|
FYI: SPDX in the OpenSSF Mobilization Plan
Some of you probably know that OpenSSF met with a bunch of US Federal organizations in Washington DC last week to discuss cyber security wrt the open source software supply chain. (our own Kate and Wi
Some of you probably know that OpenSSF met with a bunch of US Federal organizations in Washington DC last week to discuss cyber security wrt the open source software supply chain. (our own Kate and Wi
|
By
VM (Vicky) Brasseur
·
|
|
SPDX and NTIA SBOM Minimum elements
5 messages
#spdx
Hi , Is there any document reference which can be used to see mapping between SPDX tags and NTIA Minimum elements ? Some element names can be easily confused , something like "Author of SBOM Data" in
Hi , Is there any document reference which can be used to see mapping between SPDX tags and NTIA Minimum elements ? Some element names can be easily confused , something like "Author of SBOM Data" in
|
By
Patil, Sandeep
·
|
|
~24 hours left to propose SPDX talks to All Things Open!
All Things Open (ATO) is one of the largest open source conferences in the world now. In 2022 it’ll be in-person only, in its normal location of the Raleigh Convention Center in Raleigh, North Carolin
All Things Open (ATO) is one of the largest open source conferences in the world now. In 2022 it’ll be in-person only, in its normal location of the Raleigh Convention Center in Raleigh, North Carolin
|
By
VM (Vicky) Brasseur
·
|
|
The OpenChain Industry Survey 2022 - SPDX Included
The OpenChain Industry Survey 2022 covers a big topic: the global status of corporate engagement and management of open source. Please help by completing the survey from your perspective before May 1s
The OpenChain Industry Survey 2022 covers a big topic: the global status of corporate engagement and management of open source. Please help by completing the survey from your perspective before May 1s
|
By
Shane Coughlan
·
|
|
Special Presentation and SPDX Thurs General Meeting Reminder
3 messages
Please join us for a very interesting presentation to kick off the meeting: Preview of LF Study on SBOM Readiness by Steve Hendrick Abstract: The State of Software Bill of Materials (SBOM) and Cyberse
Please join us for a very interesting presentation to kick off the meeting: Preview of LF Study on SBOM Readiness by Steve Hendrick Abstract: The State of Software Bill of Materials (SBOM) and Cyberse
|
By
Phil Odence
·
|
|
SPDX Company Membership
6 messages
Dear SPDX community, With the adoption of the new project governance model for SPDX in September, one new aspect of the updated structure is the introduction of the ability for companies and other org
Dear SPDX community, With the adoption of the new project governance model for SPDX in September, one new aspect of the updated structure is the introduction of the ability for companies and other org
|
By
Phil Odence
·
|
|
SPDX Feb General Meeting MInutes
https://github.com/spdx/meetings/blob/master/general/2022-02-03.md L. Philip Odence General Manager, Black Duck Audit Business Synopsys Software Integrity Group, Burlington, MA M (781) 258-9502 | phil
https://github.com/spdx/meetings/blob/master/general/2022-02-03.md L. Philip Odence General Manager, Black Duck Audit Business Synopsys Software Integrity Group, Burlington, MA M (781) 258-9502 | phil
|
By
Phil Odence
·
|
|
[spdx-tech] Registration open for SPDX DocFest on Jan 27th
3 messages
Rose, Where can I find the target set objects to create/submit an SPDX SBOM? Thanks, Dick Brooks Never trust software, always verify and report! ™ http://www.reliableenergyanalytics.com Email: dick@..
Rose, Where can I find the target set objects to create/submit an SPDX SBOM? Thanks, Dick Brooks Never trust software, always verify and report! ™ http://www.reliableenergyanalytics.com Email: dick@..
