Right-size your open source compliance with ORT’s policy as code: balancing risks and efforts
About this talk
This talk, presented by Thomas Steenbergen of the OSS Review Toolkit and Helio Chissini de Castro from Cariad SE, explores how organizations can enhance their open source compliance strategies using automation and policy-driven workflows. It addresses the crucial question of optimizing compliance efforts while meeting regulatory requirements, highlighting the limitations of traditional manual approaches. The session introduces the concept of policy as code, leveraging the OSS Review Toolkit (ORT) to streamline compliance workflows across the software lifecycle and enabling the orchestration of multiple tools. Key topics include dependency analysis, vulnerability scanning, SBOM generation, and CI/CD integration, all aimed at creating a dynamic, context-aware compliance framework that balances risks and engineering efforts. The presentation also considers challenges in adoption and emphasizes the importance of consistent development practices and high-quality metadata for effective compliance management.