<?xml version="1.0"?>
<?xml-stylesheet type="text/css" href="https://wiki.spdx.org/skins/common/feed.css?303"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.spdx.org/index.php?action=history&amp;feed=atom&amp;title=General_Meeting%2FMinutes%2F2016-08-04</id>
		<title>General Meeting/Minutes/2016-08-04 - Revision history</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.spdx.org/index.php?action=history&amp;feed=atom&amp;title=General_Meeting%2FMinutes%2F2016-08-04"/>
		<link rel="alternate" type="text/html" href="https://wiki.spdx.org/index.php?title=General_Meeting/Minutes/2016-08-04&amp;action=history"/>
		<updated>2026-05-07T17:36:19Z</updated>
		<subtitle>Revision history for this page on the wiki</subtitle>
		<generator>MediaWiki 1.23.13</generator>

	<entry>
		<id>https://wiki.spdx.org/index.php?title=General_Meeting/Minutes/2016-08-04&amp;diff=3956&amp;oldid=prev</id>
		<title>Podence: Created page with &quot;* Attendance: 12 * Lead by Phil Odence * Minutes of July meeting approved   == Special Guest - Alexios Zavras, Intel ==  * His role is open source compliance at Intel, based i...&quot;</title>
		<link rel="alternate" type="text/html" href="https://wiki.spdx.org/index.php?title=General_Meeting/Minutes/2016-08-04&amp;diff=3956&amp;oldid=prev"/>
				<updated>2016-08-30T12:29:38Z</updated>
		
		<summary type="html">&lt;p&gt;Created page with &amp;quot;* Attendance: 12 * Lead by Phil Odence * Minutes of July meeting approved   == Special Guest - Alexios Zavras, Intel ==  * His role is open source compliance at Intel, based i...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;* Attendance: 12&lt;br /&gt;
* Lead by Phil Odence&lt;br /&gt;
* Minutes of July meeting approved&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Special Guest - Alexios Zavras, Intel ==&lt;br /&gt;
&lt;br /&gt;
* His role is open source compliance at Intel, based in Munich&lt;br /&gt;
** Now at open source tech center&lt;br /&gt;
** Will be talking about his previous role with Intel Mobile Comms&lt;br /&gt;
* Mobile Comms &lt;br /&gt;
** Based in Germany&lt;br /&gt;
** Germans are very process-oriented, well-documented&lt;br /&gt;
* His role was SW legal compliance.&lt;br /&gt;
** Ensuring all software legally compliant across all kinds of software&lt;br /&gt;
** They treat all compliance issues as a bug, just like any problem in the software&lt;br /&gt;
** Alexis learned of SPDX and was very pleased and excited about it&lt;br /&gt;
*** Didn’t manage to get everything SPDX based&lt;br /&gt;
*** Started slowly&lt;br /&gt;
*** SPDX is very valuable at many levels&lt;br /&gt;
**** Even just the license list and standard way of expressing was very helpful&lt;br /&gt;
**** Quickly standardized on SPDX notations and it started appearing in their documentation etc&lt;br /&gt;
***Included in training that was mandatory for SW devs and later extended to marketing, legal, biz dev&lt;br /&gt;
**** Everyone who touches software had to take on-line course with a deeper course available for some&lt;br /&gt;
*** Have developed number of tools, tightly coupled with dev environment&lt;br /&gt;
**** All developed internally&lt;br /&gt;
**** very tightly controlled, eg can’t check out code without a ticket&lt;br /&gt;
**** Tool chain includes license compliance&lt;br /&gt;
*** Central team provides compliance services to dev&lt;br /&gt;
**** too much for all devs to worry about&lt;br /&gt;
**** Fits with org structure&lt;br /&gt;
**** Internal teams reviews all code&lt;br /&gt;
*** Started small, then more widespread and more automated&lt;br /&gt;
**** Today every release goes though this license compliance check&lt;br /&gt;
**** Requires ‘stamp of approval’ from central team&lt;br /&gt;
*** To make the central team more efficient&lt;br /&gt;
**** Save all results&lt;br /&gt;
**** Including many of the SPDX fields&lt;br /&gt;
**** Saved in database&lt;br /&gt;
*** Last step, not yet taken, is to generate an SPDX doc for each release&lt;br /&gt;
**** Just held up by organizational issues, technically feasible&lt;br /&gt;
**** Being worked on&lt;br /&gt;
**** Have started getting the request from customers&lt;br /&gt;
***** Not mentioning SPDX by name, have not seen that yet,&lt;br /&gt;
***** but asking for data that SPDX covers, files, license, etc&lt;br /&gt;
***** (both are with Euro customers)&lt;br /&gt;
*** When they generate SPDX&lt;br /&gt;
**** Permissive license require attribution&lt;br /&gt;
**** They’ve had an issue with that going back 5 years&lt;br /&gt;
**** Their policy to handle is to deliver all OSS in source form&lt;br /&gt;
**** So, therefore include attribution in comments&lt;br /&gt;
**** They include a list of open source and model licenses, but the attribution is all in source code&lt;br /&gt;
*** Example- Modem company&lt;br /&gt;
**** Intel provides chips and software in binary form&lt;br /&gt;
**** Packaging: With binary they include &lt;br /&gt;
***** all source for open source in binary&lt;br /&gt;
***** And, list of conditions for any 3td party proprietary code&lt;br /&gt;
*** Are they being asked for security vulnerabilities associated with components&lt;br /&gt;
**** Not yet, but they are thinking about it with respect to naming (CPEs, etc)&lt;br /&gt;
* AZ- “Thanks for the wonderful work. It’s really helpful.”&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Tech Team Report - Kate ==&lt;br /&gt;
&lt;br /&gt;
* Spec&lt;br /&gt;
** Collecting feedback&lt;br /&gt;
** Addressing as it comes it&lt;br /&gt;
* Gary has taken a pass at updating tools&lt;br /&gt;
* In the polishing stage&lt;br /&gt;
** One more round of feedback&lt;br /&gt;
** Into publishing mode as of Tuesday&lt;br /&gt;
* Bake Offs&lt;br /&gt;
** Possible SF 9/27 and Europe at LCon&lt;br /&gt;
** Needs to be nailed down in the next couple week.&lt;br /&gt;
&lt;br /&gt;
== Outreach Team Report - Jack ==&lt;br /&gt;
&lt;br /&gt;
* Website&lt;br /&gt;
** Still working this week&lt;br /&gt;
** Will review at next week’s meeting&lt;br /&gt;
** Should be close with go live; shooting for Linux Con NA&lt;br /&gt;
** Still looking for some improvements that will require work from the Linux Foundation team&lt;br /&gt;
*** No show stoppers&lt;br /&gt;
** Will send out link for review&lt;br /&gt;
&lt;br /&gt;
== Legal Team Report - Jilayne ==&lt;br /&gt;
&lt;br /&gt;
* XML review&lt;br /&gt;
** Still plugging away&lt;br /&gt;
** Timeline set&lt;br /&gt;
* 2.5 release&lt;br /&gt;
** Just a few licenses&lt;br /&gt;
** Aiming for end of Oct&lt;br /&gt;
** See Legal Team meeting mins for detail&lt;br /&gt;
** Could use all the help they can get; lots to do&lt;br /&gt;
*** To review new XML master format for every license&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Cross Functional Topics - Phil ==&lt;br /&gt;
&lt;br /&gt;
* Guest stars&lt;br /&gt;
** Always looking for more&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Attendees ==&lt;br /&gt;
&lt;br /&gt;
* Phil Odence, Black Duck&lt;br /&gt;
* Alexios Zavras, Intel&lt;br /&gt;
* Kate Stewart, Linux Foundation&lt;br /&gt;
* Jilayne Lovejoy, ARM&lt;br /&gt;
* Scott Sterling, Palamida&lt;br /&gt;
* Robin Gandhi, UNO&lt;br /&gt;
* Jack Manbeck, TI&lt;br /&gt;
* Yev Bronshteyn, Black Duck&lt;br /&gt;
* Matt Germonprez, UNO&lt;br /&gt;
* Michael Herzog- nexB&lt;br /&gt;
* Georg Link, UNO&lt;br /&gt;
* Mike Dolan, Linux Foundation&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:General|Minutes]]&lt;br /&gt;
[[Category:Minutes]]&lt;/div&gt;</summary>
		<author><name>Podence</name></author>	</entry>

	</feed>