in that direction,” shares Ryan Cobb, Director of IP at Okta.

Learn more here: https://bit.ly/3ElTrSP

11/09/2022

Shane Coughlan, GM of OpenChain Project, explains how software composition analysis (SCA) tools like FOSSA support compliance with OpenChain ISO/IEC 5230:2020, the international standard for open source license compliance: https://bit.ly/3fEQRxX

Containers and Open Source License Compliance - FOSSA 11/08/2022

3 Tips on Container License Compliance

1. Consider bringing any licensing policies you’ve applied to other areas of your organization to the container environment
2. Build a pre-approved, private registry of base images that are all covered by your organization's policies
3. Use a tool like FOSSA that offers container image license scanning and management

Learn more: http://ow.ly/rmOc50Lx1Sj

Containers and Open Source License Compliance - FOSSA The container ecosystem is fueled by open source components, which means container users must be mindful of license compliance obligations.

Legal Compliance for Modern Software Development 11/08/2022

Evan LeBon, VP and Head of Legal of , shared how in-house counsel can ensure compliance processes keep pace with development.

Learn how the shift from a handful of releases each year to the modern world of dynamic build pipelines, automation, and CI/CD has forced legal teams to address various new challenges. Watch the recording: http://ow.ly/Zqo250LwYnr

Legal Compliance for Modern Software Development As a technology-focused attorney with several leading software companies, Evan LeBon has had a front-row seat to the evolution of software development — and the profound impact it’s had on in-house counsel. The shift from a handful of releases each year to the modern world of dynamic build pipel...

Why Open Source is ESG - FOSSA 11/07/2022

Is open source ESG?

"When it comes to open source, a company today is either part of the solution or part of the problem. These days, almost all companies use software, and most develop it as well.

Companies that have moved beyond the initial stage of using open source software, and matured to the point of releasing it—or even basing their businesses on it—have better reputations in technical communities," says Heather Meeker (Tech Law Partners LLP).

Read more here: http://ow.ly/y3Kj50LwPji

Why Open Source is ESG - FOSSA Leading IP attorney and open source software license compliance expert Heather Meeker explores the connection between ESG investing and OSS.

06/01/2022

We're excited to announce our partnership with Itransition! Their expertise in digital solutions combined with FOSSA’s technology will allow organizations to identify, control, and remediate risk across their open source software supply chains. Read more here: https://bit.ly/3M9WgHj

5 Highlights from the U.S. Senate’s Log4J Vulnerability Hearing - FOSSA 02/15/2022

Here's what happened during last week's U.S. Senate hearing on the Log4J vulnerability: https://fossa.com/blog/5-highlights-us-senates-log4j-vulnerability-hearing/

5 Highlights from the U.S. Senate’s Log4J Vulnerability Hearing - FOSSA The U.S. Senate's hearing on Log4Shell brought to light new information on the Log4J vulnerability and industry's response to it.

How to Ensure OSS License Compliance Doesn't Tank a Transaction 02/11/2022

Several leading legal and open source experts shared strategies to ensure license compliance doesn't get in the way of a successful IPO/M&A/fundraising round in this on-demand webinar. https://www.brighttalk.com/webcast/17752/529029?utm_source=FOSSA&utm_medium=brighttalk&utm_campaign=529029

How to Ensure OSS License Compliance Doesn't Tank a Transaction If you're an in-house lawyer, today's deal market means any day may bring news of an IPO, merger, or even fast-tracked S**C acquisition. The ubiquitous nature of open source software in modern applications means it’s likely that license compliance will be part of due diligence. And, any compliance...

6 Takeaways from the Linux Foundation's SBOM Report - FOSSA 02/07/2022

New: Here are our top takeaways from the Linux Foundation's recent report on SBOMs and software supply chain security. Some really interesting data on the Cybersecurity Executive Order, use of open source, & more. https://fossa.com/blog/6-takeaways-linux-foundations-sbom-report/

6 Takeaways from the Linux Foundation's SBOM Report - FOSSA A new report from the Linux Foundation contains a treasure trove of data on industry attitudes toward SBOMs and software supply chain security.

React Security: How to Fix Common Vulnerabilities - FOSSA 02/04/2022

NEW: A look at common vulnerabilities impacting React component libraries — and steps to mitigate them https://fossa.com/blog/react-security-how-fix-common-vulnerabilities/

React Security: How to Fix Common Vulnerabilities - FOSSA Explore several common vulnerabilities that impact React component libraries and see how to remediate them.

