|
Re: SPDX Generator with RefIDs and package hierarchy
Hi Daniel,
I take it by refID you’re referring to the SPDX ID for the packages.
There are a few tools out that that can build SBOM’s with the dependency maps. You can find information on
Hi Daniel,
I take it by refID you’re referring to the SPDX ID for the packages.
There are a few tools out that that can build SBOM’s with the dependency maps. You can find information on
|
By
Gary O'Neall
·
#1635
·
|
|
SPDX Generator with RefIDs and package hierarchy
All,
I feel like I'm missing something obvious here, but which SBOM generators actually generate SPDX SBOMs that (1) have refID's for the overall asset (documentDescribes), and (2) have package
All,
I feel like I'm missing something obvious here, but which SBOM generators actually generate SPDX SBOMs that (1) have refID's for the overall asset (documentDescribes), and (2) have package
|
By
daniel@...
·
#1634
·
|
|
Re: Link to US National Cybersecurity Strategy posted today
https://www.ntia.gov/files/ntia/publications/ntia_sbom_use_cases_roles_benefits-nov2019.pdf
--
Alfred Strauch
President
SmartTalk Security Inc.
Bus: 306-5291442
Email: alfred@...
Web:
https://www.ntia.gov/files/ntia/publications/ntia_sbom_use_cases_roles_benefits-nov2019.pdf
--
Alfred Strauch
President
SmartTalk Security Inc.
Bus: 306-5291442
Email: alfred@...
Web:
|
By
Alfred Strauch
·
#1633
·
|
|
Re: SPDX in GSoC 2023!
Hello!
Congratulations to spdx for being accepted into GSoC 2023 as an organisation!
I'm Rahul and I would love to contribute to fixing manifest parsers for the SPDX generator. I've gone through the
Hello!
Congratulations to spdx for being accepted into GSoC 2023 as an organisation!
I'm Rahul and I would love to contribute to fixing manifest parsers for the SPDX generator. I've gone through the
|
By
Rahul
·
#1632
·
|
|
Link to US National Cybersecurity Strategy posted today
https://www.whitehouse.gov/wp-content/uploads/2023/03/National-Cybersecurity-Strategy-2023.pdf
Note references to SBOM and NIST/CISA role in driving regulations.
Thanks,
Dick Brooks
https://www.whitehouse.gov/wp-content/uploads/2023/03/National-Cybersecurity-Strategy-2023.pdf
Note references to SBOM and NIST/CISA role in driving regulations.
Thanks,
Dick Brooks
|
By
Dick Brooks
·
#1631
·
|
|
Thursday SPDX General Meeting Reminder
Hello all,
Max Huber of TNG Technology Consulting will be presenting on Thursday:
In this presentation, Max will give a brief update of the recentdevelopment in the Python Tools. It went through a
Hello all,
Max Huber of TNG Technology Consulting will be presenting on Thursday:
In this presentation, Max will give a brief update of the recentdevelopment in the Python Tools. It went through a
|
By
Phil Odence
·
#1630
·
|
|
Re: JSON schema v2.2 PACKAGE_MANAGER discrepancy
Hi Keith,
Please feel free to create an issue and/or a pull requests for the 2.2 JSON schema update.
If there are no objections, we can merge it into the 2.2 spec branch.
Thanks,
Gary
Hi Keith,
Please feel free to create an issue and/or a pull requests for the 2.2 JSON schema update.
If there are no objections, we can merge it into the 2.2 spec branch.
Thanks,
Gary
|
By
Gary O'Neall
·
#1629
·
|
|
JSON schema v2.2 PACKAGE_MANAGER discrepancy
Hi All,
There has been a small discrepancy in the SPDX 2.2 JSON schema and the SPDX spec for a while: the 2.2 spec indicates External Reference Category should have a value of: SECURITY |
Hi All,
There has been a small discrepancy in the SPDX 2.2 JSON schema and the SPDX spec for a while: the 2.2 spec indicates External Reference Category should have a value of: SECURITY |
|
By
Keith Zantow
·
#1628
·
|
|
SPDX Steering Committee Nominations
Dear SPDX community,
We are approaching the end of the current term for several members of the SPDX Steering Committee. We are reaching out to let the community know about the upcoming nomination
Dear SPDX community,
We are approaching the end of the current term for several members of the SPDX Steering Committee. We are reaching out to let the community know about the upcoming nomination
|
By
Phil Odence
·
#1627
·
|
|
Minutes from last SPDX General Meeting
Pull request not yet approved in GH, so here are the minutes. Sorry they are ugly and indentation isn’t working right. All good in GH.
#SPDX General Meeting Minutes - January 5, 2023
##
Pull request not yet approved in GH, so here are the minutes. Sorry they are ugly and indentation isn’t working right. All good in GH.
