|
Not able to install all required libraries of tools-python
Hello spdx-team, I am interested in contributing to the tools-python project in the spdx organization but during setting up my development environment I am unable to install all the required libraries
Hello spdx-team, I am interested in contributing to the tools-python project in the spdx organization but during setting up my development environment I am unable to install all the required libraries
|
By
HarshVardhan Mahawar
·
|
|
Event: SPDX tech team meeting - Tuesday, March 21, 2023
#cal-reminder
Reminder: SPDX tech team meeting When: Tuesday, March 21, 2023 11:00am to 12:30pm (UTC-05:00) America/Chicago Where: https://zoom.us/j/663426859 Organizer: Kate Stewart kstewart@... View Event Descrip
Reminder: SPDX tech team meeting When: Tuesday, March 21, 2023 11:00am to 12:30pm (UTC-05:00) America/Chicago Where: https://zoom.us/j/663426859 Organizer: Kate Stewart kstewart@... View Event Descrip
|
By
Group Notification
·
|
|
Serialization: Ontologies vs Datatypes
3 messages
At the SPDX Serialisation Meeting 2023-03-16: Sean presented a deck of slides that he and Alexios had created to explain concepts relating to JSON-LD and RDF with regard to SPDX. The presentation cove
At the SPDX Serialisation Meeting 2023-03-16: Sean presented a deck of slides that he and Alexios had created to explain concepts relating to JSON-LD and RDF with regard to SPDX. The presentation cove
|
By
David Kemp
·
|
|
#spdx Gsoc contribution guidance and suggestion
#spdx
I want to contribute in https://github.com/opensbom-generator/parsers project. I would love to have some suggestions and things I need to mention in my proposal. This project seems very interesting to
I want to contribute in https://github.com/opensbom-generator/parsers project. I would love to have some suggestions and things I need to mention in my proposal. This project seems very interesting to
|
By
Utkarsh Saxena
·
|
|
Handling invalid licenses
4 messages
Team In generating SBOMs, I am encountering a lot of issues with licence information obtained from either ecosystem meta data or actual source files most do not appear to be using SPDX license identif
Team In generating SBOMs, I am encountering a lot of issues with licence information obtained from either ecosystem meta data or actual source files most do not appear to be using SPDX license identif
|
By
Anthony Harrison
·
|
|
SPDX v2.3 JSON schema diagram
4 messages
Dear SPDX tech communities, Thank you for providing a lot of useful documents about SPDX! We, OpenChain Japan SBOM-sg members, illustrated the v2.3 JSON schema a little easier to see. https://qiita.co
Dear SPDX tech communities, Thank you for providing a lot of useful documents about SPDX! We, OpenChain Japan SBOM-sg members, illustrated the v2.3 JSON schema a little easier to see. https://qiita.co
|
By
Norio Kobota
·
|
|
Released - Re: New Python tools pre-release
Hi all, we just released v0.7.1 of the tools-python! Best, Meret
Hi all, we just released v0.7.1 of the tools-python! Best, Meret
|
By
meret.behrens@...
·
|
|
Event: SPDX tech team meeting - Tuesday, March 14, 2023
#cal-reminder
Reminder: SPDX tech team meeting When: Tuesday, March 14, 2023 11:00am to 12:30pm (UTC-05:00) America/Chicago Where: https://zoom.us/j/663426859 Organizer: Kate Stewart kstewart@... View Event Descrip
Reminder: SPDX tech team meeting When: Tuesday, March 14, 2023 11:00am to 12:30pm (UTC-05:00) America/Chicago Where: https://zoom.us/j/663426859 Organizer: Kate Stewart kstewart@... View Event Descrip
|
By
Group Notification
·
|
|
FW: CISA SBOM update
FYI: Update an update today from Allan Friedman re: CISA SBOM activities – see email below. NOTE from Allan: As a reminder, CISA facilitates these open discussions, but the participants shape the agen
FYI: Update an update today from Allan Friedman re: CISA SBOM activities – see email below. NOTE from Allan: As a reminder, CISA facilitates these open discussions, but the participants shape the agen
|
By
Dick Brooks
·
|
|
Serialization subteam: Toy Example
Serialization subteam members: Alexios contributed a toy example JSON file for Issue #89, which illustrates both the correspondence and the difference between any Set class defined in a logical model
Serialization subteam members: Alexios contributed a toy example JSON file for Issue #89, which illustrates both the correspondence and the difference between any Set class defined in a logical model
|
By
David Kemp
·
|
|
OpenVEX lively discussion underway on GitHub OpenSSF
https://github.com/ossf/wg-vulnerability-disclosures/issues/125 This video leaves me questioning where Microsoft stands on OpenVEX. Art Manion’s, description of the CISA process is worth listening to:
https://github.com/ossf/wg-vulnerability-disclosures/issues/125 This video leaves me questioning where Microsoft stands on OpenVEX. Art Manion’s, description of the CISA process is worth listening to:
|
By
Dick Brooks
·
|
|
FYI: Cross pollination with the CISA ICT_SCRM Task Force SW Assurance work stream
11 messages
Just an FYI: Both Willian and I work on the CISA ICT_SCRM Task Force SW Assurance Work Stream, which is developing guidance for Federal Procurement Offers with regard to OMB M-22-18 and EO 14028. Toda
Just an FYI: Both Willian and I work on the CISA ICT_SCRM Task Force SW Assurance Work Stream, which is developing guidance for Federal Procurement Offers with regard to OMB M-22-18 and EO 14028. Toda
|
By
Dick Brooks
·
|
|
Collaborating with SPDX in GSoC 2023!
