Date   

Is an UNCOPYRIGHTABLE License (or keyword) needed? #poll

michael.kaelbling@...
 

The U.S. Copyright Office considers some works uncopyrightable "because they contain an insufficient amount of authorship", e.g. "words and short phrases ... titles ... names", "mere listing of ... contents, or a simple set of directions...", and  blank forms  (https://www.copyright.gov/circs/circ33.pdf). 

SPDX-License-Identifier: NONE and SPDX-CopyrightText: NONE state that there is no license or copyright statement, but do not say that none is needed or possible.

SPDX-License-Identifer: NOASSERTION and SPDX-CopyrightText: NOASSERTION is similarly inappropriate.

A REUSE.software scan will produce false-positives if it has no way to distinguish the case of uncopyrightable material.  This issue came up because my group has empty files (placeholders) and blank forms (templates) in OSS.  Since we require a clean scan on each build, we have to maintain a workaround to eliminate the false positives.
-----
My apologies if you find this poll inappropriate: I thought I had submitted this concern weeks ago as a message, but I am now unable to find it -- nor have I got any response. Therefore I am taking this route to get my question addressed.

Results


Re: Thursday's SPDX General Meeting Reminder

Kate Stewart
 

Hi Phil, all
     Quick update,   we will have a guest speaker this week.

Matthew Crawford will be discussing "Arm’s SPDX compliance file"

Thanks, Kate

On Wed, Mar 4, 2020 at 3:20 PM Phil Odence <phil.odence@...> wrote:

No guest speakers this month.

And, I will be out so Kate will chair in my stead.

 

 

 GENERAL MEETING

 

Meeting Time: Thurs, March 5, 8am PT / 10 am CT / 11am ET / 15:00 UTC.  http://www.timeanddate.com/worldclock/converter.html


Conf call dial-in:

New dial in number: 415-881-1586

No PIN needed

The weblink for screenshare will stay the same at: 
http://uberconference.com/SPDXTeam

 

Administrative Agenda

Attendance

Minutes Approval:   

 

Technical Team Report – Kate/Gary

 

Legal Team Report – Jilayne/Paul/Steve

 

Outreach Team Report – Jack

 

Any Cross Functional Issues –All

 

 


Thursday's SPDX General Meeting Reminder

Phil Odence
 

No guest speakers this month.

And, I will be out so Kate will chair in my stead.

 

 

 GENERAL MEETING

 

Meeting Time: Thurs, March 5, 8am PT / 10 am CT / 11am ET / 15:00 UTC.  http://www.timeanddate.com/worldclock/converter.html


Conf call dial-in:

New dial in number: 415-881-1586

No PIN needed

The weblink for screenshare will stay the same at: 
http://uberconference.com/SPDXTeam

 

Administrative Agenda

Attendance

Minutes Approval:   

 

Technical Team Report – Kate/Gary

 

Legal Team Report – Jilayne/Paul/Steve

 

Outreach Team Report – Jack

 

Any Cross Functional Issues –All

 

 


Today's SPDX General Meeting Reminder

Phil Odence
 

 GENERAL MEETING

 

Meeting Time: Thurs, Feb 6, 8am PT / 10 am CT / 11am ET / 15:00 UTC.  http://www.timeanddate.com/worldclock/converter.html


Conf call dial-in:

New dial in number: 415-881-1586

No PIN needed

The weblink for screenshare will stay the same at: 
http://uberconference.com/SPDXTeam

 

Administrative Agenda

Attendance

Minutes Approval:   

 

Technical Team Report – Kate/Gary

 

Legal Team Report – Jilayne/Paul

 

Outreach Team Report – Jack

 

Any Cross Functional Issues –All

 

 


Re: Migration to SPDX

Max Mehl
 

~ Gary O'Neall [2020-01-27 19:38 +0100]:
For the SPDX documents, I would recommend making that part of the standard
release process. When new releases are published, you can publish a new
SPDX document for that release. This will probably require a bit of
tooling, some of which is available in open source at github.com/spdx.
As a side note, if you adopt the REUSE guidelines - so marking each file
with copyright and licensing information using SPDX tags - creating an
SPDX document will be just a matter of one command with the helper tool:
`reuse spdx`

For more information: https://reuse.software

Best,
Max

--
Max Mehl - Programme Manager - Free Software Foundation Europe
Contact and information: https://fsfe.org/about/mehl | @mxmehl
Become a supporter of software freedom: https://fsfe.org/join


Re: Migration to SPDX

Gary O'Neall
 

Hi Ashok,

 

You can keep the existing license file in the distribution but we recommend adding SPDX identifiers to the source files – see https://spdx.org/ids for more information.

 

For the SPDX documents, I would recommend making that part of the standard release process.  When new releases are published, you can publish a new SPDX document for that release.  This will probably require a bit of tooling, some of which is available in open source at github.com/spdx. 

