Date   

Today's SPDX General Meeting Reminder

Philip Odence
 

They have to stop starting month’s on a Thursday, or I will never remember to get reminders out.

 

Today’s meeting should be just a quick update. Hope you will be able to join.

 

Best,

Phil


L. Philip Odence
Sr. Director/General Manager Black Duck On-Demand
Synopsys Software Integrity Group
800 District Avenue, Suite 201, Burlington, MA 01803-5061
O: +1.781.425.4479, M: +1.781.258.9502, Skype: philip.odence
www.blackducksoftware.com  

 

 

GENERAL MEETING

 

Meeting Time: Thurs, March 1, 8am PDT / 10 am CDT / 11am EDT / 15:00 UTC. http://www.timeanddate.com/worldclock/converter.html


Conf call dial-in:

New dial in number: 415-881-1586

No PIN needed

The weblink for screenshare will stay the same at: 
http://uberconference.com/SPDXTeam

 

Administrative Agenda

Attendance

Minutes Approval: https://wiki.spdx.org/view/General_Meeting/Minutes/2018-02-01

 

Technical Team Report – Phil

 

Legal Team Report – Jilayne/Paul

 

Outreach Team Report – Jack

 

Cross Functional Issues –All

 

 

 


Re: agenda for OSLS

J Lovejoy
 

oops, forgot one of the topics - added to list below!



On Feb 27, 2018, at 8:05 AM, J Lovejoy <opensource@...> wrote:

HI all SPDX teams,

Open Source Leadership Summit is coming up next week and the Linux Foundation has been generous enough to reserve a room at the venue the morning after the event ends for our face-to-face working group.  

We’ll meet on Friday, March 9th, from 9am to lunch. (room name TBD)

We have quite a few cross-functional topics lined up, so we’ll meet as a group. Topics will include:

  • Using Github for SPDX: what is our process for different repos, identify improvements, generate or update documentation
  • Adding more licenses to SPDX License List: from the Linux kernel, other licenses
    • what about lists of non-open source licenses that other people maintain; is there a way to enable that?
  • Updates to spec and next release planning
  • Communicating and explaining relationship and versioning for spec, license list, matching guidelines, tools, etc. Where/how to update website to clarify this?
  • SPDX License List and it’s related material: better organization to make it easier to find - should this all go into an Appendix in the Spec?
  • SPDX “relaxed” - some people are providing SPDX documents that lack some of mandatory fields, thus are not SPDX compliant, but this is still useful info. Should we have a “relaxed” option or some kind of grading for SPDX documents to encourage more use.

Please let me know if I’ve missed anything or if there is any kind of preferred order of topics.  


Thanks,
Jilayne

SPDX Legal Team co-lead
opensource@...


_______________________________________________
Spdx mailing list
Spdx@...
https://lists.spdx.org/mailman/listinfo/spdx


agenda for OSLS

J Lovejoy
 

HI all SPDX teams,

Open Source Leadership Summit is coming up next week and the Linux Foundation has been generous enough to reserve a room at the venue the morning after the event ends for our face-to-face working group.  

We’ll meet on Friday, March 9th, from 9am to lunch. (room name TBD)

We have quite a few cross-functional topics lined up, so we’ll meet as a group. Topics will include:

  • Using Github for SPDX: what is our process for different repos, identify improvements, generate or update documentation
  • Adding more licenses to SPDX License List: from the Linux kernel, other licenses
    • what about lists of non-open source licenses that other people maintain; is there a way to enable that?
  • Updates to spec and next release planning
  • Communicating and explaining relationship and versioning for spec, license list, matching guidelines, tools, etc. Where/how to update website to clarify this?
  • SPDX License List and it’s related material: better organization to make it easier to find - should this all go into an Appendix in the Spec?

Please let me know if I’ve missed anything or if there is any kind of preferred order of topics.  


Thanks,
Jilayne

SPDX Legal Team co-lead
opensource@...



