Date   

Re: Tutorials, sample RDF files

Bill Schineller
 

Hi Marvin,
Welcome to the list and thanks for your interest!

Is this you?

https://www.openhub.net/people?query=Marvin%20Humphrey



Regarding samples and tools, our spdx-tools repo is mirrored here:
https://github.com/spdx/tools


Primary developer for those tools is Gary O'Neall, with some contributions from others.

Have a look, and I'm certain that Gary and some hands-on tech team contributors would be happy to guide you through their use.

- Bill



Bill Schineller
VP Engineering - KnowledgeBase
Black Duck Software
781-425-4405
508-308-5921 (cell)
bschineller@...

On 2/8/16, 2:49 PM, "spdx-bounces@... on behalf of Marvin Humphrey" <spdx-bounces@... on behalf of marvin@...> wrote:

Greetings,

I'm an active contributor at the Apache Software Foundation with regards to
release policy and licensing. I'd like to explore the possibility of having
an Apache project supply SPDX data in a release.

I'm imagining that we would supply SPDX data as an RDF file, because our
official releases are 100% source. I also imagine that we would want to
either hand-craft those files or generate them using open source tools.

Can you point me to some sample RDF files, tutorials, or documentation
explaining how I would go about that? It's been surprisingly difficult to
track down such materials.

Best,

Marvin Humphrey
_______________________________________________
Spdx mailing list
Spdx@...
https://lists.spdx.org/mailman/listinfo/spdx


Tutorials, sample RDF files

Marvin Humphrey <marvin@...>
 

Greetings,

I'm an active contributor at the Apache Software Foundation with regards to
release policy and licensing. I'd like to explore the possibility of having
an Apache project supply SPDX data in a release.

I'm imagining that we would supply SPDX data as an RDF file, because our
official releases are 100% source. I also imagine that we would want to
either hand-craft those files or generate them using open source tools.

Can you point me to some sample RDF files, tutorials, or documentation
explaining how I would go about that? It's been surprisingly difficult to
track down such materials.

Best,

Marvin Humphrey


Files for call today

Manbeck, Jack
 

Copyright snippet from spdx document:

 

FileCopyrightText: <text>copyright (c) 1999

* boris fomitchev

*

* this material is provided "as is", with absolutely no warranty expressedcopyright (c) 1999

* silicon graphics computer systems, inc.</text>

 

 

Jack

 


Re: Thursday SPDX General Meeting Reminder

Manbeck, Jack
 

I’ll use the uber conference for a little show and tell. Nothing spectacular.

 

Best Regards,

 

Jack Manbeck

 

 

From: spdx-bounces@... [mailto:spdx-bounces@...] On Behalf Of Philip Odence
Sent: Wednesday, February 03, 2016 7:50 AM
To: spdx@...
Subject: Thursday SPDX General Meeting Reminder

 

There were some issues with meeting invitations. You should have a meeting in your calendar with the new dial in info, also included below

 

I have a conflict and will not be able to attend this session. Kirsten will host and take notes on my behalf. Big thanks, Kirsten!

 

Special “guest" speaker this month is our own Jack Manbeck. He will be talking about TI’s use of and plans for SPDX.

 

 

GENERAL MEETING

 

Meeting Time: Thurs, Jan 4, 8am PDT / 10 am CDT / 11am EDT / 15:00 UTC. http://www.timeanddate.com/worldclock/converter.html


Conf call dial-in:

Optional dial in number: 877-297-7470

Alternate number: 512-910-4433

No PIN needed

 

 

Administrative Agenda

Attendance

 

 

Technical Team Report – Kate 

 

 

Legal Team Report – Jilayne

 

 

Business Team Report – Jack

 

 

Cross Functional Issues - Kirsten

 


Thursday SPDX General Meeting Reminder

Philip Odence
 

There were some issues with meeting invitations. You should have a meeting in your calendar with the new dial in info, also included below

I have a conflict and will not be able to attend this session. Kirsten will host and take notes on my behalf. Big thanks, Kirsten!

