๐ฐ๐ท ํ๊ตญ์ด | ๐บ๐ธ English
์ ๋ขฐํ ์ ์๋ ์คํ์์ค ๊ณต๊ธ๋ง ๊ด๋ฆฌ โ ISO/IEC 5230 & 18974 ์ค์ ํคํธ + AI ์ฝ๋ฉยทDevSecOps ์๋ํ ๊ฐ์ด๋
์คํ์์ค ๊ด๋ฆฌ ๊ฒฝํ์ด ์ ํ ์๋ ์ ๊ท ๋ด๋น์๋ ์ด ํคํธ๋ฅผ ๋ฐ๋ผ๊ฐ๋ฉด ISO/IEC 5230๊ณผ 18974 ์์ฒด ์ธ์ฆ ์ ์ธ๊น์ง ์์ฑํ ์ ์์ต๋๋ค. Agent๊ฐ ํ์ฌ ์ํฉ์ ๋ง๋ ์ฐ์ถ๋ฌผ์ ์๋ ์์ฑํ๋ฉฐ, ์
ํ์คํฐ๋ ๋ฐฉ์์ผ๋ก ํ์ฉํ ์ ์์ต๋๋ค.
trustedoss.github.io ์์ ์น ๊ฐ์ด๋์ ๋ธ๋ผ์ฐ์ ๊ธฐ๋ฐ ๋๊ตฌ๋ฅผ ๋ฐ๋ก ์ฌ์ฉํ ์ ์์ต๋๋ค.
๋ฌด์์ ์ ๊ณตํ๋์?
๋ฉ๋ด
๋ด์ฉ
์คํ์์ค ๊ด๋ฆฌ
ISO/IEC 5230 & 18974 ๊ธฐ๋ฐ ์คํ์์ค ๊ฑฐ๋ฒ๋์ค ์ฒด๊ณ ๊ตฌ์ถ ๋จ๊ณ๋ณ ๊ฐ์ด๋
AI ์ฝ๋ฉ ๊ฑฐ๋ฒ๋์ค
Claude CodeยทCursorยทCopilot ๋ฑ AI ์ฝ๋ฉ ๋๊ตฌ์ ์คํ์์ค ์ ์ฑ
์๋ ์ค์
DevSecOps
SASTยทSCAยท์ํฌ๋ฆฟ ํ์งยท์ปจํ
์ด๋ยทIaCยทDAST CI/CD ํ์ดํ๋ผ์ธ ์๋ํ
๋ ํผ๋ฐ์ค
์ ์ฑ
ํ
ํ๋ฆฟยทSBOM ์ํยท์์ฒด ์ธ์ฆ ์ฒดํฌ๋ฆฌ์คํธ
์น์ฌ์ดํธ์์ ๋ฐ๋ก ์ฌ์ฉ (Claude Code ๋ถํ์)
๋ธ๋ผ์ฐ์ ์์ Anthropic API ํค๋ง์ผ๋ก ์ฆ์ ์ฌ์ฉํ ์ ์๋ ๋๊ตฌ๋ฅผ ์ ๊ณตํฉ๋๋ค.
# 1. ์ ์ฅ์ ํด๋ก
git clone https://github.com/trustedoss/trustedoss-agents.git
# 2. ํ๋ก์ ํธ ์ง์
๋ฐ Claude Code ์คํ
cd trustedoss-agents && claude
# 3. ์์ ์๋ด ์์ฒญ
# "์ด๋์ ์์ํด์ผ ํด?" ์
๋ ฅ
์ฒด๊ณ ๊ตฌ์ถ์ ๋ ๊ฐ์ง ๊น์ด๋ก ์งํํ ์ ์์ต๋๋ค.
๋น ๋ฅธ ์์ (1~2์๊ฐ) : ์๊ฐ์ด ๋ถ์กฑํ๋ฉด ๊ฐ์, 02 ์กฐ์ง, 03 ์ ์ฑ
์ธ ์ฑํฐ๋ง ์งํํด ์ ์ฑ
์ด์๊น์ง ๋ง๋ญ๋๋ค.
ํ ์ฝ์ค (์ฝ 12~14์๊ฐ) : 00~07 ์ฑํฐ๋ฅผ ์์๋๋ก ์งํํด ์์ฒด ์ธ์ฆ ์ ์ธ๋ฌธ๊น์ง ์์ฑํฉ๋๋ค.