Feb SPDX General Meeting Minutes

Philip Odence
 

https://wiki.spdx.org/view/General_Meeting/Minutes/2018-02-01

 

General Meeting/Minutes/2018-02-01

< General Meeting‎ | Minutes

·         Attendance: 13

·         Lead by Phil Odence

·         Minutes of Jan meeting approved 

Contents

 [hide

·         1 Tech Team Report - Kate

·         2 Outreach Team Report - Jack

·         3 Legal Team Report - Jilayne

·         4 Attendees

Tech Team Report - Kate[edit]

·         Highlights

·         Looking at multiple formats supported

·         Much of January dedicated

·         JSON and YAML

·         Some interest in deprecating

·         Submitted Google SoC project, once again

·         Have usually been accepted in advance

·         Should know by next meeting

·         Can still contribute ideas

 

Outreach Team Report – Jack [edit]

·         Website migration

·         Waiting on date from LF

·         Need a mechanism for pushing some generated pages (licensing/RDF)

·         Today’s meeting will be to lay out a roadmap

·         Linux Leadership Summit

·         Meetings Friday

·         Jilayne sending out notice to try to hustle up participation

·         Anyone who needs an invite can contact Kate

·         FOSSDEM is this weekend

·         Will be streamed from Brussels

·         Legal and Policy track

·         Jilayne speaking

 

Legal Team Report - Jilayne[edit]

·         Major release of license list recently

·         3.1 release

·         Aiming to align 3.2 version with 2.2 spec

·         Undergoing technical and legal review

·         Transitioning to taking advantage of GitHub capabilities

·         Technical stuff on track

·         Reviewing some new licenses, need naming conventions

 

Attendees[edit]

·         Phil Odence, Black Duck/Synpsys

·         Kate Stewart, Linux Foundation

·         Mike Dolan, Linux Foundation

·         Steve Winslow, LF

·         Jeff Luszcz, Flexera

·         Jack Manbeck, TI

·         Denisse Weil, 

·         Robert Musial, Progressive

·         Gary O’Neall, SourceAuditor

·         Bradlee Edmondson, Harvard

·         Matthew Crawford, ARM

·         Jilayne Lovejoy, ARM

·         Michael Herzog- nexB

 

 


SPDX General Meeting Today

Philip Odence
 

Sorry for the late reminder. I confess that Feb 1 snuck up on me.

 

 

 

GENERAL MEETING

 

Meeting Time: Thurs, Feb 1, 8am PDT / 10 am CDT / 11am EDT / 15:00 UTC. http://www.timeanddate.com/worldclock/converter.html


Conf call dial-in:

New dial in number: 415-881-1586

No PIN needed

The weblink for screenshare will stay the same at: 
http://uberconference.com/SPDXTeam

 

Administrative Agenda

Attendance

Minutes Approval: https://wiki.spdx.org/view/General_Meeting/Minutes/2017-12-07  

 

Technical Team Report – Kate/Gary

 

Legal Team Report – Jilayne/Paul

 

Outreach Team Report – Jack

 

Cross Functional Issues –All

 

 


SPDX servers rebooting over the weekend for Spectre/Meltdown remediation.

Kate Stewart
 

Hi,
   Just heard from LF IT that our SPDX site & wiki will be rebooting 
this weekend, as the apply the Meltdown/Spectre remediation.

It should just be down for 5 minutes early this weekend, so this is
mostly for your information, in case you notice something.

Kate


Re: SPDX at Leadership Summit in March

Philip Odence
 

Hello,

If you did not respond to this before, please do now. Thanks

Best regards,

Phil

 

BLACKDUCK
L. Philip Odence
VP/General Manager Black Duck On-Demand
Black Duck Software, Inc.
800 District Avenue, Suite 201
Burlington, MA 01803-5061
E: podence@...
O: +1.781.425.4479
M: +1.781.258.9502
Skype: philip.odence
www.blackducksoftware.com  

 

 

 

From: Philip Odence <podence@...>
Date: Wednesday, November 22, 2017 at 9:46 AM
To: "spdx@..." <spdx@...>, "spdx-tech@..." <spdx-tech@...>, "spdx-biz@..." <spdx-biz@...>, "spdx-legal@..." <spdx-legal@...>
Subject: SPDX at Leadership Summit in March

 

As you may know, the Linux Foundation Leadership Summit is in Sonoma, March 6-8. Additionally, there will be group meetings on the Monday before and Friday after for SPDX and Open Chain respectively.

