Dirk Riehle's Industry and Research Publications

Category: 2. Building Products

  • Is inner source collaboration like shipping boxes between companies? (Hint: No!!)

    Is inner source collaboration like shipping boxes between companies? (Hint: No!!)

    Most corporate compliance departments believe developer collaboration in inner source projects is like shipping boxes with stuff (products) between the involved parties, for example, companies in a holding. Therefore, they don’t have to change anything about tax accounting and transfer pricing. They couldn’t be more wrong. At the highest superficial level, it appears they may…

  • Inner source and work-from-home

    Inner source and work-from-home

    Inner source is the use of open source best practices inside companies to develop shared components for use in the company’s products. Inner source software doesn’t have to become open source (but might). Like open source software development, inner source software development is inherently asynchronous, distributed, and multi-timezone. Inner source is a match made in…

  • Challenges of tracking and documenting open source dependencies in products: A case study (video)

    Challenges of tracking and documenting open source dependencies in products: A case study (video)

    Today, Andreas (Andi) Bauer presented some of our work on managing open source dependencies in software products. Please watch the talk below (local copy). The presentation is based on the same-name research paper.

  • Why I gray-listed GitHub for open source

    Why I gray-listed GitHub for open source

    Most of my software development is through my professorship, where I guide my student teams in developing (mostly) open source software. We have clear rules in place for how and which open source can be used in our projects and which can’t, like any competent organization. Mostly, it is about license compliance. We owe this…

  • Challenges of tracking and documenting open source dependencies in products [OSS 2020]

    Challenges of tracking and documenting open source dependencies in products [OSS 2020]

    Software vendors need to manage the dependencies of the open source components used in their products. Without this management, license compliance would be impossible, export restrictions could not be maintained, and security vulnerabilities would remain unknown to the vendor. The management of these dependencies has grown in an ad-hoc fashion in most companies. As such,…

  • Managing the open source dependency (Tomas Gustavsson, IEEE Computer)

    Managing the open source dependency (Tomas Gustavsson, IEEE Computer)

    I’m happy to report that the sixth article in the open source column of IEEE Computer has been published. Title Managing the Open Source Dependency Keywords Computer applications, open-source software Authors Tomas Gustavsson, PrimeKey Publication Computer vol. 53, no. 2 (February 2020), pp. 83-87 Abstract: Organizations use open source software in a majority of computer…