|
Thursday's SPDX General Meeting Reminder
Hello, all, looking forward to seeing you Thursday.
Note, we’ll have guest presentation from Microsoft on what they are doing with SPDX.
Best,
Phil
GENERAL MEETING
Meeting Time: Thurs,
Hello, all, looking forward to seeing you Thursday.
Note, we’ll have guest presentation from Microsoft on what they are doing with SPDX.
Best,
Phil
GENERAL MEETING
Meeting Time: Thurs,
|
By
Phil Odence
·
#1482
·
|
|
OpenChain Automation Case Study #5 - Running a Supply Chain using open source tooling + SPDX
Recording now available. Part #5 explores how SPDX ISO/IEC 5962 works as a Software Bill of Materials (SBOM) in the supply chain through existing open source tooling for open source
Recording now available. Part #5 explores how SPDX ISO/IEC 5962 works as a Software Bill of Materials (SBOM) in the supply chain through existing open source tooling for open source
|
By
Shane Coughlan
·
#1481
·
|
|
REMINDER: SPDX in Virtual Supply Chain Webinar in 15 minutes (09:00 UTC)
REMINDER: OpenChain Automation Case Study showing SPDX Software Bill of Materials being used in a “virtual supply chain” @ 09:00 UTC.
Join without registration
REMINDER: OpenChain Automation Case Study showing SPDX Software Bill of Materials being used in a “virtual supply chain” @ 09:00 UTC.
Join without registration
|
By
Shane Coughlan
·
#1480
·
|
|
REMINDER: Today is the Automation Case Study “virtual supply chain” showing code going through multiple scanners and maintaining SPDX integrity @ 09:00 UTC
REMINDER: Today is the OpenChain Automation Case Study “virtual supply chain” showing code going through multiple scanners and maintaining SPDX integrity @ 09:00 UTC.
We will hold it on
REMINDER: Today is the OpenChain Automation Case Study “virtual supply chain” showing code going through multiple scanners and maintaining SPDX integrity @ 09:00 UTC.
We will hold it on
|
By
Shane Coughlan
·
#1479
·
|
|
Re: Taxonomy of software supply chain ecosystem?
Hi Vicky
We also have a nice website https://oss-compliance-tooling.org/
Perhaps this is better suited for getting an overview
Ciao
Oliver
Hi Vicky
We also have a nice website https://oss-compliance-tooling.org/
Perhaps this is better suited for getting an overview
Ciao
Oliver
|
By
Oliver Fendt
·
#1478
·
|
|
Re: Taxonomy of software supply chain ecosystem?
You may also want to look at the SLSA framework.
https://slsa.dev/levels
---
Mike Dolan
The Linux Foundation
Office: +1.330.460.3250 Cell: +1.440.552.5322
mdolan@...
---
You may also want to look at the SLSA framework.
https://slsa.dev/levels
---
Mike Dolan
The Linux Foundation
Office: +1.330.460.3250 Cell: +1.440.552.5322
mdolan@...
---
|
By
Michael Dolan
·
#1477
·
|
|
Re: Taxonomy of software supply chain ecosystem?
Yessssss…
It’ll take a while to get through it all, but this will be very helpful for us. Many thanks, Steve and Tooling Group Team!
--V
--
VM (Vicky) Brasseur
Director, Senior
Yessssss…
It’ll take a while to get through it all, but this will be very helpful for us. Many thanks, Steve and Tooling Group Team!
--V
--
VM (Vicky) Brasseur
Director, Senior
|
By
VM (Vicky) Brasseur
·
#1476
·
|
|
Re: Taxonomy of software supply chain ecosystem?
Hi Vicky,
There's been some great work in the OSS Compliance Tooling Group which addresses this – if you're asking what I think you're asking. See:
Hi Vicky,
There's been some great work in the OSS Compliance Tooling Group which addresses this – if you're asking what I think you're asking. See:
|
By
Steve Kilbane
·
#1475
·
|
|
Re: Taxonomy of software supply chain ecosystem?
There's been some industry wide agreement on the taxonomy to use to classify tools here: https://www.ntia.gov/files/ntia/publications/ntia_sbom_tooling_taxonomy-2021mar30.pdf I think the path of
There's been some industry wide agreement on the taxonomy to use to classify tools here: https://www.ntia.gov/files/ntia/publications/ntia_sbom_tooling_taxonomy-2021mar30.pdf I think the path of
|
By
Kate Stewart
·
#1474
·
|
|
Taxonomy of software supply chain ecosystem?
A taxonomy of this SSC ecosystem. I would like to have one, plz&thx.
For instance, looking at this (very much work in progress, just noodling about as I think about things) picture, those items in
A taxonomy of this SSC ecosystem. I would like to have one, plz&thx.
