• Company
  • Service
  • Products
  • News
  • Calendar
  • Imprint
  • Notices
  • Privacy
  • Deutsch
  • Menu
  • Company

    Background and philosophy

  • Service

    Overview of services

  • Products

    {metæffekt} products

  • News

    Current events and activities

  • Calendar

    Upcoming dates

  • Imprint

    Company details

  • Notices

    Notices on content and rights of third parties

  • Privacy

    Privacy policy and obligations

Company

Continuous Deployment, Continuous Delivery, Continuous Compliance

{metæffekt}

{metæffekt} GmbH supports and accompanies companies in the inventory and evaluation of used software components (Software Composition Analysis). Through many years of expertise and know-how in the areas of software architecture, software development, continuous integration and license compliance management {metæffekt} is a sovereign partner for the continuation of the inventory, documentation and risk assessment of products and projects in dialogue with the various competencies and responsible parties in the company.

In addition to services in the product and project context {metæffekt} offers consulting on process and policy design, as well as training and seminars on the topics of License Compliance Awareness, License Compliance Management, Vulnerability Monitoring and Vulnerability Assessment.

Background

Modern software development makes use of current methods, common tools and a multitude of existing components, libraries, development and test kits. Demands for fast, cost-effective, quality-oriented and thus competitive product or project development underline this approach. Enterprises are requested to concentrate on their core authority and technical know-how and must fall back as much as possible to existing concepts and components other manufacturers or from community projects.

Coupled with legal requirements, contractual requirements for transparency and sovereign handling and requirements from information security standards (such as BSI-200, ISO-27001), the multitude and varying granularity of the software components used creates a complexity that must be evaluated not least in the risk management of a company. However, the challenge in the company already begins with the question of which software is used and how and which properties, obligations and restrictions must be taken into account.

In its approach, {metæffekt} differs significantly from other providers. By focusing on the software components actually used a defined data quality is achieved through the application of specialized tools and case-specific consulting, which is particularly necessary for implementing license compliance in the supply chain and for identifying and monitoring public vulnerabilities. In all operations, the focus is always on documentation of the end product and risk reduction in the respective business case. The procedures are applied with precision through automation and integration into the development processes and enable continuity in the lifecycle of the products and projects.

Philosophy

In particular, the correct handling of Open Source Software is of central importance to us. For this purpose, it is necessary to understand and comprehend the perspective of the actors in the Open Source Model. We have summarized our experiences and findings in this regard in the {metæffekt} Open Source Ethics.

The {metæffekt} Using Open Source Software Manifesto is derived from the Open Source Ethics. This manifesto clarifies and supports the position and actions of {metæffekt} GmbH.

We dare to hypothesize that the Open Source Model is a foundation of our future society. We move from the Open Source Model to the open society. Industry 4.0 or the concepts based on blockchains, cryptocurrencies and smart contracts are just prominent examples of change on this path.

For this reason in particular, it is necessary to clearly define the fundamental rules, moral and ethical aspects and obligations in dealing with Open Source Software as the foundation of these developments.

Service

Overview of services

Notices

  • Our services are not a substitute for legal advice.
  • All legal issues will be referred to licensed legal counsel in consultation.

Inventory of software and hardware components

To implement compliance requirements for software and hardware the components of a product are fully recorded. For this purpose, the parts - components - are transferred to an inventory and supplemented with properties for checking the requirements. Following information are recorded:

  • Licensing of the components
  • Licensing decisions (especially in the case of multiple licensing or sublicensing)
  • Information on the fulfillment of license conditions
  • Vulnerabilities and product-specific evaluation
  • Restrictions in use and delivery
  • Patent information and terms of use
  • Efficiency and sustainability attributes
Assessment – 2-day workshop [request by email]

In a 2-day workshop a product is specifically inventoried and enriched with information. Company-specific requirements and general conditions are compared with the information in the inventory. The process is accompanied by documentation of the research.
Finally, the results are presented and possible risks, priorities and measures are discussed.

The assessment supports the risk classification of a product in the company. The risks serve as an instrument for controlling the derived measures.

Documentation - Asset Annex [Anfrage per E-Mail]

Comprehensive documentation - the Asset Annex - is created for a product (asset) consisting of software and/or hardware. The Annex contains information that is required for the operation or delivery of the product. To create the Asset Annex an inventory with the required information is processed, compiled and quality assured.
The Asset Annex includes the Bill of Materials, license list, license notices and sources of open source components.
Accompanying, on the basis of the work status of the Asset Annex, risks and measures in the company are discussed.

The Asset Annex becomes the accompanying documentation of the product. Through the contents the license conditions of the embedded components are perceived and the product is presented in the context of the specific compliance requirements and made auditable.

OnDemand research for software components [request by email]

Detailed information is required to classify and assess third-party software components. With OnDemand research for software components it is possible to compile the required information on request. Specialized automated tools are used and the results are tracked and followed up.

The researched information can be used to support software compliance processes in the company or added to software asset catalogs of IT Asset Management Systems.

As a {metæffekt} OnDemand Service, OnDemand Research For Software Components represents a central building block for Managed Security Services (MSS).

