|
Re: SPDX Oct Gen Meeting Minutes
That’s great, Dick. A very important direction for us IMO.
From:spdx@... <spdx@...> on behalf of Dick Brooks <dick@...>
Date: Friday, October 15, 2021 at 9:49 AM
To: spdx@... <spdx@...>
Subject:
That’s great, Dick. A very important direction for us IMO.
From:spdx@... <spdx@...> on behalf of Dick Brooks <dick@...>
Date: Friday, October 15, 2021 at 9:49 AM
To: spdx@... <spdx@...>
Subject:
|
By
Phil Odence
·
#1462
·
|
|
Re: SPDX Oct Gen Meeting Minutes
Thanks, Phil.
Kate/Gary, please let me know if there is anything I can do to help with a cyber risk assessment use case – I’m happy to contribute and learn.
Thanks,
Dick
Thanks, Phil.
Kate/Gary, please let me know if there is anything I can do to help with a cyber risk assessment use case – I’m happy to contribute and learn.
Thanks,
Dick
|
By
Dick Brooks
·
#1461
·
|
|
Re: SPDX Oct Gen Meeting Minutes
Dick, apologies for the slow response. Frankly we had a pretty tech team update this time. I think it’s a good idea to get some specifics from profile sub-teams next month and (herewith) suggest to
Dick, apologies for the slow response. Frankly we had a pretty tech team update this time. I think it’s a good idea to get some specifics from profile sub-teams next month and (herewith) suggest to
|
By
Phil Odence
·
#1460
·
|
|
Re: SPDX Oct Gen Meeting Minutes
Phil,
I had to attend a CISA meeting held at the same time as the SPDX meeting; I didn’t see any info in the minutes regarding the work on profiles. Any updates to share on the
Phil,
I had to attend a CISA meeting held at the same time as the SPDX meeting; I didn’t see any info in the minutes regarding the work on profiles. Any updates to share on the
|
By
Dick Brooks
·
#1459
·
|
|
SPDX Oct Gen Meeting Minutes
There were a few of anonymous participants that I did not include in the count. It would be helpful to get names for these minutes and to use them for future meetings. Also, while it’s not required
There were a few of anonymous participants that I did not include in the count. It would be helpful to get names for these minutes and to use them for future meetings. Also, while it’s not required
|
By
Phil Odence
·
#1458
·
|
|
Thursday's SPDX General Meeting Reminder
A couple of special items for this month’s meeting:
Quick status of updated SPDX governance
Short presentation by VM (Vicky) Brasseur, Director, Senior Strategy Advisor at Wipro. Her company has
A couple of special items for this month’s meeting:
Quick status of updated SPDX governance
Short presentation by VM (Vicky) Brasseur, Director, Senior Strategy Advisor at Wipro. Her company has
|
By
Phil Odence
·
#1457
·
|
|
Re: SPDX Goes ISO
Thanks, Phil – I’m very much looking forward to the configurable profiles capability.
Thanks,
Dick Brooks
Never trust software, always verify and report!
Thanks, Phil – I’m very much looking forward to the configurable profiles capability.
Thanks,
Dick Brooks
Never trust software, always verify and report!
|
By
Dick Brooks
·
#1456
·
|
|
Re: SPDX Goes ISO
Yes, understood. Thanks, Dick. For that use case, the President was more concerned with a cyber attack that a license violation. This is the point of evolving SPDX to be “configurable” with
Yes, understood. Thanks, Dick. For that use case, the President was more concerned with a cyber attack that a license violation. This is the point of evolving SPDX to be “configurable” with
|
By
Phil Odence
·
#1455
·
|
|
Re: SPDX Goes ISO
Die 14. 09. 21 et hora 17:52 Phil Odence via lists.spdx.org scripsit:
I know. I’m just excited by the prospect of synergies and more use of SPDX in
the wild!
I can already see how the wider
Die 14. 09. 21 et hora 17:52 Phil Odence via lists.spdx.org scripsit:
I know. I’m just excited by the prospect of synergies and more use of SPDX in
the wild!
I can already see how the wider
|
By
Matija Šuklje
·
#1454
·
|
|
Re: SPDX Goes ISO
Phil,
Minimal SBOM elements specified by NTIA for Executive Order (EO) 14028 do not include license data element requirements (see attached). The EO and the NTIA SBOM minimal
Phil,
Minimal SBOM elements specified by NTIA for Executive Order (EO) 14028 do not include license data element requirements (see attached). The EO and the NTIA SBOM minimal
|
By
Dick Brooks
·
#1453
·
|
|
Re: SPDX Goes ISO
Thanks, Matija. Absolutely not just license compliance. Security too is a big driver and an important part/direction of SPDX.
From:spdx@... <spdx@...> on behalf of Matija Šuklje <matija@...>
Date:
Thanks, Matija. Absolutely not just license compliance. Security too is a big driver and an important part/direction of SPDX.
From:spdx@... <spdx@...> on behalf of Matija Šuklje <matija@...>
Date:
|
By
Phil Odence
·
#1452
·
|
|
Re: SPDX Goes ISO
Congratulations!
This is indeed a massive step for the software world, and hopefully not just
in terms of license compliance!
hip hip hurrah!
Matija
--
Congratulations!
This is indeed a massive step for the software world, and hopefully not just
in terms of license compliance!
hip hip hurrah!
Matija
--
|
By
Matija Šuklje
·
#1451
·
|
|
Re: SPDX Goes ISO
The content that went into the standard is the same as what is
in our github repo today, and a pretty version is at: https://spdx.github.io/spdx-spec/.
The sources for the 2.2.1 are at:
The content that went into the standard is the same as what is
in our github repo today, and a pretty version is at: https://spdx.github.io/spdx-spec/.
The sources for the 2.2.1 are at:
|
By
Kate Stewart
·
#1450
·
|
|
Re: SPDX Goes ISO
I believe that is correct. It seems an odd systems, but as I understand it, it’s not unusual to have free and paid for versions of specs with the same content. Openchain is, I believe, and example
I believe that is correct. It seems an odd systems, but as I understand it, it’s not unusual to have free and paid for versions of specs with the same content. Openchain is, I believe, and example
|
By
Phil Odence
·
#1449
·
|
|
Re: SPDX Goes ISO
I’ll defer to Phil or Kate for an official answer, but my understanding is that SPDX will continue to publish the specification directly from the SPDX project to the community, but certain versions
I’ll defer to Phil or Kate for an official answer, but my understanding is that SPDX will continue to publish the specification directly from the SPDX project to the community, but certain versions
|
By
William Bartholomew
·
#1448
·
|
|
Re: SPDX Goes ISO
It now costs CHF198 to buy. This is the ISO way, and I think it's literally criminal.
As in: violates UN Charter of Human Rights.
If it doesn't wind up on the Publically Available Standards list,
It now costs CHF198 to buy. This is the ISO way, and I think it's literally criminal.
As in: violates UN Charter of Human Rights.
If it doesn't wind up on the Publically Available Standards list,
|
By
Michael Richardson
·
#1447
·
|
|
Re: SPDX Goes ISO
"I guess it will..." does not sound very reassuring, to be honest 🤠
So will it definitely become an "ISO Publicly Available Standard" and is that just a question of time?
Viele Grü0e,
Henk
"I guess it will..." does not sound very reassuring, to be honest 🤠
So will it definitely become an "ISO Publicly Available Standard" and is that just a question of time?
Viele Grü0e,
Henk
|
By
Henk Birkholz
·
#1446
·
|
|
Re: SPDX Goes ISO
I guess it will…
The OpenChain one took a couple of months to appear, though, so I don’t know how quickly this gets updated.
-- zvr
I guess it will…
The OpenChain one took a couple of months to appear, though, so I don’t know how quickly this gets updated.
-- zvr
|
By
Alexios Zavras
·
#1445
·
|
|
Re: SPDX Goes ISO
This is wonderful news! Congrats to Kate and everyone else who had a hand in this! Hopefully this means wider adoption and growth for the future!
Zachary Fetters
Freelance graphic/web
This is wonderful news! Congrats to Kate and everyone else who had a hand in this! Hopefully this means wider adoption and growth for the future!
Zachary Fetters
Freelance graphic/web
|
By
Zachary Fetters
·
#1444
·
|
|
Re: SPDX Goes ISO
Since the standard was not developed by ISO itself, will the standard be publicly available athttps://standards.iso.org/ittf/PubliclyAvailableStandards/ ?
I think it should.
Do we know?
Since the standard was not developed by ISO itself, will the standard be publicly available athttps://standards.iso.org/ittf/PubliclyAvailableStandards/ ?
I think it should.
Do we know?
|
By
Vargenau, Marc-Etienne (Nokia - FR/Paris-Saclay)
·
#1443
·
|