<?xml version="1.0"?>
<?xml-stylesheet type="text/css" href="https://wiki.spdx.org/skins/common/feed.css?303"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.spdx.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Mjherzog</id>
		<title>SPDX Wiki - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.spdx.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Mjherzog"/>
		<link rel="alternate" type="text/html" href="https://wiki.spdx.org/view/Special:Contributions/Mjherzog"/>
		<updated>2026-05-07T12:09:46Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.23.13</generator>

	<entry>
		<id>https://wiki.spdx.org/view/Business_Team/SPDX_Vision_and_Mission_Discussion_Document_Final_Draft</id>
		<title>Business Team/SPDX Vision and Mission Discussion Document Final Draft</title>
		<link rel="alternate" type="text/html" href="https://wiki.spdx.org/view/Business_Team/SPDX_Vision_and_Mission_Discussion_Document_Final_Draft"/>
				<updated>2012-06-26T18:16:38Z</updated>
		
		<summary type="html">&lt;p&gt;Mjherzog: Changed &amp;quot;Deliver&amp;quot; to &amp;quot;Develop&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;h3&amp;gt;Proposed SPDX Vision Statement&amp;lt;/h3&amp;gt;&amp;lt;p&amp;gt;“The vision of SPDX is to achieve license compliance with minimal cost across the supply chain. Ideally, upstream component developers begin the process by supplying SPDX files as part of their downloads. Users of those components therefore have a starting point with the SPDX files that they create for their &amp;quot;customers,&amp;quot; and so on. If everything is working properly, the provenance of each piece of code is researched and documented only once during its journey through a supply chain, and that information is passed on in parallel with the code in the SPDX format.”&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;h3&amp;gt;Proposed SPDX Mission Statement&amp;lt;/h3&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot;&amp;gt;&amp;amp;nbsp;&amp;quot;Develop and promote adoption of a specification to enable any party in a software supply chain, from the original author to the final end user, to accurately communicate the licensing information for any piece of copyrightable material that such party may create, alter, combine, pass on, or receive, and to make such information available in a consistent, understandable, and re-usable fashion, with the aim of facilitating license and other policy compliance.&amp;quot;&amp;lt;/p&amp;gt;&lt;/div&gt;</summary>
		<author><name>Mjherzog</name></author>	</entry>

	<entry>
		<id>https://wiki.spdx.org/view/Wiki_Conventions</id>
		<title>Wiki Conventions</title>
		<link rel="alternate" type="text/html" href="https://wiki.spdx.org/view/Wiki_Conventions"/>
				<updated>2012-06-22T15:27:48Z</updated>
		
		<summary type="html">&lt;p&gt;Mjherzog: corrected strange font change&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;h2&amp;gt;First:&amp;lt;/h2&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;You need an account in order to edit the wiki pages. If you haven't created an account on FOSSBazaar or spdx.org yet, please &amp;lt;a href=&amp;quot;/user/register&amp;quot;&amp;gt;sign up&amp;lt;/a&amp;gt; for one now. If you already have a FOSSBazaar account, you can use it login here.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;There are three separate SPDX teams (&amp;lt;a href=&amp;quot;http://www.spdx.org/wiki/spdx/spec-development&amp;quot;&amp;gt;Technical&amp;lt;/a&amp;gt;, &amp;lt;a href=&amp;quot;http://www.spdx.org/wiki/spdx/biz&amp;quot;&amp;gt;Business&amp;lt;/a&amp;gt; and &amp;lt;a href=&amp;quot;http://www.spdx.org/wiki/spdx/legal&amp;quot;&amp;gt;Legal&amp;lt;/a&amp;gt;) each of which has its own meetings and mailing list. There is also a regular General Meeting and mailing list, the main purposes of which is to report out on team activities. Here you can subscribe to the &amp;lt;a href=&amp;quot;http://lists.spdx.org/mailman/listinfo/spdx&amp;quot;&amp;gt;SPDX mailing list&amp;lt;/a&amp;gt;&amp;amp;nbsp;which is a good way for anyone with casual interest to participate and be notified of general meetings. To participate on the teams or get on the team mailing lists, go to their respective sections under the Participation tab.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;A good starting point for understanding the spec is the &amp;lt;a href=&amp;quot;http://www.linuxfoundation.org/sites/main/files/publications/lf_foss_compliance_spdx.pdf&amp;quot;&amp;gt;SPDX whitepaper&amp;lt;/a&amp;gt;. This &amp;lt;a href=&amp;quot;http://www.blackducksoftware.com/files/spdx/intro_to_spdx.mov&amp;quot;&amp;gt;3 minute webinar&amp;lt;/a&amp;gt; provides a very concise introduction.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Another good resource is the &amp;lt;a title=&amp;quot;SPDX mailing list archive&amp;quot; href=&amp;quot;http://lists.spdx.org/pipermail/spdx/&amp;quot;&amp;gt;mailing list archive&amp;lt;/a&amp;gt;.&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;h2&amp;gt;Wiki&amp;lt;/h2&amp;gt;&amp;lt;p&amp;gt;Here are some instructions for using the SPDX wiki. Every user who is logged into spdx.org can modify wiki pages. At the top of a page, you'll see an &amp;quot;Edit&amp;quot; option. You can then edit the page using the HTML editor. When you save the page, make sure to put in a message in &amp;quot;Log message&amp;quot; briefly explaining the change you've made. Then click on &amp;quot;Save&amp;quot; at the bottom of the page to save or on &amp;quot;Preview&amp;quot; or &amp;quot;Preview changes&amp;quot; to preview before saving.&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;If a page has been edited more than once, you'll see a &amp;quot;Revisions&amp;quot; link at the top of the page (next to &amp;quot;Edit&amp;quot;). Clicking on this link will allow you to see in detail which changes have been made to the page.&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;If you want to create a new page, click on &amp;quot;Add child page&amp;quot;.&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;If you want to add a visible comment,&amp;amp;nbsp; please start the comment by indicating the source by your initials, bolded, surrounded by angle brackets.&amp;amp;nbsp; Then put the comment itself in italics.&amp;amp;nbsp; For example: &amp;lt;strong&amp;gt;&amp;amp;lt;kes&amp;amp;gt;&amp;lt;/strong&amp;gt; &amp;lt;em&amp;gt;this is a comment or a question?.&amp;lt;/em&amp;gt;&amp;amp;nbsp; The purpose of this is to make sure its clear that this is not part of the official text of the standard at this point, and provides localized context for the discussion.&amp;lt;/p&amp;gt;&lt;/div&gt;</summary>
		<author><name>Mjherzog</name></author>	</entry>

	<entry>
		<id>https://wiki.spdx.org/view/Business_Team/SPDX_Vision_and_Mission_Discussion_Document_Final_Draft</id>
		<title>Business Team/SPDX Vision and Mission Discussion Document Final Draft</title>
		<link rel="alternate" type="text/html" href="https://wiki.spdx.org/view/Business_Team/SPDX_Vision_and_Mission_Discussion_Document_Final_Draft"/>
				<updated>2012-06-21T16:59:45Z</updated>
		
		<summary type="html">&lt;p&gt;Mjherzog: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;h3&amp;gt;Proposed SPDX Vision Statement&amp;lt;/h3&amp;gt;&amp;lt;p&amp;gt;“The vision of SPDX is to achieve license compliance with minimal cost across the supply chain. Ideally, upstream component developers begin the process by supplying SPDX files as part of their downloads. Users of those components therefore have a starting point with the SPDX files that they create for their &amp;quot;customers,&amp;quot; and so on. If everything is working properly, the provenance of each piece of code is researched and documented only once during its journey through a supply chain, and that information is passed on in parallel with the code in the SPDX format.”&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;h3&amp;gt;Proposed SPDX Mission Statement&amp;lt;/h3&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot;&amp;gt;&amp;amp;nbsp;&amp;quot;Deliver and promote adoption of a specification to enable any party in a software supply chain, from the original author to the final end user, to accurately communicate the licensing information for any piece of copyrightable material that such party may create, alter, combine, pass on, or receive, and to make such information available in a consistent, understandable, and re-usable fashion, with the aim of facilitating license and other policy compliance.&amp;quot;&amp;lt;/p&amp;gt;&lt;/div&gt;</summary>
		<author><name>Mjherzog</name></author>	</entry>

