This article was collected and archived by Digital Sovereignty Watch from an institutional or public source relevant to digital sovereignty, technology policy, cybersecurity, cloud services, artificial intelligence or European regulation.
Open Source
Watch Philippe Ombredanne on Tooling in the Software Supply Chain
For provenance, licensing, composition and dependencies, security and vulnerability, quality, obsolescence and sustainability. In this webinar we'll explore the state and trends in open source tooling and automation: Philippe Ombredanne is a FOSS hacker on a mission to enable easier and safer to reuse FOSS code. He is the maintainer of ScanCode, the industry standard license detection tool and other open source tools for software composition analysis and license & security compliance at aboutcode.org. This project is building a new system to help verify the integrity of deployed code packages and validate their origin with external data sources, with the potential to mitigate attacks on open source packages supply chains such as: detecting if a package in use is matching verified code by matching source and binaries exactly and approximately. The series will explore topics such as the software bill of materials, legal consequences, tooling, and the Cyber Resilience Act. Special thanks to all the people who made and released these excellent free resources: Transitioning from NGI to Open Internet Stack — open calls temporarily paused 2026-06-12