<?xml version="1.0"?>
<?xml-stylesheet type="text/css" href="https://wiki.spdx.org/skins/common/feed.css?303"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.spdx.org/index.php?action=history&amp;feed=atom&amp;title=Technical_Team%2FMinutes%2F2017-01-31</id>
		<title>Technical Team/Minutes/2017-01-31 - Revision history</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.spdx.org/index.php?action=history&amp;feed=atom&amp;title=Technical_Team%2FMinutes%2F2017-01-31"/>
		<link rel="alternate" type="text/html" href="https://wiki.spdx.org/index.php?title=Technical_Team/Minutes/2017-01-31&amp;action=history"/>
		<updated>2026-05-07T13:17:18Z</updated>
		<subtitle>Revision history for this page on the wiki</subtitle>
		<generator>MediaWiki 1.23.13</generator>

	<entry>
		<id>https://wiki.spdx.org/index.php?title=Technical_Team/Minutes/2017-01-31&amp;diff=4109&amp;oldid=prev</id>
		<title>Goneall: /* Questions and Clarifications from Thomas */</title>
		<link rel="alternate" type="text/html" href="https://wiki.spdx.org/index.php?title=Technical_Team/Minutes/2017-01-31&amp;diff=4109&amp;oldid=prev"/>
				<updated>2017-01-31T21:11:14Z</updated>
		
		<summary type="html">&lt;p&gt;‎&lt;span dir=&quot;auto&quot;&gt;&lt;span class=&quot;autocomment&quot;&gt;Questions and Clarifications from Thomas&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;table class='diff diff-contentalign-left'&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;tr style='vertical-align: top;'&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;Revision as of 21:11, 31 January 2017&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 88:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 88:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;{ GPL-2.0 full license text}&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;{ GPL-2.0 full license text}&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;…&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;…&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;/text&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;/text&amp;gt;LicenseComments: &amp;lt;text&amp;gt;BSD-3-Clause lines 250 – 350, GPL-2.0 line 942 - 980&amp;lt;/text&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;#160; &amp;#160; &amp;#160; &amp;#160; &amp;#160; &amp;#160; &amp;#160; &lt;/del&gt;LicenseComments: &amp;lt;text&amp;gt;BSD-3-Clause lines 250 – 350, GPL-2.0 line 942 - 980&amp;lt;/text&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;3.&amp;#160; &amp;#160; &amp;#160; @Yev Introduce a new relationship within SPDX so we can capture this in a relation between SPDX-File and SPDX-Package&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;3.&amp;#160; &amp;#160; &amp;#160; @Yev Introduce a new relationship within SPDX so we can capture this in a relation between SPDX-File and SPDX-Package&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Goneall</name></author>	</entry>

	<entry>
		<id>https://wiki.spdx.org/index.php?title=Technical_Team/Minutes/2017-01-31&amp;diff=4108&amp;oldid=prev</id>
		<title>Goneall: Created page with &quot;Jan. 31, 2017 == Attendees == * Gary O’Neall * Yev Bronshteyn * Bill Schineller * Jack Manbeck * Thomas Steenbergen  ==Topics== * SPDX Tools Jena version upgrade * Google Su...&quot;</title>
		<link rel="alternate" type="text/html" href="https://wiki.spdx.org/index.php?title=Technical_Team/Minutes/2017-01-31&amp;diff=4108&amp;oldid=prev"/>
				<updated>2017-01-31T21:10:14Z</updated>
		
