Driving compliance: ensuring embedded software visibility in automotive manufacturing
Enhancing compliance visibility in automotive manufacturing
Key takeaways
Gain deeper insight into embedded software to ensure compliance and security.
SCANOSS detects undeclared open source and dependencies, reducing hidden risks.
Stay ahead of legal and regulatory challenges by addressing risks early.
Enhancing compliance visibility in automotive manufacturing
A software supplier for an automotive industry leader faced a critical challenge: ensuring compliance in the software they developed which included both native car apps (APPs) and Internal Combustion Engine (ICE) systems. Building on the base platform provided by the brand, they needed to ensure complete clarity about the software they were delivering back to the brand. This required identifying open source software (OSS) in use, scanning GitHub branches effectively, and implementing basic compliance policies to mitigate hidden risks. Additionally, they sought a comprehensive solution to address open source in AI-generated code and compliance challenges in a unified approach.
With undisclosed software posing risks such as hidden licence obligations and copyright violations, the stakes were high. The team needed to address several technical challenges to ensure compliance and minimise risks. This included defining which licences to check against specific policies, limiting scans to production dependencies impacted by an npm install, and generating comprehensive reports for AI functions integrated into GitHub Actions. Without a solution to these issues, the company risked compliance failures, legal consequences, and operational inefficiencies.
Simplified compliance with SCANOSS
By leveraging SCANOSS’s comprehensive License Dataset, the company gained the ability to find both declared and undeclared open source components, binaries, and dependencies, including critical C and C++ code. SCANOSS offered detailed insights into licences, copyrights, and attributions, enabling the company to address compliance requirements with precision and efficiency. The integration into GitHub Actions was enhanced with the ability to include, exclude, and explicitly configure the set of licences checked. Additionally, new Policy Check reports were delivered as Workflow Artifacts, allowing the team to download each Policy Check result in Markdown format—streamlining their workflows and ensuring accessible and actionable reporting.
THE OUTCOME