 

Let us know if you have any other questions or would like more details.

 

Regards,

Gary

 

From: spdx@... <spdx@...> On Behalf Of Ashok Madugula
Sent: Sunday, January 26, 2020 11:18 PM
To: spdx@...
Subject: [spdx] Migration to SPDX

 

Hi  :

We are planning to migrate to SPDX Licenses.

If we are using general MIT  License . Can we replace the existing license file with SPDX Identifier  ?

Do we need to generate new  SPDX Document and publish them regularly   ?

 

Regards

Ashok Madugula

This email and any attachments are intended for the sole use of the named recipient(s) and contain(s) confidential information that may be proprietary, privileged or copyrighted under applicable law. If you are not the intended recipient, do not read, copy, or forward this email message or any attachments. Delete this email message and any attachments immediately.


Migration to SPDX

Ashok Madugula
 

Hi  :

We are planning to migrate to SPDX Licenses.

If we are using general MIT  License . Can we replace the existing license file with SPDX Identifier  ?

Do we need to generate new  SPDX Document and publish them regularly   ?

 

Regards

Ashok Madugula

This email and any attachments are intended for the sole use of the named recipient(s) and contain(s) confidential information that may be proprietary, privileged or copyrighted under applicable law. If you are not the intended recipient, do not read, copy, or forward this email message or any attachments. Delete this email message and any attachments immediately.


Re: Question on creating new SPDX Identifier

Gary O'Neall
 

Hi Ashok,

 

Based on the license matching guidelines, the text matches MIT.  You can test the license text using the SPDX online tools at http://13.57.134.254/app/check_license/

 

Gary

 

From: spdx@... <spdx@...> On Behalf Of Ashok Madugula
Sent: Wednesday, January 15, 2020 12:54 AM
To: spdx@...
Subject: [spdx] Question on creating new SPDX Identifier

 

HI  :

We are using the following license which is almost same as X11  . Do we need to raise a request for new SPDX Identifier  ?

If so , can you let us know the process ?

 

***************************************************

LICENSE START

Copyright (C) YYYY – YYYY Xilinx, Inc.  All rights reserved.

Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions:

The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.

LICENSE END 

*****************************************************

 

This is almost same as X11 .

 

************************************************

 

X11 License

Copyright (C) 1996 X Consortium

Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions:

The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE X CONSORTIUM BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.

Except as contained in this notice, the name of the X Consortium shall not be used in advertising or otherwise to promote the sale, use or other dealings in this Software without prior written authorization from the X Consortium.

X Window System is a trademark of X Consortium, Inc.

 

 

Regards

Ashok Madugula

This email and any attachments are intended for the sole use of the named recipient(s) and contain(s) confidential information that may be proprietary, privileged or copyrighted under applicable law. If you are not the intended recipient, do not read, copy, or forward this email message or any attachments. Delete this email message and any attachments immediately.


Question on creating new SPDX Identifier

Ashok Madugula
 

HI  :

We are using the following license which is almost same as X11  . Do we need to raise a request for new SPDX Identifier  ?

If so , can you let us know the process ?

 

***************************************************

LICENSE START

Copyright (C) YYYY – YYYY Xilinx, Inc.  All rights reserved.

Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions:

The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.

LICENSE END 

*****************************************************

 

This is almost same as X11 .

 

************************************************

 

X11 License

Copyright (C) 1996 X Consortium

Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions:

The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE X CONSORTIUM BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.

Except as contained in this notice, the name of the X Consortium shall not be used in advertising or otherwise to promote the sale, use or other dealings in this Software without prior written authorization from the X Consortium.

X Window System is a trademark of X Consortium, Inc.

 

 

Regards

Ashok Madugula

This email and any attachments are intended for the sole use of the named recipient(s) and contain(s) confidential information that may be proprietary, privileged or copyrighted under applicable law. If you are not the intended recipient, do not read, copy, or forward this email message or any attachments. Delete this email message and any attachments immediately.


[ANNOUNCE] Open source license compliance tooling meeting and hackathon on January 31st 2020 pre-FOSDEM fringe event in Bruxelles, Belgium

Philippe Ombredanne
 

If you care about open source compliance automation and if you are
going to FOSDEM there is a one day hackathon and meeting taking place
the day before FOSDEM on Friday January 31st as "fringe" event, in
Bruxelles, Belgium.

The topic is open source compliance tooling and automation... the
format is an unconference. I expect several open source projects in
that space to be represented there including ORT, Fossology,
ClearlyDefined, SPDX tools, Scancode and many more.

I am co-organizing this with Michael Jaeger from Fossology.

See https://docs.google.com/document/d/1UphruKKAlsoUEidPCwTF2LCcHFnQkvQCQ9luTXfDupw/edit#heading=h.p2d7mni4lrcu
for details.

