Elixir now complies with the OpenChain (ISO/IEC 5230) standard, enhancing its open source license compliance and aligning with best practices for supply chain and cybersecurity. Future Elixir releases will include signed Source SBoMs in CycloneDX and SPDX formats, providing greater transparency. Contributions remain under the Apache-2.0 License, with the enforcement of the Developer Certificate of Origin (DCO) to ensure clarity around contribution ownership.
Table of contents
Why OpenChain Compliance HelpsChanges for Elixir UsersChanges for ContributorsCommitmentSort: