<?xml version="1.0"?>
<?xml-stylesheet type="text/css" href="https://wiki.spdx.org/skins/common/feed.css?303"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.spdx.org/index.php?action=history&amp;feed=atom&amp;title=General_Meeting%2FMinutes%2F2021-12-02</id>
		<title>General Meeting/Minutes/2021-12-02 - Revision history</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.spdx.org/index.php?action=history&amp;feed=atom&amp;title=General_Meeting%2FMinutes%2F2021-12-02"/>
		<link rel="alternate" type="text/html" href="https://wiki.spdx.org/index.php?title=General_Meeting/Minutes/2021-12-02&amp;action=history"/>
		<updated>2026-05-07T12:07:26Z</updated>
		<subtitle>Revision history for this page on the wiki</subtitle>
		<generator>MediaWiki 1.23.13</generator>

	<entry>
		<id>https://wiki.spdx.org/index.php?title=General_Meeting/Minutes/2021-12-02&amp;diff=4931&amp;oldid=prev</id>
		<title>Podence at 15:25, 7 December 2021</title>
		<link rel="alternate" type="text/html" href="https://wiki.spdx.org/index.php?title=General_Meeting/Minutes/2021-12-02&amp;diff=4931&amp;oldid=prev"/>
				<updated>2021-12-07T15:25:46Z</updated>
		
		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table class='diff diff-contentalign-left'&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;tr style='vertical-align: top;'&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;Revision as of 15:25, 7 December 2021&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 72:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 72:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== Legal &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;team update &lt;/del&gt;- Jilayne/Pau/Steve ==&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== Legal &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;Team Report &lt;/ins&gt;- Jilayne/Pau/Steve ==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* License List version 3.15 was released and published to https://spdx.org/licenses on Nov. 14&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* License List version 3.15 was released and published to https://spdx.org/licenses on Nov. 14&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* Shortened month for meetings due to Thanksgiving holiday in US&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* Shortened month for meetings due to Thanksgiving holiday in US&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* Warner Losh presented to the team about FreeBSD's use of SPDX short-form license identifiers: https://docs.google.com/presentation/d/1mRWj7DCiicK57BqD4XzUMSZs51TpUUIYIgI-UcB8XDw/edit#slide=id.p&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* Warner Losh presented to the team about FreeBSD's use of SPDX short-form license identifiers: https://docs.google.com/presentation/d/1mRWj7DCiicK57BqD4XzUMSZs51TpUUIYIgI-UcB8XDw/edit#slide=id.p&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt; &lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt; &lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== Outreach Team -&amp;#160; ==&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== Outreach Team &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;Report &lt;/ins&gt;-&amp;#160; ==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* No update, but Sebastian sent an email to the General Meeting list with notes on behalf of the team.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* No update, but Sebastian sent an email to the General Meeting list with notes on behalf of the team.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Podence</name></author>	</entry>

	<entry>
		<id>https://wiki.spdx.org/index.php?title=General_Meeting/Minutes/2021-12-02&amp;diff=4930&amp;oldid=prev</id>
		<title>Podence: Created page with &quot;* Attendance: 33 * Lead by Phil Odence * Minutes from last approved  * Phil will company membership announcement before end of week * We will be move General Meeting minutes t...&quot;</title>
		<link rel="alternate" type="text/html" href="https://wiki.spdx.org/index.php?title=General_Meeting/Minutes/2021-12-02&amp;diff=4930&amp;oldid=prev"/>
				<updated>2021-12-07T15:25:03Z</updated>
		
