<?xml version="1.0"?>
<?xml-stylesheet type="text/css" href="https://wiki.spdx.org/skins/common/feed.css?303"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.spdx.org/index.php?action=history&amp;feed=atom&amp;title=General_Meeting%2FMinutes%2F2021-02-04</id>
		<title>General Meeting/Minutes/2021-02-04 - Revision history</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.spdx.org/index.php?action=history&amp;feed=atom&amp;title=General_Meeting%2FMinutes%2F2021-02-04"/>
		<link rel="alternate" type="text/html" href="https://wiki.spdx.org/index.php?title=General_Meeting/Minutes/2021-02-04&amp;action=history"/>
		<updated>2026-05-07T12:20:45Z</updated>
		<subtitle>Revision history for this page on the wiki</subtitle>
		<generator>MediaWiki 1.23.13</generator>

	<entry>
		<id>https://wiki.spdx.org/index.php?title=General_Meeting/Minutes/2021-02-04&amp;diff=4895&amp;oldid=prev</id>
		<title>Podence: Created page with &quot;* Attendance: 26 * Lead by Phil Odence * Minutes of Dec meeting Approved   == 3T-SBOM - Kay/Bob ==  * Basis ** To standardize, tools need to talk to each other ** Developed 9...&quot;</title>
		<link rel="alternate" type="text/html" href="https://wiki.spdx.org/index.php?title=General_Meeting/Minutes/2021-02-04&amp;diff=4895&amp;oldid=prev"/>
				<updated>2021-03-02T13:12:04Z</updated>
		