	<entry>
		<id>https://wiki.spdx.org/view/Business_Team/Team_Role</id>
		<title>Business Team/Team Role</title>
		<link rel="alternate" type="text/html" href="https://wiki.spdx.org/view/Business_Team/Team_Role"/>
				<updated>2012-06-21T16:59:12Z</updated>
		
		<summary type="html">&lt;p&gt;Mjherzog: Posted current draft to the wiki&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;p&amp;gt;Draft as of June 21, 2012&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;The SPDX Business Team promotes the adoption of the SPDX specification across software supply chains, collects feedback and requirements from stakeholders, and leads a cross-team effort to develop the SPDX Strategy/Roadmap and update it based on stakeholder feedback.&amp;lt;/p&amp;gt;&lt;/div&gt;</summary>
		<author><name>Mjherzog</name></author>	</entry>

	<entry>
		<id>https://wiki.spdx.org/view/Business_Team/SPDX_Vision_and_Mission_Discussion_Document_Final_Draft</id>
		<title>Business Team/SPDX Vision and Mission Discussion Document Final Draft</title>
		<link rel="alternate" type="text/html" href="https://wiki.spdx.org/view/Business_Team/SPDX_Vision_and_Mission_Discussion_Document_Final_Draft"/>
				<updated>2012-06-21T16:54:50Z</updated>
		
		<summary type="html">&lt;p&gt;Mjherzog: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;h3&amp;gt;Proposed SPDX Vision Statement&amp;lt;/h3&amp;gt;&amp;lt;p&amp;gt;“The vision of SPDX is to achieve license compliance with minimal cost across the supply chain. Ideally, upstream component developers begin the process by supplying SPDX files as part of their downloads. Users of those components therefore have a starting point with the SPDX files that they create for their &amp;quot;customers,&amp;quot; and so on. If everything is working properly, the provenance of each piece of code is researched and documented only once during its journey through a supply chain, and that information is passed on in parallel with the code in the SPDX format.”&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;h3&amp;gt;Proposed SPDX Mission Statement&amp;lt;/h3&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot;&amp;gt;&amp;amp;nbsp;&amp;quot;Deliver and promote adoption of a specification to enable any party in a software supply chain, from the original author to the final end user, to accurately communicate the licensing information for any piece of copyrightable material that such party may create, alter, combine, pass on, or receive, and to make such information available in a consistent, understandable, and re-usable fashion, with the aim of facilitating license and other policy compliance.&amp;quot;&amp;lt;/p&amp;gt;&lt;/div&gt;</summary>
		<author><name>Mjherzog</name></author>	</entry>

	<entry>
		<id>https://wiki.spdx.org/view/Business_Team/SPDX_Vision_and_Mission_Discussion_Document</id>
		<title>Business Team/SPDX Vision and Mission Discussion Document</title>
		<link rel="alternate" type="text/html" href="https://wiki.spdx.org/view/Business_Team/SPDX_Vision_and_Mission_Discussion_Document"/>
				<updated>2012-06-21T16:54:24Z</updated>
		
		<summary type="html">&lt;p&gt;Mjherzog: Updated title to discussion document&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;h2&amp;gt;Background&amp;lt;/h2&amp;gt;&amp;lt;p&amp;gt;This is a discussion document regarding the vision, mission and charter of SPDX.&amp;lt;span&amp;gt;&amp;amp;nbsp; &amp;lt;/span&amp;gt;This discussion is in the context of planning for version 2.0 of the SPDX specification.&amp;lt;/p&amp;gt;&amp;lt;h3&amp;gt;Original (Current) Charter&amp;lt;/h3&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Spec 1.1&amp;lt;span&amp;gt;&amp;amp;nbsp; &amp;lt;/span&amp;gt;Charter:&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot; style=&amp;quot;margin: 0in 0in 0.0001pt 0.25in; line-height: normal;&amp;quot;&amp;gt;Create a set of data exchange standards that enable companies and organizations to share license and component information (metadata) for software packages and related content with the aim of facilitating license and other policy compliance.&amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Spec 1.2 Why is a common format for data exchange needed?&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot; style=&amp;quot;margin: 0in 0in 0.0001pt 0.5in; line-height: normal;&amp;quot;&amp;gt;Companies and organizations (collectively “Organizations”) are widely using and reusing open source and other software packages. Compliance with the associated licenses requires a set of due diligence activities that each Organization performs independently: a manual and/or automated scan of software and identification of associated licenses followed by manual verification. Software development teams across the globe use the same open source packages, but they have not yet set-up a way to collaborate on license discovery – many groups are performing the same work leading to duplicated effort and redundancy. This working group seeks to create a data exchange format so that information about software packages and related content, may be collected and shared in a common format with the goal of saving time and improving data accuracy.&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;&amp;amp;nbsp;Key&amp;amp;nbsp; Themes from SPDX Intro Slides &amp;lt;/strong&amp;gt;&amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Goal: Create a defined format for a file of license fact information describing a software package.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Guiding Principle: Focus on capturing facts; avoid interpretations.&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;h3&amp;gt;Current SPDX Solution Statement from SPDX Intro Slides&amp;lt;/h3&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;A file format for license information to accompany open source packages&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;A standardized short form to refer to the official version of common licenses&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Benefits:&amp;lt;/li&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Allows easy exchange of license information between companies reducing burden on both suppliers and consumers.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Avoids due diligence redundancy where the same source code package is analyzed multiple times by different recipients.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Provides a unified method for exchanging license information.&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;h3&amp;gt;What is the issue?&amp;lt;/h3&amp;gt;&amp;lt;p&amp;gt;Our current solution approach may not be sufficient to provide the desired Benefits; e.g. the means do not seem to match the ends. &amp;lt;span&amp;gt;&amp;amp;nbsp;&amp;lt;/span&amp;gt;Many current participants do not see how we can get to the desired benefits without expanding the mission and scope to encompass more of the compliance cycle.&amp;lt;span&amp;gt;&amp;amp;nbsp;&amp;amp;nbsp; &amp;lt;/span&amp;gt;If we expand the mission, then we may also need organization changes to support that mission, especially some form of product management across the teams.&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;Many SPDX participants are now talking about a broader and deeper mission beyond a data exchange format specification including a broader/deeper role in providing standards and &amp;lt;strong&amp;gt;open source&amp;lt;/strong&amp;gt; &amp;lt;strong&amp;gt;software&amp;lt;/strong&amp;gt; to facilitate software licensing due diligence and compliance activities across the supply chain:&amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Expanding the specification to include comprehensive information for meeting license obligations such as complete attribution data required by open source licenses – e.g. copyright and other notices,&amp;lt;/li&amp;gt;&amp;lt;li type=&amp;quot;_moz&amp;quot;&amp;gt;Developing comprehensive open source tools to support many or most due diligence and compliance activities,&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Analyzing licenses in a package using scanning and/or matching techniques to detect the licenses and generate an SPDX file from that analysis,&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Managing large volume of SPDX files – inbound and outbound,&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Automating obligation fulfillment such as generation of attribution text or creation of a source code redistribution package,&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Establishing a trusted repository of more comprehensive data about licenses – e.g. extend the License List to provide data for use by license detection tools,&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Possibly establishing a trusted repository of software components with their origin and license information&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;h3&amp;gt;Specification vs. Implementation&amp;lt;/h3&amp;gt;&amp;lt;p&amp;gt;There is some fundamental creative tension between our charter to create a Software Package Data Exchange specification and foster its adoption versus a broader mission to create open source software to actively facilitate/enable that adoption.&amp;lt;span&amp;gt;&amp;amp;nbsp;&amp;lt;/span&amp;gt;&amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;The SPDX original/current charter is to create a data specification and foster its adoption.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;We agreed early on to create some basic software tools to read and write SPDX files and encourage commercial vendors to support SPDX in their existing products.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;We also agreed to emulate an open source project, but we are not an open source project whose primary “work product” is software – our primary work product is the specification itself.&amp;lt;span&amp;gt;&amp;amp;nbsp;&amp;amp;nbsp; &amp;lt;/span&amp;gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;As the SPDX specification evolves (and presumably becomes more complex), it may be highly desirable or even necessary to provide some elements of a reference implementation to validate the specification before general release.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;We may be able to better leverage and extend existing open source projects, such as FOSSology, to offer elements of a reference implementation.&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;p&amp;gt;If we change our charter to include development of open source software to support software licensing due diligence and compliance activities across the supply chain, then we need to look closely at our form of organization.&amp;lt;/p&amp;gt;&amp;lt;h2&amp;gt;Vision and Mission Statements&amp;lt;/h2&amp;gt;&amp;lt;p&amp;gt;We currently have several documents that document and explain our vision and mission including:&amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;&amp;lt;span style=&amp;quot;font-family: Symbol;&amp;quot;&amp;gt;&amp;lt;span&amp;gt;&amp;lt;span style=&amp;quot;font: 7pt 'Times New Roman';&amp;quot;&amp;gt;&amp;amp;nbsp;&amp;lt;/span&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;/span&amp;gt;The SPDX Charter, Definition and other principles listed in &amp;lt;span style=&amp;quot;text-decoration: underline;&amp;quot;&amp;gt;Section 1. Rationale&amp;lt;/span&amp;gt; of the in the specification itself&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;The white paper - &amp;lt;span style=&amp;quot;text-decoration: underline;&amp;quot;&amp;gt;A Common Software Package Data Exchange Format: 1.0 Release Update and Discussion&amp;lt;/span&amp;gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Other materials such as several versions of the introductory presentations&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot;&amp;gt;Some members have already been thinking about expanding how we talk about our vision, mission, charter, and guiding principles – there are many names for specific elements of how an organization describes itself.&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;One approach is to add a Vision statement and a Mission statement for SPDX where the Vision statement describes what the future looks like when you execute on the mission and the Mission statement says what you do on a daily basis (similar to a guiding principle).&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;The following draft Vision and Mission statements are recent draft contributions from SPDX members:&amp;lt;/p&amp;gt;&amp;lt;h3&amp;gt;Proposed Vision Statement&amp;lt;/h3&amp;gt;&amp;lt;p&amp;gt;Phil Odence has proposed the following Vision statement for the website:&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;“The vision of SPDX is to achieve license compliance with minimal cost across the supply chain. Ideally, upstream component developers begin the process by supplying SPDX files as part of their downloads. Users of those components therefore have a starting point with the SPDX files that they create for their &amp;quot;customers,&amp;quot; and so on. If everything is working properly, the provenance of each piece of code is researched and documented only once during its journey through a supply chain, and that information is passed on in parallel with the code in the SPDX format.”&amp;lt;/p&amp;gt;&amp;lt;h3&amp;gt;Proposed Mission Statement&amp;lt;/h3&amp;gt;&amp;lt;p&amp;gt;The Cisco team has proposed the following Mission statement:&amp;lt;/p&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot;&amp;gt;&amp;quot;Deliver and promote adoption of a specification to enable any party in a software supply chain, from the original author to the final end user, to accurately communicate the licensing information for any piece of copyrightable material that such party may create, alter, combine, pass on, or receive, and to make such information available in a consistent, understandable, and re-usable fashion, with the aim of facilitating license and other policy compliance.&amp;quot;&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&lt;/div&gt;</summary>
		<author><name>Mjherzog</name></author>	</entry>

