About This Project
What is Trusted OSS?
Trusted OSS is an open source initiative building the guides and tools needed to manage an open source supply chain. It is made up of three projects.
- Trusted OSS Guide, the site you are reading. A practical toolkit designed to help you complete self-certification for ISO/IEC 5230 (license compliance) and ISO/IEC 18974 (security assurance) from start to finish.
- Trusted OSS Agent, Claude Code agents that progressively produce policies, organizational setup, processes, SBOMs, training materials, and certification deliverables tailored to your organization.
- TRUSCA, a self-hosted SCA portal that manages vulnerabilities, licenses, and SBOMs in one UI.
Even practitioners with no prior open source governance experience can reach a self-certification declaration by following the guide with the agents alongside.
Alongside the guide we maintain a reference repository, AI Coding Best Practice. It implements the 5-stage AI coding strategy as working configuration files and CI workflows, so you can fork it directly or copy only the files you need.
Other tools covered in the guides are not part of the initiative. BomLens, for example, is a separate open source tool built by SK Telecom that we present as an option for SBOM generation.
Where it started: the OpenChain KWG community
Trusted OSS is an initiative that grew out of the OpenChain KWG (OpenChain Korea Work Group) community. Where KWG provides standards guidance and templates, Trusted OSS builds the tools that turn them into finished artifacts.
It is not a subgroup of KWG. It builds on the guides and templates KWG publishes under CC BY 4.0, with attribution, and its own decisions follow the process in GOVERNANCE.md.
OpenChain KWG is the Korean working group of the Linux Foundation OpenChain Project, which leads the ISO/IEC 5230 international standard. It operates guides, tools, and a community to improve open source compliance capabilities for companies in Korea.
License
All content on this site is released under the CC BY 4.0 license.
With proper attribution, you can freely copy, modify, redistribute, and use it commercially.
"Trusted OSS (CC BY 4.0)"
How to Contribute
All contributions are welcome, including typo fixes, content improvements, and new sample additions.
- GitHub: github.com/trustedoss for issues or pull requests
- Community: OpenChain KWG for quarterly meetings and a mailing list