Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
Getting It Right With Open Source Software
Rating: 4.8 out of 5(3 ratings)
29 students

Getting It Right With Open Source Software

Lean how to manage software supply chain risk
Created byMartin Callinan
Last updated 2/2025
English
English [Auto],

What you'll learn

  • Risks associated with using open source software components in software development
  • Examples of where it goes wrong with open source software including legal cases and security vulnerability exploits
  • Industry best practices and standards such as the OpenChain Project and ISO 5230
  • A case study of the benefits of implementing an open source software management program for software developers

Course content

7 sections61 lectures2h 55m total length
  • Getting it Wrong with Open Source Software6:19

    Explore how open source software can go wrong, from licensing obligations and mismanagement to source code sharing, security vulnerabilities, and business risks across development.

  • The Open Source Software Supply Chain3:47

    Explore how open source software pervades modern applications, and learn to track licenses, versions, and dependencies across direct and transitive components in the supply chain.

  • Accumulating the Risks with Open Source7:31

    Learn how open source components create licensing obligations from agPL, Apache 2.0, CC BY-NC, and GPL, and how to track versions and remediate vulnerabilities to protect your app.

  • The Organisational Impacts: Apache Struts5:17

    Highlights the organizational risks of open source by examining the Apache Struts breaches at Equifax and Alaska Airlines, showing how outdated components and weak governance drive costly security incidents.

  • The Organisational Impacts: Log4J3:23

    The Log4j2 open source Java logging framework carries a critical vulnerability enabling remote takeover, with widespread attacks; the lecture asks if your organization can identify Log4j2 usage within two hours.

  • The Organisational Impacts: Heartbleed1:07

    Explore the Heartbleed vulnerability in 2014 and its impact on OpenSSL, highlighting how unpatched secure websites and vulnerable devices risk data, fines, and the need for ongoing security management.

  • The Organisational Impacts: Supply Chain Attacks2:10

    Learn how open source risk triggers regulatory fines and security breaches, and how supply chain attacks such as Octopus Scanner on GitHub targeting NetBeans escalate developer access to critical assets.

  • Regulating Open Source Software2:57

    Clarify open source licensing and IP concepts by showing that open source means freedoms, not price, and detailing the four freedoms, Free Software Foundation, and the Open Source Initiative's definition.

  • The Open Source Definition5:28

    Examine risks in open source, including IP infringement and security issues, and consider enforcement by major companies and license obligations to share modifications.

  • The Organisational Impacts: Patrick McHardy4:47

    Explore open source licensing challenges, copyright enforcement, and the roles of Patrick McCarty, Harald Welte, GPL, Netfilter, and the Software Freedom Conservancy in protecting open software.

  • The Organisational Impacts: SFC v Vizio5:10

    Open source enforcement by the Software Freedom Conservancy uses litigation, non-litigation enforcement, and an alternative firmware project to defend copyleft licenses, highlighting the Vizio case.

  • The Organisational Impacts: Stockfish v ChessBase2:23

    Examine the 2021 Stockfish v ChessBase case, outlining GPL v3 disclosure obligations for modified work and the debate over neural network weights as derivative works.

  • The Organisational Impacts: Truth Social1:32

    Explore how open source licensing shapes organizational decisions, using Truth Social and Mastodon to illustrate GPL v3 requirements, AGPL concerns, derivative works, and privacy-focused considerations.

  • The Organisational Impacts: CoKinetic Systems v Panasonic Avionics0:57

    Examine how Panasonic Avionics' Linux-based in-flight entertainment software used open source modules without providing notices or source code, triggering GPL violations and a damages dispute with Co Kinetic, settled.

  • The Organisational Impacts: Artifex1:37

    Explore how Artifex uses a dual licensing model—copyleft licenses like the GPL or a commercial license—to monetize open source software such as Ghostscript.

  • The Organisational Impacts: Lynwood Investments v F5 Networks1:14

    Examine the Lynwood Investments v F5 Networks dispute over nginx ownership, including works for hire, Rambler assignment, and open source BSD license implications.

  • The Organisational Impacts: XimpleWare v Versata Software1:47

    Explore how a small open source XML parser from Simpleware licensed under the GPL exposed organizational risks in Versata's products, highlighting the need for code inventory and IP control.

  • The Organisational Impacts: Enforcement is not Exclusively GPL1:37

    Reveal open source intellectual property risks and infringement driven by contributors like Microsoft. Learn how unmanaged components can devalue a company and complicate due diligence and deal terms in M&A.

  • The Organisational Impacts: Due Diligence0:27

    Open source software is increasingly used across modern solutions, creating organisational impacts that require due diligence to manage vulnerabilities and licensing considerations.

  • Chapter 1 Recap0:27

    Explore why open source software is increasingly used, acknowledge its vulnerabilities, and understand licensing considerations to manage and avoid exploitation.

Requirements

  • This course presumes no knowlege of managing open source software

Description

Our popular "Get it Right With Open Source Software" course is now available as a self-paced program with certification. This course is designed to equip participants with the essential knowledge and skills needed to effectively manage the risks associated with using open source software within their organization and across their supply chain.

Whether you are a developer, legal professional, compliance officer, or business leader, this course provides practical insights into best practices for handling open source software securely and in compliance with relevant regulations. It covers key topics such as licensing, security vulnerabilities, risk assessment, and governance frameworks, ensuring that participants can make informed decisions about open source usage.

A major advantage of this self-paced format is the flexibility to learn at your own speed, allowing professionals to balance their learning with work commitments. No prior knowledge is required, making it accessible to individuals at all levels, from beginners to experienced professionals seeking a structured approach to open source risk management.

By completing this course, participants will earn a recognized certification, demonstrating their expertise in open source software compliance and security. Enroll today to enhance your skills and safeguard your organization’s software ecosystem

If you are a software developer, It risk/governance manager this course is for your


Who this course is for:

  • The course is aimed at anyone concerned with or involved in software management, from Developers to Legal Executives
  • Relevant for develoeprs, architects, legal, compliance and risk managers
  • References industry best practices such as the OpenChain Project