|
Re: SPDX Thurs General Meeting Reminder
It was not recorded and I don’t think we’ve ever really done that for general meetings specifically nor for other meetings for the most part (not to say we can’t, but that has been and is the
It was not recorded and I don’t think we’ve ever really done that for general meetings specifically nor for other meetings for the most part (not to say we can’t, but that has been and is the
|
By
J Lovejoy
·
#1533
·
|
|
Re: [spdx-defects] [spdx] VEX integration in SPDX
#spdx
Sandeep,
NIST also recommends that vendors and consumers “Maintain vendor vulnerability disclosure reports at the SBOM component level.” See 5/5
Sandeep,
NIST also recommends that vendors and consumers “Maintain vendor vulnerability disclosure reports at the SBOM component level.” See 5/5
|
By
Dick Brooks
·
#1532
·
|
|
Re: [spdx-defects] [spdx] VEX integration in SPDX
#spdx
Hi Sandeep,
The SPDX Defects working group announced security enhancements to theExternalReference section of the spec as well as an explanatory Annex about how to include security information in
Hi Sandeep,
The SPDX Defects working group announced security enhancements to theExternalReference section of the spec as well as an explanatory Annex about how to include security information in
|
By
Rose Judge
·
#1531
·
|
|
Re: SPDX Thurs General Meeting Reminder
Will the meeting be recorded? I have a conflict, but would love to listen to the updates. Thanks.
Will the meeting be recorded? I have a conflict, but would love to listen to the updates. Thanks.
|
By
May Wang
·
#1530
·
|
|
SPDX Thurs General Meeting Reminder
We will start this month’s meeting with an informal presentation from Kate about the OpenSSF “White House meeting” and implications for
We will start this month’s meeting with an informal presentation from Kate about the OpenSSF “White House meeting” and implications for
|
By
Phil Odence
·
#1529
·
|
|
VEX integration in SPDX
#spdx
Hi ,
Is there any roadmap to integrate VEX to with SPDX ? Or is there already way in current SPDX specification to integrate vulnerability information ?
Regards
Sandeep
Hi ,
Is there any roadmap to integrate VEX to with SPDX ? Or is there already way in current SPDX specification to integrate vulnerability information ?
Regards
Sandeep
|
By
Patil, Sandeep
·
#1528
·
|
|
Re: End Of Life Tag in spdx
#spdx
Armijn raises a valid concern. We’ve avoided dynamic information in the past, but even with version 1.0 you could argue the “Concluded License” could change over time if new information is
Armijn raises a valid concern. We’ve avoided dynamic information in the past, but even with version 1.0 you could argue the “Concluded License” could change over time if new information is
|
By
Gary O'Neall
·
#1527
·
|
|
Re: End Of Life Tag in spdx
#spdx
Sort of. Security information is even more likely to change after release, EOL for open source components supported by the community may, but much less frequently.
Thinking so far, is that this
Sort of. Security information is even more likely to change after release, EOL for open source components supported by the community may, but much less frequently.
Thinking so far, is that this
|
By
Kate Stewart
·
#1526
·
|
|
Re: End Of Life Tag in spdx
#spdx
Steve,
Regarding: “I have no opinion on end-of-life either way, but wouldn’t the same argument apply to security vulnerabilities?”
Yes, if a software vendor chooses to list each known
Steve,
Regarding: “I have no opinion on end-of-life either way, but wouldn’t the same argument apply to security vulnerabilities?”