For instance, looking at this (very much work in progress, just noodling about as I think about things) picture, those items in
|
By
VM (Vicky) Brasseur
·
#1473
·
|
|
Re: [spdx-tech] RFC: Creating a fairly complex SPDX document for an open source project (Julia)
Dear Marc-Etienne,
Yay! I was indeed just wondering about this earlier today, so thank
you very much for the notification :)
Best wishes,
Sebastian
Dear Marc-Etienne,
Yay! I was indeed just wondering about this earlier today, so thank
you very much for the notification :)
Best wishes,
Sebastian
|
By
Sebastian Crane
·
#1472
·
|
|
Re: [spdx-tech] RFC: Creating a fairly complex SPDX document for an open source project (Julia)
Hi all,
Great news: ISO SPDX standard is now publicly available at:
https://standards.iso.org/ittf/PubliclyAvailableStandards/
Best regards,
Marc-Etienne
Hi all,
Great news: ISO SPDX standard is now publicly available at:
https://standards.iso.org/ittf/PubliclyAvailableStandards/
Best regards,
Marc-Etienne
|
By
Vargenau, Marc-Etienne (Nokia - FR/Paris-Saclay)
·
#1471
·
|
|
Minutes from Nov 4 SPDX General Meeting
https://wiki.spdx.org/view/General_Meeting/Minutes/2021-11-04
General Meeting/Minutes/2021-11-04
< General Meeting | Minutes
· Attendance: 25
· Lead by Phil Odence
·
https://wiki.spdx.org/view/General_Meeting/Minutes/2021-11-04
General Meeting/Minutes/2021-11-04
< General Meeting | Minutes
· Attendance: 25
· Lead by Phil Odence
·
|
By
Phil Odence
·
#1470
·
|
|
Asia SPDX Meeting- China government data processing draft policy
Came up on the call today. For those interested, here is an overview:
https://asia.nikkei.com/Business/China-tech/New-China-data-transfer-rules-to-be-costly-for-foreign-companies
Asia SPDX
Came up on the call today. For those interested, here is an overview:
https://asia.nikkei.com/Business/China-tech/New-China-data-transfer-rules-to-be-costly-for-foreign-companies
Asia SPDX
|
By
Shane Coughlan
·
#1469
·
|
|
Today's SPDX General Meeting Reminder
Apologies for the late reminder.
Notes:
For Euro folks, time diff is off by an hour as US doesn’t go back to standard time until this weekend
We will have a Google Summer of Code presentation
Apologies for the late reminder.
Notes:
For Euro folks, time diff is off by an hour as US doesn’t go back to standard time until this weekend
We will have a Google Summer of Code presentation
|
By
Phil Odence
·
#1468
·
|
|
Re: Public Domain license identifier
The "public domain" part appears to be the text of the Unlicense, so
I'd assume "MIT OR Unlicense".
Richard
The "public domain" part appears to be the text of the Unlicense, so
I'd assume "MIT OR Unlicense".
Richard
|
By
Richard Fontana
·
#1467
·
|
|
Re: Message Approval Needed - tardyp@gmail.com posted to spdx@lists.spdx.org
Hi Pierre,
I am moving the general SPDX list to BCC and sending this via the SPDX legal list, as that is the right place for this question! Also not - I have approved your message and copied you here
Hi Pierre,
I am moving the general SPDX list to BCC and sending this via the SPDX legal list, as that is the right place for this question! Also not - I have approved your message and copied you here
|
By
J Lovejoy
·
#1466
·
|
|
Public Domain license identifier
Hello,
I am trying to identify this software in term of license expression
https://github.com/nothings/stb
It's is claimed to be "public domain or MIT".
I don't see any license identifier for public
Hello,
I am trying to identify this software in term of license expression
https://github.com/nothings/stb
It's is claimed to be "public domain or MIT".
I don't see any license identifier for public
|
By
Pierre Tardy
·
#1465
·
|
|
Re: SPDX Oct Gen Meeting Minutes
I’m pretty sure President Biden does too.
From:spdx@... <spdx@...> on behalf of Dick Brooks <dick@...>
Date: Friday, October 15, 2021 at 10:33 AM
To: spdx@... <spdx@...>
Subject: Re: [spdx] SPDX
I’m pretty sure President Biden does too.
From:spdx@... <spdx@...> on behalf of Dick Brooks <dick@...>
Date: Friday, October 15, 2021 at 10:33 AM
To: spdx@... <spdx@...>
Subject: Re: [spdx] SPDX
|
By
Phil Odence
·
#1464
·
|
|
Re: SPDX Oct Gen Meeting Minutes
Thanks, Phil. 100% agree with you.
Thanks,
Dick Brooks
Never trust software, always verify and report! ™
http://www.reliableenergyanalytics.com
Email: dick@...
Tel: +1 978-696-1788
Thanks, Phil. 100% agree with you.
Thanks,
Dick Brooks
Never trust software, always verify and report! ™
http://www.reliableenergyanalytics.com
Email: dick@...
Tel: +1 978-696-1788
|
By
Dick Brooks
·
#1463
·
|