Home Blog Page 98

Antmicro Doubles Down on Commitment to the Zephyr Project as Community Grows to More Than 1,000 Contributors

Wind River also advances its commitment to the open source ecosystem by joining the project as a Silver Member

SAN FRANCISCO, September 13, 2021 On the heels of its 5th anniversary and inaugural Developer Summit, the Zephyr Project today announces a major milestone with more than 1,000 contributors and 55,000 commits. Zephyr, an open source project at the Linux Foundation that builds a safe, secure and flexible real-time operating system (RTOS) for resource-constrained devices, also welcomes Antmicro as a Platinum member and Wind River as a Silver member.

Zephyr RTOS unites companies, developers and end users around the world to ensure balanced collaboration and feedback to evolve and meet the needs of its community. This innovative relationship among stakeholders advances the Zephyr Project’s support of new hardware, developer tools, sensors, and drivers, while maximizing the functionality of devices that run applications developed using the Zephyr OS.

“The number of contributors to an open source project is one of the best measures of its relevance to the open source community,” said Barna Ibrahim, Chair of the Zephyr Project Marketing Group and Strategic Partner Development Lead at Google. “Today’s announcement represents one more step in our open source journey and increased role in the advocacy, use and contribution across the Zephyr ecosystem. Ultimately, this strong ecosystem will help build secure and safe products across the globe.”

Evidence that momentum will continue growing for the project include:

The 1000th contributor – meet Embla Flatlandsmo and learn more about what and why she contributed to the project in this blog and video.Almost 700 people registered for the first-ever Zephyr Developer Summit in June. The event consisted of 5 mini-conferences, 28 sessions and 51 speakers who presented technical content, best practices, real-world use cases and more. Videos are available on the Zephyr Project Youtube Channel.Zephyr is able to automatically generate an Software Bill of Materials (SBOM) during builds with the 2.6 release, so support for ISO/IEC 5962:2021 SBOMs is already included in the second Long Term Support (LTS) release this fall.It is one of the few open source projects that has a CVE Numbering Authority(CNA) and has an active Project Security Incident Response Team(PSIRT) that manages responsible disclosure of vulnerabilities to product makers. Product creators using Zephyr can sign up for free to be notified of vulnerabilities.  Golioth, a recent new member and Zephyr tool provider, received $2.5 million in seed funding and beta testing, which was all based on the RTOS.Seamless integration with Renode (Antmicro’s simulation framework for complex IoT systems), Nanopb (Protocol buffers for embedded systems),  TensorFlow Lite Micro (software library for embedded machine learning) and others.Antmicro released the Open Source M.2 IoT Smart Module with edge ML capabilities based on EdgeTPU and Zephyr RTOS running on Nordic nrf52840 to enable fully open hardware IoT gateways.

Commitment to Zephyr

Today, the Zephyr Project announces that long-time member Antmicro has doubled down on its commitment by upgrading its membership to Platinum. Peter Gielda, CEO of Antmicro, will join the Zephyr Governing Board.

Additionally, Wind River joined the project as a Silver member. Other project member companies include Adafruit, AVSystem, BayLibre, Eclipse Foundation, Facebook, Fiware, Foundries.io, Golioth, Google, Intel, Laird Connectivity, Linaro, Memfault, Nordic Semiconductor, NXP, Oticon, Parasoft, Pat-Eta Electronics, RISC-V, SiFive, Synopsys and teenage engineering, among others.

“We are delighted to welcome Peter Gielda to the Governing Board,” said Joel Stapleton, Chair of the Zephyr Project Governing Board and Principal Engineering Manager at Nordic Semiconductor. “Antmicro has already contributed so much to Zephyr with board support, demos and documentation. We look forward to working more closely with them and strengthening our community.”

“An active member of the project since its early days, Antmicro has been pioneering the use of Zephyr in several fields, including FPGAs and the RISC-V architecture, in both hard and soft implementations,“ said Peter Gielda, CEO at Antmicro and now Member of the Zephyr Project Governing Board. “Building on top of our work combining TensorFlow Lite Micro, Zephyr and Renode for machine learning development we join our customers and partners Google, Intel, NXP and Nordic Semiconductor in a leadership position in Zephyr to strengthen the vendor-neutral RTOS option for the open source hardware, software and AI solutions that we develop.”

