<?xml version="1.0"?>
<?xml-stylesheet type="text/css" href="https://wiki.spdx.org/skins/common/feed.css?303"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.spdx.org/index.php?action=history&amp;feed=atom&amp;title=General_Meeting%2FMinutes%2F2021-07-01</id>
		<title>General Meeting/Minutes/2021-07-01 - Revision history</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.spdx.org/index.php?action=history&amp;feed=atom&amp;title=General_Meeting%2FMinutes%2F2021-07-01"/>
		<link rel="alternate" type="text/html" href="https://wiki.spdx.org/index.php?title=General_Meeting/Minutes/2021-07-01&amp;action=history"/>
		<updated>2026-05-07T12:33:20Z</updated>
		<subtitle>Revision history for this page on the wiki</subtitle>
		<generator>MediaWiki 1.23.13</generator>

	<entry>
		<id>https://wiki.spdx.org/index.php?title=General_Meeting/Minutes/2021-07-01&amp;diff=4922&amp;oldid=prev</id>
		<title>Podence: Created page with &quot;* Attendance: 22 * Lead by Phil Odence * Minutes of June meeting Approved   == SPDX Governance - Phil ==  Status of governance changes * Still working through a using the prep...&quot;</title>
		<link rel="alternate" type="text/html" href="https://wiki.spdx.org/index.php?title=General_Meeting/Minutes/2021-07-01&amp;diff=4922&amp;oldid=prev"/>
				<updated>2021-07-06T13:02:25Z</updated>
		
