这是啥
大部分情况下, 软件不是从头开始构建的,而是各种预先打好包的第三方软件组装的。因此,组织会遇到下述挑战:
In most cases, software today is not built from scratch, but rather assembled from various prepackaged third-party software components.As a result, organizations face the following challenges:
- 各种合规性检查:-使用第三方软件组件时, 许可合规性,ecc检查,IP评估等。
Verifying various aspects of compliance when using third-party software components: license compliance, ECC checks, IP assessments, etc. - 分享知识:-软件组件及其质量。例,哪个组件该被推荐?哪些该被逐步淘汰:-基于标准?
Sharing knowledge about software components and their qualities. For example, which software components should be recommended, which should be phased out based on which criteria? - 提供广泛概述:-所用组件的。 组织和其供应链管理必须具有信息:- 哪些资产集成到哪些产品或解决方案中。
Providing a broad overview of the components used: An organization and its supply chain management must have information about which assets are integrated into which products or solutions.
这三个主要用例针对不同角色:-组织中的: 质量经理, 软件开发人员,法律顾问,软件架构师,研发经理等。但是,所有这些用例有一个共同需求:- 核心:--管理组件。
These three main use cases target different roles in an organization: quality managers, software developers, legal counsels, software architects, R&D managers etc. However, all these use cases share a common need for a central hub that manages insights into software components.
SW360是一个开源软件项目:-基于EPL-1.0许可:-提供给web程序和存储库:-用于收集、组织和提供必要信息:-关于第三方软件的。它建立了一个中心:-为组织中的组件。
SW360 is an open source software project licensed under the EPL-1.0 that provides both a web application and a repository to collect, organize and make available information about software components. It establishes a central hub for software components in an organization. SW360 allows for
- 跟踪组件:-被用于项目产品
- 评估安全漏洞
- 维护许可
- 执行策略? 生成法律文件。