Software open source treatment method and device based on open source component operation trend characteristics

By obtaining asset information, conducting system inventory and classification, identifying and analyzing the asset information, license compliance and security vulnerabilities of open source software, generating software component bill of materials reports, and monitoring the operational data of open source software in the community, evaluating health status and industry influence, and calculating the system's health status index and overall risk, the problem of the inability to comprehensively manage open source software in existing technologies is solved, and comprehensive open source governance is achieved.

CN120671135APending Publication Date: 2025-09-19BANK OF HANGZHOU CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510509402.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-22
Publication Date
2025-09-19

AI Technical Summary

Technical Problem

Existing open source governance methods cannot achieve comprehensive management, especially in terms of intellectual property management and security assessment, making it difficult to effectively identify and assess the potential risks of open source software.

Method used

By obtaining asset information, conducting system inventory and classification, identifying and analyzing the asset information, license compliance and security vulnerabilities of open source software, generating a software component bill of materials report, and monitoring the operational data of open source software in the community, the health status and industry influence are assessed, the system health index and overall risk are calculated, and finally the calculation results are displayed in a visual form.

Benefits of technology

It achieves all-round governance of open source software, fully understands its usage and potential risks, provides intuitive governance information to support decision-making, and ensures the security and compliance of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120671135A_ABST
    Figure CN120671135A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a software open source treatment method and device based on open source component operation trend characteristics. The method comprises the following steps: acquiring asset information input by a terminal; performing system checking and grading classification according to the asset information to obtain the structural composition of the information system; identifying and analyzing asset information, license compliance and security vulnerabilities of the open source software according to the structural composition of the information system, and generating a software component bill of material report; monitoring and analyzing the operation data of the open source software in the community, and evaluating the health condition and the industry influence to obtain an operation trend analysis result; calculating a health condition index and an overall risk of the system to obtain a calculation result; and sending the calculation result to the terminal, so that the terminal displays the calculation result in a visual form. By implementing the method provided by the embodiment of the invention, classification and grading of the information system can be realized, and comprehensive open source management is carried out by combining measures of technology, operation and maintenance and security levels.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to computers, and more particularly to a method and apparatus for software open source governance based on operational trend characteristics of open source components. Background Art

[0002] Currently, enterprises widely utilize open source software when building software products. This is particularly true in the financial industry, where many core software products contain significant amounts of open source code. The use of open source code is particularly prevalent in emerging technologies. Fintech, as an information technology-driven innovation, has driven a shift from the traditional closed-source model to the current open-source model. Open source is more than just the release of source code; it also incorporates the concepts of openness, sharing, and collaboration, providing new impetus for fintech innovation. However, this also brings with it new challenges in open source software governance.

[0003] To effectively assess and govern the use of open source software, enterprises require a comprehensive solution to help identify potential risks within open source software applications, improve governance efficiency and accuracy, and promote the healthy and sustainable development of fintech software development. However, current open source governance challenges primarily focus on intellectual property management and open source software security assessments. Existing open source governance products primarily address technical, operational, and security issues. Technically, open source governance can leverage techniques such as software component analysis to generate a bill of materials for open source software, detailing the components used and their supply chain. This provides visibility into open source components and helps enterprises conduct security reviews and compliance management of third-party components, ensuring they adhere to corporate standards and mitigate potential risks. On the operational and security front, open source governance can continuously monitor vulnerability risks throughout the software lifecycle, issuing timely alerts when risks are discovered, providing precise problem descriptions and remediation recommendations, and analyzing security risk trends. However, open source governance should also address a management perspective, ensuring comprehensive open source governance of software. Existing open source governance methods cannot address this comprehensive aspect of software governance.

[0004] Therefore, it is necessary to design a new method to classify and grade information systems, and conduct comprehensive open source governance by combining technical, operational, and security measures. Summary of the Invention

[0005] The purpose of the present invention is to overcome the shortcomings of the prior art and provide a software open source governance method and device based on the operational trend characteristics of open source components.

[0006] To achieve the above objectives, the present invention adopts the following technical solutions: a software open source governance method based on the operational trend characteristics of open source components, comprising:

[0007] Obtain asset information input by the terminal;

[0008] Conducting system inventory and hierarchical classification based on the asset information to obtain the structural composition of the information system;

[0009] Identify and analyze asset information, license compliance, and security vulnerabilities of open source software based on the structural composition of the information system, and generate a software component bill of materials report;

[0010] Monitor and analyze the operational data of open source software in the community, assess its health status and industry influence, and obtain operational trend analysis results;

[0011] Calculating a health status index and an overall risk of the system based on the software component bill of materials report and the operation trend analysis result to obtain a calculation result;

[0012] The calculation result is sent to a terminal so that the terminal displays the calculation result in a visual form.

[0013] A further technical solution is: identifying and analyzing the asset information, license compliance, and security vulnerabilities of open source software based on the structural composition of the information system, and generating a software component bill of materials report, including:

[0014] Obtaining system project source code according to the structural composition of the information system;

[0015] Obtain configurations independently developed based on the company's open source software organizational structure and management system;

[0016] Create a scanning and analysis task based on the configuration, covering code origin, quality, and intellectual property security assessment indicators;

[0017] Perform the scanning and analysis tasks to identify and evaluate open source software assets, vulnerabilities, license usage, and whether they comply with enterprise policies to obtain analysis results;

[0018] A software component bill of materials report is generated based on the analysis results.

[0019] A further technical solution is: performing the scanning and analysis task to identify and evaluate open source software assets, vulnerabilities, license usage, and whether they comply with enterprise policies, to obtain analysis results, including:

[0020] Execute the scanning and analysis tasks, using code snippet analysis, binary analysis, and deep dependency analysis techniques to identify and evaluate open source component assets, vulnerabilities, license usage, and whether they comply with enterprise policies from the dimensions of components and versions, licenses, security vulnerabilities, and custom policies to obtain analysis results.

[0021] A further technical solution is that the software component bill of materials report includes details of all dependent components, license status, identified vulnerability data and policy violations.

[0022] The further technical solution is: the monitoring and analysis of the operational data of open source software in the community, the assessment of health status and industry influence, and the acquisition of operational trend analysis results, including:

[0023] Collect statistics on all open source software corresponding to the asset information, and monitor the activity, application rate, impact factor, defect repair rate, and version iteration of the community website where the open source software is located to obtain monitoring results;

[0024] Obtain operational data on open source software in the community;

[0025] Calculate a health assessment table and score for each open source software based on the open source software operation data in combination with a pre-set security evaluation model and indicator weights to obtain a health calculation result;

[0026] The health calculation results and the monitoring results are summarized and a comprehensive score is calculated to obtain an operation trend analysis result.

[0027] A further technical solution is: the health status index and overall risk of the system are calculated based on the software component bill of materials report and the operation trend analysis results to obtain calculation results, including:

[0028] Based on the software component bill of materials report and the operation trend analysis results, a pre-set application health assessment model is used to calculate the health status index and overall risk of the system to obtain a calculation result.

[0029] The present invention also provides a software open source governance device based on the operational trend characteristics of open source components, including:

[0030] An asset information acquisition unit, configured to acquire asset information input by a terminal;

[0031] A hierarchical classification unit, configured to perform a system inventory and hierarchical classification based on the asset information to obtain a structural composition of the information system;

[0032] a software component analysis unit, configured to identify and analyze asset information, license compliance, and security vulnerabilities of open source software based on the structural composition of the information system, and generate a software component bill of materials report;

[0033] Operation trend analysis unit, used to monitor and analyze the operational data of open source software in the community, assess its health status and industry influence, and obtain operational trend analysis results;

[0034] an overall calculation unit, configured to calculate a health status index and an overall risk of the system based on the software component bill of materials report and the operation trend analysis result, to obtain a calculation result;

[0035] The visualization display unit is used to send the calculation result to the terminal so that the terminal displays the calculation result in a visualization form.