Special “guest" speaker this month is our own Jack Manbeck. He will be talking about TI’s use of and plans for SPDX.


GENERAL MEETING

Meeting Time: Thurs, Jan 4, 8am PDT / 10 am CDT / 11am EDT / 15:00 UTC. http://www.timeanddate.com/worldclock/converter.html

Conf call dial-in:
Optional dial in number: 877-297-7470
Alternate number: 512-910-4433
No PIN needed

 
Administrative Agenda
Attendance


Technical Team Report – Kate 


Legal Team Report – Jilayne


Business Team Report – Jack


Cross Functional Issues - Kirsten


SPDX General Meeting

Philip Odence
 

I am updating the bridge info. Tried this once before but I think I only modified the January instance. Apologies.

Please accept so this recurring meeting is on your calendar, however no need to respond.


Optional dial in number: 877-297-7470
Alternate number: 512-910-4433
No PIN needed

MEETING MINUTES FOR REVIEW: http://spdx.org/wiki/meeting-minutes-and-decisions


SPDX January General Meeting Minutes

Philip Odence
 




General Meeting/Minutes/2016-1-07

  • Attendance: 9
  • Lead by Phil Odence
  • Minutes of Dec meeting approved


Tech Team Report - Kate/Gary[edit]

  • Good progress on spec
    • Settled on approaches for both
      • Snippets
      • External References
    • Jilayne assured consistency None/Assertion
  • Now working on
    • Making sure that external identifiers support security
  • Joint call upcoming with Legal Team on template language
    • Have pushed a couple of issues/ to Legal Team
  • Re-examining native from of spec under dev
    • Notion is to make it better accessible in Git Hub
    • Plan for full walk through at Collab Summit
  • Tools
    • Did maintenance release over the last week or so
    • Addressed reported bugs
    • Some other bug fixes
    • Gary will go back to the bug reporter to see if they might speak at a future General Meeting.


Outreach Team Report - Phil (Jack supplied notes in absentia)[edit]

  • Haven’t had our first meeting of the year, that will be next week.
  • I also haven’t heard from the LF yet on the new website. Im going to ping them this week to see where they are.
    • Talked to Craig.
      • Working on some technical issues with generated license list 
      • Next week we should be able to review and update
  • Were still hammering out an outreach plan on the wiki. Id like to to be done with it by the end of January and then we can share plans.


Legal Team Report - Jilayne[edit]

  • License List 2.3 is now live
    • 3 new licenses
    • 1 new exception
    • Now starting to see markup on some of the headers; rest are in process
  • Call today
    • Continuing to look at markup
      • Form 
      • Maintenance Process


Cross Functional Topics - Phil[edit]


Attendees[edit]

  • Phil Odence, Black Duck
  • Gary O’Neill, SourceAuditor 
  • Scott Sterling, Palamida
  • Yev Bronshteyn, Black Duck
  • Kate Stewart, Linux Foundation
  • Pierre LaPointe, nexB 
  • Jilayne Lovejoy, ARM
  • Kirsten Newcomer, Black Duck
  • Mark Gisi, Wind River


SPDX License List v2.3 released

J Lovejoy
 

And available in the usual places:
- “human-friendly” web pages: http://spdx.org/licenses/
- master files available here: http://git.spdx.org/?p=license-list.git;a=summary (use 2.3 tag)
- info on different ways to access the SPDX License List available here: http://wiki.spdx.org/images/SPDX-TR-2014-2.v1.0.pdf

Changes for v2.3:
- 3 new licenses; 1 new exception
- matching markup added to many standard headers (still more work to be done here)
- various minor formatting improvements/fixes

Jilayne Lovejoy
SPDX Legal Team co-lead
opensource@...



SPDX General Meeting

Philip Odence
 

Please accept so this recurring meeting is on your calendar, however no need to respond.

