|
Please participate: "State of Open Standards Survey"
The Linux Foundation (LF) has launched The State of Open Standards Survey to capture how different organizations are involved in open standards adoption and contribution, with the aim of measuring the
The Linux Foundation (LF) has launched The State of Open Standards Survey to capture how different organizations are involved in open standards adoption and contribution, with the aim of measuring the
|
By
Kate Stewart
· #1622
·
|
|
End Of Life Tag in spdx
#spdx
Sort of. Security information is even more likely to change after release, EOL for open source components supported by the community may, but much less frequently. Thinking so far, is that this would
Sort of. Security information is even more likely to change after release, EOL for open source components supported by the community may, but much less frequently. Thinking so far, is that this would
|
By
Kate Stewart
· #1526
·
|
|
End Of Life Tag in spdx
#spdx
Hi Sandeep, There is a pull request expected shortly from the Usage profile team, to add this specific field to 2.3. When it comes in, please feel free to review and make sure it's going to suffice fo
Hi Sandeep, There is a pull request expected shortly from the Usage profile team, to add this specific field to 2.3. When it comes in, please feel free to review and make sure it's going to suffice fo
|
By
Kate Stewart
· #1510
·
|
|
SPDX Thurs General Meeting Reminder
The video has been posted here: https://www.youtube.com/watch?v=8X5PWa7A6pY&list=PLciqFgcGu7TvR_f3aKZHkozX0WIs-N7vc&index=7 Thanks again to Joshua for sharing with us!
The video has been posted here: https://www.youtube.com/watch?v=8X5PWa7A6pY&list=PLciqFgcGu7TvR_f3aKZHkozX0WIs-N7vc&index=7 Thanks again to Joshua for sharing with us!
|
By
Kate Stewart
· #1508
·
|
|
Taxonomy of software supply chain ecosystem?
There's been some industry wide agreement on the taxonomy to use to classify tools here: https://www.ntia.gov/files/ntia/publications/ntia_sbom_tooling_taxonomy-2021mar30.pdf I think the path of least
There's been some industry wide agreement on the taxonomy to use to classify tools here: https://www.ntia.gov/files/ntia/publications/ntia_sbom_tooling_taxonomy-2021mar30.pdf I think the path of least
|
By
Kate Stewart
· #1474
·
|
|
SPDX Goes ISO
The content that went into the standard is the same as what is in our github repo today, and a pretty version is at: https://spdx.github.io/spdx-spec/. The sources for the 2.2.1 are at: https://github
The content that went into the standard is the same as what is in our github repo today, and a pretty version is at: https://spdx.github.io/spdx-spec/. The sources for the 2.2.1 are at: https://github
|
By
Kate Stewart
· #1450
·
|
|
[spdx-tech] Should SPDX endorse SCA tools?
We've got a lot of historical cruft in our SPDX repo as well. Coming up with some criteria for inclusion & removal is overdue. After we settle the 3.0 template issue, you up for dedicating part of a c
We've got a lot of historical cruft in our SPDX repo as well. Coming up with some criteria for inclusion & removal is overdue. After we settle the 3.0 template issue, you up for dedicating part of a c
|
By
Kate Stewart
· #1415
·
|
|
SBOM's going mainstream - Biden Cybersecurity EO
Last night Biden signed Executive Order (EO) on Improving the Nation’s Cybersecurity. As part of this Executive order the concept of SBOM is getting widespread visibility. If the question comes up ple
Last night Biden signed Executive Order (EO) on Improving the Nation’s Cybersecurity. As part of this Executive order the concept of SBOM is getting widespread visibility. If the question comes up ple
|
By
Kate Stewart
· #1403
·
|
|
Usage profile for SPDX3.0 - proposal from OpenChain Japan WG -
Thanks for sending this Takahashi-san. I'm forwarding this email for discussion on the spdx-tech mailing list where the usage profile will be discussed. spdx-tech is where we are discussing the profil
Thanks for sending this Takahashi-san. I'm forwarding this email for discussion on the spdx-tech mailing list where the usage profile will be discussed. spdx-tech is where we are discussing the profil
|
By
Kate Stewart
· #1372
·
|
|
SPDX 2.2 Specification Review Window - ends May 1, 2020
Hi all, The SPDX 2.2 specification is now in the final 2 week public review window. The SPDX tech-list participants have been working on polishing it for the last couple of months and adding in the ou
Hi all, The SPDX 2.2 specification is now in the final 2 week public review window. The SPDX tech-list participants have been working on polishing it for the last couple of months and adding in the ou
