Date   

[GSOC] SPDX Parser libraries project

Ahmed Hisham Ismail
 

Hello,
First allow me to introduce myself, My name is Ahmed Hisham I am
currently a CS student at the German University in Cairo. I hope to
spend the summer working on the SPDX parser libraries project list on
the idea page at
http://www.linuxfoundation.org/collaborate/workgroups/gsoc/gsoc-2014-spdx-projects.

I have a couple of questions about the project, regarding what version
of the spec is it expected to support.
Should it support older version than the current spec ?
Should it partially support the upcoming spec 2.0 ? If so is there a
publicly available working draft?
I say partially as the spec is expected to be release in august and by
then the summer of code will be at its end.

Best Regards,
Ahmed


New Items and SPDX General Meeting reminder

Philip Odence
 

A couple of items in addition to the regular reminder about the upcoming general meeting:
  • The Linux Foundation has dedicated a track to SPDX at the upcoming Linux Collaboration Summit, March 25-28. It will include introductory session for newbees as well as working sessions for the various teams. And, the Tech Team has scheduled a full day session on the 25th. Jack has posted the agenda.
  • It would be great if you could take 10 mins and respond to the Future of Open Source Survey. This is an annual community effort and the result of collaboration between more than 40 organizations from the open source community. Sorry for the late notice, but the survey needs to be completed by this Wednesday.
GENERAL MEETING

Meeting Time: Thurs, March 6, 8am PST / 10 am CST / 11am EST / 15:00 UTC. http://www.timeanddate.com/worldclock/converter.html

Conf call dial-in:
Conference code:  7812589502
Toll-free dial-in number (U.S. and Canada):  (877) 435-0230
International dial-in number: (253) 336-6732
For those dialing in from other regions, a list of toll free numbers can be found: 
https://www.intercallonline.com/portlets/scheduling/viewNumbers/viewNumber.do?ownerNumber=6053870&audioType=RP&viewGa=false&ga=OFF

 
Administrative Agenda
Attendance
Approve Minutes- 

Technical Team Report - Kate


Legal Team Report - Jilayne


Business Team Report – Jack


Cross Functional Issues – Phil


SPDX Announcements

Philip Odence
 

I am pleased to announce that Paul Madick and Mikael Söderberg will be joining the leadership of SPDX. Paul will co-lead the Legal Team with Jilayne, and Mikael will be Jack's co-lead on the Business Team. Both are terrific additions to the organization and we are excited to welcome them aboard.

Paul is an experienced open source attorney serving as Senior Counsel in HP's Cloud Computing & Open Source group in the Office of the General Counsel  and has already been a regular contributor to the Legal Team. Mikael is CTO and founder of Pelagicore where he has been an evangelist for the use of open source in automotive In-Vehicle Infotainment systems. Based in Sweden, Mikael is keen to build awareness of SPDX in Europe. 

Big thanks to Scott Lamons for his work as Business Team co-lead. He's been a big contributor to the effort for years, and it's been a personal pleasure for me to work with him. The good news is that Scott plans to stay active, so this is not farewell by any means.

On more operational notes: 
Best regards,
Phil

L. Philip Odence
Vice President of Corporate and Business Development
Black Duck Software, Inc.
8 New England Executive Park, Suite 211, Burlington MA 01803
Phone: 781.810.1819, Mobile: 781.258.9502
Skype: philip.odence


FOSSology+SPDX [Crossposting]

Matt Germonprez <germonprez@...>
 

Hi everyone, 

Not sure if you saw this thread over at FOSSology. I think it might be of interest to SPDX too. 

Regards,
Matt


************

Hi All, Bob,

 

This is Kotrappa, from Wipro Technologies India.

We are using Fossology on a local sever for scanning some of packages for License/copyright info.

Recently we have installed Fossology+SPDX module on a local PC, and this gives spdx results as well.