To "register", just add you name to this document! (alternatively you
can reply to me off list too)

I look forward to seeing you there!
--
Cordially
Philippe Ombredanne

+1 650 799 0949 | pombredanne@...
DejaCode - What's in your code?! - http://www.dejacode.com
AboutCode - Open source for open source - https://www.aboutcode.org
nexB Inc. - http://www.nexb.com


SPDX General Meeting

Phil Odence
 

Here’s a new invite for 2020. Please accept the recurring meeting

Note there will be no SPDX General Meeting in January.

****

New dial in number: 415-881-1586  

No PIN needed

The weblink for screenshare:
https://www.uberconference.com/room/spdxteam


MEETING MINUTES FOR REVIEW: http://spdx.org/wiki/meeting-minutes-and-decisions



Thursday SPDX General Meeting Reminder

Phil Odence
 

In addition to the General Meeting reminder: As you may know, a couple of months ago (with great help from Shane Coughlin) we launched a short survey to help steer the future of SPDX. The doors will close on the survey Dec 31. We would like to get as many responses as possible from anyone who has even the lightest level of involvement or interest. So, please, fill this out yourself and forwarded it on to any of your contacts the might be willing to provide some input. I promise we will take the feedback seriously. 

 THANK YOU!

 https://forms.gle/FK2zR5TV5E44W7Cc7

 

 

GENERAL MEETING

 

Meeting Time: Thurs, Dec 5, 8am PT / 10 am CT / 11am ET / 15:00 UTC.  http://www.timeanddate.com/worldclock/converter.html


Conf call dial-in:

New dial in number: 415-881-1586

No PIN needed

The weblink for screenshare will stay the same at: 
http://uberconference.com/SPDXTeam

 

Administrative Agenda

Attendance

Minutes Approval:   

 

Technical Team Report – Kate/Gary

 

Legal Team Report – Jilayne/Paul

 

Outreach Team Report – Jack

 

Any Cross Functional Issues –All

 

 


Thursday SPDX General Meeting Reminder

Phil Odence
 

I will not be available for this month’s meeting, but the show must go on.

Phil

 

GENERAL MEETING

 

Meeting Time: Thurs, Nov, 8am PT / 10 am CT / 11am ET / 15:00 UTC.  http://www.timeanddate.com/worldclock/converter.html


Conf call dial-in:

New dial in number: 415-881-1586

No PIN needed

The weblink for screenshare will stay the same at: 
http://uberconference.com/SPDXTeam

 

Administrative Agenda

Attendance

Minutes Approval:   https://wiki.spdx.org/view/General_Meeting/Minutes/2019-10-03

 

Technical Team Report – Kate/Gary

 

Legal Team Report – Jilayne/Paul

 

Outreach Team Report – Jack not available

 

Any Cross Functional Issues –All

 

 


Seeking public comments for the OpenChain specification ISO format version 2.1

Mark Gisi
 

We are seeking public comments for the next version of OpenChain specification which will conclude on December 10th.

 

For those new to the specification  - The OpenChain project has developed  a specification that defines a core set of requirements that a trusted open source compliance program is expected to satisfy.   To obtain a better understanding of the goals and the context in which the specification was developed before providing feedback, you can review the following FAQ list.

 

The big change over the current 2.0 version was reformatting the document layout into one acceptable for ISO submission and adoption.  Other than very minor clarification edits, the content has largely remained unchanged. If a company is conformant with version 2.0 - they would remain conformant with 2.1.

 

The current draft is available at:

   https://wiki.linuxfoundation.org/_media/openchain/openchainspec-2.1.draft.pdf

 

Past readers of the spec might find the marked up version useful:

   https://wiki.linuxfoundation.org/_media/openchain/OpenChainSpec-2.1.draft.MarkUp.pdf    

 

You can send feedback via:

·        the Mailing list: the list;

·        the issues wiki: issues list; or

·        replying to me directly if you wish to remain anonymous (mark.gisi@...)

 

best,

Mark

 

Mark Gisi | Wind River | Director, IP & Open Source

Tel (510) 749-2016 | Fax (510) 749-4552

 


SPDX General Meeting 2019 - Moving Nov Meeting

Phil Odence
 

The Nov General Meeting is moving out a week due to conflicts for most of the Core team.

I also have a conflict on the 14th, so someone else will chair in my stead.

Phil  


*****


I’m extending this recurring meeting to run through 2019. Please accept so it is updated on your calendar, however no need to send a response to me.



New dial in number: 415-881-1586

No PIN needed

The weblink for screenshare will stay the same at:
https://www.uberconference.com/room/spdxteam



MEETING MINUTES FOR REVIEW: http://spdx.org/wiki/meeting-minutes-and-decisions



Re: Thursday SPDX General Meeting Reminder

J Lovejoy
 

Hi Vladimir,

We don't record the general meetings, but there are minutes, which are logged here:

https://wiki.spdx.org/view/General_Meeting/Minutes

Thanks,
Jilayne
SPDX legal team co-lead

On 10/1/19 8:42 AM, Vladimir Sitnikov wrote:

Are the recordings available somewhere?

