<?xml version="1.0"?>
<?xml-stylesheet type="text/css" href="https://wiki.spdx.org/skins/common/feed.css?303"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.spdx.org/index.php?action=history&amp;feed=atom&amp;title=Business_Team%2FSPDX_Vision_and_Mission_Discussion_Document</id>
		<title>Business Team/SPDX Vision and Mission Discussion Document - Revision history</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.spdx.org/index.php?action=history&amp;feed=atom&amp;title=Business_Team%2FSPDX_Vision_and_Mission_Discussion_Document"/>
		<link rel="alternate" type="text/html" href="https://wiki.spdx.org/index.php?title=Business_Team/SPDX_Vision_and_Mission_Discussion_Document&amp;action=history"/>
		<updated>2026-05-07T12:53:43Z</updated>
		<subtitle>Revision history for this page on the wiki</subtitle>
		<generator>MediaWiki 1.23.13</generator>

	<entry>
		<id>https://wiki.spdx.org/index.php?title=Business_Team/SPDX_Vision_and_Mission_Discussion_Document&amp;diff=1987&amp;oldid=prev</id>
		<title>MartinMichlmayr: Convert to MediaWiki syntax</title>
		<link rel="alternate" type="text/html" href="https://wiki.spdx.org/index.php?title=Business_Team/SPDX_Vision_and_Mission_Discussion_Document&amp;diff=1987&amp;oldid=prev"/>
				<updated>2013-02-28T22:17:12Z</updated>
		
		<summary type="html">&lt;p&gt;Convert to MediaWiki syntax&lt;/p&gt;
&lt;table class='diff diff-contentalign-left'&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;tr style='vertical-align: top;'&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;Revision as of 22:17, 28 February 2013&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;h2&amp;gt;&lt;/del&gt;Background&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;/h2&amp;gt;&amp;lt;p&amp;gt;&lt;/del&gt;This is a discussion document regarding the vision, mission and charter of SPDX.&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;span&amp;gt;&amp;amp;nbsp; &amp;lt;/span&amp;gt;&lt;/del&gt;This discussion is in the context of planning for version 2.0 of the SPDX specification.&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;/p&amp;gt;&amp;lt;h3&amp;gt;&lt;/del&gt;Original (Current) Charter&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;/h3&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;&lt;/del&gt;Spec 1.1&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;span&amp;gt;&amp;amp;nbsp; &amp;lt;/span&amp;gt;&lt;/del&gt;Charter:&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot; style=&amp;quot;margin: 0in 0in 0.0001pt 0.25in; line-height: normal;&amp;quot;&amp;gt;&lt;/del&gt;Create a set of data exchange standards that enable companies and organizations to share license and component information (metadata) for software packages and related content with the aim of facilitating license and other policy compliance.&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;&lt;/del&gt;Spec 1.2 Why is a common format for data exchange needed?&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot; style=&amp;quot;margin: 0in 0in 0.0001pt 0.5in; line-height: normal;&amp;quot;&amp;gt;&lt;/del&gt;Companies and organizations (collectively “Organizations”) are widely using and reusing open source and other software packages. Compliance with the associated licenses requires a set of due diligence activities that each Organization performs independently: a manual and/or automated scan of software and identification of associated licenses followed by manual verification. Software development teams across the globe use the same open source packages, but they have not yet set-up a way to collaborate on license discovery – many groups are performing the same work leading to duplicated effort and redundancy. This working group seeks to create a data exchange format so that information about software packages and related content, may be collected and shared in a common format with the goal of saving time and improving data accuracy.&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;&amp;amp;nbsp;&lt;/del&gt;Key&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;amp;nbsp; &lt;/del&gt;Themes from SPDX Intro Slides &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;/strong&amp;gt;&amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;&lt;/del&gt;Goal: Create a defined format for a file of license fact information describing a software package.&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;&lt;/del&gt;Guiding Principle: Focus on capturing facts; avoid interpretations.&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;h3&amp;gt;&lt;/del&gt;Current SPDX Solution Statement from SPDX Intro Slides&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;/h3&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;&lt;/del&gt;A file format for license information to accompany open source packages&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;&lt;/del&gt;A standardized short form to refer to the official version of common licenses&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;&lt;/del&gt;Benefits:&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;/li&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;&lt;/del&gt;Allows easy exchange of license information between companies reducing burden on both suppliers and consumers.&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;&lt;/del&gt;Avoids due diligence redundancy where the same source code package is analyzed multiple times by different recipients.&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;&lt;/del&gt;Provides a unified method for exchanging license information.&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;h3&amp;gt;&lt;/del&gt;What is the issue?&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;/h3&amp;gt;&amp;lt;p&amp;gt;&lt;/del&gt;Our current solution approach may not be sufficient to provide the desired Benefits; e.g. the means do not seem to match the ends. &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;span&amp;gt;&amp;amp;nbsp;&amp;lt;/span&amp;gt;&lt;/del&gt;Many current participants do not see how we can get to the desired benefits without expanding the mission and scope to encompass more of the compliance cycle.&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;span&amp;gt;&amp;amp;nbsp;&amp;amp;nbsp; &amp;lt;/span&amp;gt;&lt;/del&gt;If we expand the mission, then we may also need organization changes to support that mission, especially some form of product management across the teams.&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&lt;/del&gt;Many SPDX participants are now talking about a broader and deeper mission beyond a data exchange format specification including a broader/deeper role in providing standards and &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;strong&amp;gt;&lt;/del&gt;open source&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;/strong&amp;gt; &amp;lt;strong&amp;gt;&lt;/del&gt;software&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;/strong&amp;gt; &lt;/del&gt;to facilitate software licensing due diligence and compliance activities across the supply chain:&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;&lt;/del&gt;Expanding the specification to include comprehensive information for meeting license obligations such as complete attribution data required by open source licenses – e.g. copyright and other notices,&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;/li&amp;gt;&amp;lt;li type=&amp;quot;_moz&amp;quot;&amp;gt;&lt;/del&gt;Developing comprehensive open source tools to support many or most due diligence and compliance activities,&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;&lt;/del&gt;Analyzing licenses in a package using scanning and/or matching techniques to detect the licenses and generate an SPDX file from that analysis,&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;&lt;/del&gt;Managing large volume of SPDX files – inbound and outbound,&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;&lt;/del&gt;Automating obligation fulfillment such as generation of attribution text or creation of a source code redistribution package,&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;&lt;/del&gt;Establishing a trusted repository of more comprehensive data about licenses – e.g. extend the License List to provide data for use by license detection tools,&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;&lt;/del&gt;Possibly establishing a trusted repository of software components with their origin and license information&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;h3&amp;gt;&lt;/del&gt;Specification vs. Implementation&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;/h3&amp;gt;&amp;lt;p&amp;gt;&lt;/del&gt;There is some fundamental creative tension between our charter to create a Software Package Data Exchange specification and foster its adoption versus a broader mission to create open source software to actively facilitate/enable that adoption.&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;span&amp;gt;&amp;amp;nbsp;&amp;lt;/span&amp;gt;&amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;&lt;/del&gt;The SPDX original/current charter is to create a data specification and foster its adoption.&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;&lt;/del&gt;We agreed early on to create some basic software tools to read and write SPDX files and encourage commercial vendors to support SPDX in their existing products.&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;&lt;/del&gt;We also agreed to emulate an open source project, but we are not an open source project whose primary “work product” is software – our primary work product is the specification itself.&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;span&amp;gt;&amp;amp;nbsp;&amp;amp;nbsp; &amp;lt;/span&amp;gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;&lt;/del&gt;As the SPDX specification evolves (and presumably becomes more complex), it may be highly desirable or even necessary to provide some elements of a reference implementation to validate the specification before general release.&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;&lt;/del&gt;We may be able to better leverage and extend existing open source projects, such as FOSSology, to offer elements of a reference implementation.&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;p&amp;gt;&lt;/del&gt;If we change our charter to include development of open source software to support software licensing due diligence and compliance activities across the supply chain, then we need to look closely at our form of organization.&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;/p&amp;gt;&amp;lt;h2&amp;gt;&lt;/del&gt;Vision and Mission Statements&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;/h2&amp;gt;&amp;lt;p&amp;gt;&lt;/del&gt;We currently have several documents that document and explain our vision and mission including:&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;&amp;lt;span style=&amp;quot;font-family: Symbol;&amp;quot;&amp;gt;&amp;lt;span&amp;gt;&amp;lt;span style=&amp;quot;font: 7pt 'Times New Roman';&amp;quot;&amp;gt;&amp;amp;nbsp;&amp;lt;/span&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;/span&amp;gt;&lt;/del&gt;The SPDX Charter, Definition and other principles listed in &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;span style=&amp;quot;text-decoration: underline;&amp;quot;&amp;gt;&lt;/del&gt;Section 1. Rationale&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;/span&amp;gt; &lt;/del&gt;of the in the specification itself&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;&lt;/del&gt;The white paper - &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;span style=&amp;quot;text-decoration: underline;&amp;quot;&amp;gt;&lt;/del&gt;A Common Software Package Data Exchange Format: 1.0 Release Update and Discussion&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;/span&amp;gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;&lt;/del&gt;Other materials such as several versions of the introductory presentations&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot;&amp;gt;&lt;/del&gt;Some members have already been thinking about expanding how we talk about our vision, mission, charter, and guiding principles – there are many names for specific elements of how an organization describes itself.&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&lt;/del&gt;One approach is to add a Vision statement and a Mission statement for SPDX where the Vision statement describes what the future looks like when you execute on the mission and the Mission statement says what you do on a daily basis (similar to a guiding principle).