<?xml version="1.0"?>
<?xml-stylesheet type="text/css" href="https://wiki.spdx.org/skins/common/feed.css?303"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.spdx.org/index.php?action=history&amp;feed=atom&amp;title=Technical_Team%2FMinutes%2F2015-07-28</id>
		<title>Technical Team/Minutes/2015-07-28 - Revision history</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.spdx.org/index.php?action=history&amp;feed=atom&amp;title=Technical_Team%2FMinutes%2F2015-07-28"/>
		<link rel="alternate" type="text/html" href="https://wiki.spdx.org/index.php?title=Technical_Team/Minutes/2015-07-28&amp;action=history"/>
		<updated>2026-05-07T13:17:04Z</updated>
		<subtitle>Revision history for this page on the wiki</subtitle>
		<generator>MediaWiki 1.23.13</generator>

	<entry>
		<id>https://wiki.spdx.org/index.php?title=Technical_Team/Minutes/2015-07-28&amp;diff=3637&amp;oldid=prev</id>
		<title>Goneall at 18:15, 28 July 2015</title>
		<link rel="alternate" type="text/html" href="https://wiki.spdx.org/index.php?title=Technical_Team/Minutes/2015-07-28&amp;diff=3637&amp;oldid=prev"/>
				<updated>2015-07-28T18:15:26Z</updated>
		
		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table class='diff diff-contentalign-left'&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;tr style='vertical-align: top;'&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;Revision as of 18:15, 28 July 2015&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 4:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 4:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* Kate Stewart&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* Kate Stewart&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* Matt Germonprez&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* Matt Germonprez&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;(UNO)&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;Shankar Korlimarla&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* Bill Schineller&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* Bill Schineller&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* Scott Sterling&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* Scott Sterling&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Goneall</name></author>	</entry>

	<entry>
		<id>https://wiki.spdx.org/index.php?title=Technical_Team/Minutes/2015-07-28&amp;diff=3636&amp;oldid=prev</id>
		<title>Goneall: Created page with &quot;July 28, 2015 == Attendees == * Gary O'Neall * Kate Stewart * Matt Germonprez * (UNO) * Bill Schineller * Scott Sterling * Yev Bronshteyn * Mark Gisi ==Security Identifier Pro...&quot;</title>
		<link rel="alternate" type="text/html" href="https://wiki.spdx.org/index.php?title=Technical_Team/Minutes/2015-07-28&amp;diff=3636&amp;oldid=prev"/>
				<updated>2015-07-28T18:14:30Z</updated>
		
		<summary type="html">&lt;p&gt;Created page with &amp;quot;July 28, 2015 == Attendees == * Gary O&amp;#039;Neall * Kate Stewart * Matt Germonprez * (UNO) * Bill Schineller * Scott Sterling * Yev Bronshteyn * Mark Gisi ==Security Identifier Pro...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;July 28, 2015&lt;br /&gt;
== Attendees ==&lt;br /&gt;
* Gary O'Neall&lt;br /&gt;
* Kate Stewart&lt;br /&gt;
* Matt Germonprez&lt;br /&gt;
* (UNO)&lt;br /&gt;
* Bill Schineller&lt;br /&gt;
* Scott Sterling&lt;br /&gt;
* Yev Bronshteyn&lt;br /&gt;
* Mark Gisi&lt;br /&gt;
==Security Identifier Proposal==&lt;br /&gt;
* Proposal at https://docs.google.com/document/d/1WfArS8_xR_CQ_5plOOMtj1y9ps5M-gXFjofUBXR8hyE/edit#&lt;br /&gt;
* Proposal for an SPDX Item level property to hold a reference to an external database for packages&lt;br /&gt;
* Discussion on how much duplication of other efforts&lt;br /&gt;
** Proposal to only provide a link to the other efforts (using a common ID, e.g. CPE) and not duplicate any of the effort&lt;br /&gt;
* Do we want a special section dedicated to vulnerability information or do we want it broader?&lt;br /&gt;
* Discussion on the two proposals for external systems references&lt;br /&gt;
** General need for referencing external systems&lt;br /&gt;
** Proposal that there should be one solution&lt;br /&gt;
** Concern that the CPE/SWID is different from the repositories and should be a different schema&lt;br /&gt;
* Discussion on tag/value and RDF representations&lt;br /&gt;
** For tag/value - need to be a single string for the package reference&lt;br /&gt;
** RDF can either be a single string reference or could be a more general class model&lt;br /&gt;
*** Gary to propose a follow-up after doing some research&lt;br /&gt;
* Proposal for a table with the following columns:&lt;br /&gt;
** prefix&lt;br /&gt;
** URL for database or definition of the external reference&lt;br /&gt;
** Checkbox if the syntax is validated by the SPDX&lt;br /&gt;
** ABNF format if syntax is to be validated&lt;br /&gt;
** Domain - could be checkboxes for each domain covered (e.g. security, asset management)&lt;br /&gt;
* Is this at the item level or at the package level?&lt;br /&gt;
** Other than hardware, all of the external references reference something we would describe as a package in SPDX terms&lt;br /&gt;
** There is an issue when we have a binary file which represents a package and that package is described by an SPDX document - we would like to have a way to reference the external package without requiring the full SPDX package information (which may not be available)&lt;br /&gt;
** There is a proposal for external package references in bugzilla (bug 1298 https://bugs.linuxfoundation.org/show_bug.cgi?id=1298)&lt;br /&gt;
** Agree to decide package or item level after the external package reference proposal is discussed next week&lt;br /&gt;
[[Category:Technical|Minutes]]&lt;br /&gt;
[[Category:Minutes]]&lt;/div&gt;</summary>
		<author><name>Goneall</name></author>	</entry>

	</feed>