Hi guys, I am Banula Kumarage. I am interested in contributing to the "SPDX License Submission Online Tool - increase functionality" through GSOC 2023. I have given a brief intro about myself in the g
Hi guys, I am Banula Kumarage. I am interested in contributing to the "SPDX License Submission Online Tool - increase functionality" through GSOC 2023. I have given a brief intro about myself in the g
|
By
Banula Kumarage
·
|
|
SPDX in GSoC 2023!
6 messages
Hi everyone! As every year, Google runs their Summer of Code program, where contributors get the opportunity to become part of Open Source communities. The SPDX Project has participated in the program
Hi everyone! As every year, Google runs their Summer of Code program, where contributors get the opportunity to become part of Open Source communities. The SPDX Project has participated in the program
|
By
Alexios Zavras
·
|
|
scancode-toolkit updated to SPDX 3.20 license list
3 messages
Hi everyone, We have updated the SPDX license list version in scancode-toolkit to the newly released version 3.20, and this is also updated and available at scancode-licensedb.aboutcode.org. This will
Hi everyone, We have updated the SPDX license list version in scancode-toolkit to the newly released version 3.20, and this is also updated and available at scancode-licensedb.aboutcode.org. This will
|
By
Ayan Mahapatra
·
|
|
FYI US Federal CIO comment on SBOM
Chris DeRusha, US Federal CIO at OMB mentions SBOM as part of the forthcoming CISA self-attestation form required under OMB M-22-18: “The Secure Software Development Framework is a fantastic framework
Chris DeRusha, US Federal CIO at OMB mentions SBOM as part of the forthcoming CISA self-attestation form required under OMB M-22-18: “The Secure Software Development Framework is a fantastic framework
|
By
Dick Brooks
·
|
|
Event: SPDX tech team meeting - Tuesday, March 7, 2023
#cal-reminder
Reminder: SPDX tech team meeting When: Tuesday, March 7, 2023 11:00am to 12:30pm (UTC-06:00) America/Chicago Where: https://zoom.us/j/663426859 Organizer: Kate Stewart kstewart@... View Event Descript
Reminder: SPDX tech team meeting When: Tuesday, March 7, 2023 11:00am to 12:30pm (UTC-06:00) America/Chicago Where: https://zoom.us/j/663426859 Organizer: Kate Stewart kstewart@... View Event Descript
|
By
Group Notification
·
|
|
Build Profile Meeting Cadence Update
Hi All, Since we recently prepared the build profiles PR https://github.com/spdx/spdx-3-model/pull/91, the main bulk of discussions will be happening in the spdx-tech group. We will put the monday mee
Hi All, Since we recently prepared the build profiles PR https://github.com/spdx/spdx-3-model/pull/91, the main bulk of discussions will be happening in the spdx-tech group. We will put the monday mee
|
By
Brandon Lum
·
|
|
RelationshipType packages
Hi all, how does one express "a release package was packaged by packaging-tool"? I learned that a build tool is a package. Hence, I assume that a "package tool" would probably also be a package. That
Hi all, how does one express "a release package was packaged by packaging-tool"? I learned that a build tool is a package. Hence, I assume that a "package tool" would probably also be a package. That
|
By
Henk Birkholz
·
|
|
Agent or Identity
I have created Issue #94 https://github.com/spdx/spdx-3-model/issues/94 to describe my rationale for using the name Identity as the type of the createdBy property. The name should be chosen to best al
I have created Issue #94 https://github.com/spdx/spdx-3-model/issues/94 to describe my rationale for using the name Identity as the type of the createdBy property. The name should be chosen to best al
|
By
David Kemp
·
|