Form - OnDemand Research for Software Components

Seminars

Day seminar – Innovation model Open Source in practice [request by email]

The seminar teaches the basics of efficient handling of Open Source and third-party components in your own software. In moderated exercises practical examples are transferred into a basic procedure and documentation.

The seminar is aimed at all decision-makers, process and product managers who want to take advantage of the complexity of Open Source in the product environment. In addition, the seminar is aimed at all disciplines in the company that come into contact with Open Source; on the one hand, representatives of software development, such as development managers, software architects, software developers and product managers; on the other hand, people in purchasing and the company's internal legal department.

Products

Products of {metæffekt} GmbH

{metæffekt} Universe

A targeted license analysis is based on high-quality data that must be continually processed, completed, and refined. {metæffekt} maintains an extensive license database. The {metæffekt} Universe is based on various public sources, which it incorporates, supplements, consolidates, and expands to satisfy the criteria and concepts of the applied tools.

The {metæffekt} Universe is available to {metæffekt} customers via subscription. The Universe can be used within various plugins released under a permissive open source license.

A comprehensive overview of the {metæffekt} Universe is available on GitHub. See Universe Github repository {metæffekt} Universe GitHub Repository [external Link]

Show More
›
Extent of the License Database

The {metæffekt} license database is a tool and structured dataset used to automate license documentation processes. It forms the basis for license scanners and analysis tools and enables consistent and in-depth evaluation of a wide variety of license types.

What does the license database contain?
  • 2751 modeled license terms
  • 205 exceptions
  • 9 modifiers
  • 2 restrictions
  • 294 specific and commonly used license expressions
  • 60 consolidated markers.
as of 31.07.2025
›
Commonly used License Expression and License Exceptions

The database contains 271 specific and frequently used license expressions. These expressions serve to identify licenses and license combinations. They are crucial for deriving the license under which the use and/or distribution is intended.

In addition, the database includes 190 modeled exceptions. These reduce or modify the obligations of a base license and are frequently found in open source. The database contains the expectations along with alternative identifiers, normalization rules, and linking rules.

›
Marker for Risk Identification

The 60 markers are used in the {metæffekt} license database for license risk detection. They are designed to identify potential compliance risks. Markers are evaluated on both license texts and other materials and evolved continuously in the license database.

›
Mapping to other License Databases

Appropriate references map licenses in the {metæffekt} license database to entries in other license databases. Currently, mappings to SPDX, ScanCode Toolkit, Open Source Initiative (OSI), and Open Code are supported. This ensures a uniform and consistent analysis of license information across the various data sources.

{metæffekt} Kontinuum

A comprehensive software, license, and vulnerability analysis requires the use of various tools and datasets. The {metæffekt} Kontinuum combines these into a consistent, directed, and automated workflow. Necessary measures and corrections are applied by enriching the used datasets.

The {metæffekt} consists of various building blocks that can be selected as needed. Each building block is assigned to functional modules and datasets.
The building blocks can be ordered in various service packages via a provisioning and service agreement.

In principle, all building blocks and several datasets can be obtained under Open Source license without a contract. Integration is enabled by the content available on:

  • {metæffekt} Kontinuum[external Link]
  • {metæffekt} Components (GitHub)[externalLink]
  • {metæffekt} Components (Open Code GitLab)[external Link]
Show More
›
E-1: Automated collection of Hardware or Software Asset Components
  • Analysis of hardware or software assets to identify their components.
  • Creation of a machine-readable inventory of the components.
  • Creation of Bill of Materials (BOM) in SPDX and/or CycloneDX format.
›
L-1: Automated Aggregation and License Scanning of Software Components
  • Loading identified software components in various representations (e.g., binary artifacts, archives) from online sources..
  • Analysis of the downloaded representations of the software components with the {metæffekt} license scanner.
  • Provision of license scanner results as enriched inventories.
  • Export of inventories as Bill of Materials (BOM) in SPDX and/or CycloneDX format.
›
L-2: Automated License Analysis and Evaluation
  • Processing of license scanner results from modules E-1 and/or L-1.
  • Application of corrections to the automatically generated license analysis.
  • Derivation of risk indicators based on the analysis results.
  • Consolidation of risk indicators into enriched inventories.
›
L-3: Automated License Documentation
  • Generation of PDF documents based on identified components and license scanner results. The following document types are supported:
    • License Documentation:
      A summary of the identified licenses for software assets in a single document.
    • Software-Annex:
      Documentation of software assets and their components including licenses, copyright notices, and license statements to fulfill individual license obligations.
      Aggregation of License Texts and License Notices.
      Aggregation of sources according to established guidelines.
›
V-1: Automated Aggregation of Vulnerability Information
  • Regular updating and processing of vulnerability information from various public vulnerability databases.
  • Providing the processed data for use within the organization.
›
V-2: Automated Collection of Vulnerabilities for Hardware and Software
  • Correlation of identified hardware and software components with vulnerabilities from public or vendor-specific sources.
  • Aggregation of correlated components, associated vulnerabilities, and additional vulnerability information in the HTML-based Vulnerability Assessment Dashboard.
›
V-3: Automated Vulnerability Documentation
  • Generation of report documents in PDF format based on the identified vulnerabilities. Possible report types include:
    • Asset-Level Vulnerability Report:
      A detailed report for a single asset, listing all associated vulnerabilities.
    • Asset-Summary Vulnerability Report:
      A summarized report covering multiple assets within a solution or product, including vulnerability statistics.
    • Periodic Asset-Summary Vulnerability Report:
      A time-bound summary report that includes current advisories and statistics over a defined period.
›
V-4: Automated Portfolio Vulnerability Display
  • Aggregation of the results from V-3 in a Portfolio Vulnerability Board. The Portfolio Vulnerability Board is an HTML board that provides an overview of various assets and their vulnerabilities.
  • Email notifications to groups and individuals based on the data in the Portfolio Vulnerability Board