“As we move towards an intelligent systems future, it will become increasingly important to collect and process data at the intelligent edge in real time,” said Amar Parmar, Senior Director, Solution Partners at Wind River. “For resource-constrained devices, Zephyr can be at the heart of where this data originates. Zephyr Project has fostered a vibrant and growing community addressing the technical requirements to deploy a new generation of devices, aligned with modern development practices and tooling. As an original contributor to the code base and an active member of the community, we look forward to continued collaboration.”

To learn more about Zephyr RTOS, visit the Zephyr website and blog.

About the Zephyr Project

The Zephyr Project is an open source, scalable real-time operating system (RTOS) supporting multiple hardware architectures. To learn more, please visit www.zephyrproject.org.

About the Linux Foundation

Founded in 2000, the Linux Foundation is supported by more than 1,000 members and is the world’s leading home for collaboration on open source software, open standards, open data, and open hardware. Linux Foundation’s projects are critical to the world’s infrastructure including Linux, Kubernetes, Node.js, and more.  The Linux Foundation’s methodology focuses on leveraging best practices and addressing the needs of contributors, users and solution providers to create sustainable models for open collaboration. For more information, please visit us at linuxfoundation.org.


The post Antmicro Doubles Down on Commitment to the Zephyr Project as Community Grows to More Than 1,000 Contributors appeared first on Linux Foundation.

2 Bash commands to change strings in multiple files at once

2 Bash commands to change strings in multiple files at once


Karolina Grabowska, Pexels

Search and replace text in several files simultaneously, right from the Linux terminal, to gain efficiency and minimize mistakes.

September 22, 2021


Roberto Nozaki (Red Hat, Sudoer)

Command line utilities  
Text editors  

Read the full article on redhat.com

Read More at Enable Sysadmin

Linux kernel concurrency cheat sheet

Navigating Linux kernel API’s can be very time consuming, so Linux ksplice guru Vegard Nossum put together a very handy time

Click to Read More at Oracle Linux Kernel Development

How to run Podman on Windows

With a little help from Windows Subsystem for Linux, you can use Podman to build container images, run a web server in a container, and more.

Read More at Enable Sysadmin

Michael Cheng Joins the Linux Foundation Board of Directors

We’re pleased to announce that Michael Cheng joined the Linux Foundation Board of Directors earlier this year. Michael is a product manager at Facebook, currently supporting open source and standards work across the company. Michael is a former network engineer and M&A attorney. He previously led the product, commercial, and intellectual property functions on Facebook’s M&A legal team.

Michael has built some of the world’s most valuable and innovative open source ecosystems, representing billions of dollars of value, including GraphQL, Magma, Diem, ML Commons, and many others.

In 2018, Michael helped design the Joint Development Foundation — a lightweight, turnkey solution for the development of technology standards and specifications. Michael then brought in GraphQL as the JDF’s first project. GraphQL now powers trillions of API calls every day for some of the world’s largest companies.

Michael Cheng

Michael was one of the founding members of ML Commons, an industry-wide consortium that aims to unlock the next stage of AI/ML adoption by creating useful measures of quality and performance, large-scale open data sets, and common development practices and resources. Michael served as ML Commons’ first treasurer, and it has since grown to more than 50 members and affiliates representing a broad cross-section of the ML ecosystem.

This year, Michael created the Magma Foundation, the first open source platform that enables telecom operators to build modern and efficient mobile networks at scale. Michael now chairs the board of the Magma Foundation — growing its ranks to more than 20 members this year.

Michael is also a champion of diversity. Late last year, at the height of the pandemic, Michael designed and launched the Major League Hacking (MLH) Fellowship program to address challenges faced by both early-career developers who saw many of their job and internship opportunities disappear open source maintainers struggling to keep projects afloat. The Fellowship has been effective at helping students land desirable jobs while increasing the aggregate health of the open source projects that participate in the program. Michael also launched the Black Developer Scholarship for developers who self-identify as Black or African diaspora to participate in the Fellowship.

Michael has also played an integral role in the creation of the Presto Foundation, eBPF Foundation, Ent Foundation, Reactive Foundation, Urban Computing Foundation, and OpenChain.