	<entry>
		<id>https://wiki.spdx.org/view/Business_Team/SPDX_Vision_and_Mission_Discussion_Document_Final_Draft</id>
		<title>Business Team/SPDX Vision and Mission Discussion Document Final Draft</title>
		<link rel="alternate" type="text/html" href="https://wiki.spdx.org/view/Business_Team/SPDX_Vision_and_Mission_Discussion_Document_Final_Draft"/>
				<updated>2012-06-21T16:52:18Z</updated>
		
		<summary type="html">&lt;p&gt;Mjherzog: formatting change&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;h3&amp;gt;Proposed SPDX Vision Statement &amp;lt;/h3&amp;gt;&amp;lt;p&amp;gt;“The vision of SPDX is to achieve license compliance with minimal cost across the supply chain. Ideally, upstream component developers begin the process by supplying SPDX files as part of their downloads. Users of those components therefore have a starting point with the SPDX files that they create for their &amp;quot;customers,&amp;quot; and so on. If everything is working properly, the provenance of each piece of code is researched and documented only once during its journey through a supply chain, and that information is passed on in parallel with the code in the SPDX format.”&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;h3&amp;gt;Proposed SPDX Mission Statement&amp;lt;/h3&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot;&amp;gt;&amp;amp;nbsp;&amp;quot;Deliver and promote adoption of a specification to enable any party in a software supply chain, from the original author to the final end user, to accurately communicate the licensing information for any piece of copyrightable material that such party may create, alter, combine, pass on, or receive, and to make such information available in a consistent, understandable, and re-usable fashion, with the aim of facilitating license and other policy compliance.&amp;quot;&amp;lt;/p&amp;gt;&lt;/div&gt;</summary>
		<author><name>Mjherzog</name></author>	</entry>

	<entry>
		<id>https://wiki.spdx.org/view/Business_Team/SPDX_Vision_and_Mission_Discussion_Document_Final_Draft</id>
		<title>Business Team/SPDX Vision and Mission Discussion Document Final Draft</title>
		<link rel="alternate" type="text/html" href="https://wiki.spdx.org/view/Business_Team/SPDX_Vision_and_Mission_Discussion_Document_Final_Draft"/>
				<updated>2012-06-21T16:51:36Z</updated>
		
		<summary type="html">&lt;p&gt;Mjherzog: Current draft statements as of June 21, 2012&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;h3&amp;gt;Proposed SPDX Vision Statement&amp;lt;/h3&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;“The vision of SPDX is to achieve license compliance with minimal cost across the supply chain. Ideally, upstream component developers begin the process by supplying SPDX files as part of their downloads. Users of those components therefore have a starting point with the SPDX files that they create for their &amp;quot;customers,&amp;quot; and so on. If everything is working properly, the provenance of each piece of code is researched and documented only once during its journey through a supply chain, and that information is passed on in parallel with the code in the SPDX format.”&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;h3&amp;gt;Proposed SPDX Mission Statement&amp;lt;/h3&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot;&amp;gt;&amp;quot;Deliver and promote adoption of a specification to enable any party in a software supply chain, from the original author to the final end user, to accurately communicate the licensing information for any piece of copyrightable material that such party may create, alter, combine, pass on, or receive, and to make such information available in a consistent, understandable, and re-usable fashion, with the aim of facilitating license and other policy compliance.&amp;quot;&amp;lt;/p&amp;gt;&lt;/div&gt;</summary>
		<author><name>Mjherzog</name></author>	</entry>

	<entry>
		<id>https://wiki.spdx.org/view/Business_Team/SPDX_Vision_and_Mission_Discussion_Document</id>
		<title>Business Team/SPDX Vision and Mission Discussion Document</title>
		<link rel="alternate" type="text/html" href="https://wiki.spdx.org/view/Business_Team/SPDX_Vision_and_Mission_Discussion_Document"/>
				<updated>2012-06-21T15:22:50Z</updated>
		
