|
Minutes from June 1 SPDX General Meeting
Hello SPDX Community, Thanks to the 42 of you that were able to join us for the June General Meeting last week. Another big thanks to Mike and Brandon for their presentation on GUAC. The slides from t
Hello SPDX Community, Thanks to the 42 of you that were able to join us for the June General Meeting last week. Another big thanks to Mike and Brandon for their presentation on GUAC. The slides from t
|
By
Rose Judge
·
|
|
Interpretation of Errors and Exceptions from SPDX Online Tools
4 messages
#spdx
I've been using the SPDX Online Tools recently to Validate and Convert. However, when an error or an exception is being thrown by the tool, understanding of the nature of the issue has not been clear
I've been using the SPDX Online Tools recently to Validate and Convert. However, when an error or an exception is being thrown by the tool, understanding of the nature of the issue has not been clear
|
By
arturrzgz@...
·
|
|
SPDX General Meeting Reminder.
We’ve great presentations planned for Thursday and the July meeting. Note, due to the the first week of July being a big vacation week in the US, we’ll push the July meeting a week to July 13. Today’s
We’ve great presentations planned for Thursday and the July meeting. Note, due to the the first week of July being a big vacation week in the US, we’ll push the July meeting a week to July 13. Today’s
|
By
Phil Odence
·
|
|
Announcement from Exiger
Hello Everyone, Consolidation of the SBOM market space continues at pace with this announcement of Ion Channel being acquired by Exiger. https://www.linkedin.com/posts/bob-kolasky-92ab554_exiger-acqui
Hello Everyone, Consolidation of the SBOM market space continues at pace with this announcement of Ion Channel being acquired by Exiger. https://www.linkedin.com/posts/bob-kolasky-92ab554_exiger-acqui
|
By
Dick Brooks
·
|
|
Reminder: Thursday SPDX General Meeting
Meeting Time: Thurs, May 4, 8am PT / 10 am CT / 11am ET / 15:00 UTC. http://www.timeanddate.com/worldclock/converter.html Conf call dial-in: Join the meeting: https://meet.jit.si/SPDXGeneralMeeting To
Meeting Time: Thurs, May 4, 8am PT / 10 am CT / 11am ET / 15:00 UTC. http://www.timeanddate.com/worldclock/converter.html Conf call dial-in: Join the meeting: https://meet.jit.si/SPDXGeneralMeeting To
|
By
Phil Odence
·
|
|
[SCITT] [spdx] CISA's proposed attestation form is now available and they are seeking comments
2 messages
Thank you Jean, I have added your name to the growing list of parties that have expressed an interest in joining this collaboration. FYI: I’ve also reached out to ITI and BSA to collaborate on this. I
Thank you Jean, I have added your name to the growing list of parties that have expressed an interest in joining this collaboration. FYI: I’ve also reached out to ITI and BSA to collaborate on this. I
|
By
Dick Brooks
·
|
|
CISA's proposed attestation form is now available and they are seeking comments
5 messages
Hello Everyone, CISA is seeking comments on their proposed self-attestation form for OMB M-22-18 and EO 14028. Is there any interest in doing a joint comment filing to CISA? Please respond to this ema
Hello Everyone, CISA is seeking comments on their proposed self-attestation form for OMB M-22-18 and EO 14028. Is there any interest in doing a joint comment filing to CISA? Please respond to this ema
|
By
Dick Brooks
·
|
|
[SCITT] [spdx] CISA's proposed attestation form is now available and they are seeking comments
I'm seeing a good response so far. Hoping to reach 100 small and medium businesses providing software to the US Government sign-on to this collaborative joint filing effort before the filing deadline
I'm seeing a good response so far. Hoping to reach 100 small and medium businesses providing software to the US Government sign-on to this collaborative joint filing effort before the filing deadline
|
By
Dick Brooks
·
|
|
Elucidating why I'm leaving SPDX
Dear all, I have relished the intellectual company of the SPDX community. There has been no other open source community that I have felt more welcomed in, nor one that shows so much potential for the
Dear all, I have relished the intellectual company of the SPDX community. There has been no other open source community that I have felt more welcomed in, nor one that shows so much potential for the
|
By
Sebastian Crane
·
|
|
SPDX Gen Meeting Follow up- Mistake and Thanks
10 messages
All, It hit me, out of the blue when I awoke this morning, that in Thursday’s General Meeting I neglected to mention and give thanks to May Wang for her contributions in serving on the Steering Commit
All, It hit me, out of the blue when I awoke this morning, that in Thursday’s General Meeting I neglected to mention and give thanks to May Wang for her contributions in serving on the Steering Commit
|
By
Phil Odence
·
|
|
Google announce open devs.dep API
Google have opened their deps.dev API, covering dependencies, license information and vulnerabilities. Right now, it's open and free to use – you don't even need an API key. Blog post here: https://se
Google have opened their deps.dev API, covering dependencies, license information and vulnerabilities. Right now, it's open and free to use – you don't even need an API key. Blog post here: https://se
|
By
Steve Kilbane
·
|
|
SBOMs from vcpkg?
