This is the multi-page printable view of this section. Click here to print.

Return to the regular view of this page.

About

SK Telecom’s Open Source Governance and Activities

SK Telecom’s Open Source Governance

SK Telecom has established a world-class open source management system. To maximize the technical benefits of open source while effectively managing risks related to licenses, security, and intellectual property, SK Telecom operates a systematic governance structure with two pillars: OSRB (decision-making organization) and OSPO (operations organization).

This governance approach transcends mere regulatory compliance and instead pursues a balanced approach where developers can freely utilize open source while the company manages its risks effectively. Through clear policies, transparent processes, and professional support, SK Telecom fosters a symbiotic relationship between corporate development culture and the global open source community.

How OSRB and OSPO share responsibility

OSRB (Open Source Review Board)

OSRB (Open Source Review Board) is the highest decision-making body in SK Telecom’s open source governance. Comprising leaders from the technology, legal, infrastructure, and security divisions, OSRB establishes corporate open source policies and makes critical risk-related decisions.

OSRB convenes monthly to review monthly open source compliance status and holds quarterly strategic meetings to discuss mid-to-long-term open source policy directions. When necessary, emergency meetings are called to promptly address security issues, legal disputes, and policy violations.

Learn more about OSRB →

OSPO (Open Source Program Office)

OSPO (Open Source Program Office) is the dedicated organization responsible for executing SK Telecom’s open source policies and supporting developers. While OSRB handles decision-making, OSPO operationalizes those policies, collaborates with development teams, and provides necessary guidance and support.

OSPO serves as a bridge between developers and the legal team, swiftly resolving various open source-related issues that arise during development. Additionally, OSPO establishes and executes corporate open source strategies while building and maintaining relationships with the global open source community.

Learn more about OSPO →

Characteristics of SK Telecom’s Open Source Governance

Transparency and Consistency

SK Telecom’s open source governance is founded on transparent policies and consistent processes. Every open source adoption, contribution, and release decision follows clear criteria and processes, with all decisions and their rationales documented. This ensures developers understand what is and isn’t possible and why.

Developer-Centric Support

The ultimate goal of governance is to support developers. OSPO provides guidance enabling developers to freely leverage open source, conducts prior reviews to prevent legal issues, and offers necessary training and consultation. Through this support, developers can maximize open source value while managing company risks.

International Standards Compliance

SK Telecom’s governance is built on the OpenChain international standard. This means following international best practices in open source compliance, officially certified through ISO/IEC 5230 certification. This standards compliance enhances internal trust and facilitates cooperation with global business partners.

Continuous Improvement

SK Telecom operates its open source governance not as a static system but as a continuously improving process. Policies are refined, processes streamlined, and automation tools developed based on developer feedback, community evolution, and technological advances. Through this approach, SK Telecom’s open source management capability continuously improves.

ISO/IEC 5230 (OpenChain) Certification Achievement

SK Telecom obtained ISO/IEC 5230, the OpenChain international standard by Linux Foundation, in 2021. This certification signifies:

  • Establishment of clear open source policies
  • Definition of systematic review and approval processes
  • Continuous developer training and capability enhancement
  • Transparent documentation and tracking of all decisions and activities

Through this systematic governance, SK Telecom strengthens internal confidence, enhances collaboration with the global community, and effectively manages legal risks.

Contact and Collaboration

Open Source Inquiries

All open source-related inquiries regarding SK Telecom’s products and services can be directed to OSPO:

Email: opensource@sktelecom.com

Depending on your inquiry:

  • Open Source Adoption: External open source license review, security assessment, compliance verification
  • Open Source Contribution: CLA/DCO review, legal risk assessment, contribution approval
  • Open Source Release: Project evaluation, license selection, release preparation support
  • Policy Consultation: Open source policy, guidance, and process-related consultation
  • Technical Support: Automation tool usage, compliance management, and other technical support

OSPO responds within 2-3 business days.

