Reference
This section collects the reference materials you need to build an open source management system.
Deliverable Best Practices
Completed examples of the deliverables each stage's agent generates (based on a fictional company).
Compare them with the results in your own output/ folder to spot missing items.
The per-stage list of deliverable files is canonical in the deliverables table of Overview: the two standards and the whole journey.
| Stage | Link |
|---|---|
| Organization | Organization deliverables |
| Policy | Policy deliverables |
| Process | Process deliverables |
| SBOM | SBOM deliverables |
| Vulnerability | Vulnerability deliverables |
| Training | Training deliverables |
| Conformance | Conformance deliverables |
Concepts in Depth
Canonical concept pages linked from the main guide. The policy, process, and tools chapters treat these pages as the source of truth.
| Document | Contents |
|---|---|
| License Classification | Classification criteria, impact by distribution method, distribution channel allow matrix |
| Vulnerability Response Deadlines and VEX | Response deadlines by CVSS severity (KWG baseline and organizational SLA), VEX |
| Glossary | Plain-language definitions of license, SBOM, security, and organization terms |
| Talks | Where Trusted OSS has been presented, and the slides |
Agent Selection Guide
Create deliverables with AI agents covers which agent to use in which situation. The nine program-building agents map one-to-one to chapters and deliverables, and the seven automation agents write CI and developer-tool configuration or analyze scanner output.
More on Tools and Regulations
| Topic | Link |
|---|---|
| SBOM generation tools in depth | SBOM Generation (syft, cdxgen) |
| Vulnerability management tools in depth | Vulnerability Analysis and Response (grype, OSV) |
| KWG ecosystem tools | KWG Open Source Guide — Tools (FOSSLight, SW360, FOSSology) |
| Regulatory trends | Software Supply Chain Security (EU CRA, EO 14028, Korean SBOM trends) |
| SKT Open Source Guide | Link |