 

The call for papers was just published. Please consider submitting a paper. There’s an appetite for talks on SPDX tooling, automation or usage.

http://events.linuxfoundation.org/events/open-source-leadership-summit/program/callforproposals

 

Please take this 1 minute survey to give a sense of the likelihood or your attending:

https://www.surveymonkey.com/r/NLX7KXN

 

Best regards,

Phil

 

BLACKDUCK
L. Philip Odence
VP/General Manager Black Duck On-Demand
Black Duck Software, Inc.
800 District Avenue, Suite 201
Burlington, MA 01803-5061
E: podence@...
O: +1.781.425.4479
M: +1.781.258.9502
Skype: philip.odence
www.blackducksoftware.com  

 

 


Thursday SPDX General Meeting Reminder

Philip Odence
 

Happy New Year. No guest speaker this month, therefore should be a fairly short meeting.

 

GENERAL MEETING

 

Meeting Time: Thurs, Jan 4, 8am PDT / 10 am CDT / 11am EDT / 15:00 UTC. http://www.timeanddate.com/worldclock/converter.html


Conf call dial-in:

New dial in number: 415-881-1586

No PIN needed

The weblink for screenshare will stay the same at: 
http://uberconference.com/SPDXTeam

 

Administrative Agenda

Attendance

Minutes Approval: https://wiki.spdx.org/view/General_Meeting/Minutes/2017-12-07

 

Technical Team Report – Kate/Gary

 

Legal Team Report – Jilayne/Paul

 

Outreach Team Report – Jack

 

Cross Functional Issues –All

 

 

 

 


Re: SPDX License List 3.0 is now live!

W. Trevor King
 

On Fri, Dec 29, 2017 at 03:26:47PM -0500, Neal Gompa wrote:
Aww man, you've got to be kidding? You got rid of the "+" signifier
and now we have to write out words?!

I really don't like this change. It makes things more verbose for no
benefit.
This issue has seen a a lot of discussion over the past year (going
back at least as far as May [1]). I'm also not wild about the change
(although there are *some* benefits), but discussing it should
probably be an issue for the spdx-legal@ list only (no need to drag in
spdx@ or spdx-biz@, and the spdx-tech@ folks are probably all
listening on spdx-legal@ anyway). I propose we continue this
discussion on spdx-legal@ only, and have only included the other
spdx-*@ in my message in case folks there are wondering where the
conversation went ;).

Cheers,
Trevor

[1]: https://lists.spdx.org/pipermail/spdx-legal/2017-May/001975.html
Subject: various threads on "only" suffix (for GPL)
Date: Fri, 26 May 2017 11:01:44 -0600
Message-ID: <ED57B88B-2056-44F8-B632-037E91A13907@...>

--
This email may be signed or encrypted with GnuPG (http://www.gnupg.org).
For more information, see http://en.wikipedia.org/wiki/Pretty_Good_Privacy


Re: SPDX License List 3.0 is now live!

Neal Gompa
 

On Fri, Dec 29, 2017 at 12:27 PM, J Lovejoy <opensource@...> wrote:
Hi all,

Thanks to a lot of hard work by various members of the SPDX legal team, we
have now (finally!) gone live with version 3.0 of the SPDX License List -
including use of the new XML format for the master files and changes to the
GNU license identifiers due to collaboration with the FSF. As always, you
can see the new version at the usual place: https://spdx.org/licenses/

There is still some odds and ends to tidy up, and we’ll have a blog post
with a more thorough description of the changes after the 1st of the year.
In the meantime, I hope everyone enjoys the holiday weekend and New Year’s
festivities (in whatever form you choose)!

Thanks again to the massive effort by the SPDX legal team and tech team
members who have tirelessly made this happen!
Aww man, you've got to be kidding? You got rid of the "+" signifier
and now we have to write out words?!

I really don't like this change. It makes things more verbose for no benefit.



--
真実はいつも一つ!/ Always, there's only one truth!


Re: SPDX License List 3.0 is now live!

Philip Odence
 

AMAZING!

And, of course, Jilayne deserves kudos beyond measure.

 

From: <spdx-bounces@...> on behalf of Jilayne Lovejoy <opensource@...>
Date: Friday, December 29, 2017 at 12:27 PM
To: SPDX-legal <spdx-legal@...>
Cc: "spdx-tech@..." <spdx-tech@...>, SPDX-biz <spdx-biz@...>, SPDX-general <spdx@...>
Subject: SPDX License List 3.0 is now live!