[0036] Its further technical solution is: the software component analysis unit includes:

[0037] A source code acquisition subunit, configured to acquire the system project source code according to the structural composition of the information system;

[0038] The configuration acquisition subunit is used to obtain the configuration independently formulated according to the enterprise's open source software organizational structure and management system;

[0039] A task creation subunit, configured to create a scanning and analysis task covering code origin, quality, and intellectual property security assessment indicators according to the configuration;

[0040] An assessment and analysis subunit, configured to perform the scanning and analysis tasks to identify and assess open source software assets, vulnerabilities, license usage, and whether they comply with enterprise policies, thereby obtaining analysis results;

[0041] The report generation subunit is used to generate a software component bill of materials report based on the analysis results.

[0042] The present invention further provides a computer device, comprising a memory and a processor, wherein a computer program is stored in the memory, and the processor implements the above method when executing the computer program.

[0043] The present invention also provides a storage medium, wherein the storage medium stores a computer program, and the computer program implements the above method when executed by a processor.

[0044] Compared with the prior art, the beneficial effects of the present invention are as follows: the present invention obtains asset information input by the terminal, inventories and classifies the structural composition of the information system, clarifies the open source software elements involved in the system, and then identifies and analyzes the asset information, license compliance and security vulnerabilities of the open source software, generates a software component bill of materials report, and comprehensively grasps the usage and potential risks of the open source software; monitors and analyzes the operational data of the open source software in the community, evaluates its health status and industry influence, obtains operational trend analysis results, and understands the development dynamics and stability of the open source software; based on the software component bill of materials report and operational trend analysis results, calculates the health status index and overall risk of the information system, and quantitatively evaluates the usage risk of the open source software and the system health; finally, sends the calculation results to the terminal and displays them in a visual form, providing decision makers with intuitive and comprehensive governance information, supporting the rectification and governance decisions of the open source software, and realizing all-round open source governance.

[0045] The present invention will be further described below with reference to the accompanying drawings and specific embodiments. BRIEF DESCRIPTION OF THE DRAWINGS

[0046] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0047] Figure 1 A schematic diagram of an application scenario of a software open source governance method based on open source component operation trend characteristics provided by an embodiment of the present invention;

[0048] Figure 2 A flowchart of a software open source governance method based on open source component operation trend characteristics provided by an embodiment of the present invention;

[0049] Figure 3 A schematic diagram of a sub-process of a software open source governance method based on open source component operation trend characteristics provided by an embodiment of the present invention;

[0050] Figure 4 A schematic diagram of a sub-process of a software open source governance method based on open source component operation trend characteristics provided by an embodiment of the present invention;

[0051] Figure 5 A schematic block diagram of a software open source governance device based on open source component operation trend characteristics provided by an embodiment of the present invention;

[0052] Figure 6 A schematic block diagram of a software component analysis unit of a software open source management device based on open source component operation trend characteristics provided by an embodiment of the present invention;

[0053] Figure 7 A schematic block diagram of an operation trend analysis unit of a software open source governance device based on the operation trend characteristics of open source components provided by an embodiment of the present invention;

[0054] Figure 8 A schematic block diagram of a computer device provided in an embodiment of the present invention. DETAILED DESCRIPTION

[0055] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of them. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.

[0056] It will be understood that when used in this specification and the appended claims, the terms “comprises” and “comprising” indicate the presence of described features, integers, steps, operations, elements and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components and / or groups thereof.

[0057] It should also be understood that the terminology used in this specification is for the purpose of describing particular embodiments only and is not intended to limit the present invention. As used in the specification and appended claims, the singular forms "a," "an," and "the" are intended to include the plural forms unless the context clearly indicates otherwise.

[0058] It should be further understood that the term "and / or" used in the present description and the appended claims refers to and includes any and all possible combinations of one or more of the associated listed items.

[0059] See also Figure 1 and Figure 2 , Figure 1 Schematic diagram of an application scenario of a software open source governance method based on the operational trend characteristics of open source components provided in an embodiment of the present invention. Figure 2This is a schematic flow chart of an open source software governance method based on operational trend characteristics of open source components, provided by an embodiment of the present invention. This open source software governance method based on operational trend characteristics of open source components is applied to a server. The server interacts with terminals and first obtains asset information input by the terminals to inventory and classify the information system to clarify its structural composition. Next, based on the system's structural composition, a scanning and analysis task covering code source, quality, and intellectual property security assessment indicators is used to identify and analyze the asset information, license compliance, and security vulnerabilities of the open source software, generating a detailed software component bill of materials report. Simultaneously, operational data of the open source software in the community, such as activity and adoption rate, is monitored and analyzed to assess its health status and industry influence, generating operational trend analysis results for the open source components. Then, combining the software component bill of materials report with the operational trend analysis results, a pre-defined application health assessment model is used to calculate the system's health index and overall risk. Finally, these calculated results are sent to the terminals for display, achieving comprehensive open source governance of the information system at the technical, operational, and security levels, ensuring system health and reducing risks.

[0060] Figure 2 This is a flow chart of a software open source governance method based on the operating trend characteristics of open source components provided by an embodiment of the present invention. Figure 2 As shown, the method includes the following steps S110 to S160.

[0061] S110. Acquire asset information input by the terminal.

[0062] In this embodiment, information about all components in the software system, especially open source components, is collected from various internal and external data sources. This information can be submitted to the system directly from the user terminal through manual input or automated processes.

[0063] Asset information generally includes but is not limited to the following categories:

[0064] Software component names and versions: Identify each open source software used and its specific version.

[0065] License information: This includes the type of license (e.g., GPL, MIT, etc.) that comes with the open source software, which is crucial for ensuring compliance.

[0066] Dependency diagram: Shows the interdependencies between open source software and other components, helping to understand the architecture of the entire system.

[0067] Security vulnerability status: Recording known security issues or potential risk points helps to timely patch and maintain system security.

[0068] Update History and Change Log: Provides historical updates of open source components and descriptions of any important changes.

[0069] The asset information of open source software places special emphasis on the following aspects:

[0070] Code origin verification: Confirm the authenticity and legality of open source software and avoid using uncertified third-party modified versions.

[0071] License compliance check: Ensure that the open source software used complies with the company's usage policy and adheres to the corresponding open source agreement requirements.

[0072] Quality assessment indicators: Evaluate the quality level of open source software based on factors such as community activity and the number of contributors.

[0073] Security audit results: Regularly perform security scans on open source components to identify and fix potential security risks.

[0074] This step goes beyond simply collecting data; it also involves preliminary analysis and verification to ensure the validity and accuracy of subsequent processing. This step is the foundation for achieving comprehensive open source governance, ensuring that enterprises can effectively manage their open source resources.

[0075] S120: Perform system inventory and classification based on the asset information to obtain the structural composition of the information system.

[0076] In this embodiment, the structural composition of an information system refers to a detailed description of the components of the entire information system after being broken down from a technical perspective and their interrelationships. It generally includes the following aspects:

[0077] Layer division: Shows the overall architecture of the system from the bottom to the top, such as the hardware layer, operating system layer, application service layer, user interface layer, etc.

[0078] Modular view: Identifies the independently functioning and maintainable modules of the system and how they work together to accomplish specific tasks.

[0079] Dependency diagram: Draws out the dependency relationships between components to help understand which parts are core components and which are auxiliary or supporting.

[0080] Open source software integration points: Clearly indicate the specific location and function of all open source software used in the system to facilitate subsequent management and update operations.

