<?xml version="1.0"?>
<?xml-stylesheet type="text/css" href="https://wiki.spdx.org/skins/common/feed.css?303"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.spdx.org/index.php?action=history&amp;feed=atom&amp;title=Technical_Team%2FMinutes%2F2014-10-07</id>
		<title>Technical Team/Minutes/2014-10-07 - Revision history</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.spdx.org/index.php?action=history&amp;feed=atom&amp;title=Technical_Team%2FMinutes%2F2014-10-07"/>
		<link rel="alternate" type="text/html" href="https://wiki.spdx.org/index.php?title=Technical_Team/Minutes/2014-10-07&amp;action=history"/>
		<updated>2026-05-07T12:14:37Z</updated>
		<subtitle>Revision history for this page on the wiki</subtitle>
		<generator>MediaWiki 1.23.13</generator>

	<entry>
		<id>https://wiki.spdx.org/index.php?title=Technical_Team/Minutes/2014-10-07&amp;diff=3374&amp;oldid=prev</id>
		<title>Goneall: Created page with &quot;October 10, 2014 == Attendees == * Gary O'Neall * Bill Schineller * Kate Stewart * Jack Manbeck * Scott Sterling == Agenda == * Schedule for 2.0 * External document references...&quot;</title>
		<link rel="alternate" type="text/html" href="https://wiki.spdx.org/index.php?title=Technical_Team/Minutes/2014-10-07&amp;diff=3374&amp;oldid=prev"/>
				<updated>2014-10-08T01:38:48Z</updated>
		
		<summary type="html">&lt;p&gt;Created page with &amp;quot;October 10, 2014 == Attendees == * Gary O&amp;#039;Neall * Bill Schineller * Kate Stewart * Jack Manbeck * Scott Sterling == Agenda == * Schedule for 2.0 * External document references...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;October 10, 2014&lt;br /&gt;
== Attendees ==&lt;br /&gt;
* Gary O'Neall&lt;br /&gt;
* Bill Schineller&lt;br /&gt;
* Kate Stewart&lt;br /&gt;
* Jack Manbeck&lt;br /&gt;
* Scott Sterling&lt;br /&gt;
== Agenda ==&lt;br /&gt;
* Schedule for 2.0&lt;br /&gt;
* External document references&lt;br /&gt;
* Support for multiple checksum types&lt;br /&gt;
== Schedule for 2.0   ==&lt;br /&gt;
* Key Dates:&lt;br /&gt;
** November 14: SPDX 2.0 Draft complete, distributed for internal review/comment (internal to business, legal and technical committees)&lt;br /&gt;
** Dec 1. Deadline for feedback&lt;br /&gt;
** Dec. 1-17 incorporate feedback&lt;br /&gt;
** Dec. 18 SPDX 2.0 release candidate for tools implementation and release to general mailing list&lt;br /&gt;
** Dec 19th: Tool Implementation Kickoff&lt;br /&gt;
** Feb. 18-20 Collab Summit - Tools implemented, Plug-and-Play event to test tool interoperability&lt;br /&gt;
*** compare SPDX 2.0 output of different tools for compatibility/consistency&lt;br /&gt;
*** supply chain example.  Upstream SPDX consumed by downstream SPDX.&lt;br /&gt;
*  Won't make the current plan of LInuxCon Europe (which is next week)&lt;br /&gt;
* Draft ready for Linux Open in December - either the first or 15th&lt;br /&gt;
** Kate will be offline 3 weeks last part of Nov through Dec 1&lt;br /&gt;
** Kate will publish draft before going offline - November 14th&lt;br /&gt;
** Dec 1. - deadline for feedback&lt;br /&gt;
** First 1/2 December gather feedback&lt;br /&gt;
** Target December 18th for release candidate 1 (RC1) - ready for tools implementation&lt;br /&gt;
* Remaining work - Kate will publish a list&lt;br /&gt;
** Would like to get additional checksums&lt;br /&gt;
** License identifiers in the code as an appendix&lt;br /&gt;
** License Expressions Syntax&lt;br /&gt;
*** Jack will publish a draft for this section&lt;br /&gt;
* Tools to be implemented by LinuxCon&lt;br /&gt;
** Tools demo including use cases - supply chain examples&lt;br /&gt;
** Bake-off/Plug-n-play/interoperability tests between tools&lt;br /&gt;
* Migration from 1.0 to 2.0&lt;br /&gt;
** Should the business team take on the migration collateral?&lt;br /&gt;
** Highlights of 2.0 on the 18th&lt;br /&gt;
** Migration details and &amp;quot;what's new in SPDX 2.0&amp;quot; papers should be published soon after the 18th.&lt;br /&gt;
== External document references==&lt;br /&gt;
* Reviewed email proposal&lt;br /&gt;
* Kate will do a more detailed review and email any changes&lt;br /&gt;
* Gary will update the proposal to include an SPDX default namespace for those without their own creator website&lt;br /&gt;
* We agreed not to implement the storage of SPDX documents now&lt;br /&gt;
** We will discuss this at LinuxCon&lt;br /&gt;
** we will add a page to describe the use of the document URIs to the SPDX web page that may be referenced from the default spdx namespace&lt;br /&gt;
== Additional Checksum Types ==&lt;br /&gt;
* Bruno proposed additional types&lt;br /&gt;
** SHA-256&lt;br /&gt;
* cardinality would be changed to 1 or more (from 1)&lt;br /&gt;
* Do we also allow for other types to be used in the verification code (in addition to using the checksum types for the file checksums)?&lt;br /&gt;
* Mandatory sha1, others are optional&lt;br /&gt;
* Verification code would also be a mandatory sha1 with optional other &lt;br /&gt;
* Should we change the mandatory from sha1 to sha256?&lt;br /&gt;
** sha1 has been proven vulnerable&lt;br /&gt;
** sha1 would be compatible with 1.2&lt;br /&gt;
** vulnerability would not be too severe for our use cases&lt;br /&gt;
 [[Category:Technical|Minutes]]&lt;br /&gt;
[[Category:Minutes]]&lt;/div&gt;</summary>
		<author><name>Goneall</name></author>	</entry>

	</feed>