Empowering Open Source: Insights from Eclipse Foundation’s Thabang Mashologu
Thabang Mashologu, Vice President of Community and Outreach for the Eclipse Foundation, discusses the role’s responsibilities in global initiatives and community engagement. The conversation covers the evolution of open source, its industry acceptance, and emerging security challenges. The Eclipse Foundation’s mission focuses on empowering developers and fostering collaboration. Key initiatives like the Cybersecurity Resilience Act and the OCCTET Project aim to enhance open source security.
Transcript
Good day, everyone. Welcome back here to Tech Drunk tv. My next guest, I'm happy to have him on here, is Ang Maho og.
I hope I got that right, right. Tabba, you got it right. Vice Vice President Community and Outreach for the Eclipse Foundation.
Tabba, welcome to Tech Drunk tv. It's great to have you on here. Thanks for having me, Alan.
Happy to be here. Pleasure. Thank you.
Well, it's our pleasure. Tabba, I mentioned your Vice President community and outreach for the Eclipse Foundation. Sounds like a great job.
I think we all admire the Eclipse Foundation for what it's done for, for us in the IT and software world. But let's, let's dig in a little bit. How, how did you get to be the VP for Community and Outreach?
Kinda where, what, what, where's your journey come from in going to? Great question. So, uh, maybe a bit more about my role.
Um, it's a bit of a mouthful, uh, community and outreach, but essentially what it entails is, is responsibility for our global working groups and marketing and developer outreach and engagement initiatives that we have. Anything that's community facing, I'm involved in, my team is involved in, and, uh, I'm really happy to work with a, a great group of folks around the world. Uh, the Cooks Foundation, as, as you noted, has a, you know, a strong legacy of impact, uh, continuing, uh, impact in, uh, the industry, broadly, the open source ecosystem, uh, as a whole.
And what, uh, uh, my team, uh, of, of folks gets to do on a daily basis is to advance those various, uh, projects that, uh, we steward at the Eccles Foundation and promote and drive the participation, uh, across a portfolio, a broad portfolio of technologies, uh, globally. So that's everything from developer tools to, uh, software develop, software defined vehicles, rather, uh, uh, a broad remit of, of technologies and, uh, domains in, in the modern application development, uh, industry. So, with that said, my personal background, I'm actually from a small country in Africa that no one's ever heard of, uh, Otto.
And, uh, I, um, I started my career as a hardware designer and, uh, gradually made my way into open source community development and support, and that's what led me to the, the Eclipse Foundation. I've had stints at the Linux Foundation as well. Um, and in my current role, I am able to, to really do what I have described often as the, the best job in the world, which is to promote the efforts and encourage the participation of others in, in what's really a transformative technology, um, for our world.
Uh, open source is everywhere, and I'm happy to be a part of, uh, ensuring and enabling its success. Absolutely. You know, just during my career spanning, well, more than 30 years now, I such a big difference.
When I first got involved, if you were talking to a, not even just a large company, even a medium sized company, open source was almost a dirty word, right? They didn't want to use open source because they were unsure of licensing. Of course, they didn't have support and training and, and who's gonna maintain it?
And, you know, there were a million questions. And, you know, as I said over the course of my career, that, that, that's flipped on its head, right? Today, virtually every single company is using open source, and even those who claim they're not using open source are because the tools they're using are all based on open source components and, you know, uh, snippets and so forth.
So, you know, it's been open source triumphant, right? O over the last years now, it, it's not been without bumps along the way, right? I think open source security has become an increasingly, uh, you know, divisive or, or let's call it an interesting area, not necessarily divisive.
We've learned that open source, like every other software has vulnerabilities and bugs, and, and we've gotta be vigilant about testing and remediating and patching and updating and, and all of that good stuff. Um, but nevertheless, it, it is the dominant, a dominant form of software today. Now, the Eclipse Foundation is closely tied into open source, right?
The open source is at the heart in many ways. But why don't you, how would you describe the Eclipse Foundation and give us sort of a, a 50,000 foot overview of all the different things the Eclipse Foundation's involved in? Certainly.
So the Eclipse Foundation has been around for over 20 years at this point. And, and we really see our mission as encompassing three important things to empower software developers to enable collaboration in terms of the development of, of open source, uh, technologies. And thirdly, to ensure user freedoms, right?