์ฒด๊ณ๊ตฌ์ถ Agent (ISO/IEC 5230 & 18974)
Agent
์ญํ
์คํ ๋ฐฉ๋ฒ
agents/02-organization-designer
์กฐ์งยท๋ด๋น์ ์ฐ์ถ๋ฌผ ์์ฑ
cd agents/02-organization-designer && claude
agents/03-policy-generator
์คํ์์ค ์ ์ฑ
๋ฌธ์ ์์ฑ
cd agents/03-policy-generator && claude
agents/04-process-designer
ํ๋ก์ธ์ค ๋ฌธ์ ๋ฐ ํ๋ฆ๋ ์์ฑ
cd agents/04-process-designer && claude
agents/05-sbom-guide
SBOM ์์ฑ ๋ช
๋ น์ด ๋ฐ ์คํฌ๋ฆฝํธ
cd agents/05-sbom-guide && claude
agents/05-sbom-analyst
SBOM ๋ผ์ด์ ์ค ๋ถ์ ๋ฆฌํฌํธ
cd agents/05-sbom-analyst && claude
agents/05-sbom-management
SBOM ๊ด๋ฆฌ ๊ณํ ๋ฐ ๊ณต์ ํ
ํ๋ฆฟ
cd agents/05-sbom-management && claude
agents/05-vulnerability-analyst
์ทจ์ฝ์ ๋ถ์ ๋ฆฌํฌํธ
cd agents/05-vulnerability-analyst && claude
agents/06-training-manager
๊ต์ก ์ปค๋ฆฌํ๋ผ ๋ฐ ์ด์ ์ถ์
cd agents/06-training-manager && claude
agents/07-conformance-preparer
๊ฐญ ๋ถ์ ๋ฐ ์ธ์ฆ ์ ์ธ๋ฌธ
cd agents/07-conformance-preparer && claude
AI ์ฝ๋ฉยทDevSecOps Agent (๋ ๋ฒจ 1 โ ์ค์ ํ์ผ ์์ฑ)
Agent
์ญํ
์คํ ๋ฐฉ๋ฒ
agents/ai-coding-setup
ํ๋ก์ ํธ ๋ถ์ ํ ๋ง์ถคํ Rules ํ์ผ ์์ฑ
cd agents/ai-coding-setup && claude
agents/devsecops-setup
ํ๋ก์ ํธ ๋ถ์ ํ CI/CD ํ์ดํ๋ผ์ธ ํ์ผ ์์ฑ
cd agents/devsecops-setup && claude
AI ์ฝ๋ฉยทDevSecOps Agent (๋ ๋ฒจ 1 โ ๊ฒฐ๊ณผ ๋ถ์)
Agent
์ญํ
์คํ ๋ฐฉ๋ฒ
agents/sbom-vuln-analyst
SBOMยทgrype ๊ฒฐ๊ณผ โ ์ทจ์ฝ์ ๋์ ๋ฆฌํฌํธ
cd agents/sbom-vuln-analyst && claude
agents/sast-analyst
SemgrepยทCodeQL ๊ฒฐ๊ณผ โ ์์ ๊ฐ์ด๋
cd agents/sast-analyst && claude
agents/secret-analyst
Gitleaks ๊ฒฐ๊ณผ โ ์ํฌ๋ฆฟ ๋์ ์ ์ฐจ
cd agents/secret-analyst && claude
agents/iac-fixer
Checkov ๊ฒฐ๊ณผ โ IaC ์์ ์ฝ๋ ์์ฑ
cd agents/iac-fixer && claude
CI/CD ์ฐ๋ ์๋ํ Agent (๋ ๋ฒจ 2)
Agent
์ญํ
์คํ ๋ฐฉ๋ฒ
agents/level2-automation/pr-comment
PR ๋ณด์ ๋ถ์ ์๋ ์ฝ๋ฉํธ ์ํฌํ๋ก์ฐ ์์ฑ
cd agents/level2-automation/pr-comment && claude
agents/level2-automation/issue-tracker
์ ๊ธฐ ์ค์บ ์ด์ ์๋ ๋ฑ๋ก ์ํฌํ๋ก์ฐ ์์ฑ
cd agents/level2-automation/issue-tracker && claude
trustedoss/
โโโ docs/ # ์ฑํฐ๋ณ ๊ฐ์ด๋ ๋ฌธ์ (์ฒด๊ณ๊ตฌ์ถ)
โโโ agents/ # ์ฐ์ถ๋ฌผ ์๋ ์์ฑ Agent
โ โโโ 02-organization-designer/
โ โโโ 03-policy-generator/
โ โโโ ...
