<?xml version="1.0"?>
<?xml-stylesheet type="text/css" href="https://wiki.spdx.org/skins/common/feed.css?303"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.spdx.org/index.php?action=history&amp;feed=atom&amp;title=General_Meeting%2FMinutes%2F2019-01-03</id>
		<title>General Meeting/Minutes/2019-01-03 - Revision history</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.spdx.org/index.php?action=history&amp;feed=atom&amp;title=General_Meeting%2FMinutes%2F2019-01-03"/>
		<link rel="alternate" type="text/html" href="https://wiki.spdx.org/index.php?title=General_Meeting/Minutes/2019-01-03&amp;action=history"/>
		<updated>2026-05-07T13:26:13Z</updated>
		<subtitle>Revision history for this page on the wiki</subtitle>
		<generator>MediaWiki 1.23.13</generator>

	<entry>
		<id>https://wiki.spdx.org/index.php?title=General_Meeting/Minutes/2019-01-03&amp;diff=4653&amp;oldid=prev</id>
		<title>Podence: Created page with &quot;* Attendance: 15 * Lead by Phil Odence * Minutes of Dec meeting approved    == Guest Presentation, JC Herz  ==  * Background ** Years of working with companies and DOD in open...&quot;</title>
		<link rel="alternate" type="text/html" href="https://wiki.spdx.org/index.php?title=General_Meeting/Minutes/2019-01-03&amp;diff=4653&amp;oldid=prev"/>
				<updated>2019-01-03T16:50:18Z</updated>
		