 

Spdx.org gives open source tools to convert .rdf to .spdx, .spdx to .rdf, .xls to.rdf etc.

Reference http://spdx.org/spdx-tools/tools-from-the-spdx-workgroup

 

We would like to know after Fossology+SPDX scans a package and gives results in sdpx format,

Is there any command line tools to execute on command prompt in Local PC using localhost server running Fossology agents to get results in spdx format.

( Please note I cannot use Web Interface version of https://fossologyspdx.ist.unomaha.edu/?mod=Default because packages cannot be uploaded to public)

 

I mean, I should be able to get results something like mypackage_name.spdx or mypackage_name.rdf which complies with SPDX format

specified in spdx.org, which I can use as an input to spdx open source tools for conversion, comparison etc.

 

Please help.

 

Best regards

Kotrappa.


************


Hi Kotrappa,

I’m confused why you mention that you cannot use fossologyspdx.ist.unomaha.edu since you have installed the spdx module on your own local machine.  You shouldn’t have to use the unomaha machine since you have it installed locally.

Since you have installed the FOSSology+SPDX module on your local PC, then you can create spdx files (tag files).  That option is the default but is specified in the “Output File Type” pull down on the SPDX Edit screen.  So though we call it a .tag file, I think that is the same as the .spdx file.

The command line (web api) doc is at:


However, this does not generate the full .spdx (tag) output.

If I have not understood your question completely, please ask again.  Liang Cao is the author of the SPDX module and he is on this list as well.

Thanks,
Bob Gobeille

************

Hi Kotrappa,

Liang Cao has added an option to generate a full SPDX document in TAG format from the command line. He has also provided a nice overview of how to work with the source. 

The source is pushed to here:

The documentation is here:

The option for [fullSPDXFlag] is added.
[fullSPDXFlag]: true/false. Only when this option is set to "true", low definition version of the full SPDX contents are output. Skipping this option equals setting it to "false." This option should be set to "true" when you want to generate an SPDX document from the command line.

You could generate a mypackagename.spdx by running a command like the following:
wget -qO - --no-check-certificate --post-file=./[mypackagename] --timeout=0 "https://domain/?mod=spdx_license_once&noCopyright=false&jsonOutput=false&fullSPDXFlag=true&packageNameInLog=[mypackagename]" > [mypackagename].spdx

for example:

If you have any questions, please feel free to contact me or Liang. We are happy to help. 

Regards,
Matt Germonprez and Liang Cao

--
Mutual of Omaha Associate Professor of Information Systems
University of Nebraska at Omaha
Vita
Open Communities Lab


Reminder- SPDX General Meeting Pushed to Thurs, Feb 13

Philip Odence
 

Meeting Time: Thurs, Feb 13, 8am PST / 10 am CST / 11am EST / 15:00 UTC. http://www.timeanddate.com/worldclock/converter.html

Conf call dial-in:
Conference code:  7812589502
Toll-free dial-in number (U.S. and Canada):  (877) 435-0230
International dial-in number: (253) 336-6732
For those dialing in from other regions, a list of toll free numbers can be found: 
https://www.intercallonline.com/portlets/scheduling/viewNumbers/viewNumber.do?ownerNumber=6053870&audioType=RP&viewGa=false&ga=OFF

 
Administrative Agenda
Attendance
Approve Minutes- 
http://wiki.spdx.org/view/General_Meeting/Minutes/2014-01-02 

Technical Team Report - Kate


Legal Team Report - Jilayne


Business Team Report – Jack



Cross Functional Issues – Phil


Registration Information for Linux Collab Summit in March and SPDX Meetings

Manbeck, Jack
 

All,

 

The Linux Collaboration summit is this coming March, 26-28th. There will be a technical team meeting prior to the summit on the 25th to do a deep dive on the SPDX 2.0 data model and a session for SPDX on Friday (still working to secure the room). As the Agendas firm up we will post them.

