|
Re: Using SPDX for firmware
Very nice! About the dead link, I am not sure exceptions have been published
yet, though it could be a bug too.
IMHO using your own ID extensions is quite fine, there is nothing
upsetting about it,
Very nice! About the dead link, I am not sure exceptions have been published
yet, though it could be a bug too.
IMHO using your own ID extensions is quite fine, there is nothing
upsetting about it,
|
By
Philippe Ombredanne
·
#996
·
|
|
Using SPDX for firmware
Hi all,
I've been using SPDX for years in the AppStream specification to
describe applications that can be installed in software centers. I'm
using the AND, OR extensions, and am soon to include the
Hi all,
I've been using SPDX for years in the AppStream specification to
describe applications that can be installed in software centers. I'm
using the AND, OR extensions, and am soon to include the
|
By
Richard Hughes
·
#995
·
|
|
Re: Proposed spec for external packages
Hi Uday,
I don't think so. This is an optional field to permit linkage to security information IF it exists. If it doesn't exist, its more the responsibility of the package creator or distributor
Hi Uday,
I don't think so. This is an optional field to permit linkage to security information IF it exists. If it doesn't exist, its more the responsibility of the package creator or distributor
|
By
Kate Stewart
·
#994
·
|
|
Re: Proposed spec for external packages
Hi Kate,
Thanks a ton for the clarification. It definitely helps, I am sorry for this delayed response.
I have one more question/doubt though. In 2.2.1 Corpus Tags, What I infer is that either the
Hi Kate,
Thanks a ton for the clarification. It definitely helps, I am sorry for this delayed response.
I have one more question/doubt though. In 2.2.1 Corpus Tags, What I infer is that either the
|
By
Sai Uday Shankar Korlimarla
·
#993
·
|
|
August SPDX General Meeting Minutes
Minutes here and below: http://wiki.spdx.org/view/General_Meeting/Minutes/2015-08-06
Announcements:
LinuxCon Europe: If you are attending, there will be a supply chain focused session on Thursday
Minutes here and below: http://wiki.spdx.org/view/General_Meeting/Minutes/2015-08-06
Announcements:
LinuxCon Europe: If you are attending, there will be a supply chain focused session on Thursday
|
By
Philip Odence
·
#992
·
|
|
Re: Proposed spec for external packages
All I can do is comment on the SPDX spec from the perspective of a small business and FOSS contributor. The spec is already quite heavy weight and adding this tag might make sense for the larger
All I can do is comment on the SPDX spec from the perspective of a small business and FOSS contributor. The spec is already quite heavy weight and adding this tag might make sense for the larger
|
By
Jeremiah Foster <jeremiah.foster@...>
·
#991
·
|
|
SPDX General Meeting Reminder
With no special presentation this month, I suspect the meeting will only require 30 mins.
GENERAL MEETING
Meeting Time: Thurs, Aug 6, 8am PDT / 10 am CDT / 11am EDT / 15:00 UTC.
With no special presentation this month, I suspect the meeting will only require 30 mins.
GENERAL MEETING
Meeting Time: Thurs, Aug 6, 8am PDT / 10 am CDT / 11am EDT / 15:00 UTC.
|
By
Philip Odence
·
#990
·
|
|
Re: Proposed spec for external packages
There is no SPDX tag - per se. An SPDX document for a package contains hash codes at the file level. (SHA1, SHA256 ), as well as an algorithm for a verification code to be generated from the
There is no SPDX tag - per se. An SPDX document for a package contains hash codes at the file level. (SHA1, SHA256 ), as well as an algorithm for a verification code to be generated from the
|
By
Kate Stewart
·
#989
·
|
|
Re: Proposed spec for external packages
How do you propose it be trusted? It is just a string! You need substantially more infrastructure than just a SPDX tag to generate trust.
Regards,
Jeremiah
How do you propose it be trusted? It is just a string! You need substantially more infrastructure than just a SPDX tag to generate trust.
Regards,
Jeremiah
|
By
Jeremiah Foster <jeremiah.foster@...>
·
#988
·
|
|
Re: Proposed spec for external packages
Hi Uday,
Proposal was to permit use of either. It was not mandating that one or another needs be used.
Agree.
Also, see appendix A in NIST-8060 where CPE can be derived from SWID.
see:
Hi Uday,
Proposal was to permit use of either. It was not mandating that one or another needs be used.
Agree.