News

Current events, activities and notices

{metæffekt} Kontinuum @ IT-SA 2025

Imagine

  • creating a complete and precise Bill of Materials of the hardware and software in use,
  • running a deep license and copyright scan over the Bill of Materials and different representations of the covered software,
  • matching the Bill of Materials against databases associating vulnerabilities and advisories,
  • visualizing the results in an assessment dashboard for contextualization and in-depth assessment,
  • creating internal and external reports and exports on licenses, vulnerabilities and vulnerability statistics, and
  • integrating threat analysis, validation and operational details into the vulnerability assessment.

All of this can be automated in a secure, on-premise pipeline, supported by an interdisciplinary, proactive team of experts managing identified risks and contributing knowledge.

This is exactly what {metæffekt} has been building since 2016 in real-world customer projects.

Join, support, engage or entrust us on our common journey for efficient transparency and compliance. The goal is to 'Get ahead of the Cyber Resilience Act while being based on European Open Source for Digital Sovereignty'.

Meet the team at #itsaexpo from 7th to 9th October 2025 in the Bitkom Security Area, hall 7a, booth 416.

Expansion of the {metæffekt} Universe

The {metæffekt} Universe is expanding at a steady pace. It covers models of terms, licenses, license exceptions, and risk markers used by the {metæffekt} license scanner. Since 2016 it is continuous growing and currently covers 2751 modeled terms/licenses, 205 exceptions, 294 common license expressions, and 60 risk markers.

Based on these numbers, the {metæffekt} Universe is claiming the status of the most comprehensive license database available in the field!

And further expansion is planned... The systematic evaluation of Hugging Face terms of use and licenses has been initiated to ensure coverage of AI models and datasets. Seventeen additional terms and licenses are already awaiting evaluation and integration.

Find out more on the {metæffekt} Universe [externer Link].

About Secondary Licenses

The concept of Secondary Licenses is rarely known. Only a few individuals are aware of this concept or its variants. Specifically in the FOSS licensing context, secondary licenses are a defined set of licenses available as alternative for sublicensing an asset, specifically a third-party software component. Secondary licenses may be specifically used to resolve license conflicts when distributing software.

For the development of a software product, it may be important to understand the mechanics and to have the relevant data available at any time.

In the {metæffekt} Universe, terms and licenses are modeled on a significant scale. Recently, metadata for secondary licenses has been added, providing detailed information on such options to support informed license conclusions.

Discover more on GitHub [externer Link].

Announcement - {metæffekt} Universal CVSS Calculator

The {metæffekt} Universal CVSS Calculator [external link] is the first calculator capable of calculating the severities of multiple CVSS-vectors of different versions (including the latest CVSS:4.0 version) at the same time making comparing them as easy as glancing at a single chart.

Implemented in TypeScript, published under a permissive open-source license, and directly integrated into our Vulnerability Assessment Dashboard, we are continuing to move towards a complete and publicly available tooling set.

“Contextualizing security threats is as important as identifying their existence,” says Shane Coughlan, OpenChain General Manager. “The emergence of open-source tools to visualize this is a key part of ensuring the supply chain can plan ahead and action responses. We are delighted to see the work by Metaeffekt, an official OpenChain Partner, in the domain. It aligns well with OpenChain ISO/IEC 18974, the international standard for open-source security assurance.”

The implementation is available as Open Source on GitHub [external link].

Take a look at our LinkedIn post at the following link [external link]!

Calendar

Upcoming dates

October 2025

IT-SA – 07.10. – 10.10.2025 in Nuremberg

After 2018 and 2019, {metæffekt} will once again be actively represented at the IT-SA in Nuremberg in October. Please approach us in Hall 7A in the Bitkom Security Area, Booth 7A-416.

November 2025

OSBA Connect 13.11.2025 in Berlin

Same procedure as every year. Looking forward...

Review 2025

Bitkom Open Source Forum - 18.09.2025 in Erfurt

{metæffekt} wasattending the Bitkom Open Source Forum 2025, although not as a sponsor this year.

Bitkom AK Open Source - 17.09.2025 in Erfurt

In keeping with annual tradition, the meeting of the Bitkom AK Open Source was held on September 17, 2025, just before the Bitkom Open Source Forum, under the theme ‘Open Source in Practice – Economic Perspectives’.