 

To register for the conference use this link:

 

 https://www.regonline.com/register/login.aspx?eventID=1250683

 

When registering use the SPDX workgroup code  SPDX14LFCS and choose the "Invitation Acceptance" registration type.

 

We hope to see many of you there.

 

Best regards,

 

Jack Manbeck

Business Team Co-Chair

 


SPDX General Meeting

Philip Odence
 

When: Thursday, February 13, 2014 11:00 AM-12:00 PM. (UTC-05:00) Eastern Time (US & Canada)
Where: Bridge info enclosed

*~*~*~*~*~*~*~*~*~*
Due to  lack availability of some of the team leads, we are pushing this occurrence of the General Meeting out 1 week. This is a one time move; we'll be back to the normal first Thursday cadence in March. 

I am not sure everyone on the General Meeting mailing list has this invitation on the calendar. Please excuse the redundancy of my sending out a separate notice to the list, which I will do on Monday.


**********
Please accept so this recurring meeting is on your calendar, however no need to respond.

DIAL IN:
Toll-free dial-in number (U.S. and Canada): (877) 435-0230
International dial-in number: (253) 336-6732

Conference code: 7812589502





Introduction

Daniel Hamacher <danielhamacher.dh@...>
 

Hello SPDX Team,

my name is Daniel and I am a second year University student. I would like to get involved in OpenSource and I got interested in this project. I looked through the Bug list and found item #1129 which I would like to work on. What do I need to do to get assigned to this item or any other item in the future? 

Thanks,
Daniel


SPDX Virtual General Meeting and Schedules

Philip Odence
 

GENERAL MEETING
As per my previous email, the January General Meeting was virtual, i.e. written reports from the team leads:

BUSINESS AND LEGAL TEAM SCHEDULES
The teams will continue to alternate the Thursday slot at the same time. First meetings of the year are as follows:
Business Team- January 16
Legal Team- January 23

BLOG
I posted a New Year's blog looking forward to 2014: http://spdx.org/news/2014-01-02/ring-in-the-new  


FW: WTFPL(-2.0) license entry

Philip Odence
 

Forwarding to SPDX legal list for any discussion. BCC SPDX general list,
as FYI that legal list will handle.

On 12/27/13 9:25 AM, "Jan Engelhardt" <jengelh@...> wrote:


The SPDX license list at http://spdx.org/licenses/ has an entry

Do What The F*ck You Want To Public License WTFPL

There are multiple versions of the WTFPL around, and the SPDX entry
shows the WTFPL version 2.0 text. In spirit of the SPDX naming of all
the remaining licenses, the "WTFPL" entry should be renamed to
"WTFPL-2.0".
_______________________________________________
Spdx mailing list
Spdx@...
https://lists.spdx.org/mailman/listinfo/spdx


WTFPL(-2.0) license entry

Jan Engelhardt <jengelh@...>
 

The SPDX license list at http://spdx.org/licenses/ has an entry

Do What The F*ck You Want To Public License WTFPL

There are multiple versions of the WTFPL around, and the SPDX entry
shows the WTFPL version 2.0 text. In spirit of the SPDX naming of all
the remaining licenses, the "WTFPL" entry should be renamed to
"WTFPL-2.0".


January SPDX General Meeting Goes Virtual - PLEASE READ

Philip Odence
 

Because the General Meeting falls on Jan 2 and a number of folks will be out or just back from long holidays, we'll do this one virtually, i.e. I will ask all the team leads to provide team updates to me via email and I will issue minutes and solicit comment/thoughts on this list. 

In the meantime, some recommended reading:

Jilayne, Scott and I wrote an article for the I8l FOSS Law Review: 
http://www.ifosslr.org/ifosslr/article/view/89 

I wrote a blog on the state of SPDX (and am still planning another to wrap the year…we'll see): 
http://spdx.org/news/2013-11-14/spdx...how-are-we-doing 


Finally, keep your eyes open for a v2.0 requirements doc that Kirsten Newcomer has been pulling together at the behest of the Business Team (and with review by the Tech Team).


