GithubHelp home page GithubHelp logo

Hi there πŸ‘‹

🏒 I help organizations manage open source in a strategic, safe and efficient manner that meets their business needs. Or as I like to put it "How can we do open source at scale and speed whilst staying safe, respect licenses, enable upstream sustainability, and make life easier for our devs?"

I have been working on answering the above question as an open source project maintainer/contributor of various projects and by sharing my experiences trying to help the open source commmunity move forward.

🀝 I’m looking to collaborate on open source supply chain (security), SBOM, and managing open source in organizations. Open to speaking opportunities.

πŸ’¬ Ask me anything open source, dealing with toddlers or about my two cats 😺

πŸ“« How to reach me:

πŸ³οΈβ€πŸŒˆ Pronouns: he/him

Projects

I'm regularly contributing to...

OSS Review Toolkit (ORT) provides tooling to safely use, integrate, modify and redistribute third party software including FOSS.

You can use it to:

  • Generate CycloneDX or SPDX SBOMs for your software project
  • Automate your FOSS policy using Policy as Code to do licensing, security vulnerabilities and engineering standards checks for your software project and its dependencies
  • Correct found invalid or missing package metadata (licensing, source location, etc.)
  • Overwrite scanner license findings in the sources of your software project and its dependencies
  • Mark files, directories or or package manager scopes as not included in your software project or dependency released artifacts - use it to make clear that license findings in build scripts, documentation or tests in a package sources do not apply to the release (binary) artifact
  • Create a source code archive for your software project, including its dependencies to comply with certain licenses or have your own copy as nothing on the internet is forever

I'm one of the project's maintainers and a frequent speaker at conferences as the project's spokesperson.

Software Package Data Exchange (SPDX) is an open standard for Software Bill of Materials (SBOM). SPDX allows the expression of components, licenses, copyrights, security references and other metadata relating to software. I'm currently the lead for Defects team working to exchange quality, vulnerability, and software supportability information in SPDX.

TODO is an open group of organizations that collaborate on practices, tools, and other ways to run successful and effective open source projects and programs. I'm a co-founder of the European chapter of TODO Group, creator/organizer of the OSPOlogy.live and ex-TODO steering committee member.

OpenChain Project is an open standard for open source license compliance. It allows organizations of all sizes and sectors to adopt the key requirements of a quality open source compliance program. I'm a co-founder and regular contributor to the OpenChain Reference Tooling Work Group.

OpenSSF is committed to collaboration and working both upstream and with existing communities to advance open source security for all. I am contributor to the SBOM Everywhere SIG.

The Fintech Open Source Foundation (FINOS)'s purpose is to accelerate collaboration and innovation in financial services through the adoption of open source software, standards and best practices. I am a contributor to various projects within FINOS Open Source Readiness (OSR SIG), for example Q3 2023 I co-authored to the Financial Services Certified Open Source Developer (FSOSD) exam.

Bitkom is Germany’s digital association. I am contributor to the Bitkom Open Source Work Group.

Talks

Below a selection of some of my past presentations...

Thomas Steenbergen's Projects

boost icon boost

boost 1.66.0 for ORT testing

dev-scripts icon dev-scripts

A collection of scripts for development work with Git / Hg and Android.

docassemble icon docassemble

A free, open-source expert system for guided interviews and document assembly, based on Python, YAML, and Markdown.

open-development-template icon open-development-template

Workflow and documentation templates that help teams formalize their goals, workflow and governance model to encourage participation and field contributions.

ort icon ort

A suite of tools to assist with reviewing Open Source Software dependencies.

ort-config icon ort-config

Curations and configuration files for the OSS Review Toolkit.

reportportal icon reportportal

Main Repository. Report Portal starts here - see readme below.

scancode-toolkit icon scancode-toolkit

:mag_right: ScanCode detects licenses, copyrights, package manifests & dependencies and more by scanning code ... to discover and inventory open source and third-party packages used in your code.

spdx-spec-1 icon spdx-spec-1

The SPDX specification in MarkDown and HTML formats.

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    πŸ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. πŸ“ŠπŸ“ˆπŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❀️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.