		<summary type="html">&lt;p&gt;Created page with &amp;quot;* Attendance: 26 * Lead by Phil Odence * Minutes of Dec meeting Approved   == 3T-SBOM - Kay/Bob ==  * Basis ** To standardize, tools need to talk to each other ** Developed 9...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;* Attendance: 26&lt;br /&gt;
* Lead by Phil Odence&lt;br /&gt;
* Minutes of Dec meeting Approved&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== 3T-SBOM - Kay/Bob ==&lt;br /&gt;
&lt;br /&gt;
* Basis&lt;br /&gt;
** To standardize, tools need to talk to each other&lt;br /&gt;
** Developed 9 use cases&lt;br /&gt;
** Started up in 2019; several groups involved&lt;br /&gt;
** Provenance/Pedigree distinction &lt;br /&gt;
** Started w/NTIA fields as basis&lt;br /&gt;
** Developed model very similar to SPDX&lt;br /&gt;
** Started w/ software but can be broader&lt;br /&gt;
* Merging Efforts&lt;br /&gt;
** Common goals/members; working for some time&lt;br /&gt;
** So, made sense to merge&lt;br /&gt;
** Harmonized meetings&lt;br /&gt;
*** Profile groups meeting separately from Tech meeting&lt;br /&gt;
*** All a little fluid&lt;br /&gt;
** Longer Term thoughts&lt;br /&gt;
*** Licensing and contribution agreements for spec&lt;br /&gt;
*** User scenarios, broader scope&lt;br /&gt;
**** May need to update naming scheme&lt;br /&gt;
**** Broader scope may require expanded governance and funding&lt;br /&gt;
* Questions&lt;br /&gt;
** Funding discs&lt;br /&gt;
&lt;br /&gt;
== Tech Team Report - Kate/Gary/Others ==&lt;br /&gt;
&lt;br /&gt;
* Spec - Kate&lt;br /&gt;
** Overview&lt;br /&gt;
*** SPDX 2.2 being refactored into upcoming 3.0 effort, with Core and separate topical Profiles&lt;br /&gt;
*** Has been happening in parallel with 3T SBOM efforts&lt;br /&gt;
**Core - William&lt;br /&gt;
*** Area with most overlap with 3T efforts&lt;br /&gt;
*** Have been working on identifying areas of differences between the two, gradually converging&lt;br /&gt;
*** Last month was focused on identifying remaining differences and working through them, determining how critical they are&lt;br /&gt;
*** Remaining differences are centered on (1) naming things and (2) external references&lt;br /&gt;
*** Also working through tooling and how to document the core standard&lt;br /&gt;
*** Close to done on what the model will look like, want to turn next to actually writing it up in a format that is suitable for use cases – transition from modeling to authoring of spec text&lt;br /&gt;
** Licensing - Steve&lt;br /&gt;
*** Described background of licensing fields combined with “core” in 2.2 and prior spec versions&lt;br /&gt;
*** Splitting out licensing-related fields into a separate optional profile&lt;br /&gt;
*** Previously discussed and brainstorming in a shared Google Doc&lt;br /&gt;
*** Was previously planning to wait on migrating into GitHub until spec format was finalized; sounds like that will still be some time until finalized&lt;br /&gt;
*** Will work on migrating Google Doc brainstorming outcomes into GitHub in MarkDown or plain text&lt;br /&gt;
** Defects – Thomas&lt;br /&gt;
*** Includes “vulnerabilities”&lt;br /&gt;
*** Worked with William on documenting an example&lt;br /&gt;
*** Still working on remediation-related fields&lt;br /&gt;
*** Hoping to have more concrete examples, and to restart the security discussions before the end of this month&lt;br /&gt;
** Linking – Nisha&lt;br /&gt;
*** Mockups: https://github.com/SantiagoTorres/spdx-linking-mockups&lt;br /&gt;
*** “Linking” – how different software components are related to each other, and to separate components in the broader ecosystem&lt;br /&gt;
*** Profile aims to capture, if using e.g. a container or a CNAB (Cloud Native Application Bundle), meant to surface those connections&lt;br /&gt;
*** Focused on cloud native use case, but could also be used in e.g. the embedded world, for something like an embedded OS utilizing multiple components&lt;br /&gt;
**** Kay – other scenarios thinking about: e.g. IoT devices, wanting to list out both software and hardware components&lt;br /&gt;
**** Santiago – working on similar for in-toto, to authenticate components&lt;br /&gt;
*** Currently stuck on sorting out the overlap between the Linking profile and the Integrity profile. Current thinking, integrity signatures should be handled via “relationships” between elements&lt;br /&gt;
** Integrity – Santiago&lt;br /&gt;
*** Slides: [TO BE FILLED IN]&lt;br /&gt;
*** There are a lot of outstanding questions, still being sorted through&lt;br /&gt;
*** Milestone structure: Document integrity &amp;gt;&amp;gt; Document Authentication &amp;gt;&amp;gt; Document &amp;amp; supply chain policy &amp;gt;&amp;gt; Linkage &amp;amp; supply chain integrity&lt;br /&gt;
*** Discussed roles of each stage and current status of milestones&lt;br /&gt;
** Usage and Other Emerging – Kate&lt;br /&gt;
*** Spearheaded by team in Japan&lt;br /&gt;
*** Looking at carrying e.g. contract info along in SPDX documents&lt;br /&gt;
*** Also looking at Pedigree / Provenance profiles, for fields to carry build information&lt;br /&gt;
* Tools and Google Summer of Code (GSoC) - Gary&lt;br /&gt;
** GSoC: Applications open for projects, Gary is applying now, will update next month&lt;br /&gt;
** Will post link to project page&lt;br /&gt;
** Looking at different tooling for supporting spec process&lt;br /&gt;
 &lt;br /&gt;
== Legal Team Report - Paul/Jilayne/Steve ==&lt;br /&gt;
 &lt;br /&gt;
* 3.12 release, pushed back to Feb. 19/20, may push further back depending on issue status&lt;br /&gt;
* Ran into some issues with CI/build system, thank you to Gary and William for helping to resolve&lt;br /&gt;
* Jilayne – description of what the legal team works on&lt;br /&gt;
** License list for those not familiar with it: https://spdx.org/licenses&lt;br /&gt;
 &lt;br /&gt;
== Outreach Team Report - Aveek ==&lt;br /&gt;
 &lt;br /&gt;
* Recurring meeting with several community members about how to welcome new folks to the community&lt;br /&gt;
* Discussing initial tools, assigning initial issues to newcomers&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Attendees ==&lt;br /&gt;
&lt;br /&gt;
* Phil Odence, Black Duck/Synopsys&lt;br /&gt;
* David Martin, Mitre&lt;br /&gt;
* Kay Williams, Microsoft&lt;br /&gt;
* Steve Winslow, LF&lt;br /&gt;
* Jilayne Lovejoy&lt;br /&gt;
* Paul Madick, Jenzabar&lt;br /&gt;
* Kate Stewart, Linux Foundation&lt;br /&gt;
* Gary O’Neall, SourceAuditor&lt;br /&gt;
* Aveek Basu, NextMark Printers&lt;br /&gt;
* Sean Geary, Revenera&lt;br /&gt;
* William Cox, Synopsys&lt;br /&gt;
* Maximilian Huber, TNG&lt;br /&gt;
* Emmanuel Tournier, Black Duck/Synopsys&lt;br /&gt;
* Thomas Steenbergen, HERE&lt;br /&gt;
* Alfredo Espinosa&lt;br /&gt;
* Nishad Thalhath&lt;br /&gt;
* David Edelsohn&lt;br /&gt;
* Philippe Emmanuel Douziech&lt;br /&gt;
* William Bartholomew, GitHub&lt;br /&gt;
* Alexios Zavras, Intel&lt;br /&gt;
* Santiago&lt;br /&gt;
* Henk Birkholz&lt;br /&gt;
* Ariel Patano&lt;br /&gt;
* Jorge Rodriguez-Moreno&lt;br /&gt;
* Nisha Kumar, VMware&lt;br /&gt;
* Michael Herzog- nexB&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:General|Minutes]]&lt;br /&gt;
[[Category:Minutes]]&lt;/div&gt;</summary>
		<author><name>Podence</name></author>	</entry>

	</feed>