provides software and services that enable enterprises
Live Chat 1-888-673-6564
The Enterprise Open Source Blog
  • Home
  • Search
  • Contact Us
  • Products and Support
  • Services
  • Enterprise OSS Blog
  • Wazi Technical Blog
  • Resources Library
  • Cloud Services
  • Partners
  • Customers
  • Community
  • Company
  • Careers
  • News and Events

Subscribe by Email

Your email:

Most Popular Posts

  • Enterprise Apache Tomcat 7 Clustering - Designing an Efficient, Reliable and Productive Application Server Cluster
  • Open Source Virtual Whiteboards and Dimdim Review
  • An Enterprise Apache Tomcat Clustering Guide
  • Supporting CentOS In The Cloud With Windows Azure
  • VLC License Change: A lesson in perseverance
  • An In-Depth Look at Tomcat’s Clustering Mechanisms
  • Apache HTTP Server: New Features for Version 2.4
  • Why Closed Source is Better Than Open Source
  • Access Serial Ports through Ruby
  • JBoss AS7 Clustering Using mod_cluster and http 2.4 (Part 1)

Connect With Us!

Current Articles | RSS Feed RSS Feed

OSS Provisioning for Origin, Safety, and Maturity of a Community

Posted by Jesse Hood on Fri, Jun 22, 2012
  
Email This Email Article  
Tweet  
  

A critical consideration of a corporate open source software provisioning strategy revolves around the maturity of the community and longevity of that community continuing to develop their project.

Sometimes I wonder exactly how many open source projects exist in the cyber-verse? It's a question that literally might never have an answer.  Universities are one of the a great cultivators of open source projects. This begs the question, how many college students are writing code for a sanctioned, on-going university funded project versus the student who needed to complete their final exam by authoring an open source project they then posted with a very unique URL?  How about the genius high school or even junior high student that got into coding as a hobby and then forgot about the first project they built after he or she moved on to solving much more advanced problems in a university?  What about a small group of unnamed hackers (or a large one with coordinated efforts and organization) that is intentionally building an open source project with malicious intent for the end users?  How would you know of their obfuscated intent?   The consequences of even downloading code from a hacker organization like that could be disastrous!   

The really popular projects get picked up by the worldwide communities and are potentially accepted in the ongoing development at organizations like the Apache Software Foundation.  In other cases a project may be so amazing and attractive to a major technology company that the original authors retain their intellectual property ownership under an open source license while negotiating proprietary and commercial rights to a technology company that sells commercial licenses for the project.  This commercial license may also include other services like technical support and consulting expertise.  But there are still many useful, great open source projects that aren't adopted by well-known communities or backed by commercial offerings.

3489649e-3296-4b0c-846f-9736263af138

In a previous article on this topic I found some statistics from major repositories showing that the number of documented unique OSS packages available are in the hundreds of thousands.  These statistics combined with the accelerated adoption rate of OSS in the enterprise plus the fact that locking down the internet access of employees might not be a realistic approach to manage OSS makes a provisioning strategy critical for successful adoption.  Any enterprise using open source originating either from a repository or from a commmunity maintained home page may want to start asking some of the following questions:

  • What exactly are we getting when we download from this repository?
  • Where did the organization that maintains this repository get this code from?
  • Who really wrote the code? And how long ago?
  • How many developers are going to maintain the code with new patches and new feature enhancements?
  • How long do we think they are going to maintain it for?
  • How well is the project documented on the community home page?
  • How active and helpful is the community’s own support forum?
  • How many releases are coming out from this project every year?
  • What license model has this community selected?
  • Are we downloading code that includes the correct license model that the author intended?

The answers to these questions will help to determine the maturity of the open source software projects development community.  That information in turn can help an enterprise’s development team and information security team make the threshold decision as to whether the project is even worthy of downloading to test in a technical evaluation. 

One solution to this problem is OpenLogic’s publicly available certified library of open source projects called the OpenLogic Exchange (OLEX for short).  We are dedicated to the ongoing adoption of true community versions of open source projects and OpenLogic has a very unique approach to community involvement that benefit's enterprise organizations of all industries.  On customer requests, and usually in the context of purchasing a commercial support contract on open source software products, we will do this kind of background research and community evaluation for your organization.


What other questions do you find yourself asking when evaluating the maturity of an OSS community?