		<summary type="html">&lt;p&gt;Created page with &amp;quot;* Attendance: 15 * Lead by Phil Odence * Minutes of Dec meeting approved    == Guest Presentation, JC Herz  ==  * Background ** Years of working with companies and DOD in open...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;* Attendance: 15&lt;br /&gt;
* Lead by Phil Odence&lt;br /&gt;
* Minutes of Dec meeting approved &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Guest Presentation, JC Herz  ==&lt;br /&gt;
&lt;br /&gt;
* Background&lt;br /&gt;
** Years of working with companies and DOD in open source&lt;br /&gt;
* The Issues/concerns&lt;br /&gt;
** License issues- SPDX handles well&lt;br /&gt;
** Concerns about security close on the heels&lt;br /&gt;
** Compliance is an additional step- Jumping through the hoops to document&lt;br /&gt;
* SEVA Software Evidence Archive&lt;br /&gt;
** Elements&lt;br /&gt;
*** Serves S-BOM function&lt;br /&gt;
*** Augments with content that needs to travel with software&lt;br /&gt;
*** Therefore allowing compliance work to be automated&lt;br /&gt;
*** Freeing up valuable resources to do what they are supposed to do&lt;br /&gt;
*** Can apply to a single component or a full application, so SEVA doesn’t distinguish&lt;br /&gt;
** Format Issue&lt;br /&gt;
*** Customers required XML, beyond SEVA JSON&lt;br /&gt;
*** To be useable by a highly secure facility, data has to be hardened for which XML is better suited&lt;br /&gt;
*** Can be constrained and format can be verified (and extended)&lt;br /&gt;
* SPDX and SEVA Overlap&lt;br /&gt;
** License Info&lt;br /&gt;
*** For the most part SPDX handles beautifully&lt;br /&gt;
**** Government also needs to distinguish government open source&lt;br /&gt;
**** A little more information about state of software (e.g. pre-release)&lt;br /&gt;
** Security extra needs&lt;br /&gt;
*** Some concern about spurious vulnerabilities&lt;br /&gt;
*** Answer is to extend a BoM to include patch info, etc&lt;br /&gt;
*** End of life indicator&lt;br /&gt;
*** They take SPDX familiar thing and provide some extensibility&lt;br /&gt;
** How to name “supplier”?&lt;br /&gt;
*** Working with Kate &lt;br /&gt;
*** OSS organization for example&lt;br /&gt;
*** A bank’s black list&lt;br /&gt;
** Vulnerabilities&lt;br /&gt;
*** Key requirement for vulnerabilities info in SBOM, although just a link might make more sense&lt;br /&gt;
**** Reason is “audit” function. What you knew when. So needs a time stamp.&lt;br /&gt;
**** Bureaucratic are not going to change in favor of something that makes more sense for developers &lt;br /&gt;
**** Concerns that this will get worse over time&lt;br /&gt;
* Other Side - Logistics&lt;br /&gt;
** Moving and shipping of SW/chain of custody- Where did it come from exactly&lt;br /&gt;
*** Not something OSS community has had to worry about&lt;br /&gt;
*** Bad mirror issue, for example.&lt;br /&gt;
** Signed? Timestamp? Delivery date and time for software.&lt;br /&gt;
*** Something like FedEx analogy&lt;br /&gt;
** Package URL helps identify&lt;br /&gt;
* Q&amp;amp;A&lt;br /&gt;
** What can SPDX group do?&lt;br /&gt;
*** JC thinks that they should open source SEVA&lt;br /&gt;
**** Could contribute to LinuxF perhaps&lt;br /&gt;
*** Understand and need to balance needs of OSS consumers and dev communities&lt;br /&gt;
**** Don’t want to burden them&lt;br /&gt;
**** Automate&lt;br /&gt;
*** Challenge- How to distinguish enterprise quality OSS vs. pet projects&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Tech Team Report - Kate/Gary ==&lt;br /&gt;
&lt;br /&gt;
* Tools&lt;br /&gt;
** Starting to plan for GSoC submissions with Gary/Kate&lt;br /&gt;
** Steve has been trained on releasing License list, so Gary now has backup&lt;br /&gt;
** Steve has been working on some new tools for summarizing the SPDX_license_ids based on a new SPDX go library - currently its just supporting TV, but he hopes to add in the other formats&lt;br /&gt;
* Specification&lt;br /&gt;
** Gary &amp;amp; James have been working through SeVA XML and working through how it can be added.&lt;br /&gt;
&lt;br /&gt;
== Legal Team Report - Jilayne ==&lt;br /&gt;
&lt;br /&gt;
* License List&lt;br /&gt;
** V3.4 out before Christmas&lt;br /&gt;
*** Big success to not have to scramble through holidays&lt;br /&gt;
*** Release notes in the GitHub repo&lt;br /&gt;
** Instructions for requesting now live in Repo as well&lt;br /&gt;
*** Leverage GSOC work has been automated.&lt;br /&gt;
** New frontier- Getting open hardware licenses on list&lt;br /&gt;
*** Expanding definition of what goes on the list&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Outreach Team Report  ==&lt;br /&gt;
&lt;br /&gt;
* None this month&lt;br /&gt;
&lt;br /&gt;
== Attendees ==&lt;br /&gt;
&lt;br /&gt;
* Phil Odence, Black Duck/Synopsys&lt;br /&gt;
* Kate Stewart, Linux Foundation&lt;br /&gt;
* Jilayne Lovejoy&lt;br /&gt;
* Steve Winslow, LF&lt;br /&gt;
* Alexios Zavras, Intel&lt;br /&gt;
* Luis Villa, Tidelift&lt;br /&gt;
* Jams Neushal, Neushul Solutions&lt;br /&gt;
* Matthew Crawford, ARM&lt;br /&gt;
* Kevin Nelson, Optim Tech UHG&lt;br /&gt;
* Dennis Clark, NexB&lt;br /&gt;
* Thomas Steenbergen, HERE&lt;br /&gt;
* Bradlee Edmondson, Harvard&lt;br /&gt;
* Gary O’Neall, SourceAuditor&lt;br /&gt;
* Nicholas Toussaint, Orange&lt;br /&gt;
* JC Herz, Ionchannel&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:General|Minutes]]&lt;br /&gt;
[[Category:Minutes]]&lt;/div&gt;</summary>
		<author><name>Podence</name></author>	</entry>

	</feed>