|
Re: Taxonomy of software supply chain ecosystem?
You may also want to look at the SLSA framework.
https://slsa.dev/levels
---
Mike Dolan
The Linux Foundation
Office: +1.330.460.3250 Cell: +1.440.552.5322
mdolan@...
---
You may also want to look at the SLSA framework.
https://slsa.dev/levels
---
Mike Dolan
The Linux Foundation
Office: +1.330.460.3250 Cell: +1.440.552.5322
mdolan@...
---
|
By
Michael Dolan
·
#1477
·
|
|
Re: Taxonomy of software supply chain ecosystem?
Yessssss…
It’ll take a while to get through it all, but this will be very helpful for us. Many thanks, Steve and Tooling Group Team!
--V
--
VM (Vicky) Brasseur
Director, Senior
Yessssss…
It’ll take a while to get through it all, but this will be very helpful for us. Many thanks, Steve and Tooling Group Team!
--V
--
VM (Vicky) Brasseur
Director, Senior
|
By
VM (Vicky) Brasseur
·
#1476
·
|
|
Re: Taxonomy of software supply chain ecosystem?
Hi Vicky,
There's been some great work in the OSS Compliance Tooling Group which addresses this – if you're asking what I think you're asking. See:
Hi Vicky,
There's been some great work in the OSS Compliance Tooling Group which addresses this – if you're asking what I think you're asking. See:
|
By
Steve Kilbane
·
#1475
·
|
|
Re: Taxonomy of software supply chain ecosystem?
There's been some industry wide agreement on the taxonomy to use to classify tools here: https://www.ntia.gov/files/ntia/publications/ntia_sbom_tooling_taxonomy-2021mar30.pdf I think the path of
There's been some industry wide agreement on the taxonomy to use to classify tools here: https://www.ntia.gov/files/ntia/publications/ntia_sbom_tooling_taxonomy-2021mar30.pdf I think the path of
|
By
Kate Stewart
·
#1474
·
|
|
Taxonomy of software supply chain ecosystem?
A taxonomy of this SSC ecosystem. I would like to have one, plz&thx.
For instance, looking at this (very much work in progress, just noodling about as I think about things) picture, those items in
A taxonomy of this SSC ecosystem. I would like to have one, plz&thx.
For instance, looking at this (very much work in progress, just noodling about as I think about things) picture, those items in
|
By
VM (Vicky) Brasseur
·
#1473
·
|
|
Re: [spdx-tech] RFC: Creating a fairly complex SPDX document for an open source project (Julia)
Dear Marc-Etienne,
Yay! I was indeed just wondering about this earlier today, so thank
you very much for the notification :)
Best wishes,
Sebastian
Dear Marc-Etienne,
Yay! I was indeed just wondering about this earlier today, so thank
you very much for the notification :)
Best wishes,
Sebastian
|
By
Sebastian Crane
·
#1472
·
|
|
Re: [spdx-tech] RFC: Creating a fairly complex SPDX document for an open source project (Julia)
Hi all,
Great news: ISO SPDX standard is now publicly available at:
https://standards.iso.org/ittf/PubliclyAvailableStandards/
Best regards,
Marc-Etienne
Hi all,
Great news: ISO SPDX standard is now publicly available at:
https://standards.iso.org/ittf/PubliclyAvailableStandards/
Best regards,
Marc-Etienne
|
By
Vargenau, Marc-Etienne (Nokia - FR/Paris-Saclay)
·
#1471
·
|
|
Minutes from Nov 4 SPDX General Meeting
https://wiki.spdx.org/view/General_Meeting/Minutes/2021-11-04
General Meeting/Minutes/2021-11-04
< General Meeting | Minutes
· Attendance: 25
· Lead by Phil Odence
·
https://wiki.spdx.org/view/General_Meeting/Minutes/2021-11-04
General Meeting/Minutes/2021-11-04
< General Meeting | Minutes
· Attendance: 25
· Lead by Phil Odence
·
|
By
Phil Odence
·
#1470
·
|
|
Asia SPDX Meeting- China government data processing draft policy
Came up on the call today. For those interested, here is an overview:
https://asia.nikkei.com/Business/China-tech/New-China-data-transfer-rules-to-be-costly-for-foreign-companies
Asia SPDX
Came up on the call today. For those interested, here is an overview:
https://asia.nikkei.com/Business/China-tech/New-China-data-transfer-rules-to-be-costly-for-foreign-companies
Asia SPDX
|
By
Shane Coughlan
·
#1469
·
|
|
Today's SPDX General Meeting Reminder
Apologies for the late reminder.
Notes:
For Euro folks, time diff is off by an hour as US doesn’t go back to standard time until this weekend
We will have a Google Summer of Code presentation
Apologies for the late reminder.