CEN-CLC-JTC 13 WG-9 Meeting – 02.09. – 04.09.2025 in Brussels

At the beginning of September, {metæffekt} was represented at the CEN-CLC-JTC 13 WG-9 working group meeting. The meeting provided a forum for information exchange between the European Commission and various project teams, focusing on topics related to the Cyber Resilience Act.

Review 2024

BSI Workshop – 09.12. – 12.12.2024 in Munich

From December 9 to December 12, 2024, the BSI once again organized CSAF workshops at the Information Security Hub in Munich. {metæffekt} participated with two team members to review and further refine the existing integration of CSAF into our tools

OSBA Connect – 14.11.2024 in Berlin

As every year, the OSBA Connect event took place in Berlin in 2024. During the members’ meeting in the morning, reports were given from the OSBA working groups. In particular, the activities related to the Cyber Resilience Act and the Working Group on Continuous License Compliance were highlighted.

15.10.2024 - 17.10.2024

Smart Country Convention [external link] – 15.10.2024 - 17.10.2024 in Berlin

10. Bitkom Forum Open Source – 12.09.2024 in Erfurt

The 10th Forum Open Source took place again in Erfurt on September 12, 2024. {metæffekt} presented a workshop titled ‘Automating Regulatory Requirements of the Cyber Resilience Act’. Find more details in the #bfoss2024 Programm [external Link].

Review 2023

CSAF-Workshop – 12.12.2023 - 15.12.2023 in Munich

The BSI-funded workshop on the CSAF-standard [external link] took place this year at the Munich Airport from December 12th to December 15th, 2023. CSAF is a machine-readable format to publish security advisories and serves as an automatable communication tool of security-related topics between manufacturers and consumers. The workshop covered the whole life cycle of a CSAF-document both theoretically and practically: participants learned how manufacturers create CSAF-documents for their products and services, how these documents are distributed and shared in different formats and by different roles and how end users can download, filter and update them automatically without having to check them manually. The exchange with the developers of the CSAF-format from BSI and with the other participants was particularly interesting for {metæffekt}: many of the current opportunities and challenges were addressed during the workshop such as the clear identification of products, the scoring of vulnerabilities and the development of corresponding tools. Good to know there is actively working on appropriate solutions.

Cyber Resilience Act Update

The last trilogue negotiation on the Cyber Resilience Act took place on November 30th, 2023. Compromises were made on the outstanding points to date. You find a short report here [external link].

Bitkom Open Source Monitor English Version - 2023

We’re also part of the English version of the Bitkom Open Source Monitor 2023 [external link]. Check it out and find our report on page 36!

Review Smart Country Convention 2023 – 07.11.2023 - 09.11.2023 in Berlin

This year the Smart Country Convention took place from November 7th to 9th at the exhibition center in Berlin. In addition to an extensive range of contributions, project presentations and discussions, the focus was on networking among exhibitors and visitors. From our point of view, both the perception of the trade fair programme and the opportunity for networking were successful. We are looking forward to see what comes from the new relationships!

Bitkom Open Source Monitor – 2023

This year, {metæffekt} once again contributed to the Bitkom Open Source Monitor 2023 [external link]. The monitor dealt with issues relating to the use of open-source software in the German industrial economy and public administration. As part of this, {metæffekt} focused on the Cyber Resilience Act [external link] and its significance for the two research areas. Based on the results from the monitor, {metæffekt} found in comparison that public administration is currently better prepared for the upcoming regulation. Nevertheless, both areas require intensive discussion of the Cyber Resilience Act and the usage of open-source software. You can find our article on page 36!

Review Bitkom Forum Open Source 2023 – 27.09.2023 in Erfurt

This year’s Bitkom Forum Open Source once again took place in Erfurt. This time under the motto “Open Source. Gemeinsam gestalten!”, one of the key topics was the upcoming implementation of the Cyber Resilience Act [external link]. The panel discussion on this topic gave the impression that the German IT landscape has so far had little contact with the regulation. It's exciting to see how quickly progress will be made.

Review Bitkom working group - Open Source – 26.09.2023 in Erfurt

The working group took place in the run-up to the Bitkom Forum Open Source in Erfurt. Yan Wittmann and Karsten Klein from {metæffekt} presented their progress in the area of vulnerability assessment. Customers can use a dashboard to individually display the vulnerabilities in their deployed software components. The assessment system also has the option of displaying the evaluation of vulnerabilities, corresponding risks and advisories. The {metæffekt} vulnerability assessment with its own dashboard offers a central solution component in the endeavour for cybersecurity.

Review 2021

BITKOM Guide - Open-Source-Software - Legal Basics and Action Guidelines

With the guide Open-Source-Software - Legal Basics and Action Guidelines[external link], Bitkom publishes a comprehensive introduction to the topic of Open Source Software. During the project work on the guide the deep insights and discussions with the legal colleagues were especially enriching for us as technology experts and Open Source forensic experts.

{metæffekt} Universe – 05.11.2021

With the {metæffekt} Universe the scope of the license database of {metæffekt} GmbH GitHub Repository [external link] the vis.js based representations provide interesting insights.