So the, uh, the freedoms of folks to be able to use and modify and consume open source in a way that is, is, uh, permissive and allows for the overall software industry to, to thrive. I I really want to emphasize the software industry component there, because to your point, open source is everywhere. Open source is like air and water, uh, we need it to breathe.
And the modern economy is fueled by open source. Uh, according to Harvard Business School, upwards of 96% of all commercial software includes open source components. So it's really the default and predominant way that open source, uh, sorry, that software rather is built today, uh, is, is through these open source components, these libraries, these frameworks and tools that, um, comprise, uh, a full stack of, of, uh, capabilities and technologies.
So at the Cliffs Foundation specifically, we have, uh, a long back record of enabling the, the, uh, growth and evolution of technologies that are used by commercial stakeholders, so by businesses of all sizes, uh, and as well as, uh, individual developers to advance software development. So, uh, the Eclipse IDE, uh, that we're named after, and, and the platform that, uh, the IDE is based on is probably, uh, one of the, the most successful examples, uh, in our industry of a community driven and collaboratively developed, uh, piece of infrastructure that has enabled, uh, hundreds, if not thousands of, of organizations to, to successfully commercialize software. It's used by millions of developers around the world.
And, and that's essentially, uh, the basis of, of our foundation, but we have many other technologies at, at this point. We have, uh, more than 20 working groups and interest groups, and our areas of focus include ai. Uh, we, um, are also involved in IOT and, and, uh, edge and cloud, uh, native, uh, development.
Um, and, uh, increasingly we're known as, uh, the, the real center of gravity of software defined vehicles. Our Eclipse SDV, uh, working group has attracted, uh, strong membership growth and, and, uh, and participation from a variety of stakeholders across the, uh, largest, um, uh, organizations in the world and public sector and, and small and medium sized enterprises. So really what we see as our mandate, and, and particularly, uh, this is part of my role, is to, to support, uh, and nurture the growth of a healthy and robust and diverse ecosystem of, of stakeholders, be they the largest companies in the world, the hyperscalers down to, uh, small and medium sized enterprises and startups, as well as our engagements with the public sector, with regulators and countries and regions around the world.
So, um, yeah, as I, as I said, it's a, it's a great place to be, uh, at the forefront of, uh, the innovation and evolution of our, our, our industry and the global economy. Excellent. I love it.
That was a, that was a great overview to Barn. I appreciate it. Let's, if you don't mind, I'd like to kinda shift gears a little bit and focus in on three things.
I, I'd led off with security, right? How important securities become in open source. And, you know, we, we have the Cybersecurity Resiliency Act, and then over at the Eclipse Foundation, you guys have the RC Working Group and the Octet Project.
Let's, first of all, definitions, what is the ORC working Group stand for? What is the Octet Project? How does this all work with the Cybersecurity Resilience Act, and how does it help people watching this?
Or how can it help people watching this navigate open source compliance? Uh, great question. So the ORC Working Group stands for the Open Regulatory Compliance Working Group, and that is Home Deputy, the Coasts Foundation.
But, but you know, beyond us providing a regulatory, uh, or a governance rather, uh, framework for the, the Working Group, it's really a coalition of industry leaders and small, medium sized enterprises, uh, in Europe and beyond, as well as, uh, open source foundations. Uh, we are the largest collaboration in history of open source foundations with 20 and counting, including the Apache Software Foundation, Python Foundation, rust, uh, foundation Software, heritage, and, and vs. Foundation, of course.
So you, you really have this, um, coalescence of, of all of the industry stakeholders that are impacted by the European Union's, the European Union's Cyber Resilience Act, so the CRA, and that came into force in December of 2024. And it really places, uh, uh, an un unprecedented, uh, uh, the, the, the CRA rather provides, uh, a regulatory regime that's unprecedented in our industry, where the entire software supply chain needs to build security into, into their development and operations, and ensure that vulnerabilities are managed in a way that, um, ultimately self safeguards the consumers of, of these products. So it impacts all software that is sold into the European Union.