โ โโโ ai-coding-setup/ # AI ์ฝ๋ฉ Rules ํ์ผ ์์ฑ
โ โโโ devsecops-setup/ # DevSecOps ํ์ดํ๋ผ์ธ ํ์ผ ์์ฑ
โ โโโ sbom-vuln-analyst/ # SBOM ์ทจ์ฝ์ ๋ถ์
โ โโโ sast-analyst/ # SAST ๊ฒฐ๊ณผ ๋ถ์
โ โโโ secret-analyst/ # ์ํฌ๋ฆฟ ํ์ง ๊ฒฐ๊ณผ ๋ถ์
โ โโโ iac-fixer/ # IaC ์์ ์ฝ๋ ์์ฑ
โ โโโ level2-automation/ # CI/CD ์ฐ๋ ์๋ํ
โโโ templates/ # ๋ฌธ์ ํ
ํ๋ฆฟ
โโโ samples/ # ์ค์ต์ฉ ์ํ ํ๋ก์ ํธ
โโโ output/ # ์์ฑ๋ ์ฐ์ถ๋ฌผ (.gitignore)
โโโ .claude/ # Claude Code ์ค์ ๋ฐ skills
โโโ website/ # ๋ฌธ์ ์น์ฌ์ดํธ ์์ค (Docusaurus)
์ฒด๊ณ๊ตฌ์ถ ์ฑํฐ ๋ชฉ๋ก
์ฑํฐ
๋ด์ฉ
์
ํ์คํฐ๋
00-overview
๋ ํ์ค ๊ฐ์ ๋ฐ ์ฒดํฌ๋ฆฌ์คํธ ๋งคํ
1์๊ฐ
00-overview/supply-chain
์ํํธ์จ์ด ๊ณต๊ธ๋ง ๋ณด์ + SBOM ๊ฐ๋
1์๊ฐ
01-setup
ํ๊ฒฝ ์ค๋น (Docker, Git, Claude Code)
30๋ถ~1์๊ฐ
02-organization
์กฐ์ง ๊ตฌ์ฑ ๋ฐ ๋ด๋น์ ์ง์
1์๊ฐ
03-policy
์คํ์์ค ์ ์ฑ
์๋ฆฝ
1์๊ฐ
04-process
์คํ์์ค ํ๋ก์ธ์ค ์ค๊ณ
1~2์๊ฐ
05-tools/sbom-generation
SBOM ์์ฑ
1.5์๊ฐ
05-tools/sbom-management
SBOM ๊ด๋ฆฌ ๋ฐ ๊ณต์
1์๊ฐ
05-tools/vulnerability
์ทจ์ฝ์ ๋ถ์ ๋ฐ ๋์
1์๊ฐ
05-tools/ai-sbom
AI SBOM โ ๋ชจ๋ธ ML-BOM ์์ฑ (์ ํ)
1์๊ฐ
06-training
๊ต์ก ์ฒด๊ณ ๊ตฌ์ถ
1์๊ฐ
07-conformance
์์ฒด ์ธ์ฆ ์ ์ธ
2์๊ฐ
08-developer-guide
๊ฐ๋ฐ์ ์ ์ฑ
์ ์ฉ (์ ํ)
2์๊ฐ
ํ์ผ
์ค๋ช
์ถฉ์กฑ ํ์ค
output/organization/role-definition.md
์คํ์์ค ๋ด๋น์ ์ญํ ์ ์
5230 + 18974
output/organization/raci-matrix.md
์ญํ ยท์ฑ
์ ๋งคํธ๋ฆญ์ค
5230 + 18974
output/organization/appointment-template.md
๋ด๋น์ ์ง์ ๊ณต๋ฌธ ํ
ํ๋ฆฟ
5230 + 18974
output/policy/oss-policy.md
์คํ์์ค ์ ์ฑ
๋ฌธ์
5230 + 18974
output/policy/license-allowlist.md
ํ์ฉ ๋ผ์ด์ ์ค ๋ชฉ๋ก
5230
output/process/usage-approval.md
์คํ์์ค ์ฌ์ฉ ์น์ธ ์ ์ฐจ
5230
output/process/distribution-checklist.md
๋ฐฐํฌ ์ ์ฒดํฌ๋ฆฌ์คํธ
5230
output/process/vulnerability-response.md
์ทจ์ฝ์ ๋์ ์ ์ฐจ
18974
output/process/inquiry-response.md
์ธ๋ถ ๋ฌธ์ ๋์ ์ ์ฐจ
5230 + 18974
output/process/contribution-process.md
์คํ์์ค ๊ธฐ์ฌ ํ๋ก์ธ์ค
5230
output/process/process-diagram.md
์ ์ฒด ํ๋ก์ธ์ค ๋ค์ด์ด๊ทธ๋จ
5230 + 18974
output/sbom/[project].cdx.json
SBOM (CycloneDX ํ์)
5230 + 18974
output/sbom/license-report.md
๋ผ์ด์ ์ค ๋ถ์ ๋ฆฌํฌํธ
5230
output/sbom/copyleft-risk.md
Copyleft ์ํ ๋ถ์
5230
output/sbom/sbom-management-plan.md
SBOM ๊ด๋ฆฌ ๊ณํ
18974
output/sbom/sbom-sharing-template.md
SBOM ๊ณต์ ํ
ํ๋ฆฟ
5230 + 18974
output/vulnerability/cve-report.md
CVE ์ทจ์ฝ์ ๋ถ์ ๋ฆฌํฌํธ
18974
output/vulnerability/remediation-plan.md
์ทจ์ฝ์ ๋์ ๊ณํ
18974
output/training/curriculum.md
๊ต์ก ์ปค๋ฆฌํ๋ผ
5230 + 18974
output/training/completion-tracker.md
๊ต์ก ์ด์ ์ถ์
5230 + 18974
output/training/resources.md
๊ต์ก ๋ฆฌ์์ค ๋ชฉ๋ก
5230 + 18974
output/conformance/gap-analysis.md
๊ฐญ ๋ถ์ ๋ณด๊ณ ์
5230 + 18974
output/conformance/declaration-draft.md
์์ฒด ์ธ์ฆ ์ ์ธ๋ฌธ ์ด์
5230 + 18974
output/conformance/submission-guide.md
์ธ์ฆ ๋ฑ๋ก ์๋ด
5230 + 18974
OpenChain KWG ์ปค๋ฎค๋ํฐ์ ์ฐ๊ณํ์ฌ ์ด์๋ฉ๋๋ค. PR๊ณผ ์ด์ ์ ์ถ์ ํ์ํฉ๋๋ค.
CC BY 4.0
Trusted Open Source Supply Chain Management โ ISO/IEC 5230 & 18974 Practical Kit + AI Coding & DevSecOps Automation Guide
Even those with no prior open source management experience can complete ISO/IEC 5230 and ISO/IEC 18974 self-certification declarations by following this kit. Agents automatically generate deliverables tailored to your organization, and the kit is designed for self-study.
The web guide and browser-based tools are available at trustedoss.github.io/en .
Section
Content
Open Source Management
