Project
The process required for the development and distribution of software that includes open source software is carried out sequentially.
For detailed information, please refer to the Project tutorial.
1. Identification : Open Source analysis results (FOSSLight Report) are prepared and submitted for review to the OSPO.
2. Packaging : Collect the source code to be disclosed(OSS Package).
3. Distribution : The OSS Notice and OSS Package are registered on the distribution site.
For detailed information, please refer to the Project tutorial.
1. Identification : Open Source analysis results (FOSSLight Report) are prepared and submitted for review to the OSPO.
2. Packaging : Collect the source code to be disclosed(OSS Package).
3. Distribution : The OSS Notice and OSS Package are registered on the distribution site.
Project List
You can search for a project, check the overall information of the project, and download the FOSSLight Report, OSS Notice, and OSS Package. 
1. Project Search
- You can search by the project's name. With Advanced Search feature, you can search using various conditions.
- Advanced Search
- You can search under various conditions such as ID, Creator, Model Name, etc.
- You can search under various conditions such as ID, Creator, Model Name, etc.
- Advanced Search
2. Project ID
- It is a unique number that identifies the project.
3. Projcet Name (Version)
- Double-clicking a row takes you to the project detail screen.
4. Status
- It displays the status information of the project.
| Status | Description |
|---|---|
| Progress | The user is currently writing. |
| Request | The user has requested a review in the Identification or Packaging stage. The status can be changed to Progress using Self Reject. |
| Review | The reviewer is currently reviewing in the Identification or Packaging stage. The user cannot modify the project information. If modifications are needed, please leave a Comment for the reviewer to request a reject. |
| Final Review | The OSPO manager is conducting the final review. |
| Complete | It means the project review is complete. The user cannot modify the project information. If modifications are needed, please request a reopen from the reviewer. |
| Drop | It means the OSC process is no longer being carried out. If it is not in the Complete status, the user can drop it regardless of the status, and if necessary, they can click Reopen to open it again. |
5. OSC Process
- It indicates the progress stage of the project's OSC process.
- Identification -> Packaging -> Distribution
- The color of the process stage changes based on the status.
6. Download
- (
): You can download the list entered in Identification in the FOSSLight Report.
- (
): You can download a Review Report from the Identification SBOM list when risks or important notes are detected in Open Source, License, or vulnerability reviews.
- (
): When the Packaging stage is completed, an icon will be displayed, and you can download the OSS Notice.
- (
): If the source code to be released is uploaded in Packaging, an icon will be displayed, and you can download the OSS Package file.
7. Security
It displays the Vulnerability information for the entire open source list included in the Identification stage (except the ones that ‘Exclude' is checked).
Reference: For more details about Security, see the Security tutorial.
-
How to enter the Security tab
- You can enter the Security tab by clicking the button in the Security column of each project in the Project List.
- You can enter the Security tab by clicking the button in the Security column of each project in the Project List.
-
Status
- (
) : If there is a security vulnerability with a Vulnerability score equal to or higher than the threshold based on the SBOM tab in the Identification stage (the number in parentheses is the project's vulnerability max score)
- (
) : If there is no security vulnerability with a Vulnerability score equal to or higher than the threshold based on the SBOM tab in the Identification stage (the number in parentheses is the project's vulnerability max score) - (
) : If the SBOM tab has not been saved so the OSS list has not been collected, or if no security vulnerability has been found
- (
) : If all security vulnerabilities with a Vulnerability score equal to or higher than the threshold based on the Need to resolve tab have a ‘Fixed' resolution (the number in parentheses is the project's vulnerability max score below the vulnerability score threshold)
- (