|
By
Kate Stewart
· #1321
·
|
|
Chime instead of Zoom, a modest proposal
Hi Mark, Thanks for the generous offer. :-) We're not paying for zoom, however I'm definitely up for doing an experiment during our spdx-tech meeting tomorrow, and if it works for the regular attendee
Hi Mark, Thanks for the generous offer. :-) We're not paying for zoom, however I'm definitely up for doing an experiment during our spdx-tech meeting tomorrow, and if it works for the regular attendee
|
By
Kate Stewart
· #1309
·
|
|
Thursday's SPDX General Meeting Reminder
Hi Phil, all Quick update, we will have a guest speaker this week. Matthew Crawford will be discussing "Arm’s SPDX compliance file" Thanks, Kate
Hi Phil, all Quick update, we will have a guest speaker this week. Matthew Crawford will be discussing "Arm’s SPDX compliance file" Thanks, Kate
|
By
Kate Stewart
· #1292
·
|
|
SPDX 2.1.1 specification - final review by 2019/5/21
In 2017 the project decided to move the specification from google documents to github and a repository was set up at: https://github.com/spdx/spdx-spec Before we could move forward though, we needed t
In 2017 the project decided to move the specification from google documents to github and a repository was set up at: https://github.com/spdx/spdx-spec Before we could move forward though, we needed t
|
By
Kate Stewart
· #1240
·
|
|
SPDX Feb General Meeting Minutes
Hi Phil, I've gone in and updated the tech section to put links into some of the items we discussed and added details of Asia SPDX tech call. Please let me know if you want me to revert. Tech Team Rep
Hi Phil, I've gone in and updated the tech section to put links into some of the items we discussed and added details of Asia SPDX tech call. Please let me know if you want me to revert. Tech Team Rep
|
By
Kate Stewart
· #1218
·
|
|
Standalone license tools for scanning debian/ubuntu apps?
Hi Dan, Am not sure what you're using for a build infrastructure, but there are some solutions emerging in Yocto that may be relevant, as well as the other projects that Philippe outlines. I checked w
Hi Dan, Am not sure what you're using for a build infrastructure, but there are some solutions emerging in Yocto that may be relevant, as well as the other projects that Philippe outlines. I checked w
|
By
Kate Stewart
· #1215
·
|
|
Standalone license tools for scanning debian/ubuntu apps?
There's also BANG! (Binary Analysis Next Generation) that is in beta now. see: https://github.com/armijnhemel/binaryanalysis-ng Kate
There's also BANG! (Binary Analysis Next Generation) that is in beta now. see: https://github.com/armijnhemel/binaryanalysis-ng Kate
|
By
Kate Stewart
· #1209
·
|
|
Need Help for contrubuting in GSOC 2019
#spdx
Hi Varshak, Welcome! Glad you're interested in participating in our community. I am copying the spdx-tech mail list where we discuss the GSoC efforts. Ideas we've come up with so far are listed on: ht
Hi Varshak, Welcome! Glad you're interested in participating in our community. I am copying the spdx-tech mail list where we discuss the GSoC efforts. Ideas we've come up with so far are listed on: ht
|
By
Kate Stewart
· #1201
·
|
|
Spdx Digest, Vol 93, Issue 2
Hi John, Thanks for reaching out! I think this discussion is best handled with the tech team so switching mailing lists, and moving general to bcc. :-) Some of the information you're proposing in SEvA
Hi John, Thanks for reaching out! I think this discussion is best handled with the tech team so switching mailing lists, and moving general to bcc. :-) Some of the information you're proposing in SEvA
|
By
Kate Stewart
· #1170
·
|
|
SPDX servers rebooting over the weekend for Spectre/Meltdown remediation.
Hi, Just heard from LF IT that our SPDX site & wiki will be rebooting this weekend, as the apply the Meltdown/Spectre remediation. It should just be down for 5 minutes early this weekend, so this is m
Hi, Just heard from LF IT that our SPDX site & wiki will be rebooting this weekend, as the apply the Meltdown/Spectre remediation. It should just be down for 5 minutes early this weekend, so this is m
|
By
Kate Stewart
· #1157
·
|
|
FreeBSD adding in SPDX license identifers too...
And in addition to Linux getting serious in terms of adding SPDX identifiers, we also have FreeBSD applying them to their code base. Kate ---------- Forwarded message ---------- From: Pedro Giffuni <p
And in addition to Linux getting serious in terms of adding SPDX identifiers, we also have FreeBSD applying them to their code base. Kate ---------- Forwarded message ---------- From: Pedro Giffuni <p
|
By
Kate Stewart
· #1148
·
|