Step-by-step guide to building an open source governance system based on ISO/IEC 5230 & 18974
AI Coding Governance
Automated open source policy compliance for AI coding tools like Claude Code, Cursor, and Copilot
DevSecOps
CI/CD pipeline automation for SAST, SCA, secret detection, container, IaC, and DAST
Reference
Policy templates, SBOM samples, and self-certification checklists
Use in the Browser (No Claude Code Required)
Browser-based tools are available with just an Anthropic API key.
# 1. Clone the repository
git clone https://github.com/trustedoss/trustedoss-agents.git
# 2. Enter the project and launch Claude Code
cd trustedoss-agents && claude
# 3. Ask for guidance (type in Korean)
# "์ด๋์ ์์ํด์ผ ํด?" (meaning: "Where should I start?")
You can build your program at two depths:
Quick start (1โ2 hours) : short on time? Cover just the Overview, 02 Organization, and 03 Policy chapters to reach a policy draft.
Full course (about 12โ14 hours) : work through chapters 00โ07 in order to complete your self-certification statement.
Compliance Agents (ISO/IEC 5230 & 18974)
Agent
Role
How to Run
agents/02-organization-designer
Generate organization & role deliverables
cd agents/02-organization-designer && claude
agents/03-policy-generator
Generate open source policy document
cd agents/03-policy-generator && claude
agents/04-process-designer
Generate process documents & flowcharts
cd agents/04-process-designer && claude
agents/05-sbom-guide
Generate SBOM commands & scripts
cd agents/05-sbom-guide && claude
agents/05-sbom-analyst
Generate SBOM license analysis report
cd agents/05-sbom-analyst && claude
agents/05-sbom-management
Generate SBOM management plan & templates
cd agents/05-sbom-management && claude
agents/05-vulnerability-analyst
Generate vulnerability analysis report
cd agents/05-vulnerability-analyst && claude
agents/06-training-manager
Generate training curriculum & tracking
cd agents/06-training-manager && claude
agents/07-conformance-preparer
Generate gap analysis & declaration draft
cd agents/07-conformance-preparer && claude
AI Coding & DevSecOps Agents (Level 1 โ Config Generation)
Agent
Role
How to Run
agents/ai-coding-setup
Analyze project and generate custom Rules files
cd agents/ai-coding-setup && claude
agents/devsecops-setup
Analyze project and generate CI/CD pipeline files
cd agents/devsecops-setup && claude
AI Coding & DevSecOps Agents (Level 1 โ Result Analysis)
Agent
Role
How to Run
agents/sbom-vuln-analyst
SBOM/grype results โ vulnerability report
cd agents/sbom-vuln-analyst && claude
agents/sast-analyst
Semgrep/CodeQL results โ fix guide
cd agents/sast-analyst && claude
agents/secret-analyst
Gitleaks results โ secret response procedure
cd agents/secret-analyst && claude
agents/iac-fixer
Checkov results โ auto-generate IaC fix code
cd agents/iac-fixer && claude
CI/CD Automation Agents (Level 2)
Agent
Role
How to Run
agents/level2-automation/pr-comment
Generate PR security analysis auto-comment workflow
cd agents/level2-automation/pr-comment && claude
agents/level2-automation/issue-tracker
Generate scheduled scan issue auto-filing workflow
cd agents/level2-automation/issue-tracker && claude
trustedoss/
โโโ docs/ # Chapter-by-chapter guide documents
โโโ agents/ # Deliverable auto-generation agents
โ โโโ 02-organization-designer/
โ โโโ 03-policy-generator/
โ โโโ ...