Meeting Time: Thurs, Jan 2, 8am PST / 10 am CST / 11am EST / 15:00 UTC. http://www.timeanddate.com/worldclock/converter.html

Conf call dial-in:
Conference code:  7812589502
Toll-free dial-in number (U.S. and Canada):  (877) 435-0230
International dial-in number: (253) 336-6732
For those dialing in from other regions, a list of toll free numbers can be found: 
https://www.intercallonline.com/portlets/scheduling/viewNumbers/viewNumber.do?ownerNumber=6053870&audioType=RP&viewGa=false&ga=OFF

 
Administrative Agenda
Attendance
Approve Minutes- 

Technical Team Report - Kate


Legal Team Report - Jilayne


Business Team Report – Jack/Scott



Cross Functional Issues – Phil


article about SPDX in IFOSS Law Review

Jilayne Lovejoy <lovejoylids@...>
 

Hi All,

The latest edition of the IFOSS Law Review is now available: http://www.ifosslr.org/ifosslr/issue/current
and includes an article about SPDX!!  

Happy Holidays,

Jilayne


SPDX Legal Team lead





TR: FOSS: next steps

RUFFIN MICHEL
 

On Wednesday the OMG held a meeting on standardisation issues between organizations on FOSS issues.

It was a kick-off meeting on the topic

I would like to invite you to be part of the discussion if interested.

To do so you need to send an email to request@... to be part of the FOSS OMG mailing list

Bellow is an email of Richard Soley CEO of OMG

 

Michel
----------------------------------------------
On Wednesday 11 December, the OMG hosted a FOSS Licensing Standards Workshop at the OMG Technical Meeting in Santa Clara, California. 
There was significant discussion about the need for new model-based standards (as well as best practices standards) in the area of FOSS licensing.

The areas in which discussion centered, taking into account as much as possible existing standards such as SPDX, included:

  • To kick off the discussion, a reminder of the areas of consideration for new standards, taking into account and using as much as possible existing standards such as SPDX:
  • best practices for choosing a license and potentially agreeing on standard legal FOSS clauses
  • professional certification of FOSS licensing usage
  • capturing FOSS IP information in a Wikipedia-style database
  • agreeing standard contract clauses to lower the cost of supplier/customer relationships, M&A, etc.
  • standardizing unique software identifiers to support the automation of cross-organization identification of licenses & software

The agenda for the day, including presentation materials used, is at http://www.omg.org/news/meetings/tc/ca-13/special-events/FOSS.htm

        -- Richard



 



SPDX Thursday General Meeting Reminder

Philip Odence
 

Meeting Time: Thurs, Dec 5, 8am PST / 10 am CST / 11am EST / 15:00 UTC. http://www.timeanddate.com/worldclock/converter.html

Conf call dial-in:
Conference code:  7812589502
Toll-free dial-in number (U.S. and Canada):  (877) 435-0230
International dial-in number: (253) 336-6732
For those dialing in from other regions, a list of toll free numbers can be found: 
https://www.intercallonline.com/portlets/scheduling/viewNumbers/viewNumber.do?ownerNumber=6053870&audioType=RP&viewGa=false&ga=OFF

 
Administrative Agenda
Attendance
Approve Minutes- 

Technical Team Report - Kate


Legal Team Report - Jilayne


Business Team Report – Jack/Scott



Cross Functional Issues – Phil


Nov General Meeting Minutes

Philip Odence
 

Just posted the minutes:

Special note:
The SPDX Legal group will be holding a special break out session to review a number of software examples where the SPDX licensing syntax (i.e., license list + AND/OR operators) may not be sufficient to represent the licensing terms of the software. For instance the group will be looking at the various kinds of special exception terms, the use of the ‘+’ in license names and programs derived from multiple source and library files, where each is potentially under a different license. The group will report back to the Legal and Tech working groups with its findings. If you are interested in attending or would like to submit relevant examples send email to Mark.Gisi@....

