Skip to main content

Reference

This section collects the reference materials you need to build an open source management system.

Deliverable Best Practices

Completed examples of the deliverables each stage's agent generates (based on a fictional company). Compare them with the results in your own output/ folder to spot missing items. The per-stage list of deliverable files is canonical in the deliverables table of Overview: the two standards and the whole journey.

Concepts in Depth

Canonical concept pages linked from the main guide. The policy, process, and tools chapters treat these pages as the source of truth.

DocumentContents
License ClassificationClassification criteria, impact by distribution method, distribution channel allow matrix
Vulnerability Response Deadlines and VEXResponse deadlines by CVSS severity (KWG baseline and organizational SLA), VEX
GlossaryPlain-language definitions of license, SBOM, security, and organization terms
TalksWhere Trusted OSS has been presented, and the slides

Agent Selection Guide

Create deliverables with AI agents covers which agent to use in which situation. The nine program-building agents map one-to-one to chapters and deliverables, and the seven automation agents write CI and developer-tool configuration or analyze scanner output.

More on Tools and Regulations

TopicLink
SBOM generation tools in depthSBOM Generation (syft, cdxgen)
Vulnerability management tools in depthVulnerability Analysis and Response (grype, OSV)
KWG ecosystem toolsKWG Open Source Guide — Tools (FOSSLight, SW360, FOSSology)
Regulatory trendsSoftware Supply Chain Security (EU CRA, EO 14028, Korean SBOM trends)
SKT Open Source GuideLink