Notes:
For Euro folks, time diff is off by an hour as US doesn’t go back to standard time until this weekend
We will have a Google Summer of Code presentation
|
By
Phil Odence
·
#1468
·
|
|
Re: Public Domain license identifier
The "public domain" part appears to be the text of the Unlicense, so
I'd assume "MIT OR Unlicense".
Richard
The "public domain" part appears to be the text of the Unlicense, so
I'd assume "MIT OR Unlicense".
Richard
|
By
Richard Fontana
·
#1467
·
|
|
Re: Message Approval Needed - tardyp@gmail.com posted to spdx@lists.spdx.org
Hi Pierre,
I am moving the general SPDX list to BCC and sending this via the SPDX legal list, as that is the right place for this question! Also not - I have approved your message and copied you here
Hi Pierre,
I am moving the general SPDX list to BCC and sending this via the SPDX legal list, as that is the right place for this question! Also not - I have approved your message and copied you here
|
By
J Lovejoy
·
#1466
·
|
|
Public Domain license identifier
Hello,
I am trying to identify this software in term of license expression
https://github.com/nothings/stb
It's is claimed to be "public domain or MIT".
I don't see any license identifier for public
Hello,
I am trying to identify this software in term of license expression
https://github.com/nothings/stb
It's is claimed to be "public domain or MIT".
I don't see any license identifier for public
|
By
Pierre Tardy
·
#1465
·
|
|
Re: SPDX Oct Gen Meeting Minutes
I’m pretty sure President Biden does too.
From:spdx@... <spdx@...> on behalf of Dick Brooks <dick@...>
Date: Friday, October 15, 2021 at 10:33 AM
To: spdx@... <spdx@...>
Subject: Re: [spdx] SPDX
I’m pretty sure President Biden does too.
From:spdx@... <spdx@...> on behalf of Dick Brooks <dick@...>
Date: Friday, October 15, 2021 at 10:33 AM
To: spdx@... <spdx@...>
Subject: Re: [spdx] SPDX
|
By
Phil Odence
·
#1464
·
|
|
Re: SPDX Oct Gen Meeting Minutes
Thanks, Phil. 100% agree with you.
Thanks,
Dick Brooks
Never trust software, always verify and report! ™
http://www.reliableenergyanalytics.com
Email: dick@...
Tel: +1 978-696-1788
Thanks, Phil. 100% agree with you.
Thanks,
Dick Brooks
Never trust software, always verify and report! ™
http://www.reliableenergyanalytics.com
Email: dick@...
Tel: +1 978-696-1788
|
By
Dick Brooks
·
#1463
·
|
|
Re: SPDX Oct Gen Meeting Minutes
That’s great, Dick. A very important direction for us IMO.
From:spdx@... <spdx@...> on behalf of Dick Brooks <dick@...>
Date: Friday, October 15, 2021 at 9:49 AM
To: spdx@... <spdx@...>
Subject:
That’s great, Dick. A very important direction for us IMO.
From:spdx@... <spdx@...> on behalf of Dick Brooks <dick@...>
Date: Friday, October 15, 2021 at 9:49 AM
To: spdx@... <spdx@...>
Subject:
|
By
Phil Odence
·
#1462
·
|
|
Re: SPDX Oct Gen Meeting Minutes
Thanks, Phil.
Kate/Gary, please let me know if there is anything I can do to help with a cyber risk assessment use case – I’m happy to contribute and learn.
Thanks,
Dick
Thanks, Phil.
Kate/Gary, please let me know if there is anything I can do to help with a cyber risk assessment use case – I’m happy to contribute and learn.
Thanks,
Dick
|
By
Dick Brooks
·
#1461
·
|
|
Re: SPDX Oct Gen Meeting Minutes
Dick, apologies for the slow response. Frankly we had a pretty tech team update this time. I think it’s a good idea to get some specifics from profile sub-teams next month and (herewith) suggest to
Dick, apologies for the slow response. Frankly we had a pretty tech team update this time. I think it’s a good idea to get some specifics from profile sub-teams next month and (herewith) suggest to
|
By
Phil Odence
·
#1460
·
|
|
Re: SPDX Oct Gen Meeting Minutes
Phil,
I had to attend a CISA meeting held at the same time as the SPDX meeting; I didn’t see any info in the minutes regarding the work on profiles. Any updates to share on the
Phil,
I had to attend a CISA meeting held at the same time as the SPDX meeting; I didn’t see any info in the minutes regarding the work on profiles. Any updates to share on the
|
By
Dick Brooks
·
#1459
·
|
|
SPDX Oct Gen Meeting Minutes
There were a few of anonymous participants that I did not include in the count. It would be helpful to get names for these minutes and to use them for future meetings. Also, while it’s not required
There were a few of anonymous participants that I did not include in the count. It would be helpful to get names for these minutes and to use them for future meetings. Also, while it’s not required
|
By
Phil Odence
·
#1458
·
|