		<summary type="html">&lt;p&gt;Mjherzog: Added preamble to &amp;quot;Deliver and promote...&amp;quot; based on Business Team discussions&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;h2&amp;gt;Background&amp;lt;/h2&amp;gt;&amp;lt;p&amp;gt;This is a discussion document regarding the vision, mission and charter of SPDX.&amp;lt;span&amp;gt;&amp;amp;nbsp; &amp;lt;/span&amp;gt;This discussion is in the context of planning for version 2.0 of the SPDX specification.&amp;lt;/p&amp;gt;&amp;lt;h3&amp;gt;Original (Current) Charter&amp;lt;/h3&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Spec 1.1&amp;lt;span&amp;gt;&amp;amp;nbsp; &amp;lt;/span&amp;gt;Charter:&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot; style=&amp;quot;margin: 0in 0in 0.0001pt 0.25in; line-height: normal;&amp;quot;&amp;gt;Create a set of data exchange standards that enable companies and organizations to share license and component information (metadata) for software packages and related content with the aim of facilitating license and other policy compliance.&amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Spec 1.2 Why is a common format for data exchange needed?&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot; style=&amp;quot;margin: 0in 0in 0.0001pt 0.5in; line-height: normal;&amp;quot;&amp;gt;Companies and organizations (collectively “Organizations”) are widely using and reusing open source and other software packages. Compliance with the associated licenses requires a set of due diligence activities that each Organization performs independently: a manual and/or automated scan of software and identification of associated licenses followed by manual verification. Software development teams across the globe use the same open source packages, but they have not yet set-up a way to collaborate on license discovery – many groups are performing the same work leading to duplicated effort and redundancy. This working group seeks to create a data exchange format so that information about software packages and related content, may be collected and shared in a common format with the goal of saving time and improving data accuracy.&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;&amp;amp;nbsp;Key&amp;amp;nbsp; Themes from SPDX Intro Slides &amp;lt;/strong&amp;gt;&amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Goal: Create a defined format for a file of license fact information describing a software package.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Guiding Principle: Focus on capturing facts; avoid interpretations.&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;h3&amp;gt;Current SPDX Solution Statement from SPDX Intro Slides&amp;lt;/h3&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;A file format for license information to accompany open source packages&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;A standardized short form to refer to the official version of common licenses&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Benefits:&amp;lt;/li&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Allows easy exchange of license information between companies reducing burden on both suppliers and consumers.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Avoids due diligence redundancy where the same source code package is analyzed multiple times by different recipients.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Provides a unified method for exchanging license information.&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;h3&amp;gt;What is the issue?&amp;lt;/h3&amp;gt;&amp;lt;p&amp;gt;Our current solution approach may not be sufficient to provide the desired Benefits; e.g. the means do not seem to match the ends. &amp;lt;span&amp;gt;&amp;amp;nbsp;&amp;lt;/span&amp;gt;Many current participants do not see how we can get to the desired benefits without expanding the mission and scope to encompass more of the compliance cycle.&amp;lt;span&amp;gt;&amp;amp;nbsp;&amp;amp;nbsp; &amp;lt;/span&amp;gt;If we expand the mission, then we may also need organization changes to support that mission, especially some form of product management across the teams.&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;Many SPDX participants are now talking about a broader and deeper mission beyond a data exchange format specification including a broader/deeper role in providing standards and &amp;lt;strong&amp;gt;open source&amp;lt;/strong&amp;gt; &amp;lt;strong&amp;gt;software&amp;lt;/strong&amp;gt; to facilitate software licensing due diligence and compliance activities across the supply chain:&amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Expanding the specification to include comprehensive information for meeting license obligations such as complete attribution data required by open source licenses – e.g. copyright and other notices,&amp;lt;/li&amp;gt;&amp;lt;li type=&amp;quot;_moz&amp;quot;&amp;gt;Developing comprehensive open source tools to support many or most due diligence and compliance activities,&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Analyzing licenses in a package using scanning and/or matching techniques to detect the licenses and generate an SPDX file from that analysis,&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Managing large volume of SPDX files – inbound and outbound,&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Automating obligation fulfillment such as generation of attribution text or creation of a source code redistribution package,&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Establishing a trusted repository of more comprehensive data about licenses – e.g. extend the License List to provide data for use by license detection tools,&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Possibly establishing a trusted repository of software components with their origin and license information&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;h3&amp;gt;Specification vs. Implementation&amp;lt;/h3&amp;gt;&amp;lt;p&amp;gt;There is some fundamental creative tension between our charter to create a Software Package Data Exchange specification and foster its adoption versus a broader mission to create open source software to actively facilitate/enable that adoption.&amp;lt;span&amp;gt;&amp;amp;nbsp;&amp;lt;/span&amp;gt;&amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;The SPDX original/current charter is to create a data specification and foster its adoption.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;We agreed early on to create some basic software tools to read and write SPDX files and encourage commercial vendors to support SPDX in their existing products.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;We also agreed to emulate an open source project, but we are not an open source project whose primary “work product” is software – our primary work product is the specification itself.&amp;lt;span&amp;gt;&amp;amp;nbsp;&amp;amp;nbsp; &amp;lt;/span&amp;gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;As the SPDX specification evolves (and presumably becomes more complex), it may be highly desirable or even necessary to provide some elements of a reference implementation to validate the specification before general release.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;We may be able to better leverage and extend existing open source projects, such as FOSSology, to offer elements of a reference implementation.&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;p&amp;gt;If we change our charter to include development of open source software to support software licensing due diligence and compliance activities across the supply chain, then we need to look closely at our form of organization.&amp;lt;/p&amp;gt;&amp;lt;h2&amp;gt;Vision and Mission Statements&amp;lt;/h2&amp;gt;&amp;lt;p&amp;gt;We currently have several documents that document and explain our vision and mission including:&amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;&amp;lt;span style=&amp;quot;font-family: Symbol;&amp;quot;&amp;gt;&amp;lt;span&amp;gt;&amp;lt;span style=&amp;quot;font: 7pt 'Times New Roman';&amp;quot;&amp;gt;&amp;amp;nbsp;&amp;lt;/span&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;/span&amp;gt;The SPDX Charter, Definition and other principles listed in &amp;lt;span style=&amp;quot;text-decoration: underline;&amp;quot;&amp;gt;Section 1. Rationale&amp;lt;/span&amp;gt; of the in the specification itself&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;The white paper - &amp;lt;span style=&amp;quot;text-decoration: underline;&amp;quot;&amp;gt;A Common Software Package Data Exchange Format: 1.0 Release Update and Discussion&amp;lt;/span&amp;gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Other materials such as several versions of the introductory presentations&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot;&amp;gt;Some members have already been thinking about expanding how we talk about our vision, mission, charter, and guiding principles – there are many names for specific elements of how an organization describes itself.&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;One approach is to add a Vision statement and a Mission statement for SPDX where the Vision statement describes what the future looks like when you execute on the mission and the Mission statement says what you do on a daily basis (similar to a guiding principle).&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;The following draft Vision and Mission statements are recent draft contributions from SPDX members:&amp;lt;/p&amp;gt;&amp;lt;h3&amp;gt;Proposed Vision Statement&amp;lt;/h3&amp;gt;&amp;lt;p&amp;gt;Phil Odence has proposed the following Vision statement for the website:&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;“The vision of SPDX is to achieve license compliance with minimal cost across the supply chain. Ideally, upstream component developers begin the process by supplying SPDX files as part of their downloads. Users of those components therefore have a starting point with the SPDX files that they create for their &amp;quot;customers,&amp;quot; and so on. If everything is working properly, the provenance of each piece of code is researched and documented only once during its journey through a supply chain, and that information is passed on in parallel with the code in the SPDX format.”&amp;lt;/p&amp;gt;&amp;lt;h3&amp;gt;Proposed Mission Statement&amp;lt;/h3&amp;gt;&amp;lt;p&amp;gt;The Cisco team has proposed the following Mission statement:&amp;lt;/p&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot;&amp;gt;&amp;quot;Deliver and promote adoption of a specification to enable any party in a software supply chain, from the original author to the final end user, to accurately communicate the licensing information for any piece of copyrightable material that such party may create, alter, combine, pass on, or receive, and to make such information available in a consistent, understandable, and re-usable fashion, with the aim of facilitating license and other policy compliance.&amp;quot;&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&lt;/div&gt;</summary>
		<author><name>Mjherzog</name></author>	</entry>

	<entry>
		<id>https://wiki.spdx.org/view/Business_Team/SPDX_Vision_and_Mission_Discussion_Document</id>
		<title>Business Team/SPDX Vision and Mission Discussion Document</title>
		<link rel="alternate" type="text/html" href="https://wiki.spdx.org/view/Business_Team/SPDX_Vision_and_Mission_Discussion_Document"/>
				<updated>2012-05-30T15:48:25Z</updated>
		
