Date
1 - 2 of 2
Spdx Digest, Vol 93, Issue 2
John Scott (Ion) <john.scott@...>
Hi All, Sorry for getting on the call late. For comment: https://github.com/ion-channel/SEVA We recently released this Spec. SEvA is specification for encapsulating software supply chain metadata and delivering with a clear and concise schema for parsing using automation. The SEvA definition is divided into several sections. There is a brief description of each section listed below. Our clients would like all evidence to be portable so it can move with a piece of software thru an organization. We could talk about it next month ------------------------------------------- John Scott, President, Ion Channel 240.401.6574 @johnmscott < john.scott@... > On May 3, 2018 at 11:51:32 AM, spdx-request@... (spdx-request@...) wrote:
|
|
Kate Stewart
Hi John, Thanks for reaching out! I think this discussion is best handled with the tech team so switching mailing lists, and moving general to bcc. :-) Some of the information you're proposing in SEvA is already handled in the SPDX specification. https://spdx.g which has been in development by supply chain participants for over 8 years now. Its not clear from your proposal if you're planning on using the SPDX license identifiers to capture the licensing information, can you clarify this? Also, have you compared the information you're looking to be captured in SEvA with the fields that are already in place and standardized on in the specification? The next rev of the specification will explicitly permit JSON and YAML, document expression in addition to RDF, tag:value. Prototype translators between formats are already in place if you want to experiment. If there are fields you're looking to see captured, that aren't in place already, Feel free to open an issues on https://github.com/spdx/spd with background how it will be used, and where the information should be derived from. Also, if you'd like to have a more interactive discussion, the tech team meets weekly[1], and we'd be happy to add you on to the agenda to explore collaboration options, just let us know. Looking forward to continuing the discussion. Thanks, Kate SPDX tech team co-lead. On Thu, May 3, 2018 at 11:01 AM, John Scott (Ion) <john.scott@...> wrote:
|
|