Open-Source License Audit and 60-Day Remediation Plan for Lumen Observability
Overview
What this challenge is about.
Audit 80 high-risk open-source dependencies, classify them by SPDX license, and plan remediation. Earn a verifiable certificate.
The scenario
Lumen Observability raised a Series-B round and runs a monitoring software-as-a-service product, exposing 3 customer-facing developer kits backed by 14 internal services. Like most fast-growing infrastructure companies, it adopted open-source packages faster than it tracked their licenses, and an acquisition has now made that backlog urgent.
The Brief
What you'll do, and what you'll demonstrate.
Audit roughly 1,400 open-source packages for license risk and produce an acquirer-ready remediation plan that can be executed in 60 days without derailing the product roadmap.
Earning criteria — what you'll demonstrate
- Classify open-source licenses by obligation type (permissive, weak copyleft, strong copyleft, custom/unknown) and reason about how distribution context changes the risk
- Translate a raw dependency inventory into a prioritized, evidence-backed risk audit
- Design a license policy that is operable at code-review time rather than aspirational
- Sequence remediation work realistically against finite engineering capacity and a shipping roadmap
- Communicate legal-technical risk to a non-engineering acquirer audience without overclaiming
Program Fit
Where this fits in your program.
Sharpens the same skills your degree expects you to demonstrate.
Aligned coursework coming soon.
Skills
Skills you'll demonstrate.
Each one shows up on your verified credential.
- Oss Licensing
Apply oss licensing to solve real industry problems and demonstrate production-level capability.
- Sbom
Apply sbom to solve real industry problems and demonstrate production-level capability.
- Supply Chain
Apply supply chain to solve real industry problems and demonstrate production-level capability.
- Policy Design
Apply policy design to solve real industry problems and demonstrate production-level capability.
- Audit
Apply audit to solve real industry problems and demonstrate production-level capability.
- Compliance
Apply compliance to solve real industry problems and demonstrate production-level capability.
Careers
Career paths this challenge builds toward
Completing this challenge demonstrates skills that transfer directly to these roles:
Open-Source Program Office Engineer
Engineers who run an open-source program office own exactly this work: keeping a dependency inventory clean, classifying license obligations, and writing policy developers actually follow. This challenge rehearses that loop end to end on a realistic Series-B scale.
This challenge sharpens
- oss-licensing
- sbom
- policy-design
Software Supply Chain Security Engineer
Supply-chain roles turn raw bills of materials into governed, auditable inventories. By auditing 1,400 packages and building an operable control, you practice the inventory-to-policy pipeline these teams maintain across every release.
This challenge sharpens
- sbom
- supply-chain
- audit
Technical Compliance Lead
Compliance leads must make legal risk legible to executives and acquirers. Producing the audit, policy, and diligence memo here mirrors how they translate technical findings into decisions a deal can rest on.
This challenge sharpens
- compliance
- audit
- policy-design