Bitkom Open Source Monitor – 2021

{metæffekt} is the sponsor of this year's Bitkom Open Source Monitor [external link].

Review 2020

OOP 2020 - State of Art Continuous Compliance – 03.02.2020 - 07.02.2020 in Munich

In the {metæffekt} contribution to the OOP 2020 in Munich State of Art Continuous Compliance - An Overview on 06.02.2020, we informed the conference participants about the current processes on the topic of software compliance. The focus was on Open Source initiatives and working groups. The integration into the development processes was demonstrated on the topic of Container License Compliance. The presentation was visually recorded. Many thanks to Kata and Dora.

OOP 2020 [external link]

Container Annex - Github Project – 01.02.2020

Containers are a flexible tool and are increasingly used in industry to distribute and run software. The consideration of compliance often comes too short.

In order to be able to directly integrate and track a consideration of compliance in the continuous build of the development the {metæffekt} offers some Open Source Plugins that can be used without hurdles.

A new GitHub project illustrates the basic functionality of the plugins:
https://github.com/org-metaeffekt/metaeffekt-container-annex [external link]

Review 2019

Blauer Engel für Software – Heise Artikel vom 27.12.2019

{metæffekt} welcomes the announced Blauer Engel for software as the right signal (see Blauer Engel für Software im Anflug [external link]). In general, a sustainable understanding of values should be introduced into technology and society from various perspectives and the term sustainable digitalization should be coined.

"The concept of sustainable digitization is in principle an antithesis to the current very neoliberal understanding of digitization for the largely exclusive increase of efficiency and growth. In terms of sustainable digitization it is imperative to assess the consequences along a consolidated value concept of our society and thus to take into account social and ecological factors, among others." Karsten Klein, Managing Director {metæffekt GmbH}

Bitkom working group - Open Source – 27.11.2019 in Frankfurt

The working group Open Source met this time in the PwC Tower in Frankfurt. The meeting was characterized by the review of 2019 and the thematic planning of the working group for 2020.

Digital Summit – 28.10.2019 - 29.10.2019 in Dortmund

On October 28 and 29 2019, the Ministry of Economic Affairs and Energy hosted the Digital Summit 2019 in Dortmund. The {metæffekt} was there to follow the discussions on digital platforms and to set elected accents.
Digital Summit 2019 [external link]

Smart Country Convention – 22.10.2019 - 24.10.2019 in Berlin

The digitization of administration was the central topic of the event.
In our view, the topic of Open Source is unavoidable here and Open Source License Compliance Management is a compelling necessity.
Smart Country Convention 2019 [external link]

it-sa – 08.10.2019 - 10.10.2019 in Nürnberg

{metæffekt} GmbH from Heidelberg presented itself at the joint booth of Baden-Württemberg international (BWi) under the motto software inventory, metadata, compliance from the perspective of ISO/IEC 27001 and the BSI basic protection catalogs.
it-sa 2019 [external link]

In this context, {metæffekt} presented its new service offering of OnDemand Research for Software Components. The offering supports companies to collect and provide relevant metadata on software components on demand and in a timely manner. This information can be used to support software compliance processes within the company or added to software asset catalogs of IT Asset Management Systems for operational purposes. Primary metadata includes licensing information, patent references and known vulnerabilities.

As a {metæffekt} OnDemand Service, OnDemand Research for Software Components represents a central building block Managed Security Services (MSS).







OnDemand Services

Bitkom working group - Agriculture – 26.09.2019 in Berlin

Under the motto "The agriculture of the future is sustainable - and digital!" the working group had invited. In addition to sensor technology and robotics, the topic of sustainability was also to be brought into focus for farmers. This is a topic that has already caused some controversy in many areas of the industry.

Bitkom working group - Open Source – 16.09.2019 in Erfurt

The Open Source working group met again this time in Erfurt. The meeting focused on the topic of »Inner Source«.

6th forum Open Source – 17.09.2019 in Erfurt

The 6th Open Source Forum was held under the motto "Digital ecosystems: cooperative, efficient, transparent with Open Source". A permanent fixture in the {metæffekt} calendar.
bfoss19 [external link]

Symposium digital city – 20.09.2019 - 21.09.2019 in Heidelberg

The International Building Exhibition IBA hosted the Digital City Symposium in Heidelberg at the Patrick Henry Village conversion site. The international contributions on the topic and the discussions in the specialist forums covered the entire spectrum of Digital City topics.
IBA_LAB N°7 »DIGITALE STADT?« [external link]

OSADL Special Events - HOT - Heidelberg OSADL Talks 2019 – 23.09.2019 - 24.09.2019 in Heidelberg

Local event of the OSADL. Especially the events about Open Source License Compliance are a must for {metæffekt}.
OSADL [external link]

Bitkom working group - Public Procurement – 24.09.2019 in Berlin

The Public Procurement Working Group meets to discuss the EVB-IT Cloud, among other topics. The report on the round of negotiations with the Federal Ministry of the Interior and Home Affairs is particularly noteworthy on this topic. We look forward to the discussion in the working group on relevant topics for the upcoming Smart Country Convention.