OSS License Compliance Expert Heather Meeker on the AGPL - FOSSA 01/25/2022

NEW: Leading OSS license compliance expert Heather Meeker breaks down the AGPL and its key provisions covering network deployment. https://fossa.com/blog/oss-license-compliance-expert-heather-meeker-agpl/

OSS License Compliance Expert Heather Meeker on the AGPL - FOSSA Heather Meeker, one of the world's foremost experts on open source license compliance, discusses the AGPL and its provisions covering network deployment.

Log4J Vulnerability ‘Log4Shell’ Resource Center - FOSSA 01/18/2022

Stay up to date on all things related to vulnerabilities. Check out our new Log4J Vulnerability Resource Center, featuring blogs, an on-demand webinar, and more: https://fossa.com/resource-library/log4j-vulnerability-log4shell

Log4J Vulnerability ‘Log4Shell’ Resource Center - FOSSA Access resources to help your organization detect, remove, and upgrade vulnerable versions of Log4J.

Open Source Developer Sabotages npm Packages ‘Colors,’ ‘Faker’ - FOSSA 01/11/2022

Our latest blog explores the bizarre case of an open source developer intentionally sabotaging their own libraries. Here's what happened, how to address any issues, and the big-picture view. https://fossa.com/blog/npm-packages-colors-faker-corrupted/

Open Source Developer Sabotages npm Packages ‘Colors,’ ‘Faker’ - FOSSA The developer behind popular npm libraries "Colors" and "Faker" intentionally sabotaged both packages. Here's what to do if your application is impacted.

Dependency Management in Visual Studio: NuGet and Beyond - FOSSA 01/06/2022

Hot off the presses from our engineering blog: Check out our guide to managing dependencies in Visual Studio. https://fossa.com/blog/dependency-management-visual-studio-nuget-beyond/

Dependency Management in Visual Studio: NuGet and Beyond - FOSSA Learn how to manage NuGet package dependencies for your .NET projects using Visual Studio.

Timeline photos 01/01/2022

Happy new year from the FOSSA team! Here's to a happy, healthy, and all-around awesome 2022.

Q and A: Heather Meeker on AGPL, Truth Social - FOSSA 12/29/2021

Q and A: Leading OSS license compliance expert Heather Meeker discusses the AGPL and the license compliance controversy surrounding Truth Social https://fossa.com/blog/heather-meeker-agpl-truth-social-oss-license-compliance/

Q and A: Heather Meeker on AGPL, Truth Social - FOSSA Heather Meeker, one of the world's leading OSS license compliance experts, shares insight on the AGPL and the Truth Social license compliance controversy.

Timeline photos 12/24/2021

To everyone in the open source community and beyond: wishing you and yours a happy and healthy holiday season!

Does TikTok Live Studio Violate GPL v2? - FOSSA 12/22/2021

Is TikTok Live Studio (TikTok's new streaming service) currently in violation of the GPL v2? Here's our analysis https://fossa.com/blog/does-tiktok-live-studio-violate-the-gpl-v2/

Does TikTok Live Studio Violate GPL v2? - FOSSA TikTok recently released a limited test of a new live streaming service, TikTok Live Studio, that may be in violation of the GPL v2 open source software license.

How to Quickly Find and Remediate Log4J Vulnerabilities (Log4Shell) - FOSSA 12/21/2021

NEW: Here's how you can quickly and easily find and fix vulnerabilities using our CLI https://fossa.com/blog/quickly-find-remediate-log4j-vulnerabilities-log4shell/

How to Quickly Find and Remediate Log4J Vulnerabilities (Log4Shell) - FOSSA See how your organization can quickly identify and remediate Log4J vulnerabilities in your code.

How to Fix the New Log4J DoS Vulnerability: CVE-2021-45105 - FOSSA 12/19/2021

NEW: A look at the new denial of service vulnerability, its impact, and important mitigation measures https://fossa.com/blog/how-fix-new-log4j-dos-vulnerability-cve-2021-45105/

How to Fix the New Log4J DoS Vulnerability: CVE-2021-45105 - FOSSA See the impact of the new Log4J denial of service (DoS) vulnerability, and get guidance on how to fix it.

How to Fix the New Log4J DoS Vulnerability: CVE-2021-45105 - FOSSA 12/19/2021

NEW: A look at the new denial of service vulnerability, its impact, and important mitigation measures — https://fossa.com/blog/how-fix-new-log4j-dos-vulnerability-cve-2021-45105/

How to Fix the New Log4J DoS Vulnerability: CVE-2021-45105 - FOSSA See the impact of the new Log4J denial of service (DoS) vulnerability, and get guidance on how to fix it.