&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&lt;/del&gt;The following draft Vision and Mission statements are recent draft contributions from SPDX members:&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;/p&amp;gt;&amp;lt;h3&amp;gt;&lt;/del&gt;Proposed Vision Statement&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;/h3&amp;gt;&amp;lt;p&amp;gt;&lt;/del&gt;Phil Odence has proposed the following Vision statement for the website:&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&lt;/del&gt;“The vision of SPDX is to achieve license compliance with minimal cost across the supply chain. Ideally, upstream component developers begin the process by supplying SPDX files as part of their downloads. Users of those components therefore have a starting point with the SPDX files that they create for their &amp;quot;customers,&amp;quot; and so on. If everything is working properly, the provenance of each piece of code is researched and documented only once during its journey through a supply chain, and that information is passed on in parallel with the code in the SPDX format.”&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;/p&amp;gt;&amp;lt;h3&amp;gt;&lt;/del&gt;Proposed Mission Statement&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;/h3&amp;gt;&amp;lt;p&amp;gt;&lt;/del&gt;The Cisco team has proposed the following Mission statement:&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;/p&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot;&amp;gt;&lt;/del&gt;&amp;quot;Deliver and promote adoption of a specification to enable any party in a software supply chain, from the original author to the final end user, to accurately communicate the licensing information for any piece of copyrightable material that such party may create, alter, combine, pass on, or receive, and to make such information available in a consistent, understandable, and re-usable fashion, with the aim of facilitating license and other policy compliance.&amp;quot;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;== &lt;/ins&gt;Background &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;==&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;This is a discussion document regarding the vision, mission and charter of SPDX. This discussion is in the context of planning for version 2.0 of the SPDX specification.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;=== &lt;/ins&gt;Original (Current) Charter &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;===&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;* &lt;/ins&gt;Spec 1.1 Charter:&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Create a set of data exchange standards that enable companies and organizations to share license and component information (metadata) for software packages and related content with the aim of facilitating license and other policy compliance.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;* &lt;/ins&gt;Spec 1.2 Why is a common format for data exchange needed?&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Companies and organizations (collectively “Organizations”) are widely using and reusing open source and other software packages. Compliance with the associated licenses requires a set of due diligence activities that each Organization performs independently: a manual and/or automated scan of software and identification of associated licenses followed by manual verification. Software development teams across the globe use the same open source packages, but they have not yet set-up a way to collaborate on license discovery – many groups are performing the same work leading to duplicated effort and redundancy. This working group seeks to create a data exchange format so that information about software packages and related content, may be collected and shared in a common format with the goal of saving time and improving data accuracy.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;''' &lt;/ins&gt;Key Themes from SPDX Intro Slides &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;'''&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;* &lt;/ins&gt;Goal: Create a defined format for a file of license fact information describing a software package.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;* &lt;/ins&gt;Guiding Principle: Focus on capturing facts; avoid interpretations.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;=== &lt;/ins&gt;Current SPDX Solution Statement from SPDX Intro Slides &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;===&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;* &lt;/ins&gt;A file format for license information to accompany open source packages&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;* &lt;/ins&gt;A standardized short form to refer to the official version of common licenses&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;* &lt;/ins&gt;Benefits:&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;** &lt;/ins&gt;Allows easy exchange of license information between companies reducing burden on both suppliers and consumers.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;** &lt;/ins&gt;Avoids due diligence redundancy where the same source code package is analyzed multiple times by different recipients.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;** &lt;/ins&gt;Provides a unified method for exchanging license information.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;=== &lt;/ins&gt;What is the issue? &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;===&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Our current solution approach may not be sufficient to provide the desired Benefits; e.g. the means do not seem to match the ends. &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt; &lt;/ins&gt;Many current participants do not see how we can get to the desired benefits without expanding the mission and scope to encompass more of the compliance cycle. If we expand the mission, then we may also need organization changes to support that mission, especially some form of product management across the teams.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Many SPDX participants are now talking about a broader and deeper mission beyond a data exchange format specification including a broader/deeper role in providing standards and &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;'''&lt;/ins&gt;open source&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;''' '''&lt;/ins&gt;software&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;''' &lt;/ins&gt;to facilitate software licensing due diligence and compliance activities across the supply chain:&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;* &lt;/ins&gt;Expanding the specification to include comprehensive information for meeting license obligations such as complete attribution data required by open source licenses – e.g. copyright and other notices,&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;* &lt;/ins&gt;Developing comprehensive open source tools to support many or most due diligence and compliance activities,&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;* &lt;/ins&gt;Analyzing licenses in a package using scanning and/or matching techniques to detect the licenses and generate an SPDX file from that analysis,&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;* &lt;/ins&gt;Managing large volume of SPDX files – inbound and outbound,&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;* &lt;/ins&gt;Automating obligation fulfillment such as generation of attribution text or creation of a source code redistribution package,&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;* &lt;/ins&gt;Establishing a trusted repository of more comprehensive data about licenses – e.g. extend the License List to provide data for use by license detection tools,&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;* &lt;/ins&gt;Possibly establishing a trusted repository of software components with their origin and license information&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;=== &lt;/ins&gt;Specification vs. Implementation &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;===&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;There is some fundamental creative tension between our charter to create a Software Package Data Exchange specification and foster its adoption versus a broader mission to create open source software to actively facilitate/enable that adoption.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;* &lt;/ins&gt;The SPDX original/current charter is to create a data specification and foster its adoption.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;* &lt;/ins&gt;We agreed early on to create some basic software tools to read and write SPDX files and encourage commercial vendors to support SPDX in their existing products.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;* &lt;/ins&gt;We also agreed to emulate an open source project, but we are not an open source project whose primary “work product” is software – our primary work product is the specification itself.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;* &lt;/ins&gt;As the SPDX specification evolves (and presumably becomes more complex), it may be highly desirable or even necessary to provide some elements of a reference implementation to validate the specification before general release.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;* &lt;/ins&gt;We may be able to better leverage and extend existing open source projects, such as FOSSology, to offer elements of a reference implementation.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;If we change our charter to include development of open source software to support software licensing due diligence and compliance activities across the supply chain, then we need to look closely at our form of organization.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;== &lt;/ins&gt;Vision and Mission Statements &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;==&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;We currently have several documents that document and explain our vision and mission including:&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;* &lt;/ins&gt;The SPDX Charter, Definition and other principles listed in Section 1. Rationale of the in the specification itself&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;* &lt;/ins&gt;The white paper - A Common Software Package Data Exchange Format: 1.0 Release Update and Discussion&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;* &lt;/ins&gt;Other materials such as several versions of the introductory presentations&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Some members have already been thinking about expanding how we talk about our vision, mission, charter, and guiding principles – there are many names for specific elements of how an organization describes itself.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;One approach is to add a Vision statement and a Mission statement for SPDX where the Vision statement describes what the future looks like when you execute on the mission and the Mission statement says what you do on a daily basis (similar to a guiding principle).&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;The following draft Vision and Mission statements are recent draft contributions from SPDX members:&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;=== &lt;/ins&gt;Proposed Vision Statement &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;===&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Phil Odence has proposed the following Vision statement for the website:&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;“The vision of SPDX is to achieve license compliance with minimal cost across the supply chain. Ideally, upstream component developers begin the process by supplying SPDX files as part of their downloads. Users of those components therefore have a starting point with the SPDX files that they create for their &amp;quot;customers,&amp;quot; and so on. If everything is working properly, the provenance of each piece of code is researched and documented only once during its journey through a supply chain, and that information is passed on in parallel with the code in the SPDX format.”&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;=== &lt;/ins&gt;Proposed Mission Statement &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;===&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;The Cisco team has proposed the following Mission statement:&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;quot;Deliver and promote adoption of a specification to enable any party in a software supply chain, from the original author to the final end user, to accurately communicate the licensing information for any piece of copyrightable material that such party may create, alter, combine, pass on, or receive, and to make such information available in a consistent, understandable, and re-usable fashion, with the aim of facilitating license and other policy compliance.&amp;quot;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;[[Category:Business]]&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;[[Category:Archived]]&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>MartinMichlmayr</name></author>	</entry>