โ โโโ ai-coding-setup/ # AI coding Rules file generation
โ โโโ devsecops-setup/ # DevSecOps pipeline file generation
โ โโโ sbom-vuln-analyst/ # SBOM vulnerability analysis
โ โโโ sast-analyst/ # SAST result analysis
โ โโโ secret-analyst/ # Secret detection result analysis
โ โโโ iac-fixer/ # IaC fix code generation
โ โโโ level2-automation/ # CI/CD integration automation
โโโ templates/ # Document templates
โโโ samples/ # Sample projects for practice
โโโ output/ # Generated deliverables (.gitignore)
โโโ .claude/ # Claude Code configuration & skills
โโโ website/ # Documentation website source (Docusaurus)
Chapter
Content
Self-study
00-overview
Overview of both standards & checklist mapping
1 hour
00-overview/supply-chain
Software supply chain security + SBOM concepts
1 hour
01-setup
Environment setup (Docker, Git, Claude Code)
30 minโ1 hour
02-organization
Organizational structure & role assignment
1 hour
03-policy
Open source policy establishment
1 hour
04-process
Open source process design
1โ2 hours
05-tools/sbom-generation
SBOM generation
1.5 hours
05-tools/sbom-management
SBOM management & sharing
1 hour
05-tools/vulnerability
Vulnerability analysis & response
1 hour
05-tools/ai-sbom
AI SBOM โ model ML-BOM generation (optional)
1 hour
06-training
Training program setup
1 hour
07-conformance
Self-certification declaration
2 hours
08-developer-guide
Developer policy enforcement (optional)
2 hours
File
Description
Standard
output/organization/role-definition.md
Open source program manager role definition
5230 + 18974
output/organization/raci-matrix.md
RACI responsibility matrix
5230 + 18974
output/organization/appointment-template.md
Role appointment letter template
5230 + 18974
output/policy/oss-policy.md
Open source policy document
5230 + 18974
output/policy/license-allowlist.md
Approved license list
5230
output/process/usage-approval.md
Open source usage approval procedure
5230
output/process/distribution-checklist.md
Pre-distribution checklist
5230
output/process/vulnerability-response.md
Vulnerability response procedure
18974
output/process/inquiry-response.md
External inquiry response procedure
5230 + 18974
output/process/contribution-process.md
Open source contribution process
5230
output/process/process-diagram.md
End-to-end process diagram
5230 + 18974
output/sbom/[project].cdx.json
SBOM (CycloneDX format)
5230 + 18974
output/sbom/license-report.md
License analysis report
5230
output/sbom/copyleft-risk.md
Copyleft risk analysis
5230
output/sbom/sbom-management-plan.md
SBOM management plan
18974
output/sbom/sbom-sharing-template.md
SBOM sharing template
5230 + 18974
output/vulnerability/cve-report.md
CVE vulnerability analysis report
18974
output/vulnerability/remediation-plan.md
Vulnerability remediation plan
18974
output/training/curriculum.md
Training curriculum
5230 + 18974
output/training/completion-tracker.md
Training completion tracker
5230 + 18974
output/training/resources.md
Training resource list
5230 + 18974
output/conformance/gap-analysis.md
Gap analysis report
5230 + 18974
output/conformance/declaration-draft.md
Self-certification declaration draft
5230 + 18974
output/conformance/submission-guide.md
Certification registration guide
5230 + 18974
This project is operated in collaboration with the OpenChain KWG community. Pull requests and issues are welcome.
CC BY 4.0