{metæffekt} Summer Night – 03.07.2019 in Heidelberg

On 03.07.2019 we celebrated this year's Summer Night with guests from the {metæffekt} environment. We thank all guests for the nice and entertaining evening.

Meeting of the project group Open Source - Innovation model for industry and society – 03.07.2019 in Heidelberg

It was a special honor for us to host the meeting of the Open Source - Innovationsmodell für Industrie und Gesellschaft project group of the Bitkom Open Source Working Group on our premises in Heidelberg. Many thanks for the lively discussion on techno-socio-political topics.

Forum digital city – 02.07.2019 in Heidelberg

This year's forum was again characterized by innovative ideas. The approach of the city of Mannheim must be highlighted in particular. The contribution not only impressed - as usual - with the number of projects, but the concept of "Digital Identity" shows itself to be course-setting and citizen-oriented.

Bitkom working group - Open Source – 05.06.2019 in Berlin

The Open Source Working Group met again this time in Berlin. The meeting focused on the topic of "Collaboration across company boundaries".

Bitkom forum law - responsibilities in the digital economy and society – 15.05.2019 - 16.05.2019 in Berlin

In order to do justice to a "responsibility" in the topic of "AI" the previous evening event already showed that the previous findings of various commissions should be reflected into society.
How concretely to deal with topics such as AI, chatbots, cloud services and DSGVO could be dealt with practically and in the short term and why a continuous risk assessment and process improvement in terms of the current "state of the art and science" might be necessary we learned from top-class expert contributions.

4th IT-Vergabetag 2019 – 15.05.2019 in Berlin

The speed of (agile) digital development is being merged with the requirements of the public sector in everyday procurement. A perfectly normal process, but one that requires special attention at one point or another. Exciting reports and questions from both players and a clear pleading for transparency and openness which could be solved not least by the many solutions of the "Open" movement in digitalization.
A real exchange of experiences at eye level.

{metæffekt} is OpenChain Partner – 14.05.2019

Since 14.05.2019, {metæffekt} has been an official partner of the Linux Foundation's OpenChain project.
The OpenChain project enjoys increasing attention on an international level. Through the OpenChain specification and the Self-Certify Questionnaire, foundations are being laid for Open Source License Compliance in the supply chain. On a national level, several representatives of the automotive industry and their suppliers have recently joined the project.
In particular, the project is increasingly focusing on the implementation and automation of processes within the company. Here we as {metæffekt} see the opportunity to present our experience, approaches and methods from practice to discuss them and to coordinate them on an international level.
OpenChain Welcomes {metæffekt} [external link]

Bitkom working group - digital agriculture – 10.05.2019 in Berlin

The digitization of agriculture is advancing inexorably. The collection and analysis of data require integrative, networked solutions and interdisciplinary collaboration which increasingly involves software compliance, among other things.

Digital Farming Conference 2019 – 09.05.2019 in Berlin

{metæffekt} discussed all aspects of Agriculture 4.0 with experts and decision-makers from the agricultural and digital industries, society, science and politics.

Bitkom working group - digital administration – 11.04.2019 in Berlin

A very lively overview of the new role of the Federal Chancellery in the coordination of digital policy, an understandable presentation of the role of the IT Planning Council as an IT organization in German federalism, and the current status on the Online Access Act (OZG) implementation - an interesting day in Berlin which ended with the open question of how to harmonize the agile understanding with the bulky organizational titles.

OSBA - OPEN! Round Table – 10.04.2019 in Stuttgart

With field reports on the use of Open Source and a round table format with different focal points this year's OPEN! The OSBA event was entertaining and interesting. Exciting: the discussion about Open Source and the advantages such as transparency and sovereignty is becoming more and more a social discussion. This tendency was also noticeable in the dialog with the participants this evening.

Bitkom working group - public procurement – 10.04.2019 in Berlin

The meeting day was packed with news from the various activities of the working group. First of all, an overview of the current status of the EVB-IT Cloud. Proposal and presentation of a possible cooperation between the working group Smart Cities/working group Law in Business and the working group Public Procurement in order to better present the challenge of Smart City initiatives. Presentation of the Committee: European Standardization for Procurement. Update on the Social Sustainability Commitment for IT Procurement. The coming activities will show whether this topic may even trigger a new working group within Bitkom - exciting in any case.

Bitkom working group - Intellectual Property – 03.04.2019 in Berlin

After the DSGVO the copyright reform in the EU Parliament now determines the agenda of the working group. Who exactly will be affected by these "upload filters"? Will there be a grandfathering or even a general amnesty for Germany? Particularly when it comes to software and Open Source the industry is dismissing the possible consequences.

OSADL Special Events - HOT - Heidelberg OSADL Talks 2019 – 25.03.2019 in Heidelberg

As usual, a very good and entertaining overview of Open Source, also beyond the GNU family, with a focus on licenses for delivery. The highlight of the morning session was the presentation of the "OSADL Open Source License Obligations Checklists" project to which we do not have a technical connection alone.