 

Hi all,

 

Thanks to a lot of hard work by various members of the SPDX legal team, we have now (finally!) gone live with version 3.0 of the SPDX License List - including use of the new XML format for the master files and changes to the GNU license identifiers due to collaboration with the FSF. As always, you can see the new version at the usual place: https://spdx.org/licenses/

 

There is still some odds and ends to tidy up, and we’ll have a blog post with a more thorough description of the changes after the 1st of the year.  In the meantime, I hope everyone enjoys the holiday weekend and New Year’s festivities (in whatever form you choose)!

 

Thanks again to the massive effort by the SPDX legal team and tech team members who have tirelessly made this happen!

 

Cheers,

 

Jilayne

 

SPDX Legal Team co-lead
opensource@...

 


SPDX License List 3.0 is now live!

J Lovejoy
 

Hi all,

Thanks to a lot of hard work by various members of the SPDX legal team, we have now (finally!) gone live with version 3.0 of the SPDX License List - including use of the new XML format for the master files and changes to the GNU license identifiers due to collaboration with the FSF. As always, you can see the new version at the usual place: https://spdx.org/licenses/

There is still some odds and ends to tidy up, and we’ll have a blog post with a more thorough description of the changes after the 1st of the year.  In the meantime, I hope everyone enjoys the holiday weekend and New Year’s festivities (in whatever form you choose)!

Thanks again to the massive effort by the SPDX legal team and tech team members who have tirelessly made this happen!

Cheers,

Jilayne

SPDX Legal Team co-lead
opensource@...



Re: FreeBSD adding in SPDX license identifers too...

Shane Martin Coughlan <shane@...>
 

Hi Kate

I think this is just as exciting as the kernel development. It’s a fantastic example of cross-community collaboration. I’ve shared this news on social media and also wanted to throw my hat into the ring to lend a hand where useful.

Regards

Shane

On Dec 8, 2017, at 04:02 , Kate Stewart <kstewart@...> wrote:

And in addition to Linux getting serious in terms of adding SPDX identifiers,
we also have FreeBSD applying them to their code base. 

Kate

---------- Forwarded message ----------
From: Pedro Giffuni <pfg@...>
Date: Thu, Dec 7, 2017 at 11:31 AM
Subject: SPDX ID-tag as part of FreeBSD preferred license
To: SPDX-legal <spdx-legal@...>


Hi legal-team!

As a follow up to the monthly meeting (thanks for the invitation), here is the link to FreeBSD preferred license:

https://www.freebsd.org/doc/en_US.ISO8859-1/articles/committers-guide/pref-license.html

Which of course now includes the SPDX ID-license identifier :).

Best regards,

Pedro.

_______________________________________________
Spdx-legal mailing list
Spdx-legal@...
https://lists.spdx.org/mailman/listinfo/spdx-legal

_______________________________________________
Spdx mailing list
Spdx@...
https://lists.spdx.org/mailman/listinfo/spdx


Re: SPDX license identifiers in the Linux kernel

Shane Martin Coughlan <shane@...>
 

Hi Kate

This is tremendous news and great progress. I’ve shared it on social media as well.

Regards

Shane

On Dec 8, 2017, at 03:34 , Kate Stewart <kstewart@...> wrote:


Some of you have already noticed that this started in 2016
but as of 4.14, we had a major breakthrough and cleanup
of all the files without a license reference all had SDPX identifiers
added to them. 

There are some good writeups of the work emerging.

LWN has an excellent summary with links to more references at:


There's also a good blog by one of the kernel developers 
from Samsung explaining how to add the identifiers as well
that came out last week.


Some other excellent documentation that has emerged
including how to integrate SPDX one liners into a project 
is available at:  https://reuse.software/practices/  which the linux kernel
developers have consulted and worked with for the kernel. 

Thanks, Kate
_______________________________________________
Spdx mailing list
Spdx@...
https://lists.spdx.org/mailman/listinfo/spdx


FreeBSD adding in SPDX license identifers too...

Kate Stewart
 

And in addition to Linux getting serious in terms of adding SPDX identifiers,
we also have FreeBSD applying them to their code base. 

Kate

---------- Forwarded message ----------
From: Pedro Giffuni <pfg@...>
Date: Thu, Dec 7, 2017 at 11:31 AM
Subject: SPDX ID-tag as part of FreeBSD preferred license
To: SPDX-legal <spdx-legal@...>


Hi legal-team!

As a follow up to the monthly meeting (thanks for the invitation), here is the link to FreeBSD preferred license:

https://www.freebsd.org/doc/en_US.ISO8859-1/articles/committers-guide/pref-license.html

Which of course now includes the SPDX ID-license identifier :).