[0081] Leveraging previously acquired asset information, we conduct a comprehensive scan and inventory of the enterprise's internal information systems. This step not only identifies all open source software elements, such as components, libraries, and frameworks, used within the information system but also meticulously categorizes these elements into different levels, clearly demonstrating the system's structural composition and ultimately outputting a detailed bill of materials for the software components.

[0082] Specifically, automated tools are used to perform deep scans of all enterprise information systems to identify all open source software elements contained therein. The open source software information from the scan results is summarized, including key data such as name, version number, license type, and dependencies.

[0083] Open source software can be classified by function and divided into different categories according to its functional characteristics, such as front-end framework, back-end service, database management system, etc.

[0084] Classify by risk level, evaluate the security, compliance and other factors of each open source software, and determine its risk level (high, medium, low).

[0085] Assign importance weights to each component based on business requirements and the role of the software in the overall system architecture.

[0086] By thoroughly understanding and documenting the structural components of information systems, enterprises can not only better manage their IT resources but also respond quickly to security threats or changes in compliance requirements, ensuring business continuity and security. Furthermore, detailed structural components provide valuable reference for future system upgrades and optimizations.

[0087] S130. Identify and analyze the asset information, license compliance, and security vulnerabilities of the open source software based on the structural composition of the information system, and generate a software component bill of materials report.

[0088] In this embodiment, the software component bill of materials report includes details of all dependent components, license status, identified vulnerabilities, and policy violations. The software component bill of materials report not only summarizes the use of open source software in information systems but also serves as a crucial tool for ensuring the effective implementation of an enterprise's open source governance strategy. It helps enterprises identify and manage the various risks associated with open source software, thereby ensuring the security and compliance of their information systems.

[0089] Specifically, details of all dependent components: List each open source component used in the system, and provide information such as its name, version, source (open source, self-developed, or unknown), and risk level.

[0090] License Status: Displays each component's license type, license risk level, features, and any conflicts with other licenses.

[0091] Identified vulnerability data: Details the security vulnerabilities found in each component, including vulnerability scores, proof-of-concept information, reachability verification results, and remediation recommendations.

[0092] Policy violations: Records any behavior or component that violates the enterprise's pre-set open source governance policies, and provides information on the components and baseline policies of the triggered project policies.

[0093] In one embodiment, see Figure 3 , the above-mentioned step S130 may include steps S131 to S135.

[0094] S131. Obtain system project source code according to the structural composition of the information system.

[0095] In this example, it is necessary to clearly define the structure of the enterprise's internal information system, including but not limited to different modules such as the server, client, and database. Then, the source code of the relevant projects is obtained by manual import, batch import, or direct pull from the code repository. This step not only involves system projects in various programming languages ​​​​(such as Java, Python, C++, etc.), but also includes files in various formats such as binaries, executable files, Docker images, installation packages, firmware, etc.

[0096] S132. Obtain the configuration independently formulated based on the enterprise's open source software organizational structure and management system.

[0097] In this example, enterprises need to develop a series of configuration parameters based on their open source software usage, organizational structure, and management practices. These configurations include defect management, project policy, and baseline policy. These configurations serve as a critical basis for subsequent scanning and analysis tasks, ensuring that the assessment criteria meet the enterprise's actual needs and risk tolerance. For example, an enterprise may set specific security level requirements or have preferences or restrictions for certain license types.

[0098] S133. Create a scanning analysis task covering code source, quality, and intellectual property security assessment indicators based on the configuration.

[0099] In this example, based on the enterprise-specific configuration obtained in the previous step, a comprehensive scanning and analysis task is created. This task aims to cover three major categories of security assessment indicators: code origin, code quality, and intellectual property. Specifically, the analysis task not only checks the original source of the code (whether it comes from legitimate open source resources), but also assesses the quality of the code (whether there are potential defects or performance issues) and ensures that the intellectual property used (primarily licenses) complies with the company's policy requirements.

[0100] S134. Execute the scanning and analysis task to identify and evaluate open source software assets, vulnerabilities, license usage, and whether they comply with enterprise policies to obtain analysis results.

[0101] In this embodiment, the analysis results refer to a series of evaluation conclusions obtained after executing the above-mentioned scanning and analysis tasks, mainly including:

[0102] Open source component asset identification results: As mentioned above, including component name, risk level, version, source, dependencies, etc.

[0103] Vulnerability identification results: All security vulnerabilities identified for each component, including vulnerability severity, impact scope, exploitability verification results, and remediation guidelines.

[0104] License analysis results: Provides comprehensive information about component licenses, helping you determine their legal compliance and avoid potential legal risks.

[0105] Policy compliance check results: Based on the standards and specifications established within the enterprise, check whether the use of open source software complies with the company's policy requirements, point out non-compliance areas, and provide improvement suggestions.

[0106] Specifically, the scanning and analysis task is performed, and code snippet analysis, binary analysis and deep dependency analysis techniques are used to identify and evaluate open source component assets, vulnerabilities, license usage and whether they comply with enterprise policies from the dimensions of components and versions, licenses, security vulnerabilities and custom policies to obtain analysis results.

[0107] In this embodiment, code snippet analysis, binary analysis and deep dependency analysis techniques are used to perform detailed identification of each component. This includes obtaining information such as component name, component risk level, component version, component source (open source, self-developed, unknown) and component dependency introduction. The security status of each component is deeply analyzed, all known security vulnerabilities are identified, and relevant vulnerability level distribution, vulnerability PoC information, vulnerability score and reachability verification results are collected. At the same time, detailed repair suggestions are provided for each discovered vulnerability. For each component, its license name, license risk level, license characteristics and any possible license conflicts are obtained. This helps companies ensure at a legal level that the open source software they use will not cause copyright disputes or other legal liabilities. According to the company's pre-set baseline policy, check whether the use of open source software complies with the company's governance policy. If any violations are found, record them immediately and reflect them in the final report.

[0108] S135. Generate a software component bill of materials report based on the analysis results.

[0109] In this example, all open source components used in the system are listed, including their name, version, source, risk level, and other relevant information. License details for each component are provided, including license name, risk level, features, and conflicts with other licenses. All identified security vulnerabilities are summarized, ranked by severity, and provided with corresponding remediation recommendations. All violations of corporate policies discovered during the analysis are summarized and improvement recommendations are provided.

[0110] S140. Monitor and analyze the operational data of open source software in the community, assess its health status and industry influence, and obtain operational trend analysis results.

[0111] In this embodiment, the operational trend analysis results represent a comprehensive summary of the overall health and industry influence of all open source software. It not only includes the health assessment table and score for each open source software, but also integrates various key performance indicators (KPIs) derived from long-term monitoring, such as community activity, adoption rate, impact factor, bug fix rate, and version iteration status. A comprehensive score is calculated through weighted average or other mathematical methods to guide enterprises in making more informed choices regarding future open source software selection, maintenance strategy formulation, and risk management decisions.

[0112] It can be seen that the results of the operational trend analysis are a comprehensive assessment of the current health status and future development trends of open source software, helping enterprises identify which open source software needs to continue to be supported and which may face risks, thereby optimizing their open source governance strategies.

[0113] In one embodiment, see Figure 4 , the above-mentioned step S140 may include steps S141 to S144.

[0114] S141. Collect statistics on all open source software corresponding to the asset information, and monitor the activity, application rate, impact factor, defect repair rate, and version iteration of the community website where the open source software is located to obtain monitoring results.

[0115] In this embodiment, the monitoring results are obtained by collecting statistics on all open source software and monitoring their performance on the open source community website. Specifically, they include:

[0116] Community website activity: Measure the prosperity of the community by analyzing the number of active users interacting in the open source community, the changing trends of code contributors, etc.

[0117] Application rate: Assess the popularity and actual application of open source software based on indicators such as download volume, installation times, and issue count.

[0118] Impact Factor: Considers the recognition of open source software in the industry, such as star rating, citation frequency, etc.

