New Paper: “Open Data Standards for Open Source Software Risk Management Routines: An Examination of SPDX”

I presented our paper Open Data Standards for Open Source Software Risk Management Routines: An Examination of SPDX at the ACM GROUP conference in Florida. GROUP is a single-track conference with a great group of participants. I enjoyed the interactions and presentations. GROUP is definitely worth going again. Also, single-track conferences may be my new preferences, because I do not have to decide which of several interesting session to go to.

Paper Abstract:

As the organizational use of open source software (OSS) increases, it requires the adjustment of organizational routines to manage new OSS risk. These routines may be influenced by community-developed open data standards to explicate, analyze, and report OSS risks. Open data standards are co-created in open communities for unifying the exchange of information. The SPDX® specification is such an open data standard to explicate and share OSS risk information. The development and subsequent adoption of SPDX raises the questions of how organizations make sense of SPDX when improving their own risk management routines, and of how a community benefits from the experiential knowledge that is contributed back by organizational adopters. To explore these questions, we conducted a single case, multi-component field study, connecting with members of organizations that employed SPDX. The results of this study contribute to understanding the development and adoption of open data standards within open source environments.

Read more…
The paper is Open Access and is available in the ACM Digital Library.

Full reference:

Gandhi, R., Germonprez, M., & Link, G. J. P. (2018). Open data standards for open source software risk management routines: an examination of SPDX. In Proceedings of ACM GROUP ’18 (pp. 219–229). Sanibel Island, Florida, USA: ACM.