Patrick Masson<p>This was just published:</p><p>"Open source software best practices and supply chain risk management" by the <a href="https://fosstodon.org/tags/govuk" class="mention hashtag" rel="tag">#<span>govuk</span></a>, Department for Science, Innovation & Technology.</p><p>Seems like a nice reference for a similar effort for <a href="https://fosstodon.org/tags/OpenSource" class="mention hashtag" rel="tag">#<span>OpenSource</span></a> in <a href="https://fosstodon.org/tags/HIgherEd" class="mention hashtag" rel="tag">#<span>HIgherEd</span></a>. </p><p>Organizations like <a href="https://fosstodon.org/tags/Apereo" class="mention hashtag" rel="tag">#<span>Apereo</span></a> (<span class="h-card" translate="no"><a href="https://social.fossdle.org/@apereo" class="u-url mention">@<span>apereo</span></a></span>), <a href="https://fosstodon.org/tags/JISC" class="mention hashtag" rel="tag">#<span>JISC</span></a>,(<span class="h-card" translate="no"><a href="https://bird.makeup/users/jisc" class="u-url mention">@<span>jisc</span></a></span>), EU's Open Source Observatory (<a href="https://fosstodon.org/tags/OSOR" class="mention hashtag" rel="tag">#<span>OSOR</span></a>), and <a href="https://fosstodon.org/tags/EDUCAUSE" class="mention hashtag" rel="tag">#<span>EDUCAUSE</span></a> (<span class="h-card" translate="no"><a href="https://mastodon.social/@educause" class="u-url mention">@<span>educause</span></a></span>) might help.</p><p><a href="https://www.gov.uk/government/publications/open-source-software-best-practice-supply-chain-risk-management/open-source-software-best-practices-and-supply-chain-risk-management" target="_blank" rel="nofollow noopener noreferrer" translate="no"><span class="invisible">https://www.</span><span class="ellipsis">gov.uk/government/publications</span><span class="invisible">/open-source-software-best-practice-supply-chain-risk-management/open-source-software-best-practices-and-supply-chain-risk-management</span></a></p>