<?xml version="1.0"?>
<?xml-stylesheet type="text/css" href="https://wiki.spdx.org/skins/common/feed.css?303"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.spdx.org/index.php?action=history&amp;feed=atom&amp;title=General_Meeting%2FMinutes%2F2016-07-07</id>
		<title>General Meeting/Minutes/2016-07-07 - Revision history</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.spdx.org/index.php?action=history&amp;feed=atom&amp;title=General_Meeting%2FMinutes%2F2016-07-07"/>
		<link rel="alternate" type="text/html" href="https://wiki.spdx.org/index.php?title=General_Meeting/Minutes/2016-07-07&amp;action=history"/>
		<updated>2026-05-07T15:28:16Z</updated>
		<subtitle>Revision history for this page on the wiki</subtitle>
		<generator>MediaWiki 1.23.13</generator>

	<entry>
		<id>https://wiki.spdx.org/index.php?title=General_Meeting/Minutes/2016-07-07&amp;diff=3906&amp;oldid=prev</id>
		<title>Podence: Created page with &quot;* Attendance: 13 * Lead by Phil Odence * Minutes of June meeting approved   == Special Guest - Sam Ellis, ARM ==  * Sam works in ARM’s Cambridge HQ ** SW Engineer/Mgr ** No...&quot;</title>
		<link rel="alternate" type="text/html" href="https://wiki.spdx.org/index.php?title=General_Meeting/Minutes/2016-07-07&amp;diff=3906&amp;oldid=prev"/>
				<updated>2016-07-07T15:45:02Z</updated>
		