Collaboration via GitHub

All of SK Telecom’s open source projects are managed through our GitHub Organization:

GitHub Organization: https://github.com/sktelecom

You can collaborate with us through GitHub in the following ways:

  • Issues: Report bugs, request features, ask questions
  • Discussions: Community discussions and idea sharing
  • Pull Requests: Contribute code and suggest improvements
  • Releases: Check latest versions and download

Governance Details

Developer Guides

External Standards and Communities

SK Telecom’s Open Source Vision

SK Telecom recognizes open source not merely as a development tool, but as a core value for corporate innovation and social contribution. We provide an environment where developers can freely participate and contribute to the global open source community, while simultaneously operating a balanced governance that effectively manages corporate risks.

Through this approach, SK Telecom accelerates technological innovation, strengthens collaboration with the global community, and ultimately pursues societal advancement through open source and sustainable corporate growth.

1 - OSPO

SK Telecom Open Source Program Office

What is OSPO?

OSPO (Open Source Program Office) is the organization responsible for managing open source within a company. Technology, legal, and infrastructure teams collaborate to establish and execute open source policies, and to manage community relationships.

SK Telecom’s OSPO bridges developers and the legal team. It supports developers in maximizing the benefits of open source, while managing the legal risks that open source usage brings around licensing and security. The goal is for open source adoption to be a strategic, responsible decision rather than just a technical choice.

Key Roles of SK Telecom’s OSPO

1. Strategic Planning

OSPO establishes and regularly refines the company’s open source policies, analyzes development teams’ usage patterns, and sets a mid-to-long-term roadmap so the organization can leverage open source systematically.

2. Education and Guidance

OSPO delivers regular open source training for developers and establishes clear policies and guidance on usage, contribution, and release. Compliance checklists and templates simplify the review process.

3. Community Management

OSPO encourages and supports developers’ contributions to external projects, while releasing SK Telecom’s internally developed technology as open source, managing those projects, and engaging external contributors.

4. Policy Execution

OSPO reviews license compliance when development teams use open source, and evaluates security vulnerabilities and IP issues. It also develops and operates automation tools such as ONOT to streamline recurring compliance work.

SK Telecom’s Open Source Decision-Making Structure

SK Telecom’s open source governance is a two-stage structure: OSPO (operations) and OSRB (decision-making). OSPO receives adoption, contribution, and release requests from development teams, conducts an initial review, and presents them to OSRB (Open Source Review Board). OSRB, made up of leaders from technology, legal, infrastructure, and security, conducts the final deliberation on license, security, and IP grounds and decides on approval.

The two-stage OSPO–OSRB review structure

Learn more about OSRB →

Guidance and Support Provided by OSPO

Using Open Source

Adopting external open source follows this process:

  1. License identification and policy-fit review
  2. Compatibility check against licenses already in use
  3. Security vulnerability check
  4. Approval and documentation (for future audits or disputes)

View Open Source Usage Guide →

Contributing to Open Source

Contributing to an external project is supported through this process:

  1. Reviewing the target project’s license, community activity, and legal risk
  2. CLA/DCO review and signing
  3. Contributing code that complies with the project’s license and policy
  4. Documenting the contributed code’s license and confirming IP protection

View Open Source Contribution Guide →

Releasing Open Source

Releasing internally developed technology follows this process:

  1. Pre-approval review for core IP and security concerns
  2. License selection (SK Telecom typically uses Apache 2.0)
  3. Removing internal information and writing documentation
  4. Public release on GitHub and community management

View Open Source Release Guide →

Contact and Communication

Email Contact

All inquiries regarding SK Telecom OSPO and open source management can be sent to opensource@sktelecom.com.

Online Channels

SK Telecom’s open source projects can be found on GitHub at https://github.com/sktelecom. Feedback such as bug reports and feature requests can be filed through each project’s Issues section.

View detailed contact information →

2 - OSRB

SK Telecom Open Source Review Board

What is OSRB?

OSRB (Open Source Review Board) is a decision-making body made up of leaders from technology, legal, infrastructure, security, and IP to manage open source across the enterprise.

While OSPO (Open Source Program Office) handles open source operations and guidance, OSRB is the governance body responsible for major policy decisions and risk management. It systematically reviews license, security, and IP risks before deciding whether to approve new open source adoption or releases.

Core Roles of OSRB

OSRB’s three areas of risk review

1. Policy Establishment and Process Definition

OSRB establishes basic policies for usage, contribution, and release, defines license policy and compatibility guidelines, and sets security and IP policy. It also defines the open source review/approval process and the security vulnerability response process.