I happen to be somewhat interested in SPDX (especially the licensing part of the spec), however, the meeting time does not always work for me.

Vladimir



SPDX Oct General Meeting Minutes

Phil Odence
 

https://wiki.spdx.org/view/General_Meeting/Minutes/2019-10-03

 

General Meeting/Minutes/2019-10-03

< General Meeting‎ | Minutes

·         Attendance: 10

·         Lead by Kate Stewart

·         Minutes of Sept. meeting approved 

 

Contents

 [hide

·         1 Legal Team – Steve

·         2 Tech Team Report - Kate

·         3 Outreach Team Report - Jack

·         4 Cross Functional

·         5 Attendees

Legal Team – Steve

·         Working on the next release – 3.7

·         Looking for volunteers to put together the XML and test files

·         Targeting next week

·         Small release

·         Trend – licenses that don’t strictly follow the open source definition (e.g. source available but some proprietary restrictions)

·         Discussion on whether these should be included and update the license inclusion principles – more information available at https://github.com/spdx/license-list-XML/issues/925

·         Looking to make a decision early in the 3.8 release

Tech Team Report - Kate

·         SPDX Lite

·         Changes are added as a pull request and will likely be accepted soon

·         Security fields to be added in 2.2

·         Working with Uday on a Google Doc which will be turned into a pull request

·         Coordinating with Todo group and others

·         Looking at adjusting the minimum required fields to allow for security use cases without all the licensing

·         General support for reducing the number of mandatory fields

·         Steve will bring to the legal team the discussion on removing the of the mandatory legal related fields

·         GSoC – completed, all students passed

·         SPDX Tool updates which include the GSoC contributions are all checked in

·         Plan to update the spdxtools website within the next 2 weeks

·         Amazon will start using the namespace features soon

·         Request to add specification for the namespace

·         Mark agreed and will create a pull request

·         The license ID web page can also be updated

Outreach Team Report - Jack

·         Survey

·         Working on summarizing the survey results

Cross Functional

·         Several compliance and SPDX related talks planned for the Open Source Summit Europe in Lyon at the end of the month

Attendees

·         Steve Winslow, LF

·         Gary O’Neall, SourceAuditor

·         Jack Manbeck, TI

·         Mark Atwood, Amazon

·         Paul Madick, Dimension Data

·         Nisha Kumar, VMWare

·         Rose Judge, VMWare

·         Matija Šuklje

·         William Bartholomew, Github

·         Dave McLoghlin, Rogue Wave

 


Re: Thursday SPDX General Meeting Reminder

Vladimir Sitnikov <sitnikov.vladimir@...>
 

Are the recordings available somewhere?

I happen to be somewhat interested in SPDX (especially the licensing part of the spec), however, the meeting time does not always work for me.

Vladimir


Thursday SPDX General Meeting Reminder

Phil Odence
 

We are still trying to line up a presentation from one of the GSoC students who has not yet presented; that’s up in the air.

 

I will not be able to join so one of the other Core Team members will host.

 

Best regards,

Phil

 

GENERAL MEETING

 

Meeting Time: Thurs, Oct 3, 8am PT / 10 am CT / 11am ET / 15:00 UTC.  http://www.timeanddate.com/worldclock/converter.html


Conf call dial-in:

New dial in number: 415-881-1586

No PIN needed

The weblink for screenshare will stay the same at: 
http://uberconference.com/SPDXTeam

 

Administrative Agenda

Attendance

Minutes Approval:   https://wiki.spdx.org/view/General_Meeting/Minutes/2019-09-05

  

 

Possible GSoC Presentations

 

Technical Team Report – Kate/Gary

 

Legal Team Report – Jilayne/Paul

 

Outreach Team Report – Jack

 

Any Cross Functional Issues –All

 

 


Re: In favour of what are §4.9–4.11 deprecated?

Matija Šuklje
 

On nedelja, 28. julij 2019 22:15:26 CEST, Gary O'Neall wrote:
[G.O.] The idea is that there would be a package definition. It could be in a separate SPDX document, or more likely, as a separate SPDX package definition within the same SPDX document. The originating package definition could have the FilesAnalyzed set to false which allows for a rather small number of required fields. The origin could then be indicated by a relationship between the file and the package.
I see. Is there already any tooling available to make this actually usable in practice? Sw360, DejaCode?


cheers,
Matija

P.S. Sorry about the late reply, I had a lot going on in the past few weeks/months.
--
gsm: tel:+386.41.849.552
www: https://matija.suklje.name
xmpp: matija.suklje@...
sip: matija_suklje@...