2 messages
Hey all, If anyone happens to be using or familiar with Microsoft's vcpkg tool (using it to manage dependencies for a C++ project), do you know if there's a way to generate an SBOM from it? Their late
Hey all, If anyone happens to be using or familiar with Microsoft's vcpkg tool (using it to manage dependencies for a C++ project), do you know if there's a way to generate an SBOM from it? Their late
|
By
daniel@...
·
|
|
Reminder: Thursday SPDX General Meeting and Special Presentation
4 messages
SBOMs in the Windows supply chain, an SPDX success story - Joe Bussell, Microsoft Abstract: Joe will discuss the implementation of validation of SBOMs representing software packages in the Windows sof
SBOMs in the Windows supply chain, an SPDX success story - Joe Bussell, Microsoft Abstract: Joe will discuss the implementation of validation of SBOMs representing software packages in the Windows sof
|
By
Phil Odence
·
|
|
general meeting happening right now
we are experiencing technical difficulties, but everyone is rejoining at https://meet.jit.si/SPDXGeneralMeeting - so please try again
we are experiencing technical difficulties, but everyone is rejoining at https://meet.jit.si/SPDXGeneralMeeting - so please try again
|
By
J Lovejoy
·
|
|
SPDXMerge Tool
12 messages
#spdx
Hi All, We are excited to announce that we have open sourced our SBoM Merge tool on GitHub. This tool allows you to merge multiple Software Bills of Materials (SBOMs) into a single SBOM file in SPDX f
Hi All, We are excited to announce that we have open sourced our SBoM Merge tool on GitHub. This tool allows you to merge multiple Software Bills of Materials (SBOMs) into a single SBOM file in SPDX f
|
By
Patil, Sandeep
·
|
|
GitHub blogged they are creating SBOMs in SPDX format
7 messages
Looks like GitHub has a self-service option to create SBOMs for a GitHub Project based on SPDX! See this blog from them. Best Regards, Jack Manbeck Outreach Chair
Looks like GitHub has a self-service option to create SBOMs for a GitHub Project based on SPDX! See this blog from them. Best Regards, Jack Manbeck Outreach Chair
|
By
Manbeck, Jack
·
|
|
SPDX in GSoC 2023!
3 messages
Hi everyone! As every year, Google runs their Summer of Code program, where contributors get the opportunity to become part of Open Source communities. The SPDX Project has participated in the program
Hi everyone! As every year, Google runs their Summer of Code program, where contributors get the opportunity to become part of Open Source communities. The SPDX Project has participated in the program
|
By
Alexios Zavras
·
|
|
SPDX Generator with RefIDs and package hierarchy
8 messages
All, I feel like I'm missing something obvious here, but which SBOM generators actually generate SPDX SBOMs that (1) have refID's for the overall asset (documentDescribes), and (2) have package depend
All, I feel like I'm missing something obvious here, but which SBOM generators actually generate SPDX SBOMs that (1) have refID's for the overall asset (documentDescribes), and (2) have package depend
|
By
daniel@...
·
|
|
Link to US National Cybersecurity Strategy posted today
2 messages
https://www.whitehouse.gov/wp-content/uploads/2023/03/National-Cybersecurity-Strategy-2023.pdf Note references to SBOM and NIST/CISA role in driving regulations. Thanks, Dick Brooks Active Member of t
https://www.whitehouse.gov/wp-content/uploads/2023/03/National-Cybersecurity-Strategy-2023.pdf Note references to SBOM and NIST/CISA role in driving regulations. Thanks, Dick Brooks Active Member of t
|
By
Dick Brooks
·
|
|
Thursday SPDX General Meeting Reminder
Hello all, Max Huber of TNG Technology Consulting will be presenting on Thursday: In this presentation, Max will give a brief update of the recentdevelopment in the Python Tools. It went through a hug
Hello all, Max Huber of TNG Technology Consulting will be presenting on Thursday: In this presentation, Max will give a brief update of the recentdevelopment in the Python Tools. It went through a hug
|
By
Phil Odence
·
|