Best regards,

Pedro.

_______________________________________________
Spdx-legal mailing list
Spdx-legal@...
https://lists.spdx.org/mailman/listinfo/spdx-legal


SPDX license identifiers in the Linux kernel

Kate Stewart
 


Some of you have already noticed that this started in 2016
but as of 4.14, we had a major breakthrough and cleanup
of all the files without a license reference all had SDPX identifiers
added to them. 

There are some good writeups of the work emerging.

LWN has an excellent summary with links to more references at:


There's also a good blog by one of the kernel developers 
from Samsung explaining how to add the identifiers as well
that came out last week.


Some other excellent documentation that has emerged
including how to integrate SPDX one liners into a project 
is available at:  https://reuse.software/practices/  which the linux kernel
developers have consulted and worked with for the kernel. 

Thanks, Kate


SPDX General Meeting Minutes

Gary O'Neall
 

The minutes for the general meeting have been posted at https://wiki.spdx.org/view/General_Meeting/Minutes/2017-12-07

 

Gary

 

-------------------------------------------------

Gary O'Neall

Principal Consultant

Source Auditor Inc.

Mobile: 408.805.0586

Email: gary@...

 


Thurs SPDX General Meeting (with special guest speaker) Reminder

Philip Odence
 

We are fortunate to have Pedro Giffuni speaking with us on Thursday. Pedro is a Mechanical Engineer by profession but has been using FreeBSD since 1997, and eventually became a project committer in 2012. As part of his involvement in FreeBSD he also became an OpenOffice developer and was involved in the transition from a copyleft project under Oracle's umbrella to a permissively licensed project in order to become an Apache Software Foundation Top Level Project.

Outline of the talk:
- How is Licensing handled in Open Source projects.
- About FreeBSD and it's objectives.
- Why SPDX is important to FreeBSD.
- Strategy for adoption.
- Progress Report.
- Practical issues.
- Open questions.
_______

 

Apologies, I have had a conflict arise, so Gary will be hosting.

 

GENERAL MEETING

 

Meeting Time: Thurs, Dec 7, 8am PDT / 10 am CDT / 11am EDT / 15:00 UTC. http://www.timeanddate.com/worldclock/converter.html


Conf call dial-in:

New dial in number: 415-881-1586

No PIN needed

The weblink for screenshare will stay the same at: 
http://uberconference.com/SPDXTeam

 

Administrative Agenda

Attendance

Minutes Approval: https://wiki.spdx.org/view/General_Meeting/Minutes/2017-11-02

Guest Presenation – Pedro

 

Technical Team Report – Kate/Gary

 

Legal Team Report – Jilayne/Paul

 

Outreach Team Report – Jack

 

Cross Functional Issues –All

 

 

 


SPDX at Leadership Summit in March

Philip Odence
 

As you may know, the Linux Foundation Leadership Summit is in Sonoma, March 6-8. Additionally, there will be group meetings on the Monday before and Friday after for SPDX and Open Chain respectively.

 

The call for papers was just published. Please consider submitting a paper. There’s an appetite for talks on SPDX tooling, automation or usage.

http://events.linuxfoundation.org/events/open-source-leadership-summit/program/callforproposals

 

Please take this 1 minute survey to give a sense of the likelihood or your attending:

https://www.surveymonkey.com/r/NLX7KXN

 

Best regards,

Phil

 

BLACKDUCK
L. Philip Odence
VP/General Manager Black Duck On-Demand
Black Duck Software, Inc.
800 District Avenue, Suite 201
Burlington, MA 01803-5061
E: podence@...
O: +1.781.425.4479
M: +1.781.258.9502
Skype: philip.odence
www.blackducksoftware.com  

 

 


SPDX General Meeting 2018

Philip Odence
 

Note that we will be using a different dial in and different URL for future SPDX General Meetings.


Apologies for my having to send a new invitation. For some reason Outlook won’t let me update the original. So, you’ll have to delete the old. I called this one 2018, so there would be no confusion. (I hope)


Please accept so this recurring meeting is on your calendar, however no need to respond.



New dial in number: 415-881-1586

No PIN needed

The weblink for screenshare will stay the same at:
http://uberconference.com/SPDXTeam



MEETING MINUTES FOR REVIEW: http://spdx.org/wiki/meeting-minutes-and-decisions