|
By
Dick Brooks
·
|
|
Registration open for SPDX DocFest on Jan 27th
Hello SPDX community, SPDX is hosting another DocFest on January 27th from 7-11 AM PST. The purpose of this event is to bring together producers and consumers of SPDX documents and discuss differences
Hello SPDX community, SPDX is hosting another DocFest on January 27th from 7-11 AM PST. The purpose of this event is to bring together producers and consumers of SPDX documents and discuss differences
|
By
Rose Judge
·
|
|
Archive the https://github.com/spdx/license-list repository
3 messages
Hi all, while the README at [1] documents the https://github.com/spdx/license-list repo to be archived, it's not "archived" in the GitHub sense, as available in the settings at https://github.com/spdx
Hi all, while the README at [1] documents the https://github.com/spdx/license-list repo to be archived, it's not "archived" in the GitHub sense, as available in the settings at https://github.com/spdx
|
By
Sebastian Schuberth
·
|
|
Thursday's SPDX General Meeting Reminder
2 messages
Hello, all, looking forward to seeing you Thursday. Note, we’ll have guest presentation from Microsoft on what they are doing with SPDX. Best, Phil GENERAL MEETING Meeting Time: Thurs, Dec 2, 8am PT /
Hello, all, looking forward to seeing you Thursday. Note, we’ll have guest presentation from Microsoft on what they are doing with SPDX. Best, Phil GENERAL MEETING Meeting Time: Thurs, Dec 2, 8am PT /
|
By
Phil Odence
·
|
|
License Universe
Hi all, we recently published some insights on our license database. You can find details on https://github.com/org-metaeffekt/metaeffekt-universe and a visualization of the data on https://metaeffekt
Hi all, we recently published some insights on our license database. You can find details on https://github.com/org-metaeffekt/metaeffekt-universe and a visualization of the data on https://metaeffekt
|
By
Karsten Klein
·
|
|
SPDX December General Meeting Minutes
Also attached are slides from Adrian and Steve’s very interesting presentations. https://wiki.spdx.org/view/General_Meeting/Minutes/2021-12-02 General Meeting/Minutes/2021-12-02 < General Meeting | M
Also attached are slides from Adrian and Steve’s very interesting presentations. https://wiki.spdx.org/view/General_Meeting/Minutes/2021-12-02 General Meeting/Minutes/2021-12-02 < General Meeting | M
|
By
Phil Odence
·
|
|
SPDX Outreach Team report for December General Meeting
Dear all, Since we didn't have time at the SPDX General Meeting today for the usual team reports, I'm writing to send the Outreach Team's report in textual form! Feel free to reply if you have any que
Dear all, Since we didn't have time at the SPDX General Meeting today for the usual team reports, I'm writing to send the Outreach Team's report in textual form! Feel free to reply if you have any que
|
By
Sebastian Crane
·
|
|
OpenChain Automation Case Study #5 - Running a Supply Chain using open source tooling + SPDX
Recording now available. Part #5 explores how SPDX ISO/IEC 5962 works as a Software Bill of Materials (SBOM) in the supply chain through existing open source tooling for open source compliance. https:
Recording now available. Part #5 explores how SPDX ISO/IEC 5962 works as a Software Bill of Materials (SBOM) in the supply chain through existing open source tooling for open source compliance. https:
|
By
Shane Coughlan
·
|
|
REMINDER: SPDX in Virtual Supply Chain Webinar in 15 minutes (09:00 UTC)
REMINDER: OpenChain Automation Case Study showing SPDX Software Bill of Materials being used in a “virtual supply chain” @ 09:00 UTC. Join without registration here: https://zoom.us/j/4377592799 Every
REMINDER: OpenChain Automation Case Study showing SPDX Software Bill of Materials being used in a “virtual supply chain” @ 09:00 UTC. Join without registration here: https://zoom.us/j/4377592799 Every
|
By
Shane Coughlan
·
|
|
REMINDER: Today is the Automation Case Study “virtual supply chain” showing code going through multiple scanners and maintaining SPDX integrity @ 09:00 UTC
REMINDER: Today is the OpenChain Automation Case Study “virtual supply chain” showing code going through multiple scanners and maintaining SPDX integrity @ 09:00 UTC. We will hold it on Zoom: https://
REMINDER: Today is the OpenChain Automation Case Study “virtual supply chain” showing code going through multiple scanners and maintaining SPDX integrity @ 09:00 UTC. We will hold it on Zoom: https://
|
By
Shane Coughlan
·
|
|
Taxonomy of software supply chain ecosystem?
6 messages
A taxonomy of this SSC ecosystem. I would like to have one, plz&thx. For instance, looking at this (very much work in progress, just noodling about as I think about things) picture, those items in eac
A taxonomy of this SSC ecosystem. I would like to have one, plz&thx. For instance, looking at this (very much work in progress, just noodling about as I think about things) picture, those items in eac
|
By
VM (Vicky) Brasseur
·
|
|
[spdx-tech] RFC: Creating a fairly complex SPDX document for an open source project (Julia)
2 messages
Hi all, Great news: ISO SPDX standard is now publicly available at: https://standards.iso.org/ittf/PubliclyAvailableStandards/ Best regards, Marc-Etienne
Hi all, Great news: ISO SPDX standard is now publicly available at: https://standards.iso.org/ittf/PubliclyAvailableStandards/ Best regards, Marc-Etienne
|
By
Vargenau, Marc-Etienne (Nokia - FR/Paris-Saclay)
·
|
|
Minutes from Nov 4 SPDX General Meeting
https://wiki.spdx.org/view/General_Meeting/Minutes/2021-11-04 General Meeting/Minutes/2021-11-04 < General Meeting | Minutes · Attendance: 25 · Lead by Phil Odence · Minutes from last approved · Comp
https://wiki.spdx.org/view/General_Meeting/Minutes/2021-11-04 General Meeting/Minutes/2021-11-04 < General Meeting | Minutes · Attendance: 25 · Lead by Phil Odence · Minutes from last approved · Comp
|
By
Phil Odence
·
|