“Michael is one of the rare breeds of lawyers who possess both a strong technical background and a sharp mind for process improvement.  His leadership at Facebook has made a meaningful impact within the OpenChain project and beyond.  I warmly welcome him to the Linux Foundation board.”

Dave Marr, Vice President, Legal Counsel at Qualcomm Technologies

“Facebook is built on top of open source and has shown a strong commitment to investing back into the communities from which we all benefit. Micheal’s legal background and technical knowledge make him an ideal member of the Linux Foundation board. His leadership is just another example of Facebook’s commitment to open source and collective innovation.” 

Jim Zemlin, Executive Director, Linux Foundation

“Successful open source work requires an intersection of legal, business, technical, and community thinking and Michael brings all those skills in one very integrated way.  And his perspectives from his experience shepherding multiple open source projects at scale and in production is of great value to the Linux Foundation board. I am excited to welcome him to the board and to work with him on advancing open source innovation.” 

Nithya Ruff – Chair, Linux Foundation Board of Directors, Head, Comcast Open Source Program Office

“Michael’s role in growing some of the Linux Foundation’s most valuable communities cannot be understated. He brings a level of technical depth, legal acumen, and industry credibility that has been instrumental in stitching together novel coalitions of companies, NGOs, and individuals into dynamic and sustainable communities. We’re thrilled to have him on the board.”

Chris Aniszczyk, CTO, CNCF

The post Michael Cheng Joins the Linux Foundation Board of Directors appeared first on Linux Foundation.

SPDX Becomes Internationally Recognized Standard for Software Bill of Materials

Backed by many of the world’s largest companies for more than a decade, SPDX formally becomes an internationally recognized ISO/IEC JTC 1 standard during a transformational time for software and supply chain security

SAN FRANCISCO, September 9, 2021 – The Linux Foundation, Joint Development Foundation, and the SPDX community, today announced the Software Package Data Exchange® (SPDX®) specification has been published as ISO/IEC 5962:2021 and recognized as the international open standard for security, license compliance, and other software supply chain artifacts. ISO/IEC JTC 1 is an independent, non-governmental standards body. 

Intel, Microsoft, Siemens, Sony, Synopsys, VMware, and WindRiver are just a small sample of the companies already using SPDX to communicate Software Bill of Materials (SBOM) information in policies or tools to ensure compliant, secure development across global software supply chains. 

“SPDX plays an important role in building more trust and transparency in how software is created, distributed, and consumed throughout supply chains. The transition from a de-facto industry standard to a formal ISO/IEC JTC 1 standard positions SPDX for dramatically increased adoption in the global arena,” said Jim Zemlin, executive director, the Linux Foundation. “SPDX is now perfectly positioned to support international requirements for software security and integrity across the supply chain.” 

Between eighty and ninety percent (80%-90%) of a modern application is assembled from open source software components. An SBOM accounts for the software components contained in an application — open source, proprietary, or third-party — and details their provenance, license, and security attributes. SBOMs are used as a part of a foundational practice to track and trace components across software supply chains. SBOMs also help to proactively identify software issues and risks and establish a starting point for their remediation.

SPDX results from ten years of collaboration from representatives across industries, including the leading Software Composition Analysis (SCA) vendors – making it the most robust, mature, and adopted SBOM standard. 

“As new use cases have emerged in the software supply chain over the last decade, the SPDX community has demonstrated its ability to evolve and extend the standard to meet the latest requirements. This really represents the power of collaboration on work that benefits all industries,” said Kate Stewart, SPDX tech team co-lead. “SPDX will continue to evolve with open community input, and we invite everyone, including those with new use cases, to participate in SPDX’s evolution and securing the software supply chain.”  

For more information on how to participate in and benefit from SPDX, please visit: https://spdx.dev.

To learn more about how companies and open source projects are using SPDX, recordings from the “Building Cybersecurity into the Software Supply Chain” Town Hall that was held on August 18th are available and can be viewed at: https://events.linuxfoundation.org/supply-chain-town-hall/ 

ISO/IEC JTC 1 is an independent, non-governmental international organization based in Geneva, Switzerland. Its membership represents more than 165 national standards bodies with experts who share knowledge and develop voluntary, consensus-based, market-relevant international standards that support innovation and provide solutions to global challenges.