[0119] Defect repair rate: reflects the open source software maintenance team's response speed and resolution efficiency for known issues, including vulnerability repairs, functional improvements, etc.

[0120] Version iteration: Pay attention to the release frequency, quality and innovation of updated content, and understand the development dynamics of the project.

[0121] S142. Obtain operational data of open source software in the community.

[0122] In this embodiment, this step involves collecting relevant operational data of open source software from multiple channels. These channels may include open source community websites, software hosting platforms (such as GitHub), CVE vulnerability libraries, etc. The types of data collected include but are not limited to:

[0123] Open source community interaction data (such as the number of comments and the number of people participating in the discussion);

[0124] Software usage statistics (downloads, installations, and issues);

[0125] Industry recognition indicators (star rating, number of citations);

[0126] Defect repair records (vulnerability repair time, repair status);

[0127] Version update details (release schedule, update notes).

[0128] S143. Calculate a health assessment table and score for each open source software based on the open source software operation data in combination with a pre-set security evaluation model and indicator weights to obtain a health calculation result.

[0129] In this embodiment, the health calculation result refers to a comprehensive assessment of each open source software based on the open source software operation data obtained in the previous step, combined with the enterprise's preset security evaluation model and the weights of its various indicators. This process mainly includes the following aspects:

[0130] Community activity score: Scores are given based on factors such as the activity level of users in the community and the trend of changes in contributors;

[0131] Adoption score: This quantifies the market acceptance of software by considering its actual usage (e.g., downloads and installations).

[0132] Impact Factor Rating: Scores software based on its popularity and recognition within the industry;

[0133] Defect repair efficiency score: evaluates the speed and effectiveness of vulnerability repairs;

[0134] Version iteration quality score: evaluates the frequency and content quality of version releases;

[0135] Finally, the scores of the above aspects are summarized to form a health assessment table and comprehensive score for each open source software.

[0136] S144. Summarize the health calculation results and the monitoring results and calculate a comprehensive score to obtain an operation trend analysis result.

[0137] In this embodiment, first, start with a list of existing open source software, which may be used or considered by enterprises or organizations. Regularly visit the community websites of these open source software to collect information about community activity, user interaction, the number of code contributors and its changing trends. By regularly crawling the statistical data provided by the open source software hosting platform (such as GitHub, GitLab, etc.), obtain the download volume, installation volume, issue number, etc. of the open source software to evaluate its application rate. Collect the impact factor data of the open source software, which may include community activity, user reviews, star ratings, etc., to evaluate its recognition in the industry. Regularly and automatically crawl the vulnerability information released by the open source software hosting platform and CVE vulnerability library, and count the defect repair situation, including the vulnerability repair speed, function improvement frequency, etc. Monitor the version release frequency and update content of the open source software to understand its version iteration situation.

[0138] In addition, the prosperity of open source communities is assessed by analyzing data such as the number of active users interacting with the community and trends in code contributors. For example, if an open source project has high community activity and a continuously growing number of code contributors, this generally indicates that the project is highly dynamic and sustainable.

[0139] Assess open source software's industry recognition by combining its adoption rate and impact factor. High downloads, installations, and positive user reviews generally indicate widespread industry recognition and adoption. Analyze bug fix rates and version iterations to understand the improvement and maintenance of open source software. Rapid bug fixes and frequent version updates generally indicate active maintenance and ongoing improvement.

[0140] The health index of open source software is calculated based on a pre-defined security evaluation model. This model includes multiple indicators and their corresponding weights, including adoption rate, impact factor, bug fix rate, version iteration status, and security score. Enterprises or organizations can design weightings for each indicator based on their own open source governance goals and risk tolerance. For example, an enterprise that prioritizes software security might assign higher weights to the bug fix rate and security score. Based on the scores and weights of each indicator, a comprehensive score is calculated, which serves as the health index for the open source software. This index can be used to assess whether the open source software is worth continuing to use, requires iterative updates, or should be discontinued.

[0141] The operational trend analysis process described above can be used to regularly assess the health of open source software, helping businesses or organizations understand the status of their open source software and make appropriate maintenance decisions. By monitoring defect fix rates and vulnerability information, businesses or organizations can promptly identify vulnerability risks in open source software and implement emergency response measures to mitigate security risks.

[0142] By collecting and analyzing a variety of data, this model provides a comprehensive assessment of the health of open source software. Regular data collection can dynamically reflect operational trends and changes in the health of open source software. Enterprises or organizations can flexibly design the evaluation model's indicators and weightings based on their needs and objectives, ensuring the health index better meets their specific requirements.

[0143] The above workflows and key elements can provide powerful decision-making support for enterprises or organizations, helping them to better manage and use open source software.

[0144] S150 , calculating the health status index and overall risk of the system based on the software component bill of materials report and the operation trend analysis result to obtain a calculation result.

[0145] In this embodiment, the calculation result specifically refers to:

[0146] Health Index: A numerical indicator reflecting the overall health of open source components used within a specific information system. It integrates multiple evaluations of open source components, including security, quality, intellectual property, maturity, and application, to provide a visual representation of the system's health.

[0147] Overall Risk Index: This measures the level of risk faced by information systems, particularly potential threats arising from the use of open source software, such as security vulnerabilities and legal disputes. The overall risk index can help companies identify high-risk areas and prioritize mitigation measures.

[0148] These two indices provide enterprises with a quantitative basis for understanding the current health and risk levels of their information systems and provide important insights for future adjustments to open source governance strategies. By regularly performing such analyses, enterprises can more proactively manage the use of open source software, improving information security and business continuity.

[0149] Specifically, based on the software component bill of materials report and the operation trend analysis result, a pre-set application health assessment model is used to calculate the health status index and overall risk of the system to obtain a calculation result.

[0150] In this embodiment, within the workflow of the open source software application health analysis engine, step S150 combines the software component bill of materials report with the open source software operational trend analysis results, using a pre-defined application health assessment model to calculate the information system's health index and overall risk. This step aims to provide enterprises with specific quantitative indicators of their information system health to support decision-making.

[0151] By scanning and inventorying each enterprise's information systems, we identify the various components, libraries, frameworks, and other open source software elements involved in the system and output a detailed bill of materials for the software components. We also provide data on the open source software health index, including community activity, adoption rate, bug fix rate, and version iteration status.

[0152] Combined with the application of health assessment model, wherein the application of health assessment model includes:

[0153] Open Source Code Origin Security Assessment Model: Evaluates the source security of open source components, such as whether they come from a trusted open source community or vendor. Code Quality Security Assessment Model: Considers code quality, including the number of known vulnerabilities and the speed of patching. Code Intellectual Property Security Assessment Model: Checks open source software license compliance to ensure there are no legal risks. Code Maturity Security Assessment Model: Evaluates based on the open source project's sustainable development capabilities and community support level. Code Application Security Assessment Model: Comprehensively considers the performance of open source components in actual applications, such as performance stability and compatibility.

[0154] Based on pre-defined criteria, specific scoring criteria and weights are set for each of the above evaluation dimensions. Business managers can add, modify, or delete evaluation indicators and their weights based on actual circumstances.

[0155] Each open source component in the system is comprehensively scored according to the rules of the application health assessment model. This process combines detailed information provided in the software component bill of materials report (such as the source, version, and license of the open source component) with the results of the operational trend analysis (such as community activity and adoption rate), and is calculated according to the preset scoring criteria and weights.

[0156] In this example, a comprehensive scan and inventory of all enterprise information systems is first performed. The various open source software elements, such as components, libraries, and frameworks, involved in the enterprise information system are identified, and the structural composition of the information system is clearly displayed. For example, an enterprise-level e-commerce platform may involve open source web servers (such as Apache or Nginx), databases (such as MySQL or PostgreSQL), frameworks (such as Spring or Django), and various third-party tools and libraries.