Optional dial in number: 877-297-7470
Alternate number: 512-910-4433
No PIN needed

MEETING MINUTES FOR REVIEW: http://spdx.org/wiki/meeting-minutes-and-decisions


Thursday SPDX General Meeting Reminder - IMPORTANT- NOTE NEW BRIDGE INFO

Philip Odence
 

As per the capital letters, be sure to note the new dial-in numbers below. I will re-issue the calendar invite with this included.

No special presentation this week, so I expect the meeting to be about 30 minutes.

GENERAL MEETING

Meeting Time: Thurs, Jan 7, 8am PDT / 10 am CDT / 11am EDT / 15:00 UTC. http://www.timeanddate.com/worldclock/converter.html

Conf call dial-in:
Optional dial in number: 877-297-7470
Alternate number: 512-910-4433
No PIN needed

 
Administrative Agenda
Attendance


Technical Team Report – Kate 


Legal Team Report – Jilayne


Business Team Report – Jack


Cross Functional Issues – Phil


SPDX Dec General Meeting Minutes

Philip Odence
 



General Meeting/Minutes/2015-12-03

  • Attendance: 7
  • Lead by Phil Odence
  • Minutes of Nov meeting approved

Tech Team Report - Gary[edit]

  • Only 2 tech meetings due to Thanksgiving
  • Code Snippets
    • Candidate proposal in GoogleDocs for Review
    • Background
      • A bit controversial due to legit concern that it adds a lot of effort
      • Identification at the line level requires substantial extra work
    • So, snippets are optional
    • Decision driven by important use case- Java script files
      • As they tend to bundle together a number of downloadable chunks in one file
    • For many other use cases, it may not be used much
    • Implementation
      • Just added snippet level similar to Package and File
        • Additionally adds byte range
        • Snippets relate to files analogously to how files relate to packages
  • External ID discussion is back on the table with snippet work starting to wind down
  • Tools
    • A lot of good community contribution
      • individuals from a variety of organizations- Linux, other open source (eg NPM community), some users (e.g. Black Duck)
    • Should be releasing a new rev of the SPDX tools in the next few weeks
    • Question: relation to Stefano’s work with Debian tooling described at LinuxCon Europe
      • Enabling Debian copyright files to auto-gen SPDX files
      • Gary will discuss with Kate


Legal Team Report - Jilayne/Paul[edit]

    • Went over the list of license and exceptions list
    • Added 2 or 3 licenses and some exceptions
    • Entertaining new proposal for mark up format
      • involved Tech Team as well
      • needs to be resurrected


Outreach Team Report - Jack[edit]

  • New Website
    • Work was put on hold by LF for some higher priority work
    • Should have something staged before the end of the year
    • Front page will be a big improvement
    • Early 2016 launch is targeted, but we will need to evaluate with 
  • Working on outreach plan
    • targeting groups and conferences

Cross Functional Topics - Phil[edit]

  • Always interested in guest speakers for upcoming meetings
    • Please come to Phil with ideas about organizations who are willing to do short/informal presentations on what they are doing with SPDX

Attendees[edit]

  • Phil Odence, Black Duck
  • Gary O’Neill, SourceAuditor 
  • Jack Manbeck, TI
  • Dave Marr, Qualcomm
  • Dave McLaughlin, Rogue Wave
  • Jilayne Lovejoy, ARM
  • Paul Madick, Dimension Data


SPDX General Meeting this Thursday

Philip Odence
 

No special presentation this week, so I expect the meeting to be about 30 minutes.

GENERAL MEETING

Meeting Time: Thurs, Dec 3, 8am PDT / 10 am CDT / 11am EDT / 15:00 UTC. http://www.timeanddate.com/worldclock/converter.html

Conf call dial-in:
Conference code:  7812589502
Toll-free dial-in number (U.S. and Canada):  (877) 435-0230
International dial-in number: (253) 336-6732
For those dialing in from other regions, a list of toll free numbers can be found: 
https://www.intercallonline.com/portlets/scheduling/viewNumbers/viewNumber.do?ownerNumber=6053870&audioType=RP&viewGa=false&ga=OFF

 
Administrative Agenda
Attendance


Technical Team Report – Gary 


Legal Team Report – Jilayne


Business Team Report – Jack


Cross Functional Issues – Phil


SPDX November General Meeting Minutes

Philip Odence
 

Thanks again, to Oliver.