Supporting Comments


“Software security and trust are critical to our Industry’s success. Intel has been an early participant in the development of the SPDX specification and utilizes SPDX both internally and externally for a number of software use-cases,” said Melissa Evers, Vice President – Software and Advanced Technology Group, General Manager of Strategy to Execution, Intel.


“Microsoft has adopted SPDX as our SBOM format of choice for software we produce,” says Adrian Diglio, Principal Program Manager of Software Supply Chain Security at Microsoft. “SPDX SBOMs make it easy to produce U.S. Presidential Executive Order compliant SBOMs, and the direction that SPDX is taking with the design of their next gen schema will help further improve the security of the software supply chain.”


“With ISO/IEC 5962:2021 we have the first official standard for metadata of software packages. It’s natural that SPDX is that standard, as it’s been the de facto standard for a decade. This will make license compliance in the supply chain much easier, especially because several open source tools like FOSSology, ORT, scancode, and sw360 already support SPDX,” said Oliver Fendt, senior manager, open source at Siemens. 


”The Sony team uses various approaches to managing open source compliance and governance,” says Hisashi Tamai, Senior Vice President, Deputy President of R&D Center, Representative of the Software Strategy Committee, Sony Group Corporation. “An example is the use of an OSS management template sheet that is based on SPDX Lite, a compact subset of the SPDX standard. It is important for teams to be able to quickly review the type, version, and requirements of software, and using a clear standard is a key part of this process.”


“The Black Duck team from Synopsys has been involved with SPDX since its inception, and I personally had the pleasure of coordinating the activities of the project’s leadership for more than a decade. Representatives from scores of companies have contributed to the important work of developing a standard way of describing and communicating the content of a software package,” said Phil Odence, General Manager, Black Duck Audits.


“SPDX is the essential common thread among tools under the Automating Compliance Tooling (ACT) Umbrella. SPDX enables tools written in different languages and for different software targets to achieve coherence and interoperability around SBOM production and consumption. SPDX is not just for compliance, either; the well-defined and ever-evolving spec is also able to represent security and supply chain implications. This is incredibly important for the growing community of SBOM tools as they aim to thoroughly represent the intricacies of modern software,” said Rose Judge, ACT TAC Chair and open source engineer at VMware.

Wind River

“The SPDX format greatly facilitates the sharing of software component data across the supply chain. Wind River has been providing a Software Bill of Materials (SBOM) to its customers using the SPDX format for the past 8 years. Often customers will request SBOM data in a custom format. Standardizing on SPDX has enabled us to deliver a higher quality SBOM at a lower cost,” said Mark Gisi, Wind River Open Source Program Office Director and OpenChain Specification Chair.

About SPDX

SPDX is an open standard for communicating software bill of material information, including provenance, license, security, and other related information. SPDX reduces redundant work by providing common formats for organizations and communities to share important data, thereby streamlining and improving compliance, security, and dependability. For more information, please visit us at spdx.org.


The Linux Foundation has registered trademarks and uses trademarks. For a list of trademarks of The Linux Foundation, please see our trademark usage page:  https://www.linuxfoundation.org/trademark-usage. Linux is a registered trademark of Linus Torvalds.

Media Contact

Jennifer Cloer

for the Linux Foundation



The post SPDX Becomes Internationally Recognized Standard for Software Bill of Materials appeared first on Linux Foundation.

Getting started with JBoss

Getting started with JBoss


Image by Pexels from Pixabay

Learn how to set up JBoss EAP and start using it to build, run, deploy, and manage enterprise Java applications.

September 20, 2021


Ashish Bharadwaj Madabhushana (Red Hat)


Read the full article on redhat.com

Read More at Enable Sysadmin

Audit user accounts for never-expiring passwords with a Bash script

Non-expiring passwords might violate your organization’s policies, so use this basic Bash script to quickly pick them out.

Read More at Enable Sysadmin

How I became a Linux sysadmin

Every sysadmin has an origin story. Here’s mine.

Read More at Enable Sysadmin

How OpenStack’s Keystone handles authentication and authorization

Take a deep dive into the Keystone Identity service and how it interacts with other services by creating a virtual machine.

Read More at Enable Sysadmin