Identify Critical Projects
In The Process (Roughly), you learned how to do software composition analysis (SCA) on your free and open source software supply chain (SSC). As a part of this, you learned to Reduce Scope by Focusing on Load-Bearing Links. These load-bearing links are your critical FOSS projects.
It’s possible your business will have more load-bearing links than you’re able to contribute to at first, and that’s OK. Nothing’s wrong with starting small and then scaling up your contribution process as you’re able to prove its success and value to the business.
However, you have no good way to tell how many projects your company is able to support with contributions unless you understand the needs of those critical projects. Once ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access