		<summary type="html">&lt;p&gt;Created page with &amp;quot;* Attendance: 22 * Lead by Phil Odence * Minutes of June meeting Approved   == SPDX Governance - Phil ==  Status of governance changes * Still working through a using the prep...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;* Attendance: 22&lt;br /&gt;
* Lead by Phil Odence&lt;br /&gt;
* Minutes of June meeting Approved&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== SPDX Governance - Phil ==&lt;br /&gt;
&lt;br /&gt;
Status of governance changes&lt;br /&gt;
* Still working through a using the prepackaged JDF docs with LF lawyers&lt;br /&gt;
** Lots there due to general nature&lt;br /&gt;
** It will have to go through the specified process for discussion and voting&lt;br /&gt;
* Why?&lt;br /&gt;
** More scrutiny&lt;br /&gt;
** Standards requirement- Companies supporting, logos&lt;br /&gt;
*** OMG CISQ 3T joining SPDX &lt;br /&gt;
*** ISO direction – Need more &lt;br /&gt;
*** Executive Order&lt;br /&gt;
*** Working with other standards, i.e. SWID and CycloneDX&lt;br /&gt;
 * Specific concerns that came up&lt;br /&gt;
** Community Spec License vs. CCBY&lt;br /&gt;
*** Patent license to address concerns that have arisen from companies we want to support&lt;br /&gt;
** Also, tangentially related SBOM gen tool showed up in repo&lt;br /&gt;
*** Need criteria for including&lt;br /&gt;
* A question came up about discussion of governance on the Gen Mailing list&lt;br /&gt;
** We try to limit traffic on the list so one can use to monitor activity without being overwhelmed&lt;br /&gt;
** There will be a chance for discussion of a governance proposal once process goes in motion&lt;br /&gt;
** Contact Phil with inputs&lt;br /&gt;
** We’ll look into a separate list&lt;br /&gt;
&lt;br /&gt;
== Outreach Team Report - Sebastian/Jack   ==&lt;br /&gt;
 &lt;br /&gt;
* Rebooted&lt;br /&gt;
* SPDX website rework - license for content CC-BY-4.0&lt;br /&gt;
** Looking to rebuild website as static site.&lt;br /&gt;
** Code and license - more flex over precise styling and functionality.&lt;br /&gt;
** Prototype of site in next few weeks.&lt;br /&gt;
* Technical slides - present about SPDX in own organizations.&lt;br /&gt;
** Reviewed collateral,  audience focus for collateral that will meet audience needs.&lt;br /&gt;
** More explanation of “why”.   Point to specification when get to details. &lt;br /&gt;
* IRC channel &lt;br /&gt;
** Sebastian set up #spdx on libera.chat&lt;br /&gt;
** previous channels on OFTC, Freenode; hadn’t taken off&lt;br /&gt;
** libera.chat has 11 people in it currently&lt;br /&gt;
** “cloaking” - hides IP address in some cases, replaces with badge for organization you’re associated with; Sebastian can provide “SPDX cloak”&lt;br /&gt;
* Matrix bridge - feature of libera.chat, enables joining via Matrix&lt;br /&gt;
* Meeting date and time: 1500 UTC on Wednesdays will be new meeting time, on 14th of July&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Legal Team Report - Jilayne/Paul/Steve ==&lt;br /&gt;
 &lt;br /&gt;
* Several new folks participating&lt;br /&gt;
* Ariel and Candice from ClearlyDefined have been digging into the Python stack of licenses&lt;br /&gt;
* License List 3.14 release - targeting end of July&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
== Tech Team Report - Kate/Gary/Others ==&lt;br /&gt;
 &lt;br /&gt;
* Tools &lt;br /&gt;
** GSoC - JSON support in Golang; will seek to get GSoC student to present at a future General Meeting&lt;br /&gt;
** New participants interacting with tools, and seeing pull requests.&lt;br /&gt;
** NTIA Plugfest &lt;br /&gt;
*** new tools emerging from communities &lt;br /&gt;
*** SPDX was most common format in use&lt;br /&gt;
*** Can’t get down to SPDX field to field &lt;br /&gt;
** SPDX Plugfest?&lt;br /&gt;
*** Desire to have Japan SPDX Plugfest&lt;br /&gt;
*** One for north america   &lt;br /&gt;
** Anchore has a tool supporting SPDX output if you need more 3.0 examples we can on it. (github.com/anchore/syft). We have 2.2 now but can fairly quickly iterate for some 3.0 support.&lt;br /&gt;
* Specification&lt;br /&gt;
** ISO/IEC PRF 5962 - Information Technology — SPDX® Specification V2.2.1- moved to PRF status Publication date : 2021-08&lt;br /&gt;
** OCI registry overview and how SPDX could interact with containers. &lt;br /&gt;
** Specification 3.0 Work &lt;br /&gt;
*** Looking for more 3.0 examples in serialization&lt;br /&gt;
*** Lacking critical mass for some decisions - vacations&lt;br /&gt;
**** Moving through punch list on core model.&lt;br /&gt;
*** Vulnerability - waiting for core.   Snyk put up a nice post.   &lt;br /&gt;
**** Feedback in progress.   &lt;br /&gt;
**** Serialization needs to become clearer.&lt;br /&gt;
**** More examples are needed. &lt;br /&gt;
**** Follow up VEX and CSAF&lt;br /&gt;
*** Licensing profile - pretty similar to 2.2 already.&lt;br /&gt;
**** Once formatting for how template can be expressed.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Other Topics   ==&lt;br /&gt;
&lt;br /&gt;
* Open Question - why spdx.dev vs. spdx.org;   license list dynamically generated spdx.org - Drupal → Wordpress.   How to keep License list still populate to website.&lt;br /&gt;
* Keep license list URL stable. &lt;br /&gt;
* Wikipedia page on SPDX is pretty stale.    &lt;br /&gt;
** Needs to be updated.    Outreach will take it. &lt;br /&gt;
&lt;br /&gt;
== Attendees ==&lt;br /&gt;
&lt;br /&gt;
* Phil Odence, Black Duck/Synopsys&lt;br /&gt;
* Philippe Emmanuel Douziech, CAST&lt;br /&gt;
* Bob Martin, Mitre&lt;br /&gt;
* Joshua Marpet, RM-ISAO&lt;br /&gt;
* David Edelsohn, IBM&lt;br /&gt;
* Sebastian Crane&lt;br /&gt;
* Marc Etienne Vargenau, Nokia&lt;br /&gt;
* Zach Hill, Anchore&lt;br /&gt;
* Steve Winslow, LF&lt;br /&gt;
* Kate Stewart, Linux Foundation&lt;br /&gt;
* William Cox, Synopsys&lt;br /&gt;
* Jack Manbeck, TI&lt;br /&gt;
* Alexios Zavras, Intel&lt;br /&gt;
* Warner Losh, FreeBSD&lt;br /&gt;
* Alfredo Espinosa&lt;br /&gt;
* Jilayne Lovejoy, Red Hat&lt;br /&gt;
* Chris Lusk&lt;br /&gt;
* Andrew Jorganson, AWS&lt;br /&gt;
* Thomas Steenbergen, HERE&lt;br /&gt;
* Ronda, &lt;br /&gt;
* Brian Fox, Sonotype&lt;br /&gt;
* Michael Herzog- nexB&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:General|Minutes]]&lt;br /&gt;
[[Category:Minutes]]&lt;/div&gt;</summary>
		<author><name>Podence</name></author>	</entry>

	</feed>