Yes, if a software vendor chooses to list each known
|
By
Dick Brooks
·
#1525
·
|
|
Re: End Of Life Tag in spdx
#spdx
Armijn said:
> Current information inside SPDX documents is largely static […]
> This would make SPDX a lot more cumbersome, as not only do the documents need to be generated, but they also need
Armijn said:
> Current information inside SPDX documents is largely static […]
> This would make SPDX a lot more cumbersome, as not only do the documents need to be generated, but they also need
|
By
Steve Kilbane
·
#1524
·
|
|
Re: End Of Life Tag in spdx
#spdx
I agree: “I would suggest to keep this information "out of band" and not inside SPDX documents”
Thanks,
Dick Brooks
Active Member of the CISA Critical Manufacturing Sector,
Sector
I agree: “I would suggest to keep this information "out of band" and not inside SPDX documents”
Thanks,
Dick Brooks
Active Member of the CISA Critical Manufacturing Sector,
Sector
|
By
Dick Brooks
·
#1523
·
|
|
Re: End Of Life Tag in spdx
#spdx
hello,
I would suggest to keep this information "out of band" and not inside SPDX documents. Current information inside SPDX documents is largely static: package, license,
hello,
I would suggest to keep this information "out of band" and not inside SPDX documents. Current information inside SPDX documents is largely static: package, license,
|
By
Armijn Hemel - Tjaldur Software Governance Solutions
·
#1522
·
|
|
Re: SPDXID
#spdx
Hi Sandeep,
Although the SPDX ID is internal to SPDX documents, you can refer to an SPDX ID in a different document using the SPDX Document identifier as defined in section 6.6. So the statement
Hi Sandeep,
Although the SPDX ID is internal to SPDX documents, you can refer to an SPDX ID in a different document using the SPDX Document identifier as defined in section 6.6. So the statement
|
By
Gary O'Neall
·
#1521
·
|
|
Re: SPDXID
#spdx
Hi Gary,
Thanks for reply, then SPDXID will be mostly internal ID and can not be referenced externally, Do you think this might need some change in SPDXID documentation statement ?
"Uniquely
Hi Gary,
Thanks for reply, then SPDXID will be mostly internal ID and can not be referenced externally, Do you think this might need some change in SPDXID documentation statement ?
"Uniquely
|
By
Patil, Sandeep
·
#1520
·
|
|
FYI: SPDX in the OpenSSF Mobilization Plan
Some of you probably know that OpenSSF met with a bunch of US Federal organizations in Washington DC last week to discuss cyber security wrt the open source software supply chain. (our own Kate and
Some of you probably know that OpenSSF met with a bunch of US Federal organizations in Washington DC last week to discuss cyber security wrt the open source software supply chain. (our own Kate and
|
By
VM (Vicky) Brasseur
·
#1519
·
|
|
Re: SPDXID
#spdx
Hi Sandeep – Moving the conversation over to the SPDX-tech mailing list.
Unfortunately, adding in a CPE ID or pURL would include characters disallowed in the SPDX ID.
Fortunately, there is a
Hi Sandeep – Moving the conversation over to the SPDX-tech mailing list.
Unfortunately, adding in a CPE ID or pURL would include characters disallowed in the SPDX ID.
Fortunately, there is a
|
By
Gary O'Neall
·
#1518
·
|
|
Re: SPDX and NTIA SBOM Minimum elements
#spdx
This is how Microsoft has approached this:
https://devblogs.microsoft.com/engineering-at-microsoft/generating-software-bills-of-materials-sboms-with-spdx-at-microsoft/
The one thing I’d add is
This is how Microsoft has approached this:
https://devblogs.microsoft.com/engineering-at-microsoft/generating-software-bills-of-materials-sboms-with-spdx-at-microsoft/
The one thing I’d add is
|
By
William Bartholomew (CELA)
·
#1517
·
|
|
Re: SPDX and NTIA SBOM Minimum elements
#spdx
You’re welcome.
You will most likely need SPDX V2.3 if you have any “FILE” components that need to specify version info. The new PackagePurpose field supports the version info for “FILE”
You’re welcome.
You will most likely need SPDX V2.3 if you have any “FILE” components that need to specify version info. The new PackagePurpose field supports the version info for “FILE”
|
By
Dick Brooks
·
#1516
·
|
|
Re: SPDX and NTIA SBOM Minimum elements
#spdx
Thanks you Dick, This is useful
Thanks you Dick, This is useful
|
By
Patil, Sandeep
·
#1515
·
|
|
Re: SPDX and NTIA SBOM Minimum elements
#spdx
NTIA Framing document has the mapping you seek: see page 13
https://www.ntia.gov/files/ntia/publications/ntia_sbom_framing_2nd_edition_20211021.pdf
However the “EO 14028 NTIA min element list
NTIA Framing document has the mapping you seek: see page 13
https://www.ntia.gov/files/ntia/publications/ntia_sbom_framing_2nd_edition_20211021.pdf
However the “EO 14028 NTIA min element list
|
By
Dick Brooks
·
#1514
·
|