	<entry>
		<id>https://wiki.spdx.org/index.php?title=Business_Team/SPDX_Vision_and_Mission_Discussion_Document&amp;diff=1986&amp;oldid=prev</id>
		<title>Mjherzog: Updated title to discussion document</title>
		<link rel="alternate" type="text/html" href="https://wiki.spdx.org/index.php?title=Business_Team/SPDX_Vision_and_Mission_Discussion_Document&amp;diff=1986&amp;oldid=prev"/>
				<updated>2012-06-21T16:54:24Z</updated>
		
		<summary type="html">&lt;p&gt;Updated title to discussion document&lt;/p&gt;
&lt;table class='diff diff-contentalign-left'&gt;
				&lt;tr style='vertical-align: top;'&gt;
				&lt;td colspan='1' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan='1' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;Revision as of 16:54, 21 June 2012&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan='2' style='text-align: center;'&gt;&lt;div class=&quot;mw-diff-empty&quot;&gt;(No difference)&lt;/div&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;</summary>
		<author><name>Mjherzog</name></author>	</entry>

	<entry>
		<id>https://wiki.spdx.org/index.php?title=Business_Team/SPDX_Vision_and_Mission_Discussion_Document&amp;diff=1985&amp;oldid=prev</id>
		<title>Mjherzog: Added preamble to &quot;Deliver and promote...&quot; based on Business Team discussions</title>
		<link rel="alternate" type="text/html" href="https://wiki.spdx.org/index.php?title=Business_Team/SPDX_Vision_and_Mission_Discussion_Document&amp;diff=1985&amp;oldid=prev"/>
				<updated>2012-06-21T15:22:50Z</updated>
		