Bitkom working group - Quality Management – 20.02.2019 in Frankfurt

In the presentation "Continuous *, ... Continuous Quality" we discussed the continuous automated aspects of modern development. We introduced concepts of Continuous Architecture (also Agile Architecture) and Continuous Integration. From this, further continuous concepts were derived. In the area of Continuous Compliance, we presented basic metrics for evaluating compliance with respect to software licenses and security vulnerabilities.
We venture the thesis that with sufficient automation of operations and sharp metrics and rules to assure compliance, agility and compliance can be combined with pinpoint accuracy and conclude with the challenges of doing so today.

Bitkom working group - Open Source – 14.02.2019 in Darmstadt

The Bitkom Working Group - Open Source is currently working intensively on the topic of employee contributions and collaboration with Open Source in the company. On 14.11.2018, the working group met in Darmstadt with a program of experience reports paired with legal perspectives.
For the {metæffekt} an opportunity to point out some questions from practice and to discuss them in the round.

3rd {metæffekt} seminar - Innovation model Open Source in practice – 29.01.2019 in Heidelberg

For the third time, the day seminar Innovation Model Open Source in Practice took place at the SRH University Heidelberg on January 29th, 2019. Together with students of business informatics and cross-media design, we worked on the basics of license compliance and the use of Open Source. The mixture of theory and practice was again very well received by the students.

Imprint

Company details

Company

metaeffekt GmbH
Renettenweg 6/1
69124 Heidelberg
Deutschland

Jurisdiction: Mannheim
Commercial register: Mannheim, HRB 725313
USt.-IdNr. (gemäß §27a Umsatzsteuergesetz [external link]): DE307084554

Chief execution officer: Karsten Klein

Contact

E-mail: contact [at] metaeffekt [dot] com
Tel: +49 (0) 171 / 210 8692

Contents

Person responsible for the contents according to §55 II RStV: Karsten Klein

{metæffekt} Root CA

Download: {metæffekt} Root CA

Fingerprints:
SHA-256: 12 A2 E1 EA C9 D9 AE 8E 11 B8 D0 D6 02 65 C4 61 59 83 6C 03 8D A5 DA 52 45 74 3E 9E D1 6B 4D 5F
SHA-1: C9 7A 7F C6 4A 74 7A 26 4C 87 A7 35 02 FA 59 7F 6E E2 5C EE

Notices

Notices on content and rights of third parties

Contents

{metæffekt} GmbH assumes no liability and no guarantee for the completeness and correctness of the contents on the pages at http://www.metaeffekt.de, http://www.metaeffekt.com and https://metaeffekt.com respectively. The respective provider of the page is responsible for the contents of pages referenced by links.

{metæffekt} GmbH regularly checks the contents of the referenced pages in order to keep links and contents up-to-date. Nevertheless, these contents cannot be verified constantly. {metæffekt} GmbH cannot influence the contents of external providers.

Copyright

The contents of the pages at http://www.metaeffekt.de, http://www.metaeffekt.com and https://metaeffekt.com respectively are protected by copyright.
The presentation of the contents on these pages does not allow any direct further use of the contents without the explicit permission of {metæffekt} GmbH.

Brands

The name metaeffekt is a registered word mark of {metæffekt} GmbH.

Logos

The logo of the Open Source Business Alliance was provided to us on 11.06.2017 with permission to use it on the website.

The use of the Bitkom logo is subject to the trademark license agreement between the Bundesverband Informationswirtschaft, Telekommunikation und neue Medien e.V. and {metæffekt} GmbH dated 27.09.2017.

The use of the it-sa logo takes place as a registered exhibitor and under consideration of the conditions when downloading the logo.

The use of the Netzwerk Smart Production logo takes place as a member of the Netzwerk Smart Production e.V. which was confirmed by the managing director of the network on 19.11.2018.

The use of the OpenChain logo and the OpenChain trademark takes place within the framework of the Partner Program of OpenChain and according to the Partner Agreement between the Linux Foundation and {metæffekt} GmbH.

The OOP banner and the OOP speaker logo were provided by the conference management on 06.12.2019.

Pictures

Pictures on the web pages of {metæffekt} GmbH are always shown with source reference and license.

Web Fonts

On the pages of {metæffekt} GmbH, the Google Fonts Quicksand, Nanum Gothic and Raleway and Source Sans Pro, as well as icon fonts from FontAwesome are used.

Quicksand is published under the SIL Open Font License, 1.1 [external link]. Copyright 2011 The Quicksand Project Authors (https://github.com/andrew-paglinawan/QuicksandFamily), with Reserved Font Name Quicksand.

Nanum Gothic is released under the SIL Open Font License, 1.1 [external link]. Copyright 2010 NHN Corporation. All rights reserved. Font designed by Sandoll Communications Inc.

Raleway is released under the SIL Open Font License, 1.1 [external link]. Copyright (c) 2010, Matt McInerney (matt@pixelspread.com), Copyright (c) 2011, Pablo Impallari (www.impallari.com|impallari@gmail.com), Copyright (c) 2011, Rodrigo Fuenzalida (www.rfuenzalida.com|hello@rfuenzalida.com), with Reserved Font Name Raleway

Source Sans Pro is released under the SIL Open Font License, 1.1 [external link]. Copyright 2010-2018 Adobe (http://www.adobe.com/), with Reserved Font Name 'Source'. All Rights Reserved. Source is a trademark of Adobe in the United States and/or other countries.