Thanks,
Phil

L. Philip Odence
Vice President of Corporate and Business Development
Black Duck Software, Inc.
8 New England Executive Park, Suite 211, Burlington MA 01803
Phone: 781.810.1819, Mobile: 781.258.9502
Skype: philip.odence


SPDX Cloud Server now supports SPDX 1.2 file creation

Sameer Ahmed
 

Hi All,

 

Wind River just released SPDX 1.2 support for its free SPDX file creation cloud server.

 

Here is what’s new:

·         Supports newly released SPDX 1.2 format.

·         Improved Analysis Quality – Added several new license detector agents to improve expert system analysis engine.  

·         SPDX data now available in an easy to view spreadsheet format.

·         Upload your own package or now choose from a collection of preloaded sample packages (e.g., Apache Server, U-boot…)

  

You can create an SPDX 1.2 file for free by going to: http://spdx.windriver.com

 

Regards,
Sameer Ahmed

 

 

Sameer Ahmed | Member of Technical Staff - App | Wind River

Email: sameer.ahmed@...

 


Thursday SPDX General Meeting

Philip Odence
 

First some announcements:

News from the Linux Events in Europe

Wind River Presentation on SPDX and Yocto at the Embedded Linux Conference: http://events.linuxfoundation.org/sites/events/files/slides/2013_ELC-E_YP_SPDX.pdf
I also ran a BoF at LinuxCon and presented in intro to SPDX at the Automotive Grade Linux Conference



****

Meeting Time: Thurs, Nov 7, 8am PST / 10 am CST / 11am EST / 15:00 UTC. http://www.timeanddate.com/worldclock/converter.html

Conf call dial-in:
Conference code:  7812589502
Toll-free dial-in number (U.S. and Canada):  (877) 435-0230
International dial-in number: (253) 336-6732
For those dialing in from other regions, a list of toll free numbers can be found: 
https://www.intercallonline.com/portlets/scheduling/viewNumbers/viewNumber.do?ownerNumber=6053870&audioType=RP&viewGa=false&ga=OFF

 
Administrative Agenda
Attendance
Approve Minutes- 

Technical Team Report - Kate


Legal Team Report - Jilayne


Business Team Report – Jack/Scott



Cross Functional Issues – Phil


(No subject)

RUFFIN MICHEL
 

Dear all,
The OMG (Object Management group) is organizing a workshop on standardizing open source governance practices on December 11 in Santa Clara (CA) http://www.omg.org/news/meetings/tc/ca-13/special-events/FOSS.htm
 
We would like to invite the members of the SPDX group to participate. From my discussions with a lot of companies since two years on this topic, there is more and more interested parties.
 
Michel
 
Michel.Ruffin@..., PhD
Software Coordination Manager, N&P IS/IT
Distinguished Member of Technical Staff
Tel +33 (0) 6 75 25 21 94
Alcatel-Lucent International, Centre de Villarceaux
Route De Villejust, 91620 Nozay, France
 
 
 


1.2 and BoF Report

Philip Odence
 

It's official, 1.2 is up.  Again, huge thanks to all who contributed. Credit Mark Gisi with finding this apt quote:

“people throw stones at you and you turned them into milestones”

             ― Sachin Tendulkar (Ted Williams of Cricket)


I had a good BoF session with folks from Intel, Qualcomm, HP, Orange, Valeo, and others. There were about 12 including a reporter from Munich. I thought this was a terrific turnout given that it was at the end of a long day and directly competed with the beer/wine and appetizers.I went through a presentation, but it was much more of a discussion and there was healthy discussion of just about every slide; we went for an hour and could have gone longer. At least a couple of the participants indicated enough interest to get involved and help. We'll see.