General Meeting/Minutes/2015-11-05

  • Attendance: 12
  • Lead by Phil Odence
  • Minutes of Oct meeting approved/

Siemens - Oliver Fendt[edit]

  • Open Source Group 
    • Deals with compliance issues
    • Made up of members from all parts of the company
    • Has been going for 2.5 years
    • Recognized SPDX early in their existence
      • Took a close look
      • First interest was in the license list
        • Requested some license for list; some successful, some not
        • Participated in discussion about how to handle license exceptions
    • SPDX 2.0 was coming on line
      • Voted internally to adopt SPDX
      • And to start requiring SPDX docs from their suppliers
    • Got involved with FOSSology
      • Implemented initial SPDX 2.0 in FOSSology
        • Just RDF, not yet Tag Value
    • Became aware of process of development of standard
        • Concerned about the direction, specifically snippet discussion
        • Concerns that it contradicts vision/mission
        • Minimizing costs across the supply chain
        • Concerned that granularity of snippets and that it’s hard to say, unless you are the developer
        • So, worries about usability
        • And that it adds interpretation, for example, Black Duck Protex requires the human to interpret
        • Also, since there is no open source tool that does snippets, adoption may be limited
      • Would be interested in adding other sorts of information like ECC info
    • They are currently using the latest/greatest FOSSology and encouraging suppliers to do same
    • Starting to see projects using SPDX short IDs in files
    • Suppliers normally don’t deliver source code; Siemens requires that they assert that the comply w/copyrights
      • So they typically don’t scan source.
      • They use FOSSo
      • And they encourage SPDX to supply the info


Tech Team Report - Kate/Gary[edit]

  • Busy refining external identifiers proposal
    • Aim was a single field 
    • Thought is to break into multiple fields, source of identifier and the domain
    • Wrestling with the difference between security IDs (NVD/CPE) and repos (e.g. Debian)
  • Also, recently revisited snippets proposal
    • Now is a good time to weigh in.
  • Tools
    • Active; Sebastian Schubert has been a big contributor recently
      • Mostly fixes
      • 2.1 will add some work
      • UNO repos also very active


Legal Team Report - Jilayne[edit]

  • Cross functional work with tech team on templates and matching
    • recent joint call, apologies for 10 person limit on call; will address
    • Looking to change maintenance process
    • Lots of good discussion about implementing matching guidelines
    • plan is for another joint call in early December


Biz Team Report - Jack[edit]

  • Working with LF on a new look feel for website
    • In parallel, changing some of the navigation.
    • Looks like it’s been delayed, so probably 2-3 weeks before rollout
    • Some progress already; looking good so far
  • In process of changing name of team to Outreach Team
    • Will roll out with new website
  • Eclipse Foundation
    • Might be interesting group to speak with about SPDX

Cross Functional Topics - Phil[edit]

  • See Jack’s brief blog on SPDX.org pointing must read blog by Eric Raymond on SPDX


Attendees[edit]

  • Phil Odence, Black Duck
  • Oliver Fendt, Siemens
  • Tarek Jomaa. ARM
  • Gary O’Neill, SourceAuditor 
  • Jilayne Lovejoy, ARM
  • Jack Manbeck, TI
  • Richard Christie, ARM
  • Pierre LaPointe, nexB 
  • Sami Atabani, ARM
  • Kate Stewart, Linux Foundation
  • Michael Herzog- nexB
  • Scott Sterling, Palamida


Thursday SPDX General Meeting & Special Presentation (& a very cool blog)

Philip Odence
 

First, Jack wrote a short blog about a blog, author of The Cathedral and the Bazaar, Eric Raymond’s nice little piece plugging SPDX. It’s well worth a read and will make you feel good about your involvement with SPDX: http://spdx.org/news/2015-10-26/see-what-eric-raymond-had-to-say-about-spdx 

As mentioned last month, for November we’ll by joined by Oliver Fendt who will speak about what Siemens is doing with SPDX. Big thanks to Oliver for joining us this week. I’m continuing to line up guest speakers for General Meetings. We are interested in anyone who can speak informally and briefly about their organization’s use of SPDX.