So it, it, it is expansive in nature because, um, you can imagine that, um, all companies are, all major companies, all startups that want to be successful in the European market need to, to take into account, um, the, uh, the regulation and, and, and impacts of the CRA. It's particularly notable the work that's happening at the ORC because you have this diverse ecosystem of folks coming together, this community coming together to respond to, uh, the CRA and take a role in shaping its implementation. Um, and that's something that as well is, is, is new, and, and we are really proud to be playing a supporting role in, in, uh, enabling the community to respond, to build, uh, the specifications, the tools, the best practices that will benefit the entire industry.
And that's happening, uh, through the, uh, the participation and involvement of Hyperscalers, so Microsoft and Google, and some of the largest companies in the world in, in terms of software and beyond. We have Red Hat participating, uh, Huawei, Nokia, uh, Mercedes-Benz. All of these various, uh, industry leaders and titans are working alongside small, medium-sized enterprises.
So, uh, you know, literally, uh, uh, companies that have dozens of employees who, uh, these small medium enterprises are going to be the ones who really face some of the challenges around the implementation and response to the CRA. Uh, they are folks that, um, you know, think of the startups that you know of. Uh, the vast majority of them don't have the resources to, to necessarily, um, develop secure by design, uh, software development practices and, and procedures.
They don't have the tools, uh, to effectively, uh, handle these vulnerabilities and, and report them. So that's the work that is, is happening under the aegis of the, uh, of the ORC. So that's the ORC.
The Octet Project is, is, um, is a European commission funded initiative that is hosted at the Eclipse Foundation, and we've announced the launch of that. And what that entails is a toolkit, a practical, uh, easily accessible toolkit that is available to small, medium sized enterprises. So, uh, it'll include a CRA compliance checklist, a conformity assessment specification, uh, a variety of, of, uh, uh, tools and, and capabilities that will allow, uh, the small and medium sized enterprises in Europe to respond to the CRA.
So the ORC provides the strategic, uh, response, let's say, from, from the broad base of ecosystem folks. And then the o the Octe project is the tools and, and practical guides on how to respond specifically for small, medium sized enterprises. Some Great, that was, that was a lot there, A lot packed in there.
Vo Thank you for, for laying that all out. Now, of course, everyone on here heard it, and a lot of people said, Hmm, sounds interesting. I'd like to find out more.
How can they find out more? Absolutely. So in terms of ORC, the, the, the way that the ORC works is, uh, it, it, we like to call it is, is built for and by the open source community.
So our engagement model is, is what you'd expect in open source. Everything happens out in the open transparently through get repositories. org, and, uh, find out how to contribute and participate in the development of the, the, the strategic response, the resources, et cetera, that, um, are, um, are being put into place by this, this diverse community of, of folks.
So that's how they can engage with the ORC, uh, working group. Uh, yeah, and that includes going to the, uh, GitHub, uh, repository where you can find the inventory of resources that we announced and, uh, and, you know, being able to, to use those resources. eu, uh, that folks can visit and, um, they can find out about, find out more about the, the work of the, uh, the project and sign up for a mailing list where they can be updated as these resources become available for small, medium, uh, and, uh, uh, similarly sized enterprises.
So, uh, those two venues, the, uh, ORC Working Group website and the octe, uh, uh, website are the best places for people to learn more and also to get involved in responding to what is a transformative and ultimately beneficial regulation for this industry. Uh, software, uh, open source software is everywhere. Security is everyone's job, and it's through regulations such as the CRA, uh, as, as daunting as they seem.
They really, uh, are a call to action for everyone, particularly, uh, the folks, uh, in the open source world that, uh, live and breathe, uh, uh, these challenges every day. Great. Jamba, we're about outta time.
I want to thank you for coming on here and, and telling us all about ORC Working Group OCAD project, how people can help and, and how they get their arms or head around the, uh, cyber Ster Cybersecurity Resilience Act. Right? It's something, it's, it's, it's not needless red tape regulation.
Open source security is a, is real. And, and it's a need. Keep up the great work.
Keep doing what you do. Keep the Eclipse Foundation. Great.
We appreciate you all, and, uh, come back and visit us again soon. Thank you very much for having me out. My pleasure.
Ang Micho, uh, vice President Community and Outreach, the Eclipse Foundation here on Techstrong tv. We're gonna take a break. We'll be back in a second with more.