[0157] Information systems are classified and categorized based on their function and importance. For example, core business systems (such as financial management systems and customer relationship management systems) can be classified as level 1, supporting business systems (such as internal communication tools and project management tools) can be classified as level 2, and other non-critical systems can be classified as level 3. This categorization helps determine the priority and focus of subsequent system health assessments.

[0158] For each open source component in an information system, determine its origin, for example, whether it was obtained directly from the open source community or through a third-party mirror site. Also, record the component's version number, which is crucial for assessing its stability, security, and compatibility with other components. For example, the version of an open source library used in a system may be outdated, while a newer version may fix a security vulnerability or provide better performance.

[0159] By comparing vulnerability databases (such as CVE and NVD) and open source license databases (such as SPDX), vulnerability risks and license types in open source components can be identified. For components with high-risk vulnerabilities, timely warnings can be issued and updates or replacements can be recommended. Clear license information also helps enterprises avoid potential legal risks and compliance issues.

[0160] Combined with the collected data, the component's community activity and recognition are assessed. For example, a component with a large and active community, high adoption, rapid bug fixes, and frequent version iterations is generally considered to have a high health index. The analysis engine can integrate this information into the software component bill of materials, providing a basis for subsequent comprehensive evaluation.

[0161] A pre-defined application health assessment model encompasses multiple evaluation dimensions, including open source code source security, code quality, code intellectual property security, code maturity, and code application security. Each evaluation dimension has specific indicators and scoring criteria. For example, a code source security assessment might include indicators such as the credibility of a component's source, commercial support availability, and vulnerability history.

[0162] Enterprise managers can freely add, modify, or delete evaluation metrics and weights based on their own needs and risk tolerance. This flexibility allows the evaluation model to adapt to the needs of different enterprises. For example, an enterprise that places great emphasis on code quality and test coverage can adjust the weights in the code quality and security assessment model to give them a greater proportion in the overall score.

[0163] Each open source component in the system is evaluated based on the indicators and weights in the application health assessment model. All evaluation parameters are comprehensively calculated according to the model's rules to produce the system's health index and overall risk index. The health index reflects the system's stability and security, while the overall risk index identifies risk areas that require attention and resolution.

[0164] The method of this embodiment can perform a comprehensive health assessment of an enterprise's information system, taking into account not only technical factors such as the code quality and vulnerability risks of open source software, but also operational factors such as the activity and adoption rate of the open source community, as well as legal factors such as intellectual property and licenses, providing enterprises with a comprehensive perspective on the health of open source software applications. As open source software continues to update and evolve, and as enterprise needs change, the open source software application health analysis engine can dynamically update its assessment model and data, continuously providing enterprises with the latest health assessment results. For example, when new vulnerabilities are disclosed or new versions of open source software are released, the analysis engine can promptly adjust the assessment results and remind enterprises to take appropriate measures. By monitoring and assessing the health of open source software in real time, the engine can provide risk warning functions, allowing enterprise managers to understand potential risks in advance. At the same time, based on detailed assessment results and risk indexes, it provides decision support for enterprises, helping them decide whether to continue using a certain open source component, whether it needs to be upgraded or replaced, and how to optimize the information system architecture to reduce risks.

[0165] In summary, by inventorying and categorizing enterprise information systems, conducting in-depth analysis of software component bills of materials, and combining them with application health assessment models, we provide enterprises with comprehensive and dynamic open source software health assessments and risk warnings. This helps enterprises better manage and use open source software, reduce potential security and compliance risks, and improve the stability and reliability of information systems.

[0166] S160: Send the calculation result to the terminal, so that the terminal displays the calculation result in a visual form.

[0167] The visualization process is actually displayed on the display platform. Specifically, the display platform is a tool for displaying enterprise open source software governance information. It combines current health status and historical data to provide comprehensive governance information to enterprise decision makers in a visual manner, providing a strong data basis for the rectification of open source software applications.

[0168] The display platform defines user roles based on the enterprise's open source governance strategy. These roles may include administrators, developers, security experts, auditors, and more. Different roles have varying permissions and functions within the platform to ensure information security and standardized operations. For example, administrators can manage users and assign permissions; developers can view open source software usage and related documentation; security experts can monitor vulnerability risks and security trends; and auditors can audit open source software usage and governance.

[0169] The platform assigns corresponding operational permissions based on user roles. For example, administrators can create, modify, and delete user roles, as well as configure and manage the platform. Developers can view and manage the use of open source software in their projects, including checking the health status, vulnerability information, and license information of the open source software. Security experts can track and analyze vulnerability risks and develop security policies and countermeasures. Auditors can view various data and records in the platform, conduct compliance checks, and generate audit reports.

[0170] The platform displays a dashboard showing the overall software asset information of the enterprise, providing a comprehensive overview of the enterprise's open source software governance status. The information displayed on the dashboard includes:

[0171] The health status index intuitively displays the health status of the company's current information system, helping enterprise decision makers quickly understand the stability and security of the system.

[0172] Statistics on the number of open source software currently used by the enterprise, including the total number and distribution of open source software used in different systems, help enterprises understand the scale and scope of open source software use.

[0173] Displays the number of open source software vulnerabilities that the enterprise has not yet fixed, highlights high-risk vulnerabilities, and reminds enterprises to take timely measures to repair them and reduce security risks.

[0174] Count the number of open source software components that are currently unpatched by the enterprise, including components with vulnerabilities, defects or other problems, to help the enterprise understand the number and scope of components that need attention and treatment.

[0175] Identify the number of high-risk systems currently in the enterprise, that is, those systems that use open source software with serious vulnerabilities or defects, to help enterprises focus on and prioritize these high-risk systems and prevent potential security threats.

[0176] Combining historical data, the display platform plots a trend chart of system health. This chart allows enterprise decision-makers to clearly visualize the changing trends in system health, understand the successes and shortcomings of open source governance, and promptly adjust governance strategies and measures. For example, if the chart shows a continuous decline in system health over a period of time, this may indicate that vulnerabilities and defects in open source software have not been promptly addressed, or that new security risks are constantly emerging, requiring the enterprise to strengthen governance efforts and invest resources.

[0177] The display platform presents detailed asset information from a system perspective, including information about the open source software that the system depends on. This system view allows enterprise decision-makers to understand the composition and dependencies of the open source software used in each system, as well as the health and risk profile of this open source software. For example, they can view information such as the version, license type, and number of vulnerabilities of the open source software used in a system, as well as the role and importance of this open source software within the system.

[0178] The display platform presents detailed asset information from a software perspective, including bill of materials for open source software. This software view allows enterprise decision-makers to understand the usage and distribution of each open source software within the enterprise, including information such as the number of systems using the software, usage scenarios, and versions used, as well as the health and risk profile of the software. For example, they can view the scope and frequency of use of a particular open source software within the enterprise, as well as the impact of any vulnerabilities or defects in the software on the enterprise.

[0179] The display platform provides an operational interface and functionality for the open source software governance and introduction process, helping enterprises standardize the open source software introduction process. Enterprises can apply for, review, and introduce open source software on the platform, ensuring that the introduction of open source software complies with the enterprise's governance policies and security requirements. For example, developers can submit an application for the introduction of open source software on the platform, stating the reason for the introduction, its intended purpose, and the expected benefits. This application is then reviewed and approved by security experts and administrators.

[0180] The display platform provides a recommended list of open source software, recommending suitable open source software based on an enterprise's business needs and security requirements. The open source software in this list has undergone security assessment and review by the platform, demonstrating high security and reliability, helping enterprises mitigate the risks of introducing open source software. For example, the platform can recommend commonly used and mature open source software, such as web servers, databases, and frameworks, based on an enterprise's technology stack and business scenarios.

