Don’t Legislate. Automate.
As you learned in Enforce the P&P, having policies is one thing, but enforcing them is another one entirely. I assure you, your SCA team doesn’t want to manually inspect every single inbound FOSS component to ensure that the company is staying in compliance with the terms of the license. As little as your SCA team wants to do it, your software development team wants to do it even less. Rather than risk an uprising by forcing skilled staff members to perform tedious tasks, keep the peace through automation.
The commodity policies that you created are perfect candidates for automation. Some SCA tools, such as Open Source Review Toolkit (ORT),[97] have built-in functionality for automating enforcement of inbound FOSS ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access