Skip to main content

Reference

This section collects the reference materials you need to build an open source management system.

Deliverable Best Practices

Completed examples of the deliverables each stage's agent generates (based on a fictional company). Compare them with the results in your own output/ folder to spot missing items.

DeliverableAgentLink
Organization (role-definition, raci-matrix, appointment-template)organization-designerOrganization deliverables
Policy (oss-policy, license-allowlist)policy-generatorPolicy deliverables
Process (usage-approval, distribution-checklist, vulnerability-response, inquiry-response, process-diagram)process-designerProcess deliverables
SBOM (license-report, copyleft-risk, sbom-management-plan, sbom-sharing-template)sbom-analyst / sbom-managementSBOM deliverables
Vulnerability (cve-report, remediation-plan)vulnerability-analystVulnerability deliverables
Training (curriculum, completion-tracker, resources)training-managerTraining deliverables
Conformance (gap-analysis, declaration-draft, submission-guide)conformance-preparerConformance deliverables

Concepts in Depth

Canonical concept pages linked from the main guide. The policy, process, and tools chapters treat these pages as the source of truth.

DocumentContents
License ClassificationClassification criteria, impact by distribution method, distribution channel allow matrix
Vulnerability Response Deadlines and VEXResponse deadlines by CVSS severity (KWG baseline and organizational SLA), VEX
GlossaryPlain-language definitions of license, SBOM, security, and organization terms

Agent Selection Guide

Which agent to use in which situation, and how agents map to chapters and deliverables, is covered in Creating Deliverables with AI Agents.

More on Tools and Regulations

TopicLink
SBOM generation tools in depthSBOM Generation (syft, cdxgen)
Vulnerability management tools in depthVulnerability Analysis and Response (grype, OSV)
KWG ecosystem toolsKWG Open Source Guide — Tools (FOSSLight, SW360, FOSSology)
Regulatory trendsSoftware Supply Chain Security (EU CRA, EO 14028, Korean SBOM trends)
SKT Open Source GuideLink