Truth Social, AGPL, and OSS License Compliance 12/13/2021

This Thursday: Don't miss Heather Meeker, one of the world's leading OSS license compliance experts, on the Truth Social license compliance controversy and the AGPL: https://www.brighttalk.com/webcast/17752/521473?utm_source=FOSSA&utm_medium=brighttalk&utm_campaign=521473

Truth Social, AGPL, and OSS License Compliance The AGPL — a strong network copyleft open source software license — has been in the news because of alleged license violations committed by Truth Social (a planned Trump Media and Technology Group social media website). But while the Truth Social controversy has placed a spotlight on the AGPL, t...

Log4J "Log4Shell" Zero-Day Vulnerability: Impact and Fixes - FOSSA 12/10/2021

On the severe and wide-ranging impact of the Log4J zero-day vulnerability, plus suggested fixes: https://fossa.com/blog/log4j-log4shell-zero-day-vulnerability-impact-fixes/

Log4J "Log4Shell" Zero-Day Vulnerability: Impact and Fixes - FOSSA A critical vulnerability has been discovered in Apache Log4J, the popular java open source logging library. Here's what happened and how to fix it.

Managing Dependencies in .NET: .csproj, .packages.config, project.json - FOSSA 12/07/2021

Our engineering blog tackles dependency management in .NET: the .sln file, the nuget.config file, and more: https://fossa.com/blog/managing-dependencies-net-csproj-packagesconfig/

Managing Dependencies in .NET: .csproj, .packages.config, project.json - FOSSA Get an overview of the artifacts involved in .NET dependency management, how they interact, and how to use them.

Want your business to be the top-listed Computer & Electronics Service in San Francisco?
Click here to claim your Sponsored Listing.

Videos (show all)

Companies like Slack generate Software of Bills (#SBOMs) with FOSSA in just minutes.Learn how to upload your own project...
Why are SBOMs top of mind for in-house counsel at tech companies? “Number one: security concerns. #SBOMs provide the roa...
How Software Composition Analysis (SCA) Helps with OpenChain Compliance.mp4

Address


San Francisco, CA
94104

Opening Hours

Monday 9am - 5pm
Tuesday 9am - 5pm
Wednesday 9am - 5pm
Thursday 9am - 5pm
Friday 9am - 5pm

Other Software Companies in San Francisco (show all)
Splunk Splunk
250 Brannan Street
San Francisco, 94107

Splunk is the cybersecurity and observability leader: www.splunk.com

Sama AI Sama AI
2017 Mission Street, Ste 301
San Francisco, 94110

Go Beyond Your Data

SmartRecruiters SmartRecruiters
166 Geary Street
San Francisco, 94108

SmartRecruiters enables Hiring Without Boundaries™ by freeing TA teams from legacy ATS

Aria Systems, Inc. Aria Systems, Inc.
100 Pine Street, Suite 2450
San Francisco, 94111

This page is no longer active. Stay up to date with Aria Systems by following us on LinkedIn or X.

Pepper Square Inc. Pepper Square Inc.
415 Jackson Street
San Francisco, 94111

Over the last 19 years, we have helped 300+ leading global companies maximize their outcomes with dig

Carbon Five, A West Monroe Company Carbon Five, A West Monroe Company
201 Mission Street #1800
San Francisco, 94105

Carbon Five is a digital product development consultancy. We partner with our clients to create exce

Nitro Nitro
150 Spear Street, STE 1500
San Francisco, 94105

Accelerate your business with 100% digital document workflows and powerful productivity for all.

Brightidea Brightidea
25 Pacific
San Francisco, 94111

Brightidea is the #1 Customer Rated Idea Management platform on the market. There are over 2.5 Million users worldwide, and $15+ billion in recorded business impact. We are desig...

Anaplan Anaplan
50 Hawthorne Street
San Francisco, 94105

Anaplan is a cloud-native enterprise SaaS company helping global enterprises orchestrate business performance. We enable decisive action in dynamic conditions, turning complexity i...

Autodesk Netfabb Autodesk Netfabb
1 Market Street #200
San Francisco, CA91405

This page has moved, follow us at www.facebook.com/autodeskadvancedmanufacturing for great Netfabb content.

GroundWork Open Source GroundWork Open Source
201 Spear Street, Ste 1650
San Francisco, 94105

GroundWork, Inc. makes GroundWork Monitor, software for providing clouds and data centers with Unified Monitoring for Real. http://www.gwos.com

Lab Zero Lab Zero
1390 Market Street, Ste 200
San Francisco, 94102

Designing and Building next-level experiences for our clients.