GENERAL MEETING

Meeting Time: Thurs, Nov5, 8am PDT / 10 am CDT / 11am EDT / 15:00 UTC. http://www.timeanddate.com/worldclock/converter.html

Conf call dial-in:
Conference code:  7812589502
Toll-free dial-in number (U.S. and Canada):  (877) 435-0230
International dial-in number: (253) 336-6732
For those dialing in from other regions, a list of toll free numbers can be found: 
https://www.intercallonline.com/portlets/scheduling/viewNumbers/viewNumber.do?ownerNumber=6053870&audioType=RP&viewGa=false&ga=OFF

 
Administrative Agenda
Attendance

Special Presentation –   Oliver

Technical Team Report – Kate 


Legal Team Report – Jilayne


Business Team Report – Jack


Cross Functional Issues – Phil


Re: Hello

Kate Stewart
 

Hi Dave,
    Welcome.  :-) 

    Information on the general meetings and past minutes can be found on:

Kate

On Sat, Oct 17, 2015 at 9:11 AM, Marr, David <dmarr@...> wrote:
Hi, I just joined the mail list and look forward to working with folks!

Dave Marr
_______________________________________________
Spdx mailing list
Spdx@...
https://lists.spdx.org/mailman/listinfo/spdx


Hello

Dave Marr
 

Hi, I just joined the mail list and look forward to working with folks!

Dave Marr


Re: General Meeting/Minutes/2015-10-01 - SPDX Wiki

J Lovejoy
 

Quick update post-meeting from legal team: 
version 2.2 of the SPDX License List is now available in all the usual places.  
:)

Jilayne
SPDX Legal Team co-lead
opensource@...


On Oct 1, 2015, at 4:31 PM, Philip Odence <podence@...> wrote:




* Attendance: 5
* Lead by Phil Odence

* Minutes of August meeting approved

== searchcode presentation - Nuno Brito ==

* Background
** Has been working with SPDX for two years and it’s been a good experience
** Hard to get engineers to use SPDX with out good examples for them to examine
** seachdcode seemed to be a good solution
* searchcode
** Started by a developer in Austrailia
** Seemed like a great place to make SPDX available
* Questions / Discussions
** Interest in having link from SPDX
** Files seem to have some extra fields so won’t validate
*** Nuno is very open and suggests filing bugs
** Adoption in Europe
*** Everyone that Nuno is working with is using SPDX
*** He’s found little resistance
*** Some people are more comfortable with tag value, but bigger projects are find with RDF
*** Still there is some difficulty for adoption.


== Biz Team Report - Jack ==

* Website
** Working with LF, migrating to new website/new templates
** In parallel will be implementing the new ideas for ease of use

== Tech Team Report - Kate/Gary ==

* No official update
* Main foci have been
** External references
*** Balance between specificity and handling broad cases
*** Specific discussion of vulnerabilities
** Snippets

== Legal Team Report - Jilayne ==

* No official update
* Have been processing more licenses with an eye to getting next release out

== Cross Functional Topics - Phil ==

* LinuxCon Europe 
* SW Supply Chain Summit


== Attendees ==

* Phil Odence, Black Duck
* Mark Gisi, Wind River 
* Scott Sterling, Palamida 
* Nuno Brito, TripleCheck
* Jack Manbeck, TI


  • [[Category:General|Minutes]]
  • [[Category:Minutes]]
_______________________________________________
Spdx mailing list
Spdx@...
https://lists.spdx.org/mailman/listinfo/spdx