		<summary type="html">&lt;p&gt;Added preamble to &amp;quot;Deliver and promote...&amp;quot; based on Business Team discussions&lt;/p&gt;
&lt;table class='diff diff-contentalign-left'&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;tr style='vertical-align: top;'&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;Revision as of 15:22, 21 June 2012&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;h2&amp;gt;Background&amp;lt;/h2&amp;gt;&amp;lt;p&amp;gt;This is a discussion document regarding the vision, mission and charter of SPDX.&amp;lt;span&amp;gt;&amp;amp;nbsp; &amp;lt;/span&amp;gt;This discussion is in the context of planning for version 2.0 of the SPDX specification.&amp;lt;/p&amp;gt;&amp;lt;h3&amp;gt;Original (Current) Charter&amp;lt;/h3&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Spec 1.1&amp;lt;span&amp;gt;&amp;amp;nbsp; &amp;lt;/span&amp;gt;Charter:&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot; style=&amp;quot;margin: 0in 0in 0.0001pt 0.25in; line-height: normal;&amp;quot;&amp;gt;Create a set of data exchange standards that enable companies and organizations to share license and component information (metadata) for software packages and related content with the aim of facilitating license and other policy compliance.&amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Spec 1.2 Why is a common format for data exchange needed?&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot; style=&amp;quot;margin: 0in 0in 0.0001pt 0.5in; line-height: normal;&amp;quot;&amp;gt;Companies and organizations (collectively “Organizations”) are widely using and reusing open source and other software packages. Compliance with the associated licenses requires a set of due diligence activities that each Organization performs independently: a manual and/or automated scan of software and identification of associated licenses followed by manual verification. Software development teams across the globe use the same open source packages, but they have not yet set-up a way to collaborate on license discovery – many groups are performing the same work leading to duplicated effort and redundancy. This working group seeks to create a data exchange format so that information about software packages and related content, may be collected and shared in a common format with the goal of saving time and improving data accuracy.&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;&amp;amp;nbsp;Key&amp;amp;nbsp; Themes from SPDX Intro Slides &amp;lt;/strong&amp;gt;&amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Goal: Create a defined format for a file of license fact information describing a software package.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Guiding Principle: Focus on capturing facts; avoid interpretations.&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;h3&amp;gt;Current SPDX Solution Statement from SPDX Intro Slides&amp;lt;/h3&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;A file format for license information to accompany open source packages&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;A standardized short form to refer to the official version of common licenses&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Benefits:&amp;lt;/li&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Allows easy exchange of license information between companies reducing burden on both suppliers and consumers.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Avoids due diligence redundancy where the same source code package is analyzed multiple times by different recipients.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Provides a unified method for exchanging license information.&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;h3&amp;gt;What is the issue?&amp;lt;/h3&amp;gt;&amp;lt;p&amp;gt;Our current solution approach may not be sufficient to provide the desired Benefits; e.g. the means do not seem to match the ends. &amp;lt;span&amp;gt;&amp;amp;nbsp;&amp;lt;/span&amp;gt;Many current participants do not see how we can get to the desired benefits without expanding the mission and scope to encompass more of the compliance cycle.&amp;lt;span&amp;gt;&amp;amp;nbsp;&amp;amp;nbsp; &amp;lt;/span&amp;gt;If we expand the mission, then we may also need organization changes to support that mission, especially some form of product management across the teams.&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;Many SPDX participants are now talking about a broader and deeper mission beyond a data exchange format specification including a broader/deeper role in providing standards and &amp;lt;strong&amp;gt;open source&amp;lt;/strong&amp;gt; &amp;lt;strong&amp;gt;software&amp;lt;/strong&amp;gt; to facilitate software licensing due diligence and compliance activities across the supply chain:&amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Expanding the specification to include comprehensive information for meeting license obligations such as complete attribution data required by open source licenses – e.g. copyright and other notices,&amp;lt;/li&amp;gt;&amp;lt;li type=&amp;quot;_moz&amp;quot;&amp;gt;Developing comprehensive open source tools to support many or most due diligence and compliance activities,&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Analyzing licenses in a package using scanning and/or matching techniques to detect the licenses and generate an SPDX file from that analysis,&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Managing large volume of SPDX files – inbound and outbound,&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Automating obligation fulfillment such as generation of attribution text or creation of a source code redistribution package,&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Establishing a trusted repository of more comprehensive data about licenses – e.g. extend the License List to provide data for use by license detection tools,&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Possibly establishing a trusted repository of software components with their origin and license information&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;h3&amp;gt;Specification vs. Implementation&amp;lt;/h3&amp;gt;&amp;lt;p&amp;gt;There is some fundamental creative tension between our charter to create a Software Package Data Exchange specification and foster its adoption versus a broader mission to create open source software to actively facilitate/enable that adoption.&amp;lt;span&amp;gt;&amp;amp;nbsp;&amp;lt;/span&amp;gt;&amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;The SPDX original/current charter is to create a data specification and foster its adoption.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;We agreed early on to create some basic software tools to read and write SPDX files and encourage commercial vendors to support SPDX in their existing products.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;We also agreed to emulate an open source project, but we are not an open source project whose primary “work product” is software – our primary work product is the specification itself.&amp;lt;span&amp;gt;&amp;amp;nbsp;&amp;amp;nbsp; &amp;lt;/span&amp;gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;As the SPDX specification evolves (and presumably becomes more complex), it may be highly desirable or even necessary to provide some elements of a reference implementation to validate the specification before general release.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;We may be able to better leverage and extend existing open source projects, such as FOSSology, to offer elements of a reference implementation.&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;p&amp;gt;If we change our charter to include development of open source software to support software licensing due diligence and compliance activities across the supply chain, then we need to look closely at our form of organization.&amp;lt;/p&amp;gt;&amp;lt;h2&amp;gt;Vision and Mission Statements&amp;lt;/h2&amp;gt;&amp;lt;p&amp;gt;We currently have several documents that document and explain our vision and mission including:&amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;&amp;lt;span style=&amp;quot;font-family: Symbol;&amp;quot;&amp;gt;&amp;lt;span&amp;gt;&amp;lt;span style=&amp;quot;font: 7pt 'Times New Roman';&amp;quot;&amp;gt;&amp;amp;nbsp;&amp;lt;/span&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;/span&amp;gt;The SPDX Charter, Definition and other principles listed in &amp;lt;span style=&amp;quot;text-decoration: underline;&amp;quot;&amp;gt;Section 1. Rationale&amp;lt;/span&amp;gt; of the in the specification itself&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;The white paper - &amp;lt;span style=&amp;quot;text-decoration: underline;&amp;quot;&amp;gt;A Common Software Package Data Exchange Format: 1.0 Release Update and Discussion&amp;lt;/span&amp;gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Other materials such as several versions of the introductory presentations&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot;&amp;gt;Some members have already been thinking about expanding how we talk about our vision, mission, charter, and guiding principles – there are many names for specific elements of how an organization describes itself.&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;One approach is to add a Vision statement and a Mission statement for SPDX where the Vision statement describes what the future looks like when you execute on the mission and the Mission statement says what you do on a daily basis (similar to a guiding principle).&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;The following draft Vision and Mission statements are recent draft contributions from SPDX members:&amp;lt;/p&amp;gt;&amp;lt;h3&amp;gt;Proposed Vision Statement&amp;lt;/h3&amp;gt;&amp;lt;p&amp;gt;Phil Odence has proposed the following Vision statement for the website:&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;“The vision of SPDX is to achieve license compliance with minimal cost across the supply chain. Ideally, upstream component developers begin the process by supplying SPDX files as part of their downloads. Users of those components therefore have a starting point with the SPDX files that they create for their &amp;quot;customers,&amp;quot; and so on. If everything is working properly, the provenance of each piece of code is researched and documented only once during its journey through a supply chain, and that information is passed on in parallel with the code in the SPDX format.”&amp;lt;/p&amp;gt;&amp;lt;h3&amp;gt;Proposed Mission Statement&amp;lt;/h3&amp;gt;&amp;lt;p&amp;gt;The Cisco team has proposed the following Mission statement:&amp;lt;/p&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot;&amp;gt;&amp;quot;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;To &lt;/del&gt;enable any party in a software supply chain, from the original author to the final end user, to accurately communicate the licensing information for any piece of copyrightable material that such party may create, alter, combine, pass on, or receive, and to make such information available in a consistent, understandable, and re-usable fashion, with the aim of facilitating license and other policy compliance.&amp;quot;&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;h2&amp;gt;Background&amp;lt;/h2&amp;gt;&amp;lt;p&amp;gt;This is a discussion document regarding the vision, mission and charter of SPDX.&amp;lt;span&amp;gt;&amp;amp;nbsp; &amp;lt;/span&amp;gt;This discussion is in the context of planning for version 2.0 of the SPDX specification.&amp;lt;/p&amp;gt;&amp;lt;h3&amp;gt;Original (Current) Charter&amp;lt;/h3&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Spec 1.1&amp;lt;span&amp;gt;&amp;amp;nbsp; &amp;lt;/span&amp;gt;Charter:&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot; style=&amp;quot;margin: 0in 0in 0.0001pt 0.25in; line-height: normal;&amp;quot;&amp;gt;Create a set of data exchange standards that enable companies and organizations to share license and component information (metadata) for software packages and related content with the aim of facilitating license and other policy compliance.&amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Spec 1.2 Why is a common format for data exchange needed?&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot; style=&amp;quot;margin: 0in 0in 0.0001pt 0.5in; line-height: normal;&amp;quot;&amp;gt;Companies and organizations (collectively “Organizations”) are widely using and reusing open source and other software packages. Compliance with the associated licenses requires a set of due diligence activities that each Organization performs independently: a manual and/or automated scan of software and identification of associated licenses followed by manual verification. Software development teams across the globe use the same open source packages, but they have not yet set-up a way to collaborate on license discovery – many groups are performing the same work leading to duplicated effort and redundancy. This working group seeks to create a data exchange format so that information about software packages and related content, may be collected and shared in a common format with the goal of saving time and improving data accuracy.&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;&amp;amp;nbsp;Key&amp;amp;nbsp; Themes from SPDX Intro Slides &amp;lt;/strong&amp;gt;&amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Goal: Create a defined format for a file of license fact information describing a software package.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Guiding Principle: Focus on capturing facts; avoid interpretations.&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;h3&amp;gt;Current SPDX Solution Statement from SPDX Intro Slides&amp;lt;/h3&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;A file format for license information to accompany open source packages&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;A standardized short form to refer to the official version of common licenses&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Benefits:&amp;lt;/li&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Allows easy exchange of license information between companies reducing burden on both suppliers and consumers.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Avoids due diligence redundancy where the same source code package is analyzed multiple times by different recipients.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Provides a unified method for exchanging license information.&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;h3&amp;gt;What is the issue?&amp;lt;/h3&amp;gt;&amp;lt;p&amp;gt;Our current solution approach may not be sufficient to provide the desired Benefits; e.g. the means do not seem to match the ends. &amp;lt;span&amp;gt;&amp;amp;nbsp;&amp;lt;/span&amp;gt;Many current participants do not see how we can get to the desired benefits without expanding the mission and scope to encompass more of the compliance cycle.&amp;lt;span&amp;gt;&amp;amp;nbsp;&amp;amp;nbsp; &amp;lt;/span&amp;gt;If we expand the mission, then we may also need organization changes to support that mission, especially some form of product management across the teams.&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;Many SPDX participants are now talking about a broader and deeper mission beyond a data exchange format specification including a broader/deeper role in providing standards and &amp;lt;strong&amp;gt;open source&amp;lt;/strong&amp;gt; &amp;lt;strong&amp;gt;software&amp;lt;/strong&amp;gt; to facilitate software licensing due diligence and compliance activities across the supply chain:&amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Expanding the specification to include comprehensive information for meeting license obligations such as complete attribution data required by open source licenses – e.g. copyright and other notices,&amp;lt;/li&amp;gt;&amp;lt;li type=&amp;quot;_moz&amp;quot;&amp;gt;Developing comprehensive open source tools to support many or most due diligence and compliance activities,&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Analyzing licenses in a package using scanning and/or matching techniques to detect the licenses and generate an SPDX file from that analysis,&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Managing large volume of SPDX files – inbound and outbound,&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Automating obligation fulfillment such as generation of attribution text or creation of a source code redistribution package,&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Establishing a trusted repository of more comprehensive data about licenses – e.g. extend the License List to provide data for use by license detection tools,&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Possibly establishing a trusted repository of software components with their origin and license information&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;h3&amp;gt;Specification vs. Implementation&amp;lt;/h3&amp;gt;&amp;lt;p&amp;gt;There is some fundamental creative tension between our charter to create a Software Package Data Exchange specification and foster its adoption versus a broader mission to create open source software to actively facilitate/enable that adoption.&amp;lt;span&amp;gt;&amp;amp;nbsp;&amp;lt;/span&amp;gt;&amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;The SPDX original/current charter is to create a data specification and foster its adoption.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;We agreed early on to create some basic software tools to read and write SPDX files and encourage commercial vendors to support SPDX in their existing products.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;We also agreed to emulate an open source project, but we are not an open source project whose primary “work product” is software – our primary work product is the specification itself.&amp;lt;span&amp;gt;&amp;amp;nbsp;&amp;amp;nbsp; &amp;lt;/span&amp;gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;As the SPDX specification evolves (and presumably becomes more complex), it may be highly desirable or even necessary to provide some elements of a reference implementation to validate the specification before general release.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;We may be able to better leverage and extend existing open source projects, such as FOSSology, to offer elements of a reference implementation.&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;p&amp;gt;If we change our charter to include development of open source software to support software licensing due diligence and compliance activities across the supply chain, then we need to look closely at our form of organization.&amp;lt;/p&amp;gt;&amp;lt;h2&amp;gt;Vision and Mission Statements&amp;lt;/h2&amp;gt;&amp;lt;p&amp;gt;We currently have several documents that document and explain our vision and mission including:&amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;&amp;lt;span style=&amp;quot;font-family: Symbol;&amp;quot;&amp;gt;&amp;lt;span&amp;gt;&amp;lt;span style=&amp;quot;font: 7pt 'Times New Roman';&amp;quot;&amp;gt;&amp;amp;nbsp;&amp;lt;/span&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;/span&amp;gt;The SPDX Charter, Definition and other principles listed in &amp;lt;span style=&amp;quot;text-decoration: underline;&amp;quot;&amp;gt;Section 1. Rationale&amp;lt;/span&amp;gt; of the in the specification itself&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;The white paper - &amp;lt;span style=&amp;quot;text-decoration: underline;&amp;quot;&amp;gt;A Common Software Package Data Exchange Format: 1.0 Release Update and Discussion&amp;lt;/span&amp;gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Other materials such as several versions of the introductory presentations&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot;&amp;gt;Some members have already been thinking about expanding how we talk about our vision, mission, charter, and guiding principles – there are many names for specific elements of how an organization describes itself.&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;One approach is to add a Vision statement and a Mission statement for SPDX where the Vision statement describes what the future looks like when you execute on the mission and the Mission statement says what you do on a daily basis (similar to a guiding principle).&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;The following draft Vision and Mission statements are recent draft contributions from SPDX members:&amp;lt;/p&amp;gt;&amp;lt;h3&amp;gt;Proposed Vision Statement&amp;lt;/h3&amp;gt;&amp;lt;p&amp;gt;Phil Odence has proposed the following Vision statement for the website:&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;“The vision of SPDX is to achieve license compliance with minimal cost across the supply chain. Ideally, upstream component developers begin the process by supplying SPDX files as part of their downloads. Users of those components therefore have a starting point with the SPDX files that they create for their &amp;quot;customers,&amp;quot; and so on. If everything is working properly, the provenance of each piece of code is researched and documented only once during its journey through a supply chain, and that information is passed on in parallel with the code in the SPDX format.”&amp;lt;/p&amp;gt;&amp;lt;h3&amp;gt;Proposed Mission Statement&amp;lt;/h3&amp;gt;&amp;lt;p&amp;gt;The Cisco team has proposed the following Mission statement:&amp;lt;/p&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot;&amp;gt;&amp;quot;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;Deliver and promote adoption of a specification to &lt;/ins&gt;enable any party in a software supply chain, from the original author to the final end user, to accurately communicate the licensing information for any piece of copyrightable material that such party may create, alter, combine, pass on, or receive, and to make such information available in a consistent, understandable, and re-usable fashion, with the aim of facilitating license and other policy compliance.&amp;quot;&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Mjherzog</name></author>	</entry>

