This article was collected and archived by Digital Sovereignty Watch from an institutional or public source relevant to digital sovereignty, technology policy, cybersecurity, cloud services, artificial intelligence or European regulation.
Open Source
Recording of Armijn Hemel on Open Source in Electronics Supply Chains
He gives a high level overview of how electronics supply chains work and explains where these can fail in the context of software provenance. Solutions may come from the governance side such as the Cyber Resilience Act, as well as tooling and better information sharing. Mr Hemel studied computer science at Utrecht University, where he explored reproducible builds by building the first prototype of NixOS, a Linux distribution built around the Nix build system, where reproducibility and provenance is central. Since 2005 he has been focusing on open source license compliance and supply chain management in the (consumer) electronics industry, first on the license enforcement side as part of gpl-violations.org, but later (more effectively) as a consultant helping companies come into compliance, fight off trolls and help improve processes. Mr Hemel has co-written academic research papers (MSR 2011, WCRE 2012, ASE 2014), made various open source tools for firmware reverse engineering and license compliance, and frequently talks at (industry) conferences about supply chain management in the (consumer) electronics industry. The series will explore topics such as the software bill of materials, legal consequences, tooling, and the Cyber Resilience Act.