How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

OpenChain

OpenChain is a Linux Foundation project defining conformance requirements for open-source license-compliance and security-assurance programs, ratified as ISO/IEC 5230:2020 and ISO/IEC 18974:2023. It specifies a process an organization runs, not a machine-readable artifact.

OpenChain is the odd one out in this catalog, and deliberately so. Every other specification here describes a document — a contract, an envelope, a schema, an attestation. OpenChain describes an organization: the processes a company must be able to demonstrate for its open-source license compliance (ISO/IEC 5230) and its security assurance (ISO/IEC 18974) to be considered trustworthy by the companies downstream of it.

  • Conformance, not tooling - A short list of requirements about policy, training, records and responsibility, agnostic to which tools you use to satisfy them.
  • Two ISO standards - 5230:2020 for license compliance and 18974:2023 for security assurance, both originating in this project.
  • Self-certification with a public registry - Organizations can attest conformance and be listed, which makes it checkable from outside.
  • Prose, not schema - There is no OpenChain document to parse; the artifact is the program.

It earns a place next to SPDX because the two are halves of one answer. SPDX is the machine-readable bill of materials; OpenChain is the assurance that the organization producing it has a process behind it rather than a one-off script. It is also the clearest example of the Linux Foundation’s ISO play — the same route SPDX took to ISO/IEC 5962 — and a useful reminder that not every standard worth adopting can be linted.