[0181] The display platform provides a visualization feature for vulnerability risk tracking, helping enterprises gain real-time visibility into the vulnerability risk profile of open source software. Through this vulnerability risk tracking view, enterprise decision-makers can view information such as vulnerability distribution, severity, and remediation progress, as well as the scope of impact and potential threats to the enterprise. For example, they can view the number of systems affected by a vulnerability, the business scope, and the remediation plan and timeline.

[0182] The display platform provides learning resources from the open source governance knowledge base, including open source software usage guidelines, best practices, and security policies. This knowledge base can help enterprise decision-makers and employees improve their understanding and skills in open source software governance and better address the challenges posed by open source software. For example, they can learn how to conduct open source software security assessments, select appropriate open source software, and manage open source software licenses.

[0183] The method of this embodiment uses a visual governance information display platform to enable enterprises to establish a unified, standardized and normalized process for the introduction, use and maintenance of open source software. This makes the management of open source software more orderly and controllable, avoiding the inconsistency and complex diversity of the use of open source software by various systems, as well as the existence of multiple versions of homogeneous open source software. Enterprises can manage and maintain open source software more conveniently, keep abreast of the usage and health of open source software, and take appropriate measures to optimize and improve it. A unified open source software governance process helps improve development efficiency, optimize resource allocation, and reduce costs. Enterprises can avoid repeatedly introducing and using the same open source software, reducing unnecessary waste of resources. At the same time, through standardized processes, enterprises can better manage the license compliance of open source software and avoid legal disputes and economic losses caused by license issues.

[0184] By carefully selecting open source software and conducting comprehensive security assessments and vulnerability management, enterprises can avoid security risks caused by open source software security vulnerabilities and backdoors. The vulnerability risk tracking and security assessment capabilities provided by the Visual Governance Information Display Platform help enterprises promptly discover and remediate vulnerabilities in open source software, reducing the risk of attack. Enterprises can better protect their information systems and data security and guard against potential security threats. The platform's open source software license information and intellectual property assessment capabilities help enterprises ensure intellectual property compliance for open source software. Enterprises can understand the license types and requirements of the open source software they use, avoiding legal disputes and financial losses caused by license violations. This helps enterprises safeguard their legitimate rights and interests and cultivate a positive corporate image.

[0185] Through a visual governance information display platform, enterprises can assess the severity of risks in open source software application scenarios. Combining current health status with historical data, the platform can predict future trends and help enterprises proactively identify potential risks. Based on the assessment results, enterprises can take appropriate rectification and governance measures to reduce risks and improve overall security.

[0186] The platform provides comprehensive governance information and data to help enterprises build and enhance their open source software governance capabilities. This allows them to better manage the introduction, use, and maintenance of open source software, optimize resource allocation, improve development efficiency, and reduce costs. Furthermore, they can better address the challenges posed by open source software, enhance the stability and security of their information systems, and lay the foundation for sustainable development.

[0187] For financial enterprises, open source software governance is particularly important. Through a visual governance information display platform, financial enterprises can better manage open source software usage, reduce potential risks, and improve overall security. This helps financial enterprises achieve healthy and sustainable fintech development, enhance competitiveness and innovation, and provide customers with more secure, reliable, and efficient services.

[0188] In summary, the visual governance information display platform provides comprehensive governance information to enterprise decision-makers by displaying current health status and historical data in a visual manner, providing a strong data basis for the rectification of open source software applications. This platform has significant advantages in enterprise open source governance, helping enterprises establish unified, standardized, and regularized open source software governance processes, reducing potential risks, and improving overall security and governance capabilities. In particular, it lays the foundation for financial enterprises to achieve healthy and sustainable fintech development.

[0189] The method of this embodiment classifies information systems into different levels and combines technical, operational, and security measures to develop and quantify a multi-factor open source software management evaluation model. For example, this model includes factors such as software component material information, subsequent maintenance status of open source software, code stability and contribution volume, and maturity of the open source community. This model comprehensively evaluates the operational trends and health status of open source software, making the use and management of open source software more unified, comprehensive, and precise.

[0190] The above-mentioned software open source governance method based on the operational trend characteristics of open source components obtains asset information input by the terminal, inventories and classifies the structural components of the information system, clarifies the open source software elements involved in the system, and then identifies and analyzes the asset information, license compliance and security vulnerabilities of the open source software, generates a software component bill of materials report, and comprehensively grasps the usage and potential risks of open source software; monitors and analyzes the operational data of open source software in the community, evaluates its health status and industry influence, obtains operational trend analysis results, and understands the development dynamics and stability of open source software; based on the software component bill of materials report and operational trend analysis results, calculates the health status index and overall risk of the information system, and quantitatively evaluates the use risk of open source software and the health of the system; finally, sends the calculation results to the terminal and displays them in a visual form, providing decision makers with intuitive and comprehensive governance information, supporting the rectification and governance decisions of open source software, and realizing comprehensive open source governance.

[0191] Figure 5 1 is a schematic block diagram of a software open source management device 300 based on the operating trend characteristics of open source components provided by an embodiment of the present invention. Figure 5 As shown, corresponding to the above software open source governance method based on the operating trend characteristics of open source components, the present invention also provides a software open source governance device 300 based on the operating trend characteristics of open source components. The software open source governance device 300 based on the operating trend characteristics of open source components includes a unit for executing the above software open source governance method based on the operating trend characteristics of open source components. The device can be configured in a server. Specifically, please refer to Figure 5 The software open source governance device 300 based on the operation trend characteristics of open source components includes an asset information acquisition unit 301, a hierarchical classification unit 302, a software component analysis unit 303, an operation trend analysis unit 304, an overall calculation unit 305 and a visualization display unit 306.

[0192] An asset information acquisition unit 301 is used to acquire asset information input by a terminal; a hierarchical classification unit 302 is used to perform a system inventory and hierarchical classification based on the asset information to obtain the structural composition of the information system; a software component analysis unit 303 is used to identify and analyze the asset information, license compliance and security vulnerabilities of the open source software based on the structural composition of the information system, and generate a software component bill of materials report; an operation trend analysis unit 304 is used to monitor and analyze the operation data of open source software in the community, evaluate the health status and industry influence, and obtain an operation trend analysis result; an overall calculation unit 305 is used to calculate the health status index and overall risk of the system based on the software component bill of materials report and the operation trend analysis result to obtain a calculation result; a visual display unit 306 is used to send the calculation result to the terminal so that the terminal displays the calculation result in a visual form.

[0193] In one embodiment, if Figure 6 As shown, the software component analysis unit 303 includes a source code acquisition subunit 3031 , a configuration acquisition subunit 3032 , a task creation subunit 3033 , an evaluation and analysis subunit 3034 , and a report generation subunit 3035 .

[0194] The source code acquisition sub-unit 3031 is used to obtain the system project source code according to the structural composition of the information system; the configuration acquisition sub-unit 3032 is used to obtain the configuration independently formulated according to the enterprise's open source software organizational structure and management system; the task creation sub-unit 3033 is used to create a scanning and analysis task covering code source, quality and intellectual property security assessment indicators according to the configuration; the assessment and analysis sub-unit 3034 is used to execute the scanning and analysis task to identify and evaluate open source software assets, vulnerabilities, license usage and whether they comply with enterprise policies to obtain analysis results; the report generation sub-unit 3035 is used to generate a software component bill of materials report according to the analysis results.

[0195] In one embodiment, the evaluation and analysis sub-unit 3034 is used to perform the scanning and analysis task, using code snippet analysis, binary analysis and deep dependency analysis technology to identify and evaluate open source component assets, vulnerabilities, license usage and whether they comply with enterprise policies from the dimensions of components and versions, licenses, security vulnerabilities and custom policies to obtain analysis results.