#SPDX General Meeting Minutes - January 5, 2023
##
|
By
Phil Odence
·
#1626
·
|
|
SPDX General Meeting
Extending the meeting for 2023…and beyond! Please accept this recurring invitation.
“Dial In” info:
Join the meeting:
https://meet.jit.si/SPDXGeneralMeeting
To join by phone instead,
Extending the meeting for 2023…and beyond! Please accept this recurring invitation.
“Dial In” info:
Join the meeting:
https://meet.jit.si/SPDXGeneralMeeting
To join by phone instead,
|
By
Phil Odence
·
#1625
·
|
|
SPDX in GSoC 2023!
Hi everyone!
As every year, Google runs their Summer of Code program, where contributors get the opportunity to become part of Open Source communities. The SPDX Project has participated in the
Hi everyone!
As every year, Google runs their Summer of Code program, where contributors get the opportunity to become part of Open Source communities. The SPDX Project has participated in the
|
By
Alexios Zavras
·
#1624
·
|
|
Seeking Opinions/Participants about AI SBOM Features
Researchers at Indiana University’s Luddy School of Informatics, Computing, and Engineering are looking for participants in the study of SBOM feature preferences. This is an online and asynchronous
Researchers at Indiana University’s Luddy School of Informatics, Computing, and Engineering are looking for participants in the study of SBOM feature preferences. This is an online and asynchronous
|
By
Caven, Peter
·
#1623
·
|
|
Please participate: "State of Open Standards Survey"
The Linux Foundation (LF) has launched The State of Open Standards Survey to capture how different organizations are involved in open standards adoption and contribution, with the aim of measuring the
The Linux Foundation (LF) has launched The State of Open Standards Survey to capture how different organizations are involved in open standards adoption and contribution, with the aim of measuring the
|
By
Kate Stewart
·
#1622
·
|
|
Re: SPDX Thursday General Meeting Reminder
Thanks, Max. I think that “bug” has been there for a while. I will endeavor to eliminate it going forward.
Thanks for pointing it out.
Phil
From:spdx@... <spdx@...> on behalf of Maximilian
Thanks, Max. I think that “bug” has been there for a while. I will endeavor to eliminate it going forward.
Thanks for pointing it out.
Phil
From:spdx@... <spdx@...> on behalf of Maximilian
|
By
Phil Odence
·
#1621
·
|
|
Re: SPDX Thursday General Meeting Reminder
Hey Phil,
just checked the meeting time and there seems to be an inconsistency:
8am PT / 10 am CT / 11am ET
mapps to
16:00 UTC
I assume that 16:00 UTC, as it is the usual time, is
Hey Phil,
just checked the meeting time and there seems to be an inconsistency:
8am PT / 10 am CT / 11am ET
mapps to
16:00 UTC
I assume that 16:00 UTC, as it is the usual time, is
|
By
Maximilian Huber
·
#1620
·
|
|
SPDX Thursday General Meeting Reminder
Happy New Year, all. I hope you have a meeting on your calendar for Thursday. In case there is an issue, the conference info is included below.
No special presentation this month.
Also please
Happy New Year, all. I hope you have a meeting on your calendar for Thursday. In case there is an issue, the conference info is included below.
No special presentation this month.
Also please
|
By
Phil Odence
·
#1619
·
|
|
LF Research: Participate in the State of Open Standards Survey
Hello SPDX community!
I am the ecosystem manager for Linux Foundation Research and we have recently launched The State of Open Standards Survey to capture how different organizations are involved in
Hello SPDX community!
I am the ecosystem manager for Linux Foundation Research and we have recently launched The State of Open Standards Survey to capture how different organizations are involved in
|
By
Anna Hermansen
·
#1618
·
|
|
SBOM is included in the latest Omnibus bill
‘‘SEC. 524B. ENSURING CYBERSECURITY OF DEVICES.
‘‘(3) provide to the Secretary a software bill of
20 materials, including commercial, open-source, and
21 off-the-shelf software
‘‘SEC. 524B. ENSURING CYBERSECURITY OF DEVICES.
‘‘(3) provide to the Secretary a software bill of
20 materials, including commercial, open-source, and
21 off-the-shelf software
|
By
Dick Brooks
·
#1617
·
|
|
SBOM stripped from NDAA may reappear in the Omnibus bill
Hello Everyone,
I’ve heard the SBOM provision that was in the NDAA is under consideration for the Omnibus Bill.
I sent written testimony to the Senate Appropriations Committee deliberating the
Hello Everyone,
I’ve heard the SBOM provision that was in the NDAA is under consideration for the Omnibus Bill.
I sent written testimony to the Senate Appropriations Committee deliberating the
|
By
Dick Brooks
·
#1616
·
|