		<summary type="html">&lt;p&gt;Created page with &amp;quot;* Attendance: 13 * Lead by Phil Odence * Minutes of June meeting approved   == Special Guest - Sam Ellis, ARM ==  * Sam works in ARM’s Cambridge HQ ** SW Engineer/Mgr ** No...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;* Attendance: 13&lt;br /&gt;
* Lead by Phil Odence&lt;br /&gt;
* Minutes of June meeting approved&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Special Guest - Sam Ellis, ARM ==&lt;br /&gt;
&lt;br /&gt;
* Sam works in ARM’s Cambridge HQ&lt;br /&gt;
** SW Engineer/Mgr&lt;br /&gt;
** No legal training&lt;br /&gt;
** Has gotten involved just as part as his job&lt;br /&gt;
** Now acts as bridge between dev and legal teams&lt;br /&gt;
* They use a license scanning tool&lt;br /&gt;
** That’s the implementation of SPDX&lt;br /&gt;
** Keen on the license list for name consistency&lt;br /&gt;
** And using SPDX basis of repository of data about open source in products&lt;br /&gt;
* Dev process&lt;br /&gt;
** Similar to most&lt;br /&gt;
** Are careful to separate out open source archive&lt;br /&gt;
*** Basis of license scanning&lt;br /&gt;
*** Develop an SPDX tag format report for each product&lt;br /&gt;
* Legal Approval Process&lt;br /&gt;
** They use a custom tool internally&lt;br /&gt;
** When open source comes into the company, they assess risk&lt;br /&gt;
** Recently put a new system in place&lt;br /&gt;
*** Asks the type of questions that SPDX captures&lt;br /&gt;
**** Package name, licenses, copyright notices, where downloaded, etc.&lt;br /&gt;
*** Goal is to to eventually import/export SPDX for this purposes&lt;br /&gt;
** Tracks OSS use cases&lt;br /&gt;
* Two systems using&lt;br /&gt;
** Approval process&lt;br /&gt;
** Data from the build&lt;br /&gt;
** Will eventually try to compare to ensure sync&lt;br /&gt;
*** Can be hard to maintain, particularly when removing stuff.&lt;br /&gt;
* Sam’s projects use and exceptionally large amount of OSS&lt;br /&gt;
** Need to explain to customers&lt;br /&gt;
** Ideally would like to auto-gen the list of licenses they publish&lt;br /&gt;
*** Practical Problem: They don’t want to declare all&lt;br /&gt;
**** For example, disjunctive license, may only want declare one&lt;br /&gt;
* Would like to ship SPDX&lt;br /&gt;
** Need to work out how much to declare&lt;br /&gt;
** They get a lot of queries&lt;br /&gt;
*** Concern is does providing more info, generate more queries&lt;br /&gt;
** * Certainly they feel that SPDX is the right format&lt;br /&gt;
* Observations&lt;br /&gt;
** Tag file is large - 130 MB for one product&lt;br /&gt;
*** Too large to ship, but could include on website&lt;br /&gt;
*** Too much info to be comprehensible&lt;br /&gt;
** People who need to use, don’t have the tools&lt;br /&gt;
*** Need something that can open and filter/summarize&lt;br /&gt;
* Learning&lt;br /&gt;
** In the past have developed one big SPDX file&lt;br /&gt;
** Probably a mistake, should have broken it down&lt;br /&gt;
* Discussion&lt;br /&gt;
** Tooling- perhaps the convertor to spreadsheet&lt;br /&gt;
** Supply chain partners are really interested in use cases, not just what’s in product&lt;br /&gt;
** Any sharing SPDX docs within company yet? - No, not yet.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Tech Team Report - Kate/Gary ==&lt;br /&gt;
&lt;br /&gt;
* Spec&lt;br /&gt;
** 2.1 draft is out for review&lt;br /&gt;
*** open until the end of the month&lt;br /&gt;
*** assuming no show stoppers, that should be it&lt;br /&gt;
* Tooling&lt;br /&gt;
** Started updating for 2.1 last week&lt;br /&gt;
** External references implementation taking more time than anticipated&lt;br /&gt;
** Tooling first pass should be ready with 2.1 release timeframe&lt;br /&gt;
** Gary is keen for feedback on our tools and any issues in implementing other tools&lt;br /&gt;
&lt;br /&gt;
== Outreach Team Report - Jack ==&lt;br /&gt;
&lt;br /&gt;
* Website&lt;br /&gt;
** Very close to wrapping up&lt;br /&gt;
** Looking at final review next week&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Legal Team Report - Jilayne ==&lt;br /&gt;
&lt;br /&gt;
* XML templates&lt;br /&gt;
** Review continuing&lt;br /&gt;
** Call today will checkpoint where we are and remaining work&lt;br /&gt;
* 2.5 list release&lt;br /&gt;
** Should be live in the next day or two&lt;br /&gt;
** Not too many new licenses&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Cross Functional Topics - Phil ==&lt;br /&gt;
&lt;br /&gt;
* Guest stars&lt;br /&gt;
** Always looking for more&lt;br /&gt;
* LinuxCon&lt;br /&gt;
** Looks light nothing official &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Attendees ==&lt;br /&gt;
&lt;br /&gt;
* Phil Odence, Black Duck&lt;br /&gt;
* Kate Stewart, Linux Foundation&lt;br /&gt;
* Jilayne Lovejoy, ARM&lt;br /&gt;
* Scott Sterling, Palamida&lt;br /&gt;
* Robin Gandhi, UNO&lt;br /&gt;
* Jack Manbeck, TI&lt;br /&gt;
* Yev Bronshteyn, Black Duck&lt;br /&gt;
* Gary O’Neill, SourceAuditor &lt;br /&gt;
* Mark Gisi, Wind River &lt;br /&gt;
* Dave Marr, Qualcomm&lt;br /&gt;
* Matt Germonprez, UNO&lt;br /&gt;
* Michael Herzog- nexB&lt;br /&gt;
* Sam Ellis, ARM&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:General|Minutes]]&lt;br /&gt;
[[Category:Minutes]]&lt;/div&gt;</summary>
		<author><name>Podence</name></author>	</entry>

	</feed>