[0196] In one embodiment, if Figure 7 As shown, the operation trend analysis unit 304 includes a monitoring subunit 3041 , a data acquisition subunit 3042 , a health calculation subunit 3043 and a comprehensive calculation subunit 3044 .

[0197] The monitoring sub-unit 3041 is used to collect statistics on all open source software corresponding to the asset information, and monitor the activity, application rate, impact factor, defect repair rate and version iteration of the community website where the open source software is located to obtain monitoring results; the data acquisition sub-unit 3042 is used to obtain the operation data of the open source software in the community; the health calculation sub-unit 3043 is used to calculate the health assessment table and score of each open source software based on the open source software operation data combined with a pre-set security evaluation model and indicator weights to obtain a health calculation result; the comprehensive calculation sub-unit 3044 is used to summarize the health calculation results and the monitoring results and calculate a comprehensive score to obtain an operation trend analysis result.

[0198] In one embodiment, the overall calculation unit 305 is used to calculate the health status index and overall risk of the system using a preset application health assessment model based on the software component bill of materials report and the operation trend analysis result to obtain a calculation result.

[0199] It should be noted that technical personnel in the relevant field can clearly understand that the specific implementation process of the above-mentioned software open source governance device 300 based on the operating trend characteristics of open source components and each unit can refer to the corresponding description in the aforementioned method embodiment. For the convenience and brevity of the description, it will not be repeated here.

[0200] The software open source management device 300 based on the operating trend characteristics of open source components can be implemented in the form of a computer program. The computer program can be used in Figure 8 Runs on the computer equipment shown.

[0201] See also Figure 8 , Figure 8 1 is a schematic block diagram of a computer device provided in an embodiment of the present application. The computer device 500 may be a server, wherein the server may be an independent server or a server cluster composed of multiple servers.

[0202] See Figure 8 The computer device 500 includes a processor 502 , a memory, and a network interface 505 connected via a system bus 501 , wherein the memory may include a non-volatile storage medium 503 and an internal memory 504 .

[0203] The non-volatile storage medium 503 can store an operating system 5031 and a computer program 5032. The computer program 5032 includes program instructions, which, when executed, can cause the processor 502 to execute a software open source governance method based on the operational trend characteristics of open source components.

[0204] The processor 502 is used to provide computing and control capabilities to support the operation of the entire computer device 500.

[0205] The internal memory 504 provides an environment for the operation of the computer program 5032 in the non-volatile storage medium 503. When the computer program 5032 is executed by the processor 502, the processor 502 can execute a software open source governance method based on the operating trend characteristics of open source components.

[0206] The network interface 505 is used to communicate with other devices through the network. Figure 8 The structure shown in the figure is merely a block diagram of a portion of the structure related to the solution of the present application, and does not constitute a limitation on the computer device 500 to which the solution of the present application is applied. The specific computer device 500 may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.

[0207] The processor 502 is configured to execute a computer program 5032 stored in the memory to implement the following steps:

[0208] Acquire asset information input by a terminal; perform system inventory and hierarchical classification based on the asset information to obtain the structural composition of the information system; identify and analyze the asset information, license compliance, and security vulnerabilities of the open source software based on the structural composition of the information system, and generate a software component bill of materials report; monitor and analyze the operational data of the open source software in the community, evaluate the health status and industry influence, and obtain operational trend analysis results; calculate the health status index and overall risk of the system based on the software component bill of materials report and the operational trend analysis results to obtain a calculation result; send the calculation result to the terminal so that the terminal displays the calculation result in a visual form.

[0209] The software component bill of materials report includes details of all dependent components, license status, identified vulnerability data, and policy violations.

[0210] In one embodiment, when implementing the step of identifying and analyzing asset information, license compliance, and security vulnerabilities of open source software based on the structure of the information system and generating a software component bill of materials report, the processor 502 specifically implements the following steps:

[0211] Obtain system project source code based on the structural composition of the information system; obtain a configuration independently formulated based on the enterprise's open source software organizational structure and management system; create a scanning and analysis task covering code source, quality, and intellectual property security assessment indicators based on the configuration; execute the scanning and analysis task to identify and evaluate open source software assets, vulnerabilities, license usage, and whether it complies with enterprise policies to obtain analysis results; and generate a software component bill of materials report based on the analysis results.

[0212] In one embodiment, when the processor 502 performs the scanning and analysis task to identify and evaluate open source software assets, vulnerabilities, license usage, and whether they comply with enterprise policies to obtain an analysis result, the processor 502 specifically implements the following steps:

[0213] Execute the scanning and analysis tasks, using code snippet analysis, binary analysis, and deep dependency analysis techniques to identify and evaluate open source component assets, vulnerabilities, license usage, and whether they comply with enterprise policies from the dimensions of components and versions, licenses, security vulnerabilities, and custom policies to obtain analysis results.

[0214] In one embodiment, when the processor 502 implements the step of monitoring and analyzing the operational data of open source software in the community, evaluating the health status and industry influence, and obtaining the operational trend analysis results, the processor 502 specifically implements the following steps:

[0215] Statistics are collected for all open source software corresponding to the asset information, and the activity, application rate, impact factor, defect repair rate and version iteration of the community website where the open source software is located are monitored to obtain monitoring results; the operation data of the open source software in the community is obtained; based on the open source software operation data combined with a pre-set security evaluation model and indicator weights, a health assessment table and score for each open source software is calculated to obtain a health calculation result; the health calculation result and the monitoring result are summarized and a comprehensive score is calculated to obtain an operation trend analysis result.

[0216] In one embodiment, when the processor 502 calculates the health status index and overall risk of the system based on the software component bill of materials report and the operation trend analysis result to obtain the calculation result, the processor 502 specifically implements the following steps:

[0217] Based on the software component bill of materials report and the operation trend analysis results, a pre-set application health assessment model is used to calculate the health status index and overall risk of the system to obtain a calculation result.

[0218] It should be understood that in the embodiment of the present application, the processor 502 may be a central processing unit (CPU), and the processor 502 may also be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor, etc.

[0219] Those skilled in the art will appreciate that all or part of the steps in the method of the above-described embodiment can be implemented by instructing the relevant hardware through a computer program. The computer program includes program instructions, which can be stored in a storage medium that is computer-readable. The program instructions are executed by at least one processor in the computer system to implement the steps in the method of the above-described embodiment.

[0220] Therefore, the present invention also provides a storage medium. The storage medium may be a computer-readable storage medium. The storage medium stores a computer program, wherein when the computer program is executed by a processor, the processor performs the following steps:

[0221] Acquire asset information input by a terminal; perform system inventory and hierarchical classification based on the asset information to obtain the structural composition of the information system; identify and analyze the asset information, license compliance, and security vulnerabilities of the open source software based on the structural composition of the information system, and generate a software component bill of materials report; monitor and analyze the operational data of the open source software in the community, evaluate the health status and industry influence, and obtain operational trend analysis results; calculate the health status index and overall risk of the system based on the software component bill of materials report and the operational trend analysis results to obtain a calculation result; send the calculation result to the terminal so that the terminal displays the calculation result in a visual form.

[0222] The software component bill of materials report includes details of all dependent components, license status, identified vulnerability data, and policy violations.

[0223] In one embodiment, when the processor executes the computer program to implement the step of identifying and analyzing asset information, license compliance, and security vulnerabilities of open source software based on the structural composition of the information system and generating a software component bill of materials report, the processor specifically implements the following steps:

[0224] Obtain system project source code based on the structural composition of the information system; obtain a configuration independently formulated based on the enterprise's open source software organizational structure and management system; create a scanning and analysis task covering code source, quality, and intellectual property security assessment indicators based on the configuration; execute the scanning and analysis task to identify and evaluate open source software assets, vulnerabilities, license usage, and whether it complies with enterprise policies to obtain analysis results; and generate a software component bill of materials report based on the analysis results.