		<summary type="html">&lt;p&gt;Mjherzog: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;h2&amp;gt;Background&amp;lt;/h2&amp;gt;&amp;lt;p&amp;gt;This is a discussion document regarding the vision, mission and charter of SPDX.&amp;lt;span&amp;gt;&amp;amp;nbsp; &amp;lt;/span&amp;gt;This discussion is in the context of planning for version 2.0 of the SPDX specification.&amp;lt;/p&amp;gt;&amp;lt;h3&amp;gt;Original (Current) Charter&amp;lt;/h3&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Spec 1.1&amp;lt;span&amp;gt;&amp;amp;nbsp; &amp;lt;/span&amp;gt;Charter:&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot; style=&amp;quot;margin: 0in 0in 0.0001pt 0.25in; line-height: normal;&amp;quot;&amp;gt;Create a set of data exchange standards that enable companies and organizations to share license and component information (metadata) for software packages and related content with the aim of facilitating license and other policy compliance.&amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Spec 1.2 Why is a common format for data exchange needed?&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot; style=&amp;quot;margin: 0in 0in 0.0001pt 0.5in; line-height: normal;&amp;quot;&amp;gt;Companies and organizations (collectively “Organizations”) are widely using and reusing open source and other software packages. Compliance with the associated licenses requires a set of due diligence activities that each Organization performs independently: a manual and/or automated scan of software and identification of associated licenses followed by manual verification. Software development teams across the globe use the same open source packages, but they have not yet set-up a way to collaborate on license discovery – many groups are performing the same work leading to duplicated effort and redundancy. This working group seeks to create a data exchange format so that information about software packages and related content, may be collected and shared in a common format with the goal of saving time and improving data accuracy.&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;&amp;amp;nbsp;Key&amp;amp;nbsp; Themes from SPDX Intro Slides &amp;lt;/strong&amp;gt;&amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Goal: Create a defined format for a file of license fact information describing a software package.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Guiding Principle: Focus on capturing facts; avoid interpretations.&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;h3&amp;gt;Current SPDX Solution Statement from SPDX Intro Slides&amp;lt;/h3&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;A file format for license information to accompany open source packages&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;A standardized short form to refer to the official version of common licenses&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Benefits:&amp;lt;/li&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Allows easy exchange of license information between companies reducing burden on both suppliers and consumers.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Avoids due diligence redundancy where the same source code package is analyzed multiple times by different recipients.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Provides a unified method for exchanging license information.&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;h3&amp;gt;What is the issue?&amp;lt;/h3&amp;gt;&amp;lt;p&amp;gt;Our current solution approach may not be sufficient to provide the desired Benefits; e.g. the means do not seem to match the ends. &amp;lt;span&amp;gt;&amp;amp;nbsp;&amp;lt;/span&amp;gt;Many current participants do not see how we can get to the desired benefits without expanding the mission and scope to encompass more of the compliance cycle.&amp;lt;span&amp;gt;&amp;amp;nbsp;&amp;amp;nbsp; &amp;lt;/span&amp;gt;If we expand the mission, then we may also need organization changes to support that mission, especially some form of product management across the teams.&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;Many SPDX participants are now talking about a broader and deeper mission beyond a data exchange format specification including a broader/deeper role in providing standards and &amp;lt;strong&amp;gt;open source&amp;lt;/strong&amp;gt; &amp;lt;strong&amp;gt;software&amp;lt;/strong&amp;gt; to facilitate software licensing due diligence and compliance activities across the supply chain:&amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Expanding the specification to include comprehensive information for meeting license obligations such as complete attribution data required by open source licenses – e.g. copyright and other notices,&amp;lt;/li&amp;gt;&amp;lt;li type=&amp;quot;_moz&amp;quot;&amp;gt;Developing comprehensive open source tools to support many or most due diligence and compliance activities,&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Analyzing licenses in a package using scanning and/or matching techniques to detect the licenses and generate an SPDX file from that analysis,&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Managing large volume of SPDX files – inbound and outbound,&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Automating obligation fulfillment such as generation of attribution text or creation of a source code redistribution package,&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Establishing a trusted repository of more comprehensive data about licenses – e.g. extend the License List to provide data for use by license detection tools,&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Possibly establishing a trusted repository of software components with their origin and license information&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;h3&amp;gt;Specification vs. Implementation&amp;lt;/h3&amp;gt;&amp;lt;p&amp;gt;There is some fundamental creative tension between our charter to create a Software Package Data Exchange specification and foster its adoption versus a broader mission to create open source software to actively facilitate/enable that adoption.&amp;lt;span&amp;gt;&amp;amp;nbsp;&amp;lt;/span&amp;gt;&amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;The SPDX original/current charter is to create a data specification and foster its adoption.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;We agreed early on to create some basic software tools to read and write SPDX files and encourage commercial vendors to support SPDX in their existing products.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;We also agreed to emulate an open source project, but we are not an open source project whose primary “work product” is software – our primary work product is the specification itself.&amp;lt;span&amp;gt;&amp;amp;nbsp;&amp;amp;nbsp; &amp;lt;/span&amp;gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;As the SPDX specification evolves (and presumably becomes more complex), it may be highly desirable or even necessary to provide some elements of a reference implementation to validate the specification before general release.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;We may be able to better leverage and extend existing open source projects, such as FOSSology, to offer elements of a reference implementation.&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;p&amp;gt;If we change our charter to include development of open source software to support software licensing due diligence and compliance activities across the supply chain, then we need to look closely at our form of organization.&amp;lt;/p&amp;gt;&amp;lt;h2&amp;gt;Vision and Mission Statements&amp;lt;/h2&amp;gt;&amp;lt;p&amp;gt;We currently have several documents that document and explain our vision and mission including:&amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;&amp;lt;span style=&amp;quot;font-family: Symbol;&amp;quot;&amp;gt;&amp;lt;span&amp;gt;&amp;lt;span style=&amp;quot;font: 7pt 'Times New Roman';&amp;quot;&amp;gt;&amp;amp;nbsp;&amp;lt;/span&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;/span&amp;gt;The SPDX Charter, Definition and other principles listed in &amp;lt;span style=&amp;quot;text-decoration: underline;&amp;quot;&amp;gt;Section 1. Rationale&amp;lt;/span&amp;gt; of the in the specification itself&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;The white paper - &amp;lt;span style=&amp;quot;text-decoration: underline;&amp;quot;&amp;gt;A Common Software Package Data Exchange Format: 1.0 Release Update and Discussion&amp;lt;/span&amp;gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Other materials such as several versions of the introductory presentations&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot;&amp;gt;Some members have already been thinking about expanding how we talk about our vision, mission, charter, and guiding principles – there are many names for specific elements of how an organization describes itself.&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;One approach is to add a Vision statement and a Mission statement for SPDX where the Vision statement describes what the future looks like when you execute on the mission and the Mission statement says what you do on a daily basis (similar to a guiding principle).&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;The following draft Vision and Mission statements are recent draft contributions from SPDX members:&amp;lt;/p&amp;gt;&amp;lt;h3&amp;gt;Proposed Vision Statement&amp;lt;/h3&amp;gt;&amp;lt;p&amp;gt;Phil Odence has proposed the following Vision statement for the website:&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;“The vision of SPDX is to achieve license compliance with minimal cost across the supply chain. Ideally, upstream component developers begin the process by supplying SPDX files as part of their downloads. Users of those components therefore have a starting point with the SPDX files that they create for their &amp;quot;customers,&amp;quot; and so on. If everything is working properly, the provenance of each piece of code is researched and documented only once during its journey through a supply chain, and that information is passed on in parallel with the code in the SPDX format.”&amp;lt;/p&amp;gt;&amp;lt;h3&amp;gt;Proposed Mission Statement&amp;lt;/h3&amp;gt;&amp;lt;p&amp;gt;The Cisco team has proposed the following Mission statement:&amp;lt;/p&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot;&amp;gt;&amp;quot;To enable any party in a software supply chain, from the original author to the final end user, to accurately communicate the licensing information for any piece of copyrightable material that such party may create, alter, combine, pass on, or receive, and to make such information available in a consistent, understandable, and re-usable fashion, with the aim of facilitating license and other policy compliance.&amp;quot;&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&lt;/div&gt;</summary>
		<author><name>Mjherzog</name></author>	</entry>

