|
SPDX License Diff browser extension not producing report 2 messages
Dear all, Recently the SPDX License Diff browser extension has ceased to work for me. Selecting a piece of text and running the plugin displays the 'Processing...' progress bar, but no report is produ
Dear all, Recently the SPDX License Diff browser extension has ceased to work for me. Selecting a piece of text and running the plugin displays the 'Processing...' progress bar, but no report is produ
|
By
Sebastian Crane
·
|
|
God
#cal-notice
God,.....
By
hoseintorshani48@...
·
|
|
Event: SPDX tech team meeting - Tuesday, December 27, 2022 2 messages
#cal-reminder
Reminder: SPDX tech team meeting When: Tuesday, December 27, 2022 11:00am to 12:30pm (UTC-06:00) America/Chicago Where: https://zoom.us/j/663426859 Organizer: Kate Stewart kstewart@... View Event Desc
Reminder: SPDX tech team meeting When: Tuesday, December 27, 2022 11:00am to 12:30pm (UTC-06:00) America/Chicago Where: https://zoom.us/j/663426859 Organizer: Kate Stewart kstewart@... View Event Desc
|
By
Group Notification
·
|
|
I highly recommend reading Steve Springett's thoughtful analysis of VEX and VDR
Steve is the Architect of CycloneDX SBOM and the very useful Dependency Track Tool. REA uses Dependency Track to monitor for new vulnerabilities in SAG-PM, which is then used to update the “living” SA
Steve is the Architect of CycloneDX SBOM and the very useful Dependency Track Tool. REA uses Dependency Track to monitor for new vulnerabilities in SAG-PM, which is then used to update the “living” SA
|
By
Dick Brooks
·
|
|
Daggerboard SPDX SBOM
Kate, REA has successfully tested the Daggerboard SPDX SBOM and has created a baseline NIST Vulnerability Disclosure Report based on the SBOM provided. Any chance we could get the Daggerboard authors
Kate, REA has successfully tested the Daggerboard SPDX SBOM and has created a baseline NIST Vulnerability Disclosure Report based on the SBOM provided. Any chance we could get the Daggerboard authors
|
By
Dick Brooks
·
|
|
Next Python tools sync meeting on January 12th
Greetings everyone, we would like to inform you that the next regular sync for the development of the SPDX Python tools will be held on January 12th at the usual time of 4:30pm GMT (here is the link a
Greetings everyone, we would like to inform you that the next regular sync for the development of the SPDX Python tools will be held on January 12th at the usual time of 4:30pm GMT (here is the link a
|
By
armin.taenzer@...
·
|
|
Event: SPDX tech team meeting - Tuesday, December 20, 2022
#cal-reminder
Reminder: SPDX tech team meeting When: Tuesday, December 20, 2022 11:00am to 12:30pm (UTC-06:00) America/Chicago Where: https://zoom.us/j/663426859 Organizer: Kate Stewart kstewart@... View Event Desc
Reminder: SPDX tech team meeting When: Tuesday, December 20, 2022 11:00am to 12:30pm (UTC-06:00) America/Chicago Where: https://zoom.us/j/663426859 Organizer: Kate Stewart kstewart@... View Event Desc
|
By
Group Notification
·
|
|
Current status of Usage Profile discussion after SPDX mini-summit at Yokohama
Hello SPDX tech community members, As in the presentation at the SPDX mini-summit at Yokohama Japan with Kate-san , Brandon-san and Gopi-san, I’ve discussing about proposals about Usage Profile in the
Hello SPDX tech community members, As in the presentation at the SPDX mini-summit at Yokohama Japan with Kate-san , Brandon-san and Gopi-san, I’ve discussing about proposals about Usage Profile in the
|
By
yoshiyuki.ito.ub@renesas.com
·
|
|
SPDX Tech Call Agenda and schedule
Greetings SPDX tech community, With the holidays approaching at the end of this month, we will be cancelling the SPDX tech call for the last Tuesday of this month (December 27th). We will have our reg
Greetings SPDX tech community, With the holidays approaching at the end of this month, we will be cancelling the SPDX tech call for the last Tuesday of this month (December 27th). We will have our reg
|
By
Gary O'Neall
·
|
|
Modeling actors
Some thoughts from today's model discussion: 1) Boxes in the model have names and definitions. Definitions must be captured correctly, names are just labels, not things that we reason about to drive d
Some thoughts from today's model discussion: 1) Boxes in the model have names and definitions. Definitions must be captured correctly, names are just labels, not things that we reason about to drive d
|
By
David Kemp
