|
Re: SPDX Goes ISO
Yes, understood. Thanks, Dick. For that use case, the President was more concerned with a cyber attack that a license violation. This is the point of evolving SPDX to be “configurable” with
Yes, understood. Thanks, Dick. For that use case, the President was more concerned with a cyber attack that a license violation. This is the point of evolving SPDX to be “configurable” with
|
By
Phil Odence
·
#1455
·
|
|
Re: SPDX Goes ISO
Die 14. 09. 21 et hora 17:52 Phil Odence via lists.spdx.org scripsit:
I know. I’m just excited by the prospect of synergies and more use of SPDX in
the wild!
I can already see how the wider
Die 14. 09. 21 et hora 17:52 Phil Odence via lists.spdx.org scripsit:
I know. I’m just excited by the prospect of synergies and more use of SPDX in
the wild!
I can already see how the wider
|
By
Matija Šuklje
·
#1454
·
|
|
Re: SPDX Goes ISO
Phil,
Minimal SBOM elements specified by NTIA for Executive Order (EO) 14028 do not include license data element requirements (see attached). The EO and the NTIA SBOM minimal
Phil,
Minimal SBOM elements specified by NTIA for Executive Order (EO) 14028 do not include license data element requirements (see attached). The EO and the NTIA SBOM minimal
|
By
Dick Brooks
·
#1453
·
|
|
Re: SPDX Goes ISO
Thanks, Matija. Absolutely not just license compliance. Security too is a big driver and an important part/direction of SPDX.
From:spdx@... <spdx@...> on behalf of Matija Šuklje <matija@...>
Date:
Thanks, Matija. Absolutely not just license compliance. Security too is a big driver and an important part/direction of SPDX.
From:spdx@... <spdx@...> on behalf of Matija Šuklje <matija@...>
Date:
|
By
Phil Odence
·
#1452
·
|
|
Re: SPDX Goes ISO
Congratulations!
This is indeed a massive step for the software world, and hopefully not just
in terms of license compliance!
hip hip hurrah!
Matija
--
Congratulations!
This is indeed a massive step for the software world, and hopefully not just
in terms of license compliance!
hip hip hurrah!
Matija
--
|
By
Matija Šuklje
·
#1451
·
|
|
Re: SPDX Goes ISO
The content that went into the standard is the same as what is
in our github repo today, and a pretty version is at: https://spdx.github.io/spdx-spec/.
The sources for the 2.2.1 are at:
The content that went into the standard is the same as what is
in our github repo today, and a pretty version is at: https://spdx.github.io/spdx-spec/.
The sources for the 2.2.1 are at:
|
By
Kate Stewart
·
#1450
·
|
|
Re: SPDX Goes ISO
I believe that is correct. It seems an odd systems, but as I understand it, it’s not unusual to have free and paid for versions of specs with the same content. Openchain is, I believe, and example
I believe that is correct. It seems an odd systems, but as I understand it, it’s not unusual to have free and paid for versions of specs with the same content. Openchain is, I believe, and example
|
By
Phil Odence
·
#1449
·
|
|
Re: SPDX Goes ISO
I’ll defer to Phil or Kate for an official answer, but my understanding is that SPDX will continue to publish the specification directly from the SPDX project to the community, but certain versions
I’ll defer to Phil or Kate for an official answer, but my understanding is that SPDX will continue to publish the specification directly from the SPDX project to the community, but certain versions
|
By
William Bartholomew
·
#1448
·
|
|
Re: SPDX Goes ISO
It now costs CHF198 to buy. This is the ISO way, and I think it's literally criminal.
As in: violates UN Charter of Human Rights.
If it doesn't wind up on the Publically Available Standards list,
It now costs CHF198 to buy. This is the ISO way, and I think it's literally criminal.
As in: violates UN Charter of Human Rights.
If it doesn't wind up on the Publically Available Standards list,
|
By
Michael Richardson
·
#1447
·
|
|
Re: SPDX Goes ISO
"I guess it will..." does not sound very reassuring, to be honest 🤠
So will it definitely become an "ISO Publicly Available Standard" and is that just a question of time?