	<entry>
		<id>https://wiki.spdx.org/index.php?title=Business_Team/SPDX_Vision_and_Mission_Discussion_Document&amp;diff=1984&amp;oldid=prev</id>
		<title>Mjherzog at 15:48, 30 May 2012</title>
		<link rel="alternate" type="text/html" href="https://wiki.spdx.org/index.php?title=Business_Team/SPDX_Vision_and_Mission_Discussion_Document&amp;diff=1984&amp;oldid=prev"/>
				<updated>2012-05-30T15:48:25Z</updated>
		
		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table class='diff diff-contentalign-left'&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;tr style='vertical-align: top;'&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;Revision as of 15:48, 30 May 2012&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;h2&amp;gt;Background &amp;lt;/h2&amp;gt;&amp;lt;p&amp;gt;This is a discussion document regarding the vision, mission and charter of SPDX.&amp;lt;span&amp;gt;&amp;amp;nbsp; &amp;lt;/span&amp;gt;This discussion is in the context of planning for version 2.0 of the SPDX specification. &amp;lt;/p&amp;gt;&amp;lt;h3&amp;gt;Original (Current) Charter &amp;lt;/h3&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Spec 1.1&amp;lt;span&amp;gt;&amp;amp;nbsp; &amp;lt;/span&amp;gt;Charter: &amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot; style=&amp;quot;margin: 0in 0in 0.0001pt 0.25in; line-height: normal;&amp;quot;&amp;gt;Create a set of data exchange standards that enable companies and organizations to share license and component information (metadata) for software packages and related content with the aim of facilitating license and other policy compliance.&amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Spec 1.2 Why is a common format for data exchange needed? &amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot; style=&amp;quot;margin: 0in 0in 0.0001pt 0.5in; line-height: normal;&amp;quot;&amp;gt;Companies and organizations (collectively “Organizations”) are widely using and reusing open source and other software packages. Compliance with the associated licenses requires a set of due diligence activities that each Organization performs independently: a manual and/or automated scan of software and identification of associated licenses followed by manual verification. Software development teams across the globe use the same open source packages, but they have not yet set-up a way to collaborate on license discovery – many groups are performing the same work leading to duplicated effort and redundancy. This working group seeks to create a data exchange format so that information about software packages and related content, may be collected and shared in a common format with the goal of saving time and improving data accuracy.&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;&amp;amp;nbsp;Key&amp;amp;nbsp; Themes from SPDX Intro Slides &amp;lt;/strong&amp;gt;&amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Goal: Create a defined format for a file of license fact information describing a software package.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Guiding Principle: Focus on capturing facts; avoid interpretations. &amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;h3&amp;gt;Current SPDX Solution Statement from SPDX Intro Slides &amp;lt;/h3&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;A file format for license information to accompany open source packages&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;A standardized short form to refer to the official version of common licenses&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Benefits:&amp;lt;/li&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Allows easy exchange of license information between companies reducing burden on both suppliers and consumers.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Avoids due diligence redundancy where the same source code package is analyzed multiple times by different recipients.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Provides a unified method for exchanging license information. &amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;h3&amp;gt;What is the issue? &amp;lt;/h3&amp;gt;&amp;lt;p&amp;gt;Our current solution approach may not be sufficient to provide the desired Benefits; e.g. the means do not seem to match the ends. &amp;lt;span&amp;gt;&amp;amp;nbsp;&amp;lt;/span&amp;gt;Many current participants do not see how we can get to the desired benefits without expanding the mission and scope to encompass more of the compliance cycle.&amp;lt;span&amp;gt;&amp;amp;nbsp;&amp;amp;nbsp; &amp;lt;/span&amp;gt;If we expand the mission, then we may also need organization changes to support that mission, especially some form of product management across the teams. &amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;Many SPDX participants are now talking about a broader and deeper mission beyond a data exchange format specification including a broader/deeper role in providing standards and &amp;lt;strong&amp;gt;open source&amp;lt;/strong&amp;gt; &amp;lt;strong&amp;gt;software&amp;lt;/strong&amp;gt; to facilitate software licensing due diligence and compliance activities across the supply chain: &amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Expanding the specification to include comprehensive information for meeting license obligations such as complete attribution data required by open source licenses – e.g. copyright and other notices,&amp;lt;/li&amp;gt;&amp;lt;li type=&amp;quot;_moz&amp;quot;&amp;gt;Developing comprehensive open source tools to support many or most due diligence and compliance activities,&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Analyzing licenses in a package using scanning and/or matching techniques to detect the licenses and generate an SPDX file from that analysis,&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Managing large volume of SPDX files – inbound and outbound,&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Automating obligation fulfillment such as generation of attribution text or creation of a source code redistribution package,&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Establishing a trusted repository of more comprehensive data about licenses – e.g. extend the License List to provide data for use by license detection tools,&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Possibly establishing a trusted repository of software components with their origin and license information &amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;h3&amp;gt;Specification vs. Implementation &amp;lt;/h3&amp;gt;&amp;lt;p&amp;gt;There is some fundamental creative tension between our charter to create a Software Package Data Exchange specification and foster its adoption versus a broader mission to create open source software to actively facilitate/enable that adoption.&amp;lt;span&amp;gt;&amp;amp;nbsp;&amp;lt;/span&amp;gt; &amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;The SPDX original/current charter is to create a data specification and foster its adoption.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;We agreed early on to create some basic software tools to read and write SPDX files and encourage commercial vendors to support SPDX in their existing products.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;We also agreed to emulate an open source project, but we are not an open source project whose primary “work product” is software – our primary work product is the specification itself.&amp;lt;span&amp;gt;&amp;amp;nbsp;&amp;amp;nbsp; &amp;lt;/span&amp;gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;As the SPDX specification evolves (and presumably becomes more complex), it may be highly desirable or even necessary to provide some elements of a reference implementation to validate the specification before general release.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;We may be able to better leverage and extend existing open source projects, such as FOSSology, to offer elements of a reference implementation. &amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;p&amp;gt;If we change our charter to include development of open source software to support software licensing due diligence and compliance activities across the supply chain, then we need to look closely at our form of organization. &amp;lt;/p&amp;gt;&amp;lt;h2&amp;gt;Vision and Mission Statements &amp;lt;/h2&amp;gt;&amp;lt;p&amp;gt;We currently have several documents that document and explain our vision and mission including: &amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;&amp;lt;span style=&amp;quot;font-family: Symbol;&amp;quot;&amp;gt;&amp;lt;span&amp;gt;&amp;lt;span style=&amp;quot;font: 7pt 'Times New Roman';&amp;quot;&amp;gt;&amp;amp;nbsp;&amp;lt;/span&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;/span&amp;gt;The SPDX Charter, Definition and other principles listed in &amp;lt;span style=&amp;quot;text-decoration: underline;&amp;quot;&amp;gt;Section 1. Rationale&amp;lt;/span&amp;gt; of the in the specification itself &amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;The white paper - &amp;lt;span style=&amp;quot;text-decoration: underline;&amp;quot;&amp;gt;A Common Software Package Data Exchange Format: 1.0 Release Update and Discussion&amp;lt;/span&amp;gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Other materials such as several versions of the introductory presentations&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot;&amp;gt;Some members have already been thinking about expanding how we talk about our vision, mission, charter, and guiding principles – there are many names for specific elements of how an organization describes itself.&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;One approach is to add a Vision statement and a Mission statement for SPDX where the Vision statement describes what the future looks like when you execute on the mission and the Mission statement says what you do on a daily basis (similar to a guiding principle). &amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;The following draft Vision and Mission statements are recent draft contributions from SPDX members: &amp;lt;/p&amp;gt;&amp;lt;h3&amp;gt;Proposed Vision Statement &amp;lt;/h3&amp;gt;&amp;lt;p&amp;gt;Phil Odence has proposed the following Vision statement for the website: &amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;“The vision of SPDX is to achieve license compliance with minimal cost across the supply chain. Ideally, upstream component developers begin the process by supplying SPDX files as part of their downloads. Users of those components therefore have a starting point with the SPDX files that they create for their &amp;quot;customers,&amp;quot; and so on. If everything is working properly, the provenance of each piece of code is researched and documented only once during its journey through a supply chain, and that information is passed on in parallel with the code in the SPDX format.” &amp;lt;/p&amp;gt;&amp;lt;h3&amp;gt;Proposed Mission Statement &amp;lt;/h3&amp;gt;&amp;lt;p&amp;gt;The Cisco team has proposed the following Mission statement: &amp;lt;/p&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot;&amp;gt;&amp;quot;To enable any party in a software supply chain, from the original author to the final end user, to accurately communicate the licensing information for any piece of copyrightable material that such party may create, alter, combine, pass on, or receive, and to make such information available in a consistent, understandable, and re-usable fashion, with the aim of facilitating license and other policy compliance.&amp;quot;&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;h2&amp;gt;Background&amp;lt;/h2&amp;gt;&amp;lt;p&amp;gt;This is a discussion document regarding the vision, mission and charter of SPDX.&amp;lt;span&amp;gt;&amp;amp;nbsp; &amp;lt;/span&amp;gt;This discussion is in the context of planning for version 2.0 of the SPDX specification.&amp;lt;/p&amp;gt;&amp;lt;h3&amp;gt;Original (Current) Charter&amp;lt;/h3&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Spec 1.1&amp;lt;span&amp;gt;&amp;amp;nbsp; &amp;lt;/span&amp;gt;Charter:&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot; style=&amp;quot;margin: 0in 0in 0.0001pt 0.25in; line-height: normal;&amp;quot;&amp;gt;Create a set of data exchange standards that enable companies and organizations to share license and component information (metadata) for software packages and related content with the aim of facilitating license and other policy compliance.&amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Spec 1.2 Why is a common format for data exchange needed?&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot; style=&amp;quot;margin: 0in 0in 0.0001pt 0.5in; line-height: normal;&amp;quot;&amp;gt;Companies and organizations (collectively “Organizations”) are widely using and reusing open source and other software packages. Compliance with the associated licenses requires a set of due diligence activities that each Organization performs independently: a manual and/or automated scan of software and identification of associated licenses followed by manual verification. Software development teams across the globe use the same open source packages, but they have not yet set-up a way to collaborate on license discovery – many groups are performing the same work leading to duplicated effort and redundancy. This working group seeks to create a data exchange format so that information about software packages and related content, may be collected and shared in a common format with the goal of saving time and improving data accuracy.&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;&amp;amp;nbsp;Key&amp;amp;nbsp; Themes from SPDX Intro Slides &amp;lt;/strong&amp;gt;&amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Goal: Create a defined format for a file of license fact information describing a software package.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Guiding Principle: Focus on capturing facts; avoid interpretations.&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;h3&amp;gt;Current SPDX Solution Statement from SPDX Intro Slides&amp;lt;/h3&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;A file format for license information to accompany open source packages&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;A standardized short form to refer to the official version of common licenses&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Benefits:&amp;lt;/li&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Allows easy exchange of license information between companies reducing burden on both suppliers and consumers.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Avoids due diligence redundancy where the same source code package is analyzed multiple times by different recipients.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Provides a unified method for exchanging license information.&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;h3&amp;gt;What is the issue?&amp;lt;/h3&amp;gt;&amp;lt;p&amp;gt;Our current solution approach may not be sufficient to provide the desired Benefits; e.g. the means do not seem to match the ends. &amp;lt;span&amp;gt;&amp;amp;nbsp;&amp;lt;/span&amp;gt;Many current participants do not see how we can get to the desired benefits without expanding the mission and scope to encompass more of the compliance cycle.&amp;lt;span&amp;gt;&amp;amp;nbsp;&amp;amp;nbsp; &amp;lt;/span&amp;gt;If we expand the mission, then we may also need organization changes to support that mission, especially some form of product management across the teams.&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;Many SPDX participants are now talking about a broader and deeper mission beyond a data exchange format specification including a broader/deeper role in providing standards and &amp;lt;strong&amp;gt;open source&amp;lt;/strong&amp;gt; &amp;lt;strong&amp;gt;software&amp;lt;/strong&amp;gt; to facilitate software licensing due diligence and compliance activities across the supply chain:&amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Expanding the specification to include comprehensive information for meeting license obligations such as complete attribution data required by open source licenses – e.g. copyright and other notices,&amp;lt;/li&amp;gt;&amp;lt;li type=&amp;quot;_moz&amp;quot;&amp;gt;Developing comprehensive open source tools to support many or most due diligence and compliance activities,&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Analyzing licenses in a package using scanning and/or matching techniques to detect the licenses and generate an SPDX file from that analysis,&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Managing large volume of SPDX files – inbound and outbound,&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Automating obligation fulfillment such as generation of attribution text or creation of a source code redistribution package,&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Establishing a trusted repository of more comprehensive data about licenses – e.g. extend the License List to provide data for use by license detection tools,&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Possibly establishing a trusted repository of software components with their origin and license information&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;h3&amp;gt;Specification vs. Implementation&amp;lt;/h3&amp;gt;&amp;lt;p&amp;gt;There is some fundamental creative tension between our charter to create a Software Package Data Exchange specification and foster its adoption versus a broader mission to create open source software to actively facilitate/enable that adoption.&amp;lt;span&amp;gt;&amp;amp;nbsp;&amp;lt;/span&amp;gt;&amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;The SPDX original/current charter is to create a data specification and foster its adoption.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;We agreed early on to create some basic software tools to read and write SPDX files and encourage commercial vendors to support SPDX in their existing products.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;We also agreed to emulate an open source project, but we are not an open source project whose primary “work product” is software – our primary work product is the specification itself.&amp;lt;span&amp;gt;&amp;amp;nbsp;&amp;amp;nbsp; &amp;lt;/span&amp;gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;As the SPDX specification evolves (and presumably becomes more complex), it may be highly desirable or even necessary to provide some elements of a reference implementation to validate the specification before general release.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;We may be able to better leverage and extend existing open source projects, such as FOSSology, to offer elements of a reference implementation.&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;p&amp;gt;If we change our charter to include development of open source software to support software licensing due diligence and compliance activities across the supply chain, then we need to look closely at our form of organization.&amp;lt;/p&amp;gt;&amp;lt;h2&amp;gt;Vision and Mission Statements&amp;lt;/h2&amp;gt;&amp;lt;p&amp;gt;We currently have several documents that document and explain our vision and mission including:&amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;&amp;lt;span style=&amp;quot;font-family: Symbol;&amp;quot;&amp;gt;&amp;lt;span&amp;gt;&amp;lt;span style=&amp;quot;font: 7pt 'Times New Roman';&amp;quot;&amp;gt;&amp;amp;nbsp;&amp;lt;/span&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;/span&amp;gt;The SPDX Charter, Definition and other principles listed in &amp;lt;span style=&amp;quot;text-decoration: underline;&amp;quot;&amp;gt;Section 1. Rationale&amp;lt;/span&amp;gt; of the in the specification itself&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;The white paper - &amp;lt;span style=&amp;quot;text-decoration: underline;&amp;quot;&amp;gt;A Common Software Package Data Exchange Format: 1.0 Release Update and Discussion&amp;lt;/span&amp;gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Other materials such as several versions of the introductory presentations&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot;&amp;gt;Some members have already been thinking about expanding how we talk about our vision, mission, charter, and guiding principles – there are many names for specific elements of how an organization describes itself.&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;One approach is to add a Vision statement and a Mission statement for SPDX where the Vision statement describes what the future looks like when you execute on the mission and the Mission statement says what you do on a daily basis (similar to a guiding principle).&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;The following draft Vision and Mission statements are recent draft contributions from SPDX members:&amp;lt;/p&amp;gt;&amp;lt;h3&amp;gt;Proposed Vision Statement&amp;lt;/h3&amp;gt;&amp;lt;p&amp;gt;Phil Odence has proposed the following Vision statement for the website:&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;“The vision of SPDX is to achieve license compliance with minimal cost across the supply chain. Ideally, upstream component developers begin the process by supplying SPDX files as part of their downloads. Users of those components therefore have a starting point with the SPDX files that they create for their &amp;quot;customers,&amp;quot; and so on. If everything is working properly, the provenance of each piece of code is researched and documented only once during its journey through a supply chain, and that information is passed on in parallel with the code in the SPDX format.”&amp;lt;/p&amp;gt;&amp;lt;h3&amp;gt;Proposed Mission Statement&amp;lt;/h3&amp;gt;&amp;lt;p&amp;gt;The Cisco team has proposed the following Mission statement:&amp;lt;/p&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot;&amp;gt;&amp;quot;To enable any party in a software supply chain, from the original author to the final end user, to accurately communicate the licensing information for any piece of copyrightable material that such party may create, alter, combine, pass on, or receive, and to make such information available in a consistent, understandable, and re-usable fashion, with the aim of facilitating license and other policy compliance.&amp;quot;&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;

&lt;!-- diff cache key spdx_mediawiki:diff:version:1.11a:oldid:1983:newid:1984 --&gt;
&lt;/table&gt;</summary>
		<author><name>Mjherzog</name></author>	</entry>