	<entry>
		<id>https://wiki.spdx.org/view/Business_Team/SPDX_Vision_and_Mission_Discussion_Document</id>
		<title>Business Team/SPDX Vision and Mission Discussion Document</title>
		<link rel="alternate" type="text/html" href="https://wiki.spdx.org/view/Business_Team/SPDX_Vision_and_Mission_Discussion_Document"/>
				<updated>2012-05-30T15:47:14Z</updated>
		
		<summary type="html">&lt;p&gt;Mjherzog: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;h2&amp;gt;Background &amp;lt;/h2&amp;gt;&amp;lt;p&amp;gt;This is a discussion document regarding the vision, mission and charter of SPDX.&amp;lt;span&amp;gt;&amp;amp;nbsp; &amp;lt;/span&amp;gt;This discussion is in the context of planning for version 2.0 of the SPDX specification. &amp;lt;/p&amp;gt;&amp;lt;h3&amp;gt;Original (Current) Charter &amp;lt;/h3&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Spec 1.1&amp;lt;span&amp;gt;&amp;amp;nbsp; &amp;lt;/span&amp;gt;Charter: &amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot; style=&amp;quot;margin: 0in 0in 0.0001pt 0.25in; line-height: normal;&amp;quot;&amp;gt;Create a set of data exchange standards that enable companies and organizations to share license and component information (metadata) for software packages and related content with the aim of facilitating license and other policy compliance.&amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Spec 1.2 Why is a common format for data exchange needed? &amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot; style=&amp;quot;margin: 0in 0in 0.0001pt 0.5in; line-height: normal;&amp;quot;&amp;gt;Companies and organizations (collectively “Organizations”) are widely using and reusing open source and other software packages. Compliance with the associated licenses requires a set of due diligence activities that each Organization performs independently: a manual and/or automated scan of software and identification of associated licenses followed by manual verification. Software development teams across the globe use the same open source packages, but they have not yet set-up a way to collaborate on license discovery – many groups are performing the same work leading to duplicated effort and redundancy. This working group seeks to create a data exchange format so that information about software packages and related content, may be collected and shared in a common format with the goal of saving time and improving data accuracy.&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;&amp;amp;nbsp;Key&amp;amp;nbsp; Themes from SPDX Intro Slides &amp;lt;/strong&amp;gt;&amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Goal: Create a defined format for a file of license fact information describing a software package.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Guiding Principle: Focus on capturing facts; avoid interpretations. &amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;h3&amp;gt;Current SPDX Solution Statement from SPDX Intro Slides &amp;lt;/h3&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;A file format for license information to accompany open source packages&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;A standardized short form to refer to the official version of common licenses&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Benefits:&amp;lt;/li&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Allows easy exchange of license information between companies reducing burden on both suppliers and consumers.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Avoids due diligence redundancy where the same source code package is analyzed multiple times by different recipients.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Provides a unified method for exchanging license information. &amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;h3&amp;gt;What is the issue? &amp;lt;/h3&amp;gt;&amp;lt;p&amp;gt;Our current solution approach may not be sufficient to provide the desired Benefits; e.g. the means do not seem to match the ends. &amp;lt;span&amp;gt;&amp;amp;nbsp;&amp;lt;/span&amp;gt;Many current participants do not see how we can get to the desired benefits without expanding the mission and scope to encompass more of the compliance cycle.&amp;lt;span&amp;gt;&amp;amp;nbsp;&amp;amp;nbsp; &amp;lt;/span&amp;gt;If we expand the mission, then we may also need organization changes to support that mission, especially some form of product management across the teams. &amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;Many SPDX participants are now talking about a broader and deeper mission beyond a data exchange format specification including a broader/deeper role in providing standards and &amp;lt;strong&amp;gt;open source&amp;lt;/strong&amp;gt; &amp;lt;strong&amp;gt;software&amp;lt;/strong&amp;gt; to facilitate software licensing due diligence and compliance activities across the supply chain: &amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Expanding the specification to include comprehensive information for meeting license obligations such as complete attribution data required by open source licenses – e.g. copyright and other notices,&amp;lt;/li&amp;gt;&amp;lt;li type=&amp;quot;_moz&amp;quot;&amp;gt;Developing comprehensive open source tools to support many or most due diligence and compliance activities,&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Analyzing licenses in a package using scanning and/or matching techniques to detect the licenses and generate an SPDX file from that analysis,&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Managing large volume of SPDX files – inbound and outbound,&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Automating obligation fulfillment such as generation of attribution text or creation of a source code redistribution package,&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Establishing a trusted repository of more comprehensive data about licenses – e.g. extend the License List to provide data for use by license detection tools,&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Possibly establishing a trusted repository of software components with their origin and license information &amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;h3&amp;gt;Specification vs. Implementation &amp;lt;/h3&amp;gt;&amp;lt;p&amp;gt;There is some fundamental creative tension between our charter to create a Software Package Data Exchange specification and foster its adoption versus a broader mission to create open source software to actively facilitate/enable that adoption.&amp;lt;span&amp;gt;&amp;amp;nbsp;&amp;lt;/span&amp;gt; &amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;The SPDX original/current charter is to create a data specification and foster its adoption.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;We agreed early on to create some basic software tools to read and write SPDX files and encourage commercial vendors to support SPDX in their existing products.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;We also agreed to emulate an open source project, but we are not an open source project whose primary “work product” is software – our primary work product is the specification itself.&amp;lt;span&amp;gt;&amp;amp;nbsp;&amp;amp;nbsp; &amp;lt;/span&amp;gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;As the SPDX specification evolves (and presumably becomes more complex), it may be highly desirable or even necessary to provide some elements of a reference implementation to validate the specification before general release.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;We may be able to better leverage and extend existing open source projects, such as FOSSology, to offer elements of a reference implementation. &amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;p&amp;gt;If we change our charter to include development of open source software to support software licensing due diligence and compliance activities across the supply chain, then we need to look closely at our form of organization. &amp;lt;/p&amp;gt;&amp;lt;h2&amp;gt;Vision and Mission Statements &amp;lt;/h2&amp;gt;&amp;lt;p&amp;gt;We currently have several documents that document and explain our vision and mission including: &amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;&amp;lt;span style=&amp;quot;font-family: Symbol;&amp;quot;&amp;gt;&amp;lt;span&amp;gt;&amp;lt;span style=&amp;quot;font: 7pt 'Times New Roman';&amp;quot;&amp;gt;&amp;amp;nbsp;&amp;lt;/span&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;/span&amp;gt;The SPDX Charter, Definition and other principles listed in &amp;lt;span style=&amp;quot;text-decoration: underline;&amp;quot;&amp;gt;Section 1. Rationale&amp;lt;/span&amp;gt; of the in the specification itself &amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;The white paper - &amp;lt;span style=&amp;quot;text-decoration: underline;&amp;quot;&amp;gt;A Common Software Package Data Exchange Format: 1.0 Release Update and Discussion&amp;lt;/span&amp;gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Other materials such as several versions of the introductory presentations&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot;&amp;gt;Some members have already been thinking about expanding how we talk about our vision, mission, charter, and guiding principles – there are many names for specific elements of how an organization describes itself.&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;One approach is to add a Vision statement and a Mission statement for SPDX where the Vision statement describes what the future looks like when you execute on the mission and the Mission statement says what you do on a daily basis (similar to a guiding principle). &amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;The following draft Vision and Mission statements are recent draft contributions from SPDX members: &amp;lt;/p&amp;gt;&amp;lt;h3&amp;gt;Proposed Vision Statement &amp;lt;/h3&amp;gt;&amp;lt;p&amp;gt;Phil Odence has proposed the following Vision statement for the website: &amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;“The vision of SPDX is to achieve license compliance with minimal cost across the supply chain. Ideally, upstream component developers begin the process by supplying SPDX files as part of their downloads. Users of those components therefore have a starting point with the SPDX files that they create for their &amp;quot;customers,&amp;quot; and so on. If everything is working properly, the provenance of each piece of code is researched and documented only once during its journey through a supply chain, and that information is passed on in parallel with the code in the SPDX format.” &amp;lt;/p&amp;gt;&amp;lt;h3&amp;gt;Proposed Mission Statement &amp;lt;/h3&amp;gt;&amp;lt;p&amp;gt;The Cisco team has proposed the following Mission statement: &amp;lt;/p&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot;&amp;gt;&amp;quot;To enable any party in a software supply chain, from the original author to the final end user, to accurately communicate the licensing information for any piece of copyrightable material that such party may create, alter, combine, pass on, or receive, and to make such information available in a consistent, understandable, and re-usable fashion, with the aim of facilitating license and other policy compliance.&amp;quot;&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&lt;/div&gt;</summary>
		<author><name>Mjherzog</name></author>	</entry>