OSRB further defines the roles of OSPO, development teams, legal, and security teams through R&R (Roles & Responsibilities), so open source management stays consistent across the organization.

2. Risk Review and Approval

OSRB reviews risk across three areas and grants final approval.

  • License review: Evaluating license type, compatibility, and risk level for new open source
  • Security review: Pre-examining vulnerabilities, defining response measures, checking against security standards
  • IP review: Deliberating patent, trademark, and copyright issues, and reviewing IP protection measures

3. Issue Management and Response

OSRB analyzes issues that arise during open source management and defines a rapid response. Legal disputes are handled together with the legal team, with external experts consulted as needed. Critical issues are reported to executives to finalize an enterprise-wide response.

SK Telecom’s OSRB Composition

Organizational Structure and Roles

SK Telecom’s OSRB is chaired by the IPR Team, with the DevOps, Security, and HR teams participating.

  • IPR Team (chair): Reviews open source licenses, protects IP, checks legal compliance
  • DevOps Team: Evaluates infrastructure/environment-related open source, reviews deployment and operations risk
  • Security Team: Reviews security vulnerabilities, confirms compliance with security and information security policy
  • HR Team: Runs open source training and capability development, supports open source culture, checks policy consistency

Regular Meetings and Decision-Making

OSRB holds monthly meetings to review the month’s open source activity, discuss major issues and risks, and refine policy and process. Long-term strategy, community contribution, and enterprise-wide compliance status are also reviewed. Emergency meetings are convened as needed for security issues, legal disputes, or policy violations.

Contact and Communication

All inquiries regarding SK Telecom’s OSRB and open source management can be directed to opensource@sktelecom.com. We respond within 2-3 business days.

For more detailed information, please refer to the following links:

3 - Contact

SK Telecom OSPO Contact and Inquiry

SK Telecom OSPO Contact

All open source-related inquiries and requests regarding SK Telecom’s products and services can be directed to OSPO (Open Source Program Office). OSPO is the dedicated organization responsible for enterprise open source management, responding to inquiries on various topics including license review, security assessment, policy consultation, and technical support.


Email Contact

SK Telecom OSPO Email Address: opensource@sktelecom.com

You can inquire about various topics via email:

  • Open Source Adoption: You can request license review, security assessment, and compliance verification when planning to adopt external open source in your products.
  • Open Source Contribution: You can request CLA/DCO review, legal risk assessment, and contribution approval when contributing to external open source projects.
  • Open Source Release: You can consult on project evaluation, license selection, and release preparation when planning to publicly release technology developed at SK Telecom as open source.
  • Policy and Guidance: You can consult on open source policies, usage/contribution/release guidance, license understanding, and compliance processes.
  • Technical Support: You can consult on technical issues such as open source management tool usage, automation methods, and security vulnerability response.

Response Time: We respond within 2-3 business days.

Online Channels

GitHub

All of SK Telecom’s open source projects are managed through our GitHub Organization.

GitHub Organization: https://github.com/sktelecom

You can engage in the following activities in each project’s repository:

  • Issues: Report bugs, request features, ask questions, and make suggestions. SK Telecom’s development team regularly monitors and responds.
  • Discussions: Engage in general discussions, share ideas, and participate in community conversations.
  • Pull Requests: Contribute code, fix bugs, and suggest improvements to directly participate in projects.

Security Issue Reporting

If you discover a security vulnerability in an open source project, we recommend not reporting it as a public issue. Instead, please email the security contact specified in the project’s README or SECURITY.md file directly. This prevents vulnerabilities from being exploited before patches are distributed to other users.

When reporting security issues, please include:

  • Detailed description of the vulnerability
  • Reproduction method (PoC, Proof of Concept)
  • Impact assessment
  • Proposed solution (if available)

Before You Inquire

FAQ and Guidance Documents

Reviewing the following documents first can help you find answers to most common questions:

Common Questions

Q: Can we use a specific open source?

Q: We want to publicly release code our team developed as open source.

Q: We want to contribute code to an external open source project.

Q: What is a license?

Q: What open source projects has SK Telecom released?

Internal Governance Organizations

SK Telecom’s open source governance is operated through collaboration between OSPO and OSRB:

For more detailed governance information, please refer to the About page.