	<entry>
		<id>https://wiki.spdx.org/index.php?title=Business_Team/SPDX_Vision_and_Mission_Discussion_Document&amp;diff=1983&amp;oldid=prev</id>
		<title>Mjherzog at 15:47, 30 May 2012</title>
		<link rel="alternate" type="text/html" href="https://wiki.spdx.org/index.php?title=Business_Team/SPDX_Vision_and_Mission_Discussion_Document&amp;diff=1983&amp;oldid=prev"/>
				<updated>2012-05-30T15:47:14Z</updated>
		
		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table class='diff diff-contentalign-left'&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;tr style='vertical-align: top;'&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;Revision as of 15:47, 30 May 2012&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;h2&amp;gt;Background&amp;lt;/h2&amp;gt;&amp;lt;p&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot;&lt;/del&gt;&amp;gt;This is a discussion document regarding the vision, mission and charter of SPDX.&amp;lt;span&amp;gt;&amp;amp;nbsp; &amp;lt;/span&amp;gt;This discussion is in the context of planning for version 2.0 of the SPDX specification.&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&lt;/del&gt;&amp;lt;/p&amp;gt;&amp;lt;h3&amp;gt;Original (Current) Charter&amp;lt;/h3&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&lt;/del&gt;&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Spec 1.1&amp;lt;span&amp;gt;&amp;amp;nbsp; &amp;lt;/span&amp;gt;Charter:&amp;lt;/li&amp;gt;&amp;lt;/ul&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&lt;/del&gt;&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot; style=&amp;quot;margin: 0in 0in 0.0001pt 0.25in; line-height: normal;&amp;quot;&amp;gt;Create a set of data exchange standards that enable companies and organizations to share license and component information (metadata) for software packages and related content with the aim of facilitating license and other policy compliance.&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&lt;/del&gt;&amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Spec 1.2 Why is a common format for data exchange needed?&amp;lt;/li&amp;gt;&amp;lt;/ul&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&lt;/del&gt;&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot; style=&amp;quot;margin: 0in 0in 0.0001pt 0.5in; line-height: normal;&amp;quot;&amp;gt;Companies and organizations (collectively “Organizations”) are widely using and reusing open source and other software packages. Compliance with the associated licenses requires a set of due diligence activities that each Organization performs independently: a manual and/or automated scan of software and identification of associated licenses followed by manual verification. Software development teams across the globe use the same open source packages, but they have not yet set-up a way to collaborate on license discovery – many groups are performing the same work leading to duplicated effort and redundancy. This working group seeks to create a data exchange format so that information about software packages and related content, may be collected and shared in a common format with the goal of saving time and improving data accuracy.&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;amp;nbsp;&lt;/del&gt;&amp;lt;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;/p&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot; style=&amp;quot;margin: 0in 0in 0.0001pt 0.5in; line-height: normal;&amp;quot;&lt;/del&gt;&amp;gt;&amp;amp;nbsp;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;h3&amp;gt;&lt;/del&gt;Key&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;span&amp;gt;&lt;/del&gt;&amp;amp;nbsp; &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;/span&amp;gt;&lt;/del&gt;Themes from SPDX Intro Slides&amp;lt;/&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;h3&lt;/del&gt;&amp;gt;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&lt;/del&gt;&amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Goal: Create a defined format for a file of license fact information describing a software package.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Guiding Principle: Focus on capturing facts; avoid interpretations.&amp;lt;/li&amp;gt;&amp;lt;/ul&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&lt;/del&gt;&amp;gt;&amp;lt;h3&amp;gt;Current SPDX Solution Statement from SPDX Intro Slides&amp;lt;/h3&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&lt;/del&gt;&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;A file format for license information to accompany open source packages&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;A standardized short form to refer to the official version of common licenses&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Benefits:&amp;lt;/li&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Allows easy exchange of license information between companies reducing burden on both suppliers and consumers.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Avoids due diligence redundancy where the same source code package is analyzed multiple times by different recipients.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Provides a unified method for exchanging license information.&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;/ul&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&lt;/del&gt;&amp;gt;&amp;lt;h3&amp;gt;What is the issue?&amp;lt;/h3&amp;gt;&amp;lt;p&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot;&lt;/del&gt;&amp;gt;Our current solution approach may not be sufficient to provide the desired Benefits; e.g. the means do not seem to match the ends. &amp;lt;span&amp;gt;&amp;amp;nbsp;&amp;lt;/span&amp;gt;Many current participants do not see how we can get to the desired benefits without expanding the mission and scope to encompass more of the compliance cycle.&amp;lt;span&amp;gt;&amp;amp;nbsp;&amp;amp;nbsp; &amp;lt;/span&amp;gt;If we expand the mission, then we may also need organization changes to support that mission, especially some form of product management across the teams.&amp;lt;/p&amp;gt;&amp;lt;p&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot;&lt;/del&gt;&amp;gt;Many SPDX participants are now talking about a broader and deeper mission beyond a data exchange format specification including a broader/deeper role in providing standards and &amp;lt;strong&amp;gt;open source&amp;lt;/strong&amp;gt; &amp;lt;strong&amp;gt;software&amp;lt;/strong&amp;gt; to facilitate software licensing due diligence and compliance activities across the supply chain:&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&lt;/del&gt;&amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Expanding the specification to include comprehensive information for meeting license obligations such as complete attribution data required by open source licenses – e.g. copyright and other notices,&amp;lt;/li&amp;gt;&amp;lt;li type=&amp;quot;_moz&amp;quot;&amp;gt;Developing comprehensive open source tools to support many or most due diligence and compliance activities,&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Analyzing licenses in a package using scanning and/or matching techniques to detect the licenses and generate an SPDX file from that analysis,&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Managing large volume of SPDX files – inbound and outbound,&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Automating obligation fulfillment such as generation of attribution text or creation of a source code redistribution package,&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Establishing a trusted repository of more comprehensive data about licenses – e.g. extend the License List to provide data for use by license detection tools,&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Possibly establishing a trusted repository of software components with their origin and license information&amp;lt;/li&amp;gt;&amp;lt;/ul&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&lt;/del&gt;&amp;gt;&amp;lt;h3&amp;gt;Specification vs. Implementation&amp;lt;/h3&amp;gt;&amp;lt;p&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot;&lt;/del&gt;&amp;gt;There is some fundamental creative tension between our charter to create a Software Package Data Exchange specification and foster its adoption versus a broader mission to create open source software to actively facilitate/enable that adoption.&amp;lt;span&amp;gt;&amp;amp;nbsp; &amp;lt;/span&amp;gt;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&lt;/del&gt;&amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;The SPDX original/current charter is to create a data specification and foster its adoption.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;We agreed early on to create some basic software tools to read and write SPDX files and encourage commercial vendors to support SPDX in their existing products.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;We also agreed to emulate an open source project, but we are not an open source project whose primary “work product” is software – our primary work product is the specification itself.&amp;lt;span&amp;gt;&amp;amp;nbsp;&amp;amp;nbsp; &amp;lt;/span&amp;gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;As the SPDX specification evolves (and presumably becomes more complex), it may be highly desirable or even necessary to provide some elements of a reference implementation to validate the specification before general release.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;We may be able to better leverage and extend existing open source projects, such as FOSSology, to offer elements of a reference implementation.&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;p&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot;&lt;/del&gt;&amp;gt;If we change our charter to include development of open source software to support software licensing due diligence and compliance activities across the supply chain, then we need to look closely at our form of organization.&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&lt;/del&gt;&amp;lt;/p&amp;gt;&amp;lt;h2&amp;gt;Vision and Mission Statements&amp;lt;/h2&amp;gt;&amp;lt;p&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot; style=&amp;quot;margin-bottom: 0.0001pt;&amp;quot;&lt;/del&gt;&amp;gt;We currently have several documents that document and explain our vision and mission including:&amp;lt;/p&amp;gt;&amp;lt;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;p&lt;/del&gt;&amp;gt;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;amp;nbsp;&lt;/del&gt;&amp;lt;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;/p&amp;gt;&amp;lt;p class=&amp;quot;MsoListParagraphCxSpFirst&amp;quot; style=&amp;quot;margin-bottom: 0.0001pt; text-indent: -0.25in;&amp;quot;&lt;/del&gt;&amp;gt;&amp;lt;span style=&amp;quot;font-family: Symbol;&amp;quot;&amp;gt;&amp;lt;span&amp;gt;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;·&lt;/del&gt;&amp;lt;span style=&amp;quot;font: 7pt 'Times New Roman';&amp;quot;&amp;gt;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;/del&gt;&amp;amp;nbsp; &amp;lt;/span&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;/span&amp;gt;The SPDX Charter, Definition and other principles listed in &amp;lt;span style=&amp;quot;text-decoration: underline;&amp;quot;&amp;gt;Section 1. Rationale&amp;lt;/span&amp;gt; of the in the specification itself&amp;lt;/&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;p&lt;/del&gt;&amp;gt;&amp;lt;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;p class=&amp;quot;MsoListParagraphCxSpMiddle&amp;quot; style=&amp;quot;text-indent: -0.25in;&amp;quot;&amp;gt;&amp;lt;span style=&amp;quot;font-family: Symbol;&amp;quot;&amp;gt;&amp;lt;span&amp;gt;·&amp;lt;span style=&amp;quot;font: 7pt 'Times New Roman';&amp;quot;&amp;gt;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp; &amp;lt;/span&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;/span&lt;/del&gt;&amp;gt;The white paper - &amp;lt;span style=&amp;quot;text-decoration: underline;&amp;quot;&amp;gt;A Common Software Package Data Exchange Format: 1.0 Release Update and Discussion&amp;lt;/span&amp;gt;&amp;lt;/&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;p&lt;/del&gt;&amp;gt;&amp;lt;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;p class=&amp;quot;MsoListParagraphCxSpLast&amp;quot; style=&amp;quot;text-indent: -0.25in;&amp;quot;&amp;gt;&amp;lt;span style=&amp;quot;font-family: Symbol;&amp;quot;&amp;gt;&amp;lt;span&amp;gt;·&amp;lt;span style=&amp;quot;font: 7pt 'Times New Roman';&amp;quot;&amp;gt;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp; &amp;lt;/span&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;/span&lt;/del&gt;&amp;gt;Other materials such as several versions of the introductory presentations&amp;lt;/&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;p&lt;/del&gt;&amp;gt;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&lt;/del&gt;&amp;lt;/&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;p&lt;/del&gt;&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;gt;&amp;lt;span&amp;gt;&amp;amp;nbsp;&amp;lt;/span&lt;/del&gt;&amp;gt;Some members have already been thinking about expanding how we talk about our vision, mission, charter, and guiding principles – there are many names for specific elements of how an organization describes itself.&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;/p&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot;&amp;gt;&lt;/del&gt;One approach is to add a Vision statement and a Mission statement for SPDX where the Vision statement describes what the future looks like when you execute on the mission and the Mission statement says what you do on a daily basis (similar to a guiding principle).