Viele Grü0e,
Henk
"I guess it will..." does not sound very reassuring, to be honest 🤠
So will it definitely become an "ISO Publicly Available Standard" and is that just a question of time?
Viele Grü0e,
Henk
|
By
Henk Birkholz
·
#1446
·
|
|
Re: SPDX Goes ISO
I guess it will…
The OpenChain one took a couple of months to appear, though, so I don’t know how quickly this gets updated.
-- zvr
I guess it will…
The OpenChain one took a couple of months to appear, though, so I don’t know how quickly this gets updated.
-- zvr
|
By
Alexios Zavras
·
#1445
·
|
|
Re: SPDX Goes ISO
This is wonderful news! Congrats to Kate and everyone else who had a hand in this! Hopefully this means wider adoption and growth for the future!
Zachary Fetters
Freelance graphic/web
This is wonderful news! Congrats to Kate and everyone else who had a hand in this! Hopefully this means wider adoption and growth for the future!
Zachary Fetters
Freelance graphic/web
|
By
Zachary Fetters
·
#1444
·
|
|
Re: SPDX Goes ISO
Since the standard was not developed by ISO itself, will the standard be publicly available athttps://standards.iso.org/ittf/PubliclyAvailableStandards/ ?
I think it should.
Do we know?
Since the standard was not developed by ISO itself, will the standard be publicly available athttps://standards.iso.org/ittf/PubliclyAvailableStandards/ ?
I think it should.
Do we know?
|
By
Vargenau, Marc-Etienne (Nokia - FR/Paris-Saclay)
·
#1443
·
|
|
Re: SPDX Goes ISO
I just realized that the DocFest will be demonstrating interoperability of an ISO standard SBOM.
Great timing getting the ISO standard status before the 9/16 DocFest. Very cool!
Thanks,
Dick
I just realized that the DocFest will be demonstrating interoperability of an ISO standard SBOM.
Great timing getting the ISO standard status before the 9/16 DocFest. Very cool!
Thanks,
Dick
|
By
Dick Brooks
·
#1442
·
|
|
Re: SPDX Goes ISO
Please do 🙂
By
Shane Coughlan
·
#1441
·
|
|
Re: SPDX Goes ISO
This is great news, very happy to see it and kudos to everyone involved.
People may also be interested to know that we just merged SPDX SBOM generation
into OpenEmbedded-Core, just before our feature
This is great news, very happy to see it and kudos to everyone involved.
People may also be interested to know that we just merged SPDX SBOM generation
into OpenEmbedded-Core, just before our feature
|
By
Richard Purdie
·
#1440
·
|
|
Re: SPDX Goes ISO
We may quote you on that!
From:spdx@... <spdx@...> on behalf of Shane Coughlan <scoughlan@...>
Date: Thursday, September 9, 2021 at 9:16 PM
To: spdx@... <spdx@...>
Subject: Re: [spdx] SPDX Goes
We may quote you on that!
From:spdx@... <spdx@...> on behalf of Shane Coughlan <scoughlan@...>
Date: Thursday, September 9, 2021 at 9:16 PM
To: spdx@... <spdx@...>
Subject: Re: [spdx] SPDX Goes
|
By
Phil Odence
·
#1439
·
|
|
Re: SPDX Goes ISO
Seconded!
This is tremendously important for the governance ecosystem.
Regards
Shane
Seconded!
This is tremendously important for the governance ecosystem.
Regards
Shane
|
By
Shane Coughlan
·
#1438
·
|
|
Re: SPDX Goes ISO
A truly amazing achievement – well done and congratulations to Kate and the entire SPDX and Linux Foundation community that made this happen.
So much looking forward to advancing SPDX
A truly amazing achievement – well done and congratulations to Kate and the entire SPDX and Linux Foundation community that made this happen.
So much looking forward to advancing SPDX
|
By
Dick Brooks
·
#1437
·
|
|
Re: SPDX Goes ISO
A big +1 from me. Thank you to all the SPDX contributors and everyone involved in the years-long process of getting the SPDX standard to where it is today, and especially to Kate for her tireless
A big +1 from me. Thank you to all the SPDX contributors and everyone involved in the years-long process of getting the SPDX standard to where it is today, and especially to Kate for her tireless
|
By
Steve Winslow
·
#1436
·
|