		<summary type="html">&lt;p&gt;Created page with &amp;quot;* Attendance: 33 * Lead by Phil Odence * Minutes from last approved  * Phil will company membership announcement before end of week * We will be move General Meeting minutes t...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;* Attendance: 33&lt;br /&gt;
* Lead by Phil Odence&lt;br /&gt;
* Minutes from last approved&lt;br /&gt;
&lt;br /&gt;
* Phil will company membership announcement before end of week&lt;br /&gt;
* We will be move General Meeting minutes to GitHub and crowdsource during meetings.&lt;br /&gt;
&lt;br /&gt;
== Microsoft and SPDX - Adrian/Steve  ==&lt;br /&gt;
&lt;br /&gt;
* Microsoft standardizing on SPDX [Adrian Giglio]&lt;br /&gt;
** Why SPDX?&lt;br /&gt;
*** On ISO standard path&lt;br /&gt;
*** Already participating&lt;br /&gt;
*** Great group&lt;br /&gt;
** Why build their own tool?&lt;br /&gt;
*** Already had tooling&lt;br /&gt;
*** Easy to move to SPDX&lt;br /&gt;
*** Needed certainty to meet NTiA standards&lt;br /&gt;
*** Utilize MS Detection&lt;br /&gt;
*** Needed a great range of environments&lt;br /&gt;
*** Support for very large, complex build systems; layered builds&lt;br /&gt;
** The Tool&lt;br /&gt;
*** Built on .Net and available for Windows/Linux/Mac&lt;br /&gt;
*** Available as build step in Azure&lt;br /&gt;
*** Plan is to open source&lt;br /&gt;
*** Pulls OSS data from a variety of build system formats&lt;br /&gt;
** Future&lt;br /&gt;
*** Proving by early March, then rolling out across Microsoft&lt;br /&gt;
*** Exploring different methods of SBOM distribution including web portal&lt;br /&gt;
*** Exploring signing with others in the industry&lt;br /&gt;
&lt;br /&gt;
* MCR Distributing SPDX SBoMs for Microsoft content [Steve Lasker]&lt;br /&gt;
** How to distribute secured supply chain components? Specifically SBOMs&lt;br /&gt;
** Supply chain artifact challenges:&lt;br /&gt;
*** artifacts get promoted across environments, including production assets getting pulled from the Internet into restricted networks&lt;br /&gt;
*** private virtual networks within cloud infrastructure&lt;br /&gt;
** Solution: Validation artifacts need to travel together with the supply chain objects&lt;br /&gt;
*** by default, SBOM might get blocked from being accessed due to &amp;quot;airgapped&amp;quot; / VNet setup&lt;br /&gt;
*** instead, create a private registry within each vnet; with shared internal registry hosting all artifacts + SBOMs, then promoted into each vnet&lt;br /&gt;
** ORAS: need signatures to be separable, verifiable, able to be validated, prior to bringing artifact / binary into the environment&lt;br /&gt;
*** Microsoft built this for Azure Container Registry, but customers share with other registries and other infrastructure; registries should be a broader standard =&amp;gt; OCI Artifacts, ORAS Artifacts&lt;br /&gt;
*** Signatures and SPDX SBOMs get attached to the graph&lt;br /&gt;
*** ACR support for ORAS Artifacts today =&amp;gt; customers can store SPDX SBOMs today: https://aka.ms/acr/supply-chain-artifacts&lt;br /&gt;
** Opportunity: having SPDX document travel alongside the target artifact; CLI that can natively push / pull / validate SPDX SBOMs to Registries&lt;br /&gt;
** What does the SPDX community want to see in an SBOM?&lt;br /&gt;
*** recording EULA text?&lt;br /&gt;
*** something validated at the time the content is used? =&amp;gt; needs to be accessible along with the artifact itself&lt;br /&gt;
&lt;br /&gt;
* Questions/Comments&lt;br /&gt;