·
|
|
Event: SPDX tech team meeting - Tuesday, December 13, 2022
#cal-reminder
Reminder: SPDX tech team meeting When: Tuesday, December 13, 2022 11:00am to 12:30pm (UTC-06:00) America/Chicago Where: https://zoom.us/j/663426859 Organizer: Kate Stewart kstewart@... View Event Desc
Reminder: SPDX tech team meeting When: Tuesday, December 13, 2022 11:00am to 12:30pm (UTC-06:00) America/Chicago Where: https://zoom.us/j/663426859 Organizer: Kate Stewart kstewart@... View Event Desc
|
By
Group Notification
·
|
|
Canceled: SPDX Canonicalisation Committee Meeting
By
Martin, Robert A
·
|
|
Please help people understand what a VEX really is, according to the VEX Author, Thomas Schmidt
I attended a meeting in Washington this past week and it’s very clear that people are confused over VEX. Today, I read an article that confirms this confusion over VEX so I wrote a small piece that cl
I attended a meeting in Washington this past week and it’s very clear that people are confused over VEX. Today, I read an article that confirms this confusion over VEX so I wrote a small piece that cl
|
By
Dick Brooks
·
|
|
Change proposal, 2023 meeting schedule, etc.
Hi SPDX legal and tech teams, I’m cross-posting this for wider visibility as some of this impacts both teams: In regard to legal team meetings for the rest of 2022: we will have our regularly schedule
Hi SPDX legal and tech teams, I’m cross-posting this for wider visibility as some of this impacts both teams: In regard to legal team meetings for the rest of 2022: we will have our regularly schedule
|
By
J Lovejoy
·
|
|
Tech core team minutes
Greetings tech team, I just got caught up on adding our core team minutes to the meetings repo. Those of you on the call, please review and add comments /suggestions for anything we missed – especiall
Greetings tech team, I just got caught up on adding our core team minutes to the meetings repo. Those of you on the call, please review and add comments /suggestions for anything we missed – especiall
|
By
Gary O'Neall
·
|
|
[SCITT] Another party claiming that SBOM is bad 8 messages
Eliot, I agree, the BSA letter wasn’t as critical of SBOM as the ITI letter. I’m thinking all of this may be moot now that the State Department Evolve RFP removed all doubt about expectations regardin
Eliot, I agree, the BSA letter wasn’t as critical of SBOM as the ITI letter. I’m thinking all of this may be moot now that the State Department Evolve RFP removed all doubt about expectations regardin
|
By
Dick Brooks
·
|
|
External document namespace before SPDX id? 2 messages
Hello everyone, I've got a question regarding the SPDX id of packages, files or snippets. According to spec the format must be "SPDXRef-[idstring]" for tag-value, but rdf in addition has a namespace b
Hello everyone, I've got a question regarding the SPDX id of packages, files or snippets. According to spec the format must be "SPDXRef-[idstring]" for tag-value, but rdf in addition has a namespace b
|
By
armin.taenzer@...
·
|
|
Multiple Licenses in a single LicenseRef? 3 messages
Hi there, This is a question regarding LicenseRefs, specifically for the PackageLicenseDeclared field. Tern is a tool that can generate SPDX documents for containers. When we are collecting license in
Hi there, This is a question regarding LicenseRefs, specifically for the PackageLicenseDeclared field. Tern is a tool that can generate SPDX documents for containers. When we are collecting license in
|
By
Rose Judge
·
|
|
Outstanding job on the SBOM video 3 messages
Gentlemen, I just wanted to commend you for your honest and accurate analysis of the state of SBOM today in this video: https://www.youtube.com/watch?v=Yu9-_0Dmvjk I was not aware that Google is also
Gentlemen, I just wanted to commend you for your honest and accurate analysis of the state of SBOM today in this video: https://www.youtube.com/watch?v=Yu9-_0Dmvjk I was not aware that Google is also
|
By
Dick Brooks
·
|
|
[SCITT] Another party claiming that SBOM is bad
I think there is some confusion about that letter. Nowhere does it say that "SBOM is bad". The concern is that Congress would specify one way of doing things, the military another, and DISA yet a thir
I think there is some confusion about that letter. Nowhere does it say that "SBOM is bad". The concern is that Congress would specify one way of doing things, the military another, and DISA yet a thir
|
By
Eliot Lear
·
|