&amp;lt;/p&amp;gt;&amp;lt;p&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot;&lt;/del&gt;&amp;gt;The following draft Vision and Mission statements are recent draft contributions from SPDX members:&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&lt;/del&gt;&amp;lt;/p&amp;gt;&amp;lt;h3&amp;gt;Proposed Vision Statement&amp;lt;/h3&amp;gt;&amp;lt;p&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot;&lt;/del&gt;&amp;gt;Phil Odence has proposed the following Vision statement for the website:&amp;lt;/p&amp;gt;&amp;lt;p&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot;&lt;/del&gt;&amp;gt;“The vision of SPDX is to achieve license compliance with minimal cost across the supply chain. Ideally, upstream component developers begin the process by supplying SPDX files as part of their downloads. Users of those components therefore have a starting point with the SPDX files that they create for their &amp;quot;customers,&amp;quot; and so on. If everything is working properly, the provenance of each piece of code is researched and documented only once during its journey through a supply chain, and that information is passed on in parallel with the code in the SPDX format.”&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&lt;/del&gt;&amp;lt;/p&amp;gt;&amp;lt;h3&amp;gt;Proposed Mission Statement&amp;lt;/h3&amp;gt;&amp;lt;p&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot;&lt;/del&gt;&amp;gt;The Cisco team has proposed the following Mission statement:&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&lt;/del&gt;&amp;lt;/p&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot;&amp;gt;&amp;quot;To enable any party in a software supply chain, from the original author to the final end user, to accurately communicate the licensing information for any piece of copyrightable material that such party may create, alter, combine, pass on, or receive, and to make such information available in a consistent, understandable, and re-usable fashion, with the aim of facilitating license and other policy compliance.&amp;quot;&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;h2&amp;gt;Background &amp;lt;/h2&amp;gt;&amp;lt;p&amp;gt;This is a discussion document regarding the vision, mission and charter of SPDX.&amp;lt;span&amp;gt;&amp;amp;nbsp; &amp;lt;/span&amp;gt;This discussion is in the context of planning for version 2.0 of the SPDX specification. &amp;lt;/p&amp;gt;&amp;lt;h3&amp;gt;Original (Current) Charter &amp;lt;/h3&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Spec 1.1&amp;lt;span&amp;gt;&amp;amp;nbsp; &amp;lt;/span&amp;gt;Charter: &amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot; style=&amp;quot;margin: 0in 0in 0.0001pt 0.25in; line-height: normal;&amp;quot;&amp;gt;Create a set of data exchange standards that enable companies and organizations to share license and component information (metadata) for software packages and related content with the aim of facilitating license and other policy compliance.&amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Spec 1.2 Why is a common format for data exchange needed? &amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot; style=&amp;quot;margin: 0in 0in 0.0001pt 0.5in; line-height: normal;&amp;quot;&amp;gt;Companies and organizations (collectively “Organizations”) are widely using and reusing open source and other software packages. Compliance with the associated licenses requires a set of due diligence activities that each Organization performs independently: a manual and/or automated scan of software and identification of associated licenses followed by manual verification. Software development teams across the globe use the same open source packages, but they have not yet set-up a way to collaborate on license discovery – many groups are performing the same work leading to duplicated effort and redundancy. This working group seeks to create a data exchange format so that information about software packages and related content, may be collected and shared in a common format with the goal of saving time and improving data accuracy.&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;lt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;strong&lt;/ins&gt;&amp;gt;&amp;amp;nbsp;Key&amp;amp;nbsp; Themes from SPDX Intro Slides &amp;lt;/&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;strong&lt;/ins&gt;&amp;gt;&amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Goal: Create a defined format for a file of license fact information describing a software package.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Guiding Principle: Focus on capturing facts; avoid interpretations. &amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;h3&amp;gt;Current SPDX Solution Statement from SPDX Intro Slides &amp;lt;/h3&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;A file format for license information to accompany open source packages&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;A standardized short form to refer to the official version of common licenses&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Benefits:&amp;lt;/li&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Allows easy exchange of license information between companies reducing burden on both suppliers and consumers.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Avoids due diligence redundancy where the same source code package is analyzed multiple times by different recipients.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Provides a unified method for exchanging license information. &amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;h3&amp;gt;What is the issue? &amp;lt;/h3&amp;gt;&amp;lt;p&amp;gt;Our current solution approach may not be sufficient to provide the desired Benefits; e.g. the means do not seem to match the ends. &amp;lt;span&amp;gt;&amp;amp;nbsp;&amp;lt;/span&amp;gt;Many current participants do not see how we can get to the desired benefits without expanding the mission and scope to encompass more of the compliance cycle.&amp;lt;span&amp;gt;&amp;amp;nbsp;&amp;amp;nbsp; &amp;lt;/span&amp;gt;If we expand the mission, then we may also need organization changes to support that mission, especially some form of product management across the teams. &amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;Many SPDX participants are now talking about a broader and deeper mission beyond a data exchange format specification including a broader/deeper role in providing standards and &amp;lt;strong&amp;gt;open source&amp;lt;/strong&amp;gt; &amp;lt;strong&amp;gt;software&amp;lt;/strong&amp;gt; to facilitate software licensing due diligence and compliance activities across the supply chain: &amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Expanding the specification to include comprehensive information for meeting license obligations such as complete attribution data required by open source licenses – e.g. copyright and other notices,&amp;lt;/li&amp;gt;&amp;lt;li type=&amp;quot;_moz&amp;quot;&amp;gt;Developing comprehensive open source tools to support many or most due diligence and compliance activities,&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Analyzing licenses in a package using scanning and/or matching techniques to detect the licenses and generate an SPDX file from that analysis,&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Managing large volume of SPDX files – inbound and outbound,&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Automating obligation fulfillment such as generation of attribution text or creation of a source code redistribution package,&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Establishing a trusted repository of more comprehensive data about licenses – e.g. extend the License List to provide data for use by license detection tools,&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Possibly establishing a trusted repository of software components with their origin and license information &amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;h3&amp;gt;Specification vs. Implementation &amp;lt;/h3&amp;gt;&amp;lt;p&amp;gt;There is some fundamental creative tension between our charter to create a Software Package Data Exchange specification and foster its adoption versus a broader mission to create open source software to actively facilitate/enable that adoption.&amp;lt;span&amp;gt;&amp;amp;nbsp;&amp;lt;/span&amp;gt; &amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;The SPDX original/current charter is to create a data specification and foster its adoption.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;We agreed early on to create some basic software tools to read and write SPDX files and encourage commercial vendors to support SPDX in their existing products.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;We also agreed to emulate an open source project, but we are not an open source project whose primary “work product” is software – our primary work product is the specification itself.&amp;lt;span&amp;gt;&amp;amp;nbsp;&amp;amp;nbsp; &amp;lt;/span&amp;gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;As the SPDX specification evolves (and presumably becomes more complex), it may be highly desirable or even necessary to provide some elements of a reference implementation to validate the specification before general release.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;We may be able to better leverage and extend existing open source projects, such as FOSSology, to offer elements of a reference implementation. &amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;p&amp;gt;If we change our charter to include development of open source software to support software licensing due diligence and compliance activities across the supply chain, then we need to look closely at our form of organization. &amp;lt;/p&amp;gt;&amp;lt;h2&amp;gt;Vision and Mission Statements &amp;lt;/h2&amp;gt;&amp;lt;p&amp;gt;We currently have several documents that document and explain our vision and mission including: &amp;lt;/p&amp;gt;&amp;lt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;ul&lt;/ins&gt;&amp;gt;&amp;lt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;li&lt;/ins&gt;&amp;gt;&amp;lt;span style=&amp;quot;font-family: Symbol;&amp;quot;&amp;gt;&amp;lt;span&amp;gt;&amp;lt;span style=&amp;quot;font: 7pt 'Times New Roman';&amp;quot;&amp;gt;&amp;amp;nbsp;&amp;lt;/span&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;/span&amp;gt;The SPDX Charter, Definition and other principles listed in &amp;lt;span style=&amp;quot;text-decoration: underline;&amp;quot;&amp;gt;Section 1. Rationale&amp;lt;/span&amp;gt; of the in the specification itself &amp;lt;/&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;li&lt;/ins&gt;&amp;gt;&amp;lt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;li&lt;/ins&gt;&amp;gt;The white paper - &amp;lt;span style=&amp;quot;text-decoration: underline;&amp;quot;&amp;gt;A Common Software Package Data Exchange Format: 1.0 Release Update and Discussion&amp;lt;/span&amp;gt;&amp;lt;/&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;li&lt;/ins&gt;&amp;gt;&amp;lt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;li&lt;/ins&gt;&amp;gt;Other materials such as several versions of the introductory presentations&amp;lt;/&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;li&lt;/ins&gt;&amp;gt;&amp;lt;/&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;ul&lt;/ins&gt;&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot;&amp;gt;Some members have already been thinking about expanding how we talk about our vision, mission, charter, and guiding principles – there are many names for specific elements of how an organization describes itself.&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;One approach is to add a Vision statement and a Mission statement for SPDX where the Vision statement describes what the future looks like when you execute on the mission and the Mission statement says what you do on a daily basis (similar to a guiding principle). &amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;The following draft Vision and Mission statements are recent draft contributions from SPDX members: &amp;lt;/p&amp;gt;&amp;lt;h3&amp;gt;Proposed Vision Statement &amp;lt;/h3&amp;gt;&amp;lt;p&amp;gt;Phil Odence has proposed the following Vision statement for the website: &amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;“The vision of SPDX is to achieve license compliance with minimal cost across the supply chain. Ideally, upstream component developers begin the process by supplying SPDX files as part of their downloads. Users of those components therefore have a starting point with the SPDX files that they create for their &amp;quot;customers,&amp;quot; and so on. If everything is working properly, the provenance of each piece of code is researched and documented only once during its journey through a supply chain, and that information is passed on in parallel with the code in the SPDX format.” &amp;lt;/p&amp;gt;&amp;lt;h3&amp;gt;Proposed Mission Statement &amp;lt;/h3&amp;gt;&amp;lt;p&amp;gt;The Cisco team has proposed the following Mission statement: &amp;lt;/p&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot;&amp;gt;&amp;quot;To enable any party in a software supply chain, from the original author to the final end user, to accurately communicate the licensing information for any piece of copyrightable material that such party may create, alter, combine, pass on, or receive, and to make such information available in a consistent, understandable, and re-usable fashion, with the aim of facilitating license and other policy compliance.&amp;quot;&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;