** Dick: what about having vulnerability disclosures together as a part of the distributed info?&lt;br /&gt;
*** Appreciate that the SPDX structure enables describing all the pieces of what went into a software build in the first place =&amp;gt; static information at a point in time&lt;br /&gt;
*** Scan results are things that you learn about over time =&amp;gt; e.g. might learn later about a problem that was discovered after it was shipped&lt;br /&gt;
*** Scan results will continue to be additive, whereas the SBOM itself doesn't change&lt;br /&gt;
*** Dick: some vendors are running scans and producing NVD reports together with vendor's findings; making that info available together with the SBOM. During customer risk assessments, they can see beforehand if a CVE is reported =&amp;gt; if shows up in the disclosure, that helps address the risk.&lt;br /&gt;
*** Scan results, etc., could be attached to the other documents that are included in the registry&lt;br /&gt;
*** Eventually, looking to have a web-browsable portal to easily access these documents. But, the automation is the interesting part.&lt;br /&gt;
** Just this morning, this was announced to be becoming part of an OCI working group; previously getting proven within the ORAS project&lt;br /&gt;
** Sebastian: Ostree (Fedora): https://fedoraproject.org/wiki/Changes/OstreeNativeContainer&lt;br /&gt;
** Signature format: shipped in Notary v2, but working on expanding via conversations with the broader community. Needs to be able to be validated broadly.&lt;br /&gt;
** Dick: NIST workshop that took place this week: ability to distribute SDLC evidence and policy data. Will that be part of this?&lt;br /&gt;
*** Viewing this as plumbing / core infrastructure, in a generic way; new types will emerge for what types of artifacts are used to be deployed / promoted on this infrastructure&lt;br /&gt;
*** Because it's generic / abstracted, any new type can be hosted on this infrastructure&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
== Tech Team Report – Kate/Gary/Others ==&lt;br /&gt;
* Tools&lt;br /&gt;
** New release of SPDX Java Tools available at https://github.com/spdx/tools-java/releases/tag/v1.0.3&lt;br /&gt;
* Specification&lt;br /&gt;
** Focused on the Core modeling&lt;br /&gt;
** Made progress on collections, packages, and document definitions and relationships&lt;br /&gt;
** Significant testing of the model with different use cases and serialization considerations&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Legal team update - Jilayne/Pau/Steve ==&lt;br /&gt;
* License List version 3.15 was released and published to https://spdx.org/licenses on Nov. 14&lt;br /&gt;
* Shortened month for meetings due to Thanksgiving holiday in US&lt;br /&gt;
* Warner Losh presented to the team about FreeBSD's use of SPDX short-form license identifiers: https://docs.google.com/presentation/d/1mRWj7DCiicK57BqD4XzUMSZs51TpUUIYIgI-UcB8XDw/edit#slide=id.p&lt;br /&gt;
 &lt;br /&gt;
== Outreach Team -  ==&lt;br /&gt;
* No update, but Sebastian sent an email to the General Meeting list with notes on behalf of the team.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Attendees ==&lt;br /&gt;
&lt;br /&gt;
* Phil Odence, Black Duck/Synopsys&lt;br /&gt;
* Adrian Digli, Microsoft&lt;br /&gt;
* Steve Lasker, Microsoft&lt;br /&gt;
* Sebastian Crane&lt;br /&gt;
* Steve Winslow, Boston Technology Law&lt;br /&gt;
* Dick Brooks, REA&lt;br /&gt;
* Rich Steenwyk, GE Healthcare&lt;br /&gt;
* Annie &lt;br /&gt;
* Brad Goldring, GTC&lt;br /&gt;
* Jeff Schutt, Cisco&lt;br /&gt;
* David Edelsohn, IBM&lt;br /&gt;
* Jilayne Lovejoy, Red Hat&lt;br /&gt;
* Aveek Basu, NextMark Printers&lt;br /&gt;
* Marc Gisi, Windriver&lt;br /&gt;
* Gary O’Neall, SourceAuditor&lt;br /&gt;
* Philippe Ombrédanne- nexB&lt;br /&gt;
* Dick Brooks&lt;br /&gt;
* Alex Rybek&lt;br /&gt;
* Brend Smits, Philips&lt;br /&gt;
* Christopher Lusk, Lenovo&lt;br /&gt;
* Christopher Phillips&lt;br /&gt;
* Fellow Jitser&lt;br /&gt;
* Jilayne Lovejoy, Red Hat&lt;br /&gt;
* Mashid&lt;br /&gt;
* Kendra Morton&lt;br /&gt;
* Marco&lt;br /&gt;
* Majira&lt;br /&gt;
* Michael Herzog- nexB&lt;br /&gt;
* Mike Nemmers&lt;br /&gt;
* Molly Menoni&lt;br /&gt;
* Paul Madick, Jenzabar&lt;br /&gt;
* Rose Judge, VMWare&lt;br /&gt;
* Vicky Brasseur, Wipro&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:General|Minutes]]&lt;br /&gt;
[[Category:Minutes]]&lt;/div&gt;</summary>
		<author><name>Podence</name></author>	</entry>

	</feed>