Building Open Source Management into Software Development

Build Open Source Management Into Software Development: Open Source Development Tip #8

November 17, 2011
By Terry Bernstein

2 minute read time

We've been publishing a series of tips on managing your use of open source to maximize benefits and minimize risks. In today's post, we continue with a tip on building open source management into your software development process.

8. Build Open Source Management Into Your Software Development Process

We've found that many organizations wait until development is nearly complete before they run scans to verify that their open source policies have been followed. What else have we found? That developers find this maddeningly frustrating. For example, if an application scan discovers that a component is unacceptable licensed, such as with GPL, you'll have to find a replacement component, rework the code, and retest the application. The project will cost more than expected and be delivered late. The disruption will likely impact the next project, as the team will be stuck longer than expected on the original project.

Frustrated developers often tell us that they'd much rather catch and fix issues during development, rather than wait until the end. We agree.

Here are some of our ideas for ensuring open source compliance without disrupting development:

At this point, you may think all this sounds great, but would be hard to implement in practice without automated tooling. We agree with you, which is why we created Sonatype Insight.

Written by Terry Bernstein
Terry is the former Director of Product Marketing at Sonatype. He is now the Director of Product Management at Verisign.