	<entry>
		<id>https://wiki.spdx.org/view/Business_Team/SPDX_Vision_and_Mission_Discussion_Document</id>
		<title>Business Team/SPDX Vision and Mission Discussion Document</title>
		<link rel="alternate" type="text/html" href="https://wiki.spdx.org/view/Business_Team/SPDX_Vision_and_Mission_Discussion_Document"/>
				<updated>2012-05-30T15:43:45Z</updated>
		
		<summary type="html">&lt;p&gt;Mjherzog: First draft version&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;h2&amp;gt;Background&amp;lt;/h2&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot;&amp;gt;This is a discussion document regarding the vision, mission and charter of SPDX.&amp;lt;span&amp;gt;&amp;amp;nbsp; &amp;lt;/span&amp;gt;This discussion is in the context of planning for version 2.0 of the SPDX specification.&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;h3&amp;gt;Original (Current) Charter&amp;lt;/h3&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Spec 1.1&amp;lt;span&amp;gt;&amp;amp;nbsp; &amp;lt;/span&amp;gt;Charter:&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot; style=&amp;quot;margin: 0in 0in 0.0001pt 0.25in; line-height: normal;&amp;quot;&amp;gt;Create a set of data exchange standards that enable companies and organizations to share license and component information (metadata) for software packages and related content with the aim of facilitating license and other policy compliance.&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Spec 1.2 Why is a common format for data exchange needed?&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot; style=&amp;quot;margin: 0in 0in 0.0001pt 0.5in; line-height: normal;&amp;quot;&amp;gt;Companies and organizations (collectively “Organizations”) are widely using and reusing open source and other software packages. Compliance with the associated licenses requires a set of due diligence activities that each Organization performs independently: a manual and/or automated scan of software and identification of associated licenses followed by manual verification. Software development teams across the globe use the same open source packages, but they have not yet set-up a way to collaborate on license discovery – many groups are performing the same work leading to duplicated effort and redundancy. This working group seeks to create a data exchange format so that information about software packages and related content, may be collected and shared in a common format with the goal of saving time and improving data accuracy.&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot; style=&amp;quot;margin: 0in 0in 0.0001pt 0.5in; line-height: normal;&amp;quot;&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;h3&amp;gt;Key&amp;lt;span&amp;gt;&amp;amp;nbsp; &amp;lt;/span&amp;gt;Themes from SPDX Intro Slides&amp;lt;/h3&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Goal: Create a defined format for a file of license fact information describing a software package.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Guiding Principle: Focus on capturing facts; avoid interpretations.&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;h3&amp;gt;Current SPDX Solution Statement from SPDX Intro Slides&amp;lt;/h3&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;A file format for license information to accompany open source packages&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;A standardized short form to refer to the official version of common licenses&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Benefits:&amp;lt;/li&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Allows easy exchange of license information between companies reducing burden on both suppliers and consumers.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Avoids due diligence redundancy where the same source code package is analyzed multiple times by different recipients.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Provides a unified method for exchanging license information.&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;h3&amp;gt;What is the issue?&amp;lt;/h3&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot;&amp;gt;Our current solution approach may not be sufficient to provide the desired Benefits; e.g. the means do not seem to match the ends. &amp;lt;span&amp;gt;&amp;amp;nbsp;&amp;lt;/span&amp;gt;Many current participants do not see how we can get to the desired benefits without expanding the mission and scope to encompass more of the compliance cycle.&amp;lt;span&amp;gt;&amp;amp;nbsp;&amp;amp;nbsp; &amp;lt;/span&amp;gt;If we expand the mission, then we may also need organization changes to support that mission, especially some form of product management across the teams.&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot;&amp;gt;Many SPDX participants are now talking about a broader and deeper mission beyond a data exchange format specification including a broader/deeper role in providing standards and &amp;lt;strong&amp;gt;open source&amp;lt;/strong&amp;gt; &amp;lt;strong&amp;gt;software&amp;lt;/strong&amp;gt; to facilitate software licensing due diligence and compliance activities across the supply chain:&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Expanding the specification to include comprehensive information for meeting license obligations such as complete attribution data required by open source licenses – e.g. copyright and other notices,&amp;lt;/li&amp;gt;&amp;lt;li type=&amp;quot;_moz&amp;quot;&amp;gt;Developing comprehensive open source tools to support many or most due diligence and compliance activities,&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Analyzing licenses in a package using scanning and/or matching techniques to detect the licenses and generate an SPDX file from that analysis,&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Managing large volume of SPDX files – inbound and outbound,&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Automating obligation fulfillment such as generation of attribution text or creation of a source code redistribution package,&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Establishing a trusted repository of more comprehensive data about licenses – e.g. extend the License List to provide data for use by license detection tools,&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Possibly establishing a trusted repository of software components with their origin and license information&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;h3&amp;gt;Specification vs. Implementation&amp;lt;/h3&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot;&amp;gt;There is some fundamental creative tension between our charter to create a Software Package Data Exchange specification and foster its adoption versus a broader mission to create open source software to actively facilitate/enable that adoption.&amp;lt;span&amp;gt;&amp;amp;nbsp; &amp;lt;/span&amp;gt;&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;The SPDX original/current charter is to create a data specification and foster its adoption.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;We agreed early on to create some basic software tools to read and write SPDX files and encourage commercial vendors to support SPDX in their existing products.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;We also agreed to emulate an open source project, but we are not an open source project whose primary “work product” is software – our primary work product is the specification itself.&amp;lt;span&amp;gt;&amp;amp;nbsp;&amp;amp;nbsp; &amp;lt;/span&amp;gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;As the SPDX specification evolves (and presumably becomes more complex), it may be highly desirable or even necessary to provide some elements of a reference implementation to validate the specification before general release.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;We may be able to better leverage and extend existing open source projects, such as FOSSology, to offer elements of a reference implementation.&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot;&amp;gt;If we change our charter to include development of open source software to support software licensing due diligence and compliance activities across the supply chain, then we need to look closely at our form of organization.&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;h2&amp;gt;Vision and Mission Statements&amp;lt;/h2&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot; style=&amp;quot;margin-bottom: 0.0001pt;&amp;quot;&amp;gt;We currently have several documents that document and explain our vision and mission including:&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;p class=&amp;quot;MsoListParagraphCxSpFirst&amp;quot; style=&amp;quot;margin-bottom: 0.0001pt; text-indent: -0.25in;&amp;quot;&amp;gt;&amp;lt;span style=&amp;quot;font-family: Symbol;&amp;quot;&amp;gt;&amp;lt;span&amp;gt;·&amp;lt;span style=&amp;quot;font: 7pt 'Times New Roman';&amp;quot;&amp;gt;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp; &amp;lt;/span&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;/span&amp;gt;The SPDX Charter, Definition and other principles listed in &amp;lt;span style=&amp;quot;text-decoration: underline;&amp;quot;&amp;gt;Section 1. Rationale&amp;lt;/span&amp;gt; of the in the specification itself&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;p class=&amp;quot;MsoListParagraphCxSpMiddle&amp;quot; style=&amp;quot;text-indent: -0.25in;&amp;quot;&amp;gt;&amp;lt;span style=&amp;quot;font-family: Symbol;&amp;quot;&amp;gt;&amp;lt;span&amp;gt;·&amp;lt;span style=&amp;quot;font: 7pt 'Times New Roman';&amp;quot;&amp;gt;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp; &amp;lt;/span&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;/span&amp;gt;The white paper - &amp;lt;span style=&amp;quot;text-decoration: underline;&amp;quot;&amp;gt;A Common Software Package Data Exchange Format: 1.0 Release Update and Discussion&amp;lt;/span&amp;gt;&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;p class=&amp;quot;MsoListParagraphCxSpLast&amp;quot; style=&amp;quot;text-indent: -0.25in;&amp;quot;&amp;gt;&amp;lt;span style=&amp;quot;font-family: Symbol;&amp;quot;&amp;gt;&amp;lt;span&amp;gt;·&amp;lt;span style=&amp;quot;font: 7pt 'Times New Roman';&amp;quot;&amp;gt;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp; &amp;lt;/span&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;/span&amp;gt;Other materials such as several versions of the introductory presentations&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot;&amp;gt;&amp;lt;span&amp;gt;&amp;amp;nbsp;&amp;lt;/span&amp;gt;Some members have already been thinking about expanding how we talk about our vision, mission, charter, and guiding principles – there are many names for specific elements of how an organization describes itself.&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot;&amp;gt;One approach is to add a Vision statement and a Mission statement for SPDX where the Vision statement describes what the future looks like when you execute on the mission and the Mission statement says what you do on a daily basis (similar to a guiding principle).&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot;&amp;gt;The following draft Vision and Mission statements are recent draft contributions from SPDX members:&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;h3&amp;gt;Proposed Vision Statement&amp;lt;/h3&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot;&amp;gt;Phil Odence has proposed the following Vision statement for the website:&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot;&amp;gt;“The vision of SPDX is to achieve license compliance with minimal cost across the supply chain. Ideally, upstream component developers begin the process by supplying SPDX files as part of their downloads. Users of those components therefore have a starting point with the SPDX files that they create for their &amp;quot;customers,&amp;quot; and so on. If everything is working properly, the provenance of each piece of code is researched and documented only once during its journey through a supply chain, and that information is passed on in parallel with the code in the SPDX format.”&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;h3&amp;gt;Proposed Mission Statement&amp;lt;/h3&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot;&amp;gt;The Cisco team has proposed the following Mission statement:&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot;&amp;gt;&amp;quot;To enable any party in a software supply chain, from the original author to the final end user, to accurately communicate the licensing information for any piece of copyrightable material that such party may create, alter, combine, pass on, or receive, and to make such information available in a consistent, understandable, and re-usable fashion, with the aim of facilitating license and other policy compliance.&amp;quot;&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&lt;/div&gt;</summary>
		<author><name>Mjherzog</name></author>	</entry>