FontAwesome is used in the free variant under Creative Commons BY 4.0 [external link] (icons), SIL Open Font License, 1.1 (icon-fonts) and MIT License (Code) genutzt. Details are listet at https://fontawesome.com/license/free [external link].
The copyright - Copyright (c) Font Awesome - was placed without explicit license reference.
The MIT license template was not populated by FontAwesome:

Permission is hereby granted, free of charge, to any person obtaining
a copy of this software and associated documentation files (the
"Software"), to deal in the Software without restriction, including
without limitation the rights to use, copy, modify, merge, publish,
distribute, sublicense, and/or sell copies of the Software, and to
permit persons to whom the Software is furnished to do so, subject to
the following conditions:

The above copyright notice and this permission notice shall be
included in all copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF
MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND
NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE
LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION
OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION
WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.

Javascript

The {metæffekt} pages use JQuery 3.4.1. JQuery is released under MIT License:

Copyright JS Foundation and other contributors, https://js.foundation/

Permission is hereby granted, free of charge, to any person obtaining
a copy of this software and associated documentation files (the
"Software"), to deal in the Software without restriction, including
without limitation the rights to use, copy, modify, merge, publish,
distribute, sublicense, and/or sell copies of the Software, and to
permit persons to whom the Software is furnished to do so, subject to
the following conditions:

The above copyright notice and this permission notice shall be
included in all copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF
MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND
NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE
LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION
OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION
WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.

Besides JQuery, other Javascript libraries are used. The files breakpoints.js and browser.js come from the Repository Responsive Tools (https://github.com/ajlkn/responsive-tools) and are also under MIT Lizenz:

Responsive Tools is released under the MIT license.

Copyright (c) @ajlkn

Permission is hereby granted, free of charge, to any person obtaining
a copy of this software and associated documentation files (the
"Software"), to deal in the Software without restriction, including
without limitation the rights to use, copy, modify, merge, publish,
distribute, sublicense, and/or sell copies of the Software, and to
permit persons to whom the Software is furnished to do so, subject to
the following conditions:

The above copyright notice and this permission notice shall be
included in all copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF
MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND
NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE
LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION
OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION
WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.

Other Javascript files (main.js und util.js) are part ot the HTML5 UP template.

The Javascript file metaeffekt.js was created by the {metæffekt} and may only be used within the {metæffekt} pages.

HTML5 UP Template Future Imperfect

The pages were created based on the HTML5 UP template Future Imperfect.

The template files are licensed under Creative Commons Attribution 3.0 Unported [external link] and were developed by AJ aj@lkn.io | @ajlkn. The template was obtained from HTML5 UP [external link]. The template files were adapted and supplemented.

Privacy

Privacy Policy and obligations

Privacy Policy

The Privacy Policy of {metæffekt} GmbH explains the data processing operations of personal data in accordance with the European Data Protection Regulation (DSGVO: Datenschutzgrundverordnung). The data processing of the pages at http://www.metaeffekt.de, http://www.metaeffekt.com and https://metaeffekt.com respectively is fully covered therein.

Cookies

Cookies are not used on the pages of {metæffekt} GmbH.

Access statistics

The statistics collected by the hoster of the websites do not contain any personal data. Tools for analyzing visitor behavior are not used.

Karsten Klein - Oktober, 2025

{metæffekt} Vulnerability Assessment Dashboard

Over the past four years, {metæffekt}'s Vulnerability Assessment Dashboard has continuously evolved. We currently refer to its fourth generation. It compiles the software components of selected assets along with their vulnerabilities and supports a contextualization within a given product. It enables an assessment of vulnerabilities on batch and individual level. For this purpose, various data sources related to the vulnerabilities are aggregated and presented in specialized views. Recently, reference information from threat analysis, CAPEC and CWE details, was incorporated.

Karsten Klein - January, 2024

{metæffekt} Universal CVSS Calculator

The {metæffekt} Universal CVSS Calculator [external link] is the first calculator capable of calculating the severities of multiple CVSS-vectors of different versions (including the latest CVSS:4.0 version) at the same time making comparing them as easy as glancing at a single chart. Implemented in TypeScript, published under a permissive open source license, and directly integrated into our Vulnerability Assessment Dashboard, we are continuing to move towards a complete and publicly available tooling set.

Service

Karsten Klein - October, 2019

Photo 'Time' by Alex Lehner, CC BY 2.0 [external Link]. The photo was cropped.

OnDemand Research for Software Components

OnDemand Research for Software Components supports companies in capturing and providing relevant metadata on software components on demand and in a timely manner. This information can be used to support software compliance processes or added to software asset catalogs of IT Asset Management Systems for operational purposes.

  • E-Mail

© {metæffekt} GmbH 2021. Original Design: HTML5 UP.