[0225] In one embodiment, when the processor executes the computer program to implement the step of performing the scanning and analysis task to identify and evaluate open source software assets, vulnerabilities, license usage, and whether they comply with enterprise policies to obtain an analysis result, the processor specifically implements the following steps:

[0226] Execute the scanning and analysis tasks, using code snippet analysis, binary analysis, and deep dependency analysis techniques to identify and evaluate open source component assets, vulnerabilities, license usage, and whether they comply with enterprise policies from the dimensions of components and versions, licenses, security vulnerabilities, and custom policies to obtain analysis results.

[0227] In one embodiment, when the processor executes the computer program to implement the step of monitoring and analyzing the operational data of open source software in the community, evaluating the health status and industry influence, and obtaining an operational trend analysis result, the processor specifically implements the following steps:

[0228] Statistics are collected for all open source software corresponding to the asset information, and the activity, application rate, impact factor, defect repair rate and version iteration of the community website where the open source software is located are monitored to obtain monitoring results; the operation data of the open source software in the community is obtained; based on the open source software operation data combined with a pre-set security evaluation model and indicator weights, a health assessment table and score for each open source software is calculated to obtain a health calculation result; the health calculation result and the monitoring result are summarized and a comprehensive score is calculated to obtain an operation trend analysis result.

[0229] In one embodiment, when the processor executes the computer program to implement the step of calculating the health status index and overall risk of the system based on the software component bill of materials report and the operation trend analysis result to obtain a calculation result, the processor specifically implements the following steps:

[0230] Based on the software component bill of materials report and the operation trend analysis results, a pre-set application health assessment model is used to calculate the health status index and overall risk of the system to obtain a calculation result.

[0231] The storage medium may be any computer-readable storage medium that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a magnetic disk, or an optical disk.

[0232] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the above description has generally described the composition and steps of each example according to function. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of the present invention.

[0233] In the several embodiments provided herein, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the various units is merely a logical functional division, and actual implementation may employ other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be omitted or not implemented.

[0234] The steps in the methods of the embodiments of the present invention may be adjusted in order, combined, or deleted as needed. The units in the devices of the embodiments of the present invention may be combined, divided, or deleted as needed. Furthermore, the functional units in the various embodiments of the present invention may be integrated into a single processing unit, each unit may exist physically separately, or two or more units may be integrated into a single unit.

[0235] If this integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the existing technology, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes a number of instructions for causing a computer device (which can be a personal computer, terminal, or network device, etc.) to execute all or part of the steps of the method described in various embodiments of the present invention.

[0236] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in the present invention, and such modifications or substitutions are intended to be within the scope of protection of the present invention. Therefore, the scope of protection of the present invention shall be subject to the scope of protection of the claims.

Claims

1. A software open source governance method based on the operational trend characteristics of open source components, characterized by: include: Obtain asset information input by the terminal; Conducting system inventory and hierarchical classification based on the asset information to obtain the structural composition of the information system; Identify and analyze asset information, license compliance, and security vulnerabilities of open source software based on the structural composition of the information system, and generate a software component bill of materials report; Monitor and analyze the operational data of open source software in the community, assess its health status and industry influence, and obtain operational trend analysis results; Calculating a health status index and an overall risk of the system based on the software component bill of materials report and the operation trend analysis result to obtain a calculation result; The calculation result is sent to a terminal so that the terminal displays the calculation result in a visual form.

2. The software open source governance method based on the open source component operation trend characteristics according to claim 1 is characterized in that: The identifying and analyzing asset information, license compliance, and security vulnerabilities of open source software based on the structural composition of the information system to generate a software component bill of materials report includes: Obtaining system project source code according to the structural composition of the information system; Obtain configurations independently developed based on the company's open source software organizational structure and management system; Create a scanning and analysis task based on the configuration, covering code origin, quality, and intellectual property security assessment indicators; Perform the scanning and analysis tasks to identify and evaluate open source software assets, vulnerabilities, license usage, and whether they comply with enterprise policies to obtain analysis results; A software component bill of materials report is generated based on the analysis results.

3. The software open source governance method based on the operating trend characteristics of open source components according to claim 2 is characterized in that: The scanning and analysis task is performed to identify and evaluate open source software assets, vulnerabilities, license usage, and whether they comply with enterprise policies, to obtain analysis results, including: Execute the scanning and analysis tasks, using code snippet analysis, binary analysis, and deep dependency analysis techniques to identify and evaluate open source component assets, vulnerabilities, license usage, and whether they comply with enterprise policies from the dimensions of components and versions, licenses, security vulnerabilities, and custom policies to obtain analysis results.

4. The software open source governance method based on the operating trend characteristics of open source components according to claim 1 is characterized in that: The software component bill of materials report includes details of all dependent components, license status, data on identified vulnerabilities, and policy violations.

5. The software open source governance method based on the operating trend characteristics of open source components according to claim 1 is characterized in that: The monitoring and analysis of open source software operational data in the community, assessment of health status and industry influence, and analysis of operational trends will be conducted, including: Collect statistics on all open source software corresponding to the asset information, and monitor the activity, application rate, impact factor, defect repair rate, and version iteration of the community website where the open source software is located to obtain monitoring results; Obtain operational data on open source software in the community; Calculate a health assessment table and score for each open source software based on the open source software operation data in combination with a pre-set security evaluation model and indicator weights to obtain a health calculation result; The health calculation results and the monitoring results are summarized and a comprehensive score is calculated to obtain an operation trend analysis result.

6. The software open source governance method based on the open source component operation trend characteristics according to claim 1 is characterized in that: The calculating of the health status index and overall risk of the system based on the software component bill of materials report and the operation trend analysis result to obtain the calculation result includes: Based on the software component bill of materials report and the operation trend analysis results, a pre-set application health assessment model is used to calculate the health status index and overall risk of the system to obtain a calculation result.

7. A software open source management device based on the operating trend characteristics of open source components, characterized by: include: An asset information acquisition unit, configured to acquire asset information input by a terminal; A hierarchical classification unit, configured to perform a system inventory and hierarchical classification based on the asset information to obtain a structural composition of the information system; a software component analysis unit, configured to identify and analyze asset information, license compliance, and security vulnerabilities of open source software based on the structural composition of the information system, and generate a software component bill of materials report; Operation trend analysis unit, used to monitor and analyze the operational data of open source software in the community, assess its health status and industry influence, and obtain operational trend analysis results; an overall calculation unit, configured to calculate a health status index and an overall risk of the system based on the software component bill of materials report and the operation trend analysis result, to obtain a calculation result; The visualization display unit is used to send the calculation result to the terminal so that the terminal displays the calculation result in a visualization form.

8. The software open source management device based on the open source component operation trend characteristics according to claim 7 is characterized in that: The software component analysis unit includes: A source code acquisition subunit, configured to acquire the system project source code according to the structural composition of the information system; The configuration acquisition subunit is used to obtain the configuration independently formulated according to the enterprise's open source software organizational structure and management system; A task creation subunit, configured to create a scanning and analysis task covering code origin, quality, and intellectual property security assessment indicators according to the configuration; An assessment and analysis subunit, configured to perform the scanning and analysis tasks to identify and assess open source software assets, vulnerabilities, license usage, and whether they comply with enterprise policies, thereby obtaining analysis results; The report generation subunit is used to generate a software component bill of materials report based on the analysis results.

9. A computer device, characterized in that: The computer device includes a memory and a processor, the memory stores a computer program, and the processor implements the method according to any one of claims 1 to 6 when executing the computer program.

10. A storage medium, characterized in that: The storage medium stores a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 6 is implemented.