&lt;!-- diff cache key spdx_mediawiki:diff:version:1.11a:oldid:1982:newid:1983 --&gt;
&lt;/table&gt;</summary>
		<author><name>Mjherzog</name></author>	</entry>

	<entry>
		<id>https://wiki.spdx.org/index.php?title=Business_Team/SPDX_Vision_and_Mission_Discussion_Document&amp;diff=1982&amp;oldid=prev</id>
		<title>Mjherzog: First draft version</title>
		<link rel="alternate" type="text/html" href="https://wiki.spdx.org/index.php?title=Business_Team/SPDX_Vision_and_Mission_Discussion_Document&amp;diff=1982&amp;oldid=prev"/>
				<updated>2012-05-30T15:43:45Z</updated>
		
		<summary type="html">&lt;p&gt;First draft version&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;h2&amp;gt;Background&amp;lt;/h2&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot;&amp;gt;This is a discussion document regarding the vision, mission and charter of SPDX.&amp;lt;span&amp;gt;&amp;amp;nbsp; &amp;lt;/span&amp;gt;This discussion is in the context of planning for version 2.0 of the SPDX specification.&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;h3&amp;gt;Original (Current) Charter&amp;lt;/h3&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Spec 1.1&amp;lt;span&amp;gt;&amp;amp;nbsp; &amp;lt;/span&amp;gt;Charter:&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot; style=&amp;quot;margin: 0in 0in 0.0001pt 0.25in; line-height: normal;&amp;quot;&amp;gt;Create a set of data exchange standards that enable companies and organizations to share license and component information (metadata) for software packages and related content with the aim of facilitating license and other policy compliance.&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Spec 1.2 Why is a common format for data exchange needed?&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot; style=&amp;quot;margin: 0in 0in 0.0001pt 0.5in; line-height: normal;&amp;quot;&amp;gt;Companies and organizations (collectively “Organizations”) are widely using and reusing open source and other software packages. Compliance with the associated licenses requires a set of due diligence activities that each Organization performs independently: a manual and/or automated scan of software and identification of associated licenses followed by manual verification. Software development teams across the globe use the same open source packages, but they have not yet set-up a way to collaborate on license discovery – many groups are performing the same work leading to duplicated effort and redundancy. This working group seeks to create a data exchange format so that information about software packages and related content, may be collected and shared in a common format with the goal of saving time and improving data accuracy.&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot; style=&amp;quot;margin: 0in 0in 0.0001pt 0.5in; line-height: normal;&amp;quot;&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;h3&amp;gt;Key&amp;lt;span&amp;gt;&amp;amp;nbsp; &amp;lt;/span&amp;gt;Themes from SPDX Intro Slides&amp;lt;/h3&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Goal: Create a defined format for a file of license fact information describing a software package.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Guiding Principle: Focus on capturing facts; avoid interpretations.&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;h3&amp;gt;Current SPDX Solution Statement from SPDX Intro Slides&amp;lt;/h3&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;A file format for license information to accompany open source packages&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;A standardized short form to refer to the official version of common licenses&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Benefits:&amp;lt;/li&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Allows easy exchange of license information between companies reducing burden on both suppliers and consumers.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Avoids due diligence redundancy where the same source code package is analyzed multiple times by different recipients.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Provides a unified method for exchanging license information.&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;h3&amp;gt;What is the issue?&amp;lt;/h3&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot;&amp;gt;Our current solution approach may not be sufficient to provide the desired Benefits; e.g. the means do not seem to match the ends. &amp;lt;span&amp;gt;&amp;amp;nbsp;&amp;lt;/span&amp;gt;Many current participants do not see how we can get to the desired benefits without expanding the mission and scope to encompass more of the compliance cycle.&amp;lt;span&amp;gt;&amp;amp;nbsp;&amp;amp;nbsp; &amp;lt;/span&amp;gt;If we expand the mission, then we may also need organization changes to support that mission, especially some form of product management across the teams.&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot;&amp;gt;Many SPDX participants are now talking about a broader and deeper mission beyond a data exchange format specification including a broader/deeper role in providing standards and &amp;lt;strong&amp;gt;open source&amp;lt;/strong&amp;gt; &amp;lt;strong&amp;gt;software&amp;lt;/strong&amp;gt; to facilitate software licensing due diligence and compliance activities across the supply chain:&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Expanding the specification to include comprehensive information for meeting license obligations such as complete attribution data required by open source licenses – e.g. copyright and other notices,&amp;lt;/li&amp;gt;&amp;lt;li type=&amp;quot;_moz&amp;quot;&amp;gt;Developing comprehensive open source tools to support many or most due diligence and compliance activities,&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Analyzing licenses in a package using scanning and/or matching techniques to detect the licenses and generate an SPDX file from that analysis,&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Managing large volume of SPDX files – inbound and outbound,&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Automating obligation fulfillment such as generation of attribution text or creation of a source code redistribution package,&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Establishing a trusted repository of more comprehensive data about licenses – e.g. extend the License List to provide data for use by license detection tools,&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Possibly establishing a trusted repository of software components with their origin and license information&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;h3&amp;gt;Specification vs. Implementation&amp;lt;/h3&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot;&amp;gt;There is some fundamental creative tension between our charter to create a Software Package Data Exchange specification and foster its adoption versus a broader mission to create open source software to actively facilitate/enable that adoption.&amp;lt;span&amp;gt;&amp;amp;nbsp; &amp;lt;/span&amp;gt;&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;The SPDX original/current charter is to create a data specification and foster its adoption.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;We agreed early on to create some basic software tools to read and write SPDX files and encourage commercial vendors to support SPDX in their existing products.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;We also agreed to emulate an open source project, but we are not an open source project whose primary “work product” is software – our primary work product is the specification itself.&amp;lt;span&amp;gt;&amp;amp;nbsp;&amp;amp;nbsp; &amp;lt;/span&amp;gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;As the SPDX specification evolves (and presumably becomes more complex), it may be highly desirable or even necessary to provide some elements of a reference implementation to validate the specification before general release.&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;We may be able to better leverage and extend existing open source projects, such as FOSSology, to offer elements of a reference implementation.&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot;&amp;gt;If we change our charter to include development of open source software to support software licensing due diligence and compliance activities across the supply chain, then we need to look closely at our form of organization.&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;h2&amp;gt;Vision and Mission Statements&amp;lt;/h2&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot; style=&amp;quot;margin-bottom: 0.0001pt;&amp;quot;&amp;gt;We currently have several documents that document and explain our vision and mission including:&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;p class=&amp;quot;MsoListParagraphCxSpFirst&amp;quot; style=&amp;quot;margin-bottom: 0.0001pt; text-indent: -0.25in;&amp;quot;&amp;gt;&amp;lt;span style=&amp;quot;font-family: Symbol;&amp;quot;&amp;gt;&amp;lt;span&amp;gt;·&amp;lt;span style=&amp;quot;font: 7pt 'Times New Roman';&amp;quot;&amp;gt;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp; &amp;lt;/span&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;/span&amp;gt;The SPDX Charter, Definition and other principles listed in &amp;lt;span style=&amp;quot;text-decoration: underline;&amp;quot;&amp;gt;Section 1. Rationale&amp;lt;/span&amp;gt; of the in the specification itself&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;p class=&amp;quot;MsoListParagraphCxSpMiddle&amp;quot; style=&amp;quot;text-indent: -0.25in;&amp;quot;&amp;gt;&amp;lt;span style=&amp;quot;font-family: Symbol;&amp;quot;&amp;gt;&amp;lt;span&amp;gt;·&amp;lt;span style=&amp;quot;font: 7pt 'Times New Roman';&amp;quot;&amp;gt;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp; &amp;lt;/span&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;/span&amp;gt;The white paper - &amp;lt;span style=&amp;quot;text-decoration: underline;&amp;quot;&amp;gt;A Common Software Package Data Exchange Format: 1.0 Release Update and Discussion&amp;lt;/span&amp;gt;&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;p class=&amp;quot;MsoListParagraphCxSpLast&amp;quot; style=&amp;quot;text-indent: -0.25in;&amp;quot;&amp;gt;&amp;lt;span style=&amp;quot;font-family: Symbol;&amp;quot;&amp;gt;&amp;lt;span&amp;gt;·&amp;lt;span style=&amp;quot;font: 7pt 'Times New Roman';&amp;quot;&amp;gt;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp; &amp;lt;/span&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;/span&amp;gt;Other materials such as several versions of the introductory presentations&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot;&amp;gt;&amp;lt;span&amp;gt;&amp;amp;nbsp;&amp;lt;/span&amp;gt;Some members have already been thinking about expanding how we talk about our vision, mission, charter, and guiding principles – there are many names for specific elements of how an organization describes itself.&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot;&amp;gt;One approach is to add a Vision statement and a Mission statement for SPDX where the Vision statement describes what the future looks like when you execute on the mission and the Mission statement says what you do on a daily basis (similar to a guiding principle).&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot;&amp;gt;The following draft Vision and Mission statements are recent draft contributions from SPDX members:&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;h3&amp;gt;Proposed Vision Statement&amp;lt;/h3&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot;&amp;gt;Phil Odence has proposed the following Vision statement for the website:&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot;&amp;gt;“The vision of SPDX is to achieve license compliance with minimal cost across the supply chain. Ideally, upstream component developers begin the process by supplying SPDX files as part of their downloads. Users of those components therefore have a starting point with the SPDX files that they create for their &amp;quot;customers,&amp;quot; and so on. If everything is working properly, the provenance of each piece of code is researched and documented only once during its journey through a supply chain, and that information is passed on in parallel with the code in the SPDX format.”&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;h3&amp;gt;Proposed Mission Statement&amp;lt;/h3&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot;&amp;gt;The Cisco team has proposed the following Mission statement:&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&amp;lt;p class=&amp;quot;MsoNormal&amp;quot;&amp;gt;&amp;quot;To enable any party in a software supply chain, from the original author to the final end user, to accurately communicate the licensing information for any piece of copyrightable material that such party may create, alter, combine, pass on, or receive, and to make such information available in a consistent, understandable, and re-usable fashion, with the aim of facilitating license and other policy compliance.&amp;quot;&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;amp;nbsp;&amp;lt;/p&amp;gt;&lt;/div&gt;</summary>
		<author><name>Mjherzog</name></author>	</entry>

	</feed>