Follow @openlogic
Follow @OSCloudServices

This work is licensed under a Creative Commons Attribution 3.0 Unported License
Creative Commons License.
Tags: Scanning & Provisioning, Governance, Security

Comments

Currently, there are no comments. Be the first to post one!
Post Comment
Name
 *
Email
 *
Website (optional)
Comment
 *

Allowed tags: <a> link, <b> bold, <i> italics

Loading...
Error sending email
Email sent successfully

Email article
Email To : 
Your name : 
Message : (maximum 200 characters)

Enterprise OSS Blog Policy

If you read a post on The Enterprise OSS Blog, please leave a comment. Let us know what you think, even if it's just a few words. Comments do not require approval, but they are moderated.OpenLogic reserves the right to remove any comments it deems inappropriate.

 

click-to-chat-with-a-live-open-source-expert

get-a-quote-on-support

download-the-support-evaluation-kit

Browse by Tag

  • 2013 (2)
  • Agile (1)
  • Apache (2)
  • apache tomcat (1)
  • AS 7 (1)
  • as7 (1)
  • Auditing (5)
  • Azure (2)
  • Budget (1)
  • BusyBox (1)
  • CentOS (3)
  • Closed Source Software (1)
  • cloud (4)
  • clustering (1)
  • CMS (1)
  • Code Scanning (1)
  • commercial distribution (1)
  • Community (4)
  • compliance (40)
  • C-Suite (1)
  • Database (1)
  • developers (2)
  • DevOps (15)
  • diploma (1)
  • Drupal (1)
  • enterprise software (2)
  • foss (5)
  • Gitbhub (1)
  • GNU-Bash (1)
  • Governance (36)
  • guide (1)
  • Hadoop (2)
  • HBase (2)
  • http 2.4 (1)
  • httpd 2.4 (1)
  • Java (1)
  • javascript (1)
  • jboss (3)
  • JBoss Cluster (1)
  • Joomla (1)
  • Legal (21)
  • Legal & Compliance (62)
  • Legal and Compliance (2)
  • license compliance (1)
  • Licenses (12)
  • Linux (4)
  • lisp code (1)
  • martin fowler (1)
  • Mobile (3)
  • mod_cluster (2)
  • MySQL (1)
  • Neal Ford (1)
  • open source (19)
  • open source compliance (1)
  • open source components (1)
  • open source events (1)
  • Open Source Governance (2)
  • open source legal issues (1)
  • Open Source Licensing (3)
  • Open Source Management (38)
  • Open Source Policy (3)
  • open source software (15)
  • Open Source Software Adoption (4)
  • open source software policy (1)
  • Open Source Training (1)
  • Open Source Trends (337)
  • Open Source vs. Commercial Software (3)
  • OSS (5)
  • OSS Packages (2)
  • PaaS (1)
  • paredit (1)
  • picketlink (1)
  • Policy (4)
  • PostgreSQL (1)
  • Presentations (1)
  • Programming (2)
  • red hat (1)
  • RHEL (1)
  • Ruby (1)
  • Scanning (27)
  • Scanning & Governance (12)
  • Scanning & Provisioning (30)
  • Security (13)
  • Shibboleth (1)
  • software compliance (1)
  • Software Development (2)
  • Software Development Lifecycle (7)
  • software infrastructure (1)
  • Solr (1)
  • struts (1)
  • Support (48)
  • Support & Services (2)
  • SUSE (1)
  • Technical Governance (1)
  • The Cloud (35)
  • The C-Suite (2)
  • tomcat (4)
  • Training (10)
  • Ubuntu (1)
  • Uncategorized (69)
  • Windows (1)
  • Windows Azure (1)
  • Wordpress (1)
  • Zookeeper (1)
Home | Search | Contact Us | Products and Support | Services | Enterprise OSS Blog | Wazi Technical Blog | Resources Library | Cloud Services | Partners | Customers | Community | Company | Careers | News and Events
Products
OpenLogic Exchange (OLEX)
License Compliance Module
OSS Discovery
OSS Deep Discovery
OpenUpdate
Services
Open Source Support
CentOS Support
Scanning & Compliance
Open Source Training
Professional Services
Solutions
Support & Indemnification
Open Source Governance
Open Source Scanning
Open Source Provisioning
Consulting & Training
Contact Us
1-888-673-6564


© 2013 OpenLogic, Inc. All rights reserved.
Site Map  |  Privacy Policy