Also, see appendix A in NIST-8060 where CPE can be derived from SWID.
see:
|
By
Kate Stewart
·
#987
·
|
|
Re: Proposed spec for external packages
Adding to Kate’s comments, the SPDX presumption is that developers of open source software would like to:
a. have their software used by others
b. make sure the software is used under the terms they
Adding to Kate’s comments, the SPDX presumption is that developers of open source software would like to:
a. have their software used by others
b. make sure the software is used under the terms they
|
By
Philip Odence
·
#985
·
|
|
Re: Proposed spec for external packages
The base document that these changes are being proposed for is SPDX 2.0 see: http://spdx.org/SPDX-specifications/spdx-version-2.0
The goal of software package data exchange (SPDX) is to create a
The base document that these changes are being proposed for is SPDX 2.0 see: http://spdx.org/SPDX-specifications/spdx-version-2.0
The goal of software package data exchange (SPDX) is to create a
|
By
Kate Stewart
·
#984
·
|
|
Re: Proposed spec for external packages
Its impossible to answer this question, largely because there's not enough data -- what are these "other systems" (Windows?) and what are the "external packages"?
This is my assumption as well.
I
Its impossible to answer this question, largely because there's not enough data -- what are these "other systems" (Windows?) and what are the "external packages"?
This is my assumption as well.
I
|
By
Jeremiah Foster <jeremiah.foster@...>
·
#983
·
|
|
Re: Proposed spec for external packages
Beats me. But to me the proposed solution looks much worse than whatever problem it is that you're trying to solve. Speaking of which, where is the document that describes the problem you're trying to
Beats me. But to me the proposed solution looks much worse than whatever problem it is that you're trying to solve. Speaking of which, where is the document that describes the problem you're trying to
|
By
Mike Milinkovich
·
#982
·
|
|
Re: Proposed spec for external packages
The SPEC being referred to is a NIST one, rather than ANSI. see: http://csrc.nist.gov/publications/PubsDrafts.html#NIST-IR-8060
Which is open.
Its in its second reading right now, and its in a
The SPEC being referred to is a NIST one, rather than ANSI. see: http://csrc.nist.gov/publications/PubsDrafts.html#NIST-IR-8060
Which is open.
Its in its second reading right now, and its in a
|
By
Kate Stewart
·
#981
·
|
|
Re: Proposed spec for external packages
here's the link:
https://docs.google.com/document/d/1j6LWnkh5GbMV9Xo5_zJ0wTNLROEIa4o1OU279YueI90/edit
here's the link:
https://docs.google.com/document/d/1j6LWnkh5GbMV9Xo5_zJ0wTNLROEIa4o1OU279YueI90/edit
|
By
Kate Stewart
·
#980
·
|
|
Re: Proposed spec for external packages
To add to Philippe's comments, and speaking on behalf of a major producer of open source software, the proposal for an "External Security and Asset Management Identifier" seems to be fundamentally
To add to Philippe's comments, and speaking on behalf of a major producer of open source software, the proposal for an "External Security and Asset Management Identifier" seems to be fundamentally
|
By
Mike Milinkovich
·
#979
·
|
|
Re: Proposed spec for external packages
Hi Philippe,
The document you commented on was from last week's discussion.
Your input is appreciated and you're opinion is lining up
with some of the thoughts expressed as part of the external
Hi Philippe,
The document you commented on was from last week's discussion.
Your input is appreciated and you're opinion is lining up
with some of the thoughts expressed as part of the external
|
By
Kate Stewart
·
#978
·
|
|
Re: Proposed spec for external packages
Hi Philippe, HI Yev
Philippe, You are right about SWID.
Yev, I may be biased over using CPEs and not using SWIDs. Here are my points on SWID.
1. SWID looks nice to have for software asset management
Hi Philippe, HI Yev
Philippe, You are right about SWID.
Yev, I may be biased over using CPEs and not using SWIDs. Here are my points on SWID.
1. SWID looks nice to have for software asset management
|
By
Sai Uday Shankar Korlimarla
·
#986
·
|
|
Re: Proposed spec for external packages
D’oh! Arrgh! Other grunting noises!
Here is the correct link. Terribly sorry for the confusion/inconvenience.
https://docs.google.com/document/d/1HTgrEKBlza_U3yZBKpgu9JDYhZkZ6Jbj9jNsmRreCMo/edit
D’oh! Arrgh! Other grunting noises!
Here is the correct link. Terribly sorry for the confusion/inconvenience.
https://docs.google.com/document/d/1HTgrEKBlza_U3yZBKpgu9JDYhZkZ6Jbj9jNsmRreCMo/edit
|
By
Yev Bronshteyn
·
#977
·
|