	<entry>
		<id>https://wiki.spdx.org/view/Technical_Team/Use_Cases/2.0/Aggregators_aggregating_other_aggregations_for_redistribution</id>
		<title>Technical Team/Use Cases/2.0/Aggregators aggregating other aggregations for redistribution</title>
		<link rel="alternate" type="text/html" href="https://wiki.spdx.org/view/Technical_Team/Use_Cases/2.0/Aggregators_aggregating_other_aggregations_for_redistribution"/>
				<updated>2012-05-22T18:40:42Z</updated>
		
		<summary type="html">&lt;p&gt;Mjherzog: corrected spelling&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;ol style=&amp;quot;color: #4d4d4d; font-family: Arial, Helvetica, sans-serif; font-size: 13px;&amp;quot;&amp;gt;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Title:&amp;lt;/strong&amp;gt;&amp;amp;nbsp;Aggregators aggregating other aggregations for redistribution&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Primary Actor: Aggregator of aggregations&amp;lt;/strong&amp;gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Goal in Context:&amp;lt;/strong&amp;gt;&amp;amp;nbsp;To allow an aggregator of aggregations to express in SPDX the internal structure of what the copyrightable artifacts they are shipping are, how they are organized hierarchically, and the licensing information for all of it.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Stakeholders and Interests:&amp;lt;/strong&amp;gt;&amp;amp;nbsp;&amp;lt;ol&amp;gt;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;&amp;lt;strong&amp;gt;Aggregator of aggregations&amp;lt;/strong&amp;gt;:&amp;amp;nbsp;&amp;lt;/strong&amp;gt;&amp;lt;ol&amp;gt;&amp;lt;li&amp;gt;To communicate the licensing information for their aggregate of aggregations including the internal structure and provenance.&amp;lt;/li&amp;gt;&amp;lt;/ol&amp;gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Consumers of Embedded Images:&amp;lt;/strong&amp;gt;&amp;lt;ol&amp;gt;&amp;lt;li&amp;gt;To receive accurate and clear information of licensing of the aggregate and all they contain.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;To be able to comply easily with licenses for the aggregate and all it contains.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;To be able to trust that the aggregate SPDX data is in alignment with the upstream maintainers license assertions of the pieces it contains.&amp;lt;/li&amp;gt;&amp;lt;/ol&amp;gt;&amp;lt;/li&amp;gt;&amp;lt;/ol&amp;gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Preconditions:&amp;lt;/strong&amp;gt;&amp;amp;nbsp;&amp;lt;ol&amp;gt;&amp;lt;li&amp;gt;Aggregator of aggregates understands the things it contains, including any SPDX data if provided.&amp;lt;/li&amp;gt;&amp;lt;/ol&amp;gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Main Success Senario:&amp;lt;/strong&amp;gt;&amp;amp;nbsp;Aggregator of aggregates communicates accurate complete licensing information for their package in an SPDX data format for the Aggregate and all it contains.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Failed End Condition:&amp;lt;/strong&amp;gt;&amp;amp;nbsp;Aggregator of aggregates does not communicates accurate complete licensing information for their package in an SPDX data format for the Aggregate and all it contains.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Trigger:&amp;lt;/strong&amp;gt;&amp;lt;ol&amp;gt;&amp;lt;li&amp;gt;Release of a new aggregate.&amp;lt;/li&amp;gt;&amp;lt;/ol&amp;gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Notes:&amp;lt;/strong&amp;gt;&amp;amp;nbsp;&amp;amp;nbsp;&amp;lt;/li&amp;gt;&amp;lt;/ol&amp;gt;&lt;/div&gt;</summary>
		<author><name>Mjherzog</name></author>	</entry>

	<entry>
		<id>https://wiki.spdx.org/view/Old/Linux_Collaboration_Summit_2011</id>
		<title>Old/Linux Collaboration Summit 2011</title>
		<link rel="alternate" type="text/html" href="https://wiki.spdx.org/view/Old/Linux_Collaboration_Summit_2011"/>
				<updated>2011-03-23T22:53:06Z</updated>
		
		<summary type="html">&lt;p&gt;Mjherzog: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;p&amp;gt;The &amp;lt;a href=&amp;quot;http://events.linuxfoundation.org/events/collaboration-summit&amp;quot;&amp;gt;Linux Collaboration Summit&amp;lt;/a&amp;gt; is in San Francisco, April 6-8. The SPDX &amp;lt;a href=&amp;quot;http://events.linuxfoundation.org/events/collaboration-summit/spdx-technical&amp;quot;&amp;gt;Technical&amp;lt;/a&amp;gt; and &amp;lt;a href=&amp;quot;http://events.linuxfoundation.org/events/collaboration-summit/spdx-business&amp;quot;&amp;gt;Business&amp;lt;/a&amp;gt; teams will be holding face to face meetings. If you would like to participate, please &amp;lt;a href=&amp;quot;http://www.regonline.com/Register/Checkin.aspx?EventID=923747&amp;quot;&amp;gt;request an invitation&amp;lt;/a&amp;gt; to the event from the Linux Foundation. If you alert Phil Koltun&amp;amp;nbsp;pkoltun@linuxfoundation.org that you have requested an invitation because you are interested in SPDX parrticipation, he can streamline the approval process.&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;And, if you are coming, please edit your name into the RSVP list(s) below:&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;I'm coming to the SPDX Technical Team Face to Face&amp;lt;/strong&amp;gt;:&amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Kate Stewart, Canonical&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Phil Odence, Black Duck Software&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Phil Koltun, Linux Foundation&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt; Peter Williams, OpenLogic&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Michael Herzog, nexB&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;I'm coming to the SPDX Business Team Face to Face:&amp;lt;/strong&amp;gt;&amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Kim Weins, Open Logic&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Phil Odence, Black Duck Software&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Phil Koltun, Linux Foundation&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Pierre Lapointe, nexB&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Michael Herzog, nexB&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&lt;/div&gt;</summary>
		<author><name>Mjherzog</name></author>	</entry>

	</feed>