General Meeting/Minutes/2015-10-01 - SPDX Wiki

Philip Odence
 




* Attendance: 5

* Lead by Phil Odence


* Minutes of August meeting approved


== searchcode presentation - Nuno Brito ==


* Background

** Has been working with SPDX for two years and it’s been a good experience

** Hard to get engineers to use SPDX with out good examples for them to examine

** seachdcode seemed to be a good solution

* searchcode

** Started by a developer in Austrailia

** Seemed like a great place to make SPDX available

* Questions / Discussions

** Interest in having link from SPDX

** Files seem to have some extra fields so won’t validate

*** Nuno is very open and suggests filing bugs

** Adoption in Europe

*** Everyone that Nuno is working with is using SPDX

*** He’s found little resistance

*** Some people are more comfortable with tag value, but bigger projects are find with RDF

*** Still there is some difficulty for adoption.



== Biz Team Report - Jack ==


* Website

** Working with LF, migrating to new website/new templates

** In parallel will be implementing the new ideas for ease of use


== Tech Team Report - Kate/Gary ==


* No official update

* Main foci have been

** External references

*** Balance between specificity and handling broad cases

*** Specific discussion of vulnerabilities

** Snippets


== Legal Team Report - Jilayne ==


* No official update

* Have been processing more licenses with an eye to getting next release out


== Cross Functional Topics - Phil ==


* LinuxCon Europe 

* SW Supply Chain Summit



== Attendees ==


* Phil Odence, Black Duck

* Mark Gisi, Wind River 

* Scott Sterling, Palamida 

* Nuno Brito, TripleCheck

* Jack Manbeck, TI



  • [[Category:General|Minutes]]
  • [[Category:Minutes]]


Thursday SPDX General Meeting & Special Presentation

Philip Odence
 

As you may have noticed, I’m striving to get guest speakers for every General Meeting. We are interested in anyone who can speak informally and briefly about their organization’s use of SPDX
This month we welcome Nuno Brito from Triplecheck, an SPDX proponent in Europe. He’ll talk about work he’s done with searchcode (free source code and documentation search engine) to include the search of SPDX docs. 
For the November, we’ll by joined by another European, Oliver Fendt who will speak about what Siemens is doing with SPDX.


GENERAL MEETING

Meeting Time: Thurs, Oct 1, 8am PDT / 10 am CDT / 11am EDT / 15:00 UTC. http://www.timeanddate.com/worldclock/converter.html

Conf call dial-in:
Conference code:  7812589502
Toll-free dial-in number (U.S. and Canada):  (877) 435-0230
International dial-in number: (253) 336-6732
For those dialing in from other regions, a list of toll free numbers can be found: 
https://www.intercallonline.com/portlets/scheduling/viewNumbers/viewNumber.do?ownerNumber=6053870&audioType=RP&viewGa=false&ga=OFF

 
Administrative Agenda
Attendance

Special Presentation –   Nuno

Technical Team Report – Gary 


Legal Team Report – Jilayne


Business Team Report – Jack


Cross Functional Issues – Phil


Announce: Supply Chain Mini-Summit on October 8 in Dublin

Kate Stewart
 


For those interested in improving the automated tracking of copyright, licensing and security information
in the supply chain, we've managed to get a Supply Chain mini-summit added on after LinuxCon on 
October 8th.

Agenda
9:00 - Intro to Supply Chain mini-summit (Kate Stewart)
9:05 - Overview of OpenChain, goals and status. (Dave Marr)
9:20 - Overview of SPDX project, review of 2.0 and plans for 2.1 (Phil Odence)
9:35 - Debsources as a community curated DB of copyright and license information (Stephano Zaccharoli)
10:20 - break
10:30 - DoSOCS - integrating security with license compliance (Sai Uday Shankar Korlimarla)
11:15 - OpenChain working session on the checklist (Dave Marr)
13:15 - lunch break
14:30 - Group brainstorming session on ways to improve automation around open source license compliance and tracking of relevant security information. (Kate to facilitate)
17:00 - wrap up and next steps


Event Details
Date: Thursday, October 8 
Time: 9:00am-5:00pm
Location: Liffey Meeting Room 3
Cost: Free for LinuxCon + Cloud Open + ELC Europe attendees
Register: RSVP Here


Hope you see there,
Kate





581 - 600 of 1604