		<summary type="html">&lt;p&gt;Created page with &amp;quot;Jan. 31, 2017 == Attendees == * Gary O’Neall * Yev Bronshteyn * Bill Schineller * Jack Manbeck * Thomas Steenbergen  ==Topics== * SPDX Tools Jena version upgrade * Google Su...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;Jan. 31, 2017&lt;br /&gt;
== Attendees ==&lt;br /&gt;
* Gary O’Neall&lt;br /&gt;
* Yev Bronshteyn&lt;br /&gt;
* Bill Schineller&lt;br /&gt;
* Jack Manbeck&lt;br /&gt;
* Thomas Steenbergen&lt;br /&gt;
&lt;br /&gt;
==Topics==&lt;br /&gt;
* SPDX Tools Jena version upgrade&lt;br /&gt;
* Google Summer of Code&lt;br /&gt;
* Questions from Thomas on SPDX Spec and implementation&lt;br /&gt;
==SPDX Tools Jena version upgrade==&lt;br /&gt;
* Yev submitted a pull request which upgrades the Jena version&lt;br /&gt;
* The upgrade has a dependency on Java 8&lt;br /&gt;
* Agreed to create a branch “Java6Support” prior to merging the pull request&lt;br /&gt;
* Gary to create the branch&lt;br /&gt;
* Yev will merge in the branch after verifying the Java version in the POM file&lt;br /&gt;
==Google Summer of Code==&lt;br /&gt;
* Applications need to be in by Jan. 9&lt;br /&gt;
* Submittal is nearly ready (just need to upload the logo)&lt;br /&gt;
* Need a second administrator&lt;br /&gt;
** Waiting for a response from Philippe&lt;br /&gt;
** Jack agreed to co-sponsor if we don’t hear back by Thursday&lt;br /&gt;
* Discussed project ideas&lt;br /&gt;
** Leverage ideas from last year at http://wiki.spdx.org/view/Technical_Team/Ideas_List&lt;br /&gt;
** Some of the same library migrations apply&lt;br /&gt;
** Should add Git integration, but the project may need to be broken up into sub-projects.  We’ll have a meeting on the topic at the leadership summit&lt;br /&gt;
** We should add online tools as a project idea (Gary)&lt;br /&gt;
** Jack suggested an attribution document generator tool (Gary will add)&lt;br /&gt;
** Build integration projects such as Gradle (could leverage the Maven integration)&lt;br /&gt;
** Thomas had some build and package manager related projects that may be appropriate for GSoC (Thomas will follow up and add to the project list wiki)&lt;br /&gt;
==Questions and Clarifications from Thomas==&lt;br /&gt;
Q1: I am correct to say “#” is the comment statement in tag-value format and I use it after a tag statement&lt;br /&gt;
&lt;br /&gt;
It is invalid is to put a comment statement in SPDX tag-value behind value. It has to be on a separate line. &lt;br /&gt;
&lt;br /&gt;
Example:&lt;br /&gt;
&lt;br /&gt;
LicenseConcluded: Apache-2.0 #INVALID&lt;br /&gt;
&lt;br /&gt;
#VALID&lt;br /&gt;
LicenseConcluded: Apache-2.0&lt;br /&gt;
&lt;br /&gt;
Q2: If a big source file has license texts at line 3, 400 and 600 do one put in in one FileNotice within SPDX-File or into multiple SPDX-Files?&lt;br /&gt;
&lt;br /&gt;
Combining all license text in a FileNotice within a SPDX-File is OK if it’s all of the different licensed code always below to the package. If the license statements come from code copied from other packages one should use SPDX-Snippet&lt;br /&gt;
&lt;br /&gt;
@HERE  we use “…” as delimiter to indicate multiple lines are present in the file between license texts&lt;br /&gt;
Example:&lt;br /&gt;
&lt;br /&gt;
FileNotice:&amp;lt;text&amp;gt;&lt;br /&gt;
&lt;br /&gt;
BSD-3-Clause full license text&lt;br /&gt;
&lt;br /&gt;
…&lt;br /&gt;
&lt;br /&gt;
Happy bunny full license text&lt;br /&gt;
&amp;lt;/text&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Q3: How would you encode within the SPDX-File’s FileNotice scanner line number findings?&lt;br /&gt;
&lt;br /&gt;
Example:&lt;br /&gt;
&lt;br /&gt;
FileNotice: &amp;lt;text&amp;gt; &lt;br /&gt;
{ BSD-3-Clause full license text} &amp;lt;=  line 250 – 350 &lt;br /&gt;
…&lt;br /&gt;
{GPL-2.0 full license text } &amp;lt;= line 942 - 980&lt;br /&gt;
&amp;lt;/text&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Solutions:&lt;br /&gt;
&lt;br /&gt;
1.      Use a comment statement&lt;br /&gt;
&lt;br /&gt;
# BSD-3-Clause lines 250 – 350, GPL-2.0 line 942 - 980&lt;br /&gt;
FileNotice: &amp;lt;text&amp;gt; &lt;br /&gt;
{ BSD-3-Clause full license text}&lt;br /&gt;
…&lt;br /&gt;
{ GPL-2.0 full license text}&lt;br /&gt;
…&lt;br /&gt;
&amp;lt;/text&amp;gt;&lt;br /&gt;
&lt;br /&gt;
2.      Use LicenseComments&lt;br /&gt;
&lt;br /&gt;
FileNotice: &amp;lt;text&amp;gt; &lt;br /&gt;
{ BSD-3-Clause full license text}&lt;br /&gt;
…&lt;br /&gt;
{ GPL-2.0 full license text}&lt;br /&gt;
…&lt;br /&gt;
&amp;lt;/text&amp;gt;&lt;br /&gt;
              LicenseComments: &amp;lt;text&amp;gt;BSD-3-Clause lines 250 – 350, GPL-2.0 line 942 - 980&amp;lt;/text&amp;gt;&lt;br /&gt;
3.      @Yev Introduce a new relationship within SPDX so we can capture this in a relation between SPDX-File and SPDX-Package&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Q4:  Which of the below statement is correct. I think B is correct per the spec. &lt;br /&gt;
&lt;br /&gt;
Answer: B is correct but commonly tools will support/implement A. This is a bug in the tooling.  @Thomas: Our experience is that most novice SPDX users think A is correct for simplicity reasons but form spec point of view B makes sense.&lt;br /&gt;
&lt;br /&gt;
A)&lt;br /&gt;
&lt;br /&gt;
LicenseConcluded: (LicenseRef-FSF-MIT AND GPL-2.0+ WITH Autoconf-exception-2.0)&lt;br /&gt;
LicenseInfoInFile: LicenseRef-FSF-MIT &lt;br /&gt;
LicenseInfoInFile: GPL-2.0+ WITH Autoconf-exception-2.0&lt;br /&gt;
&lt;br /&gt;
Or&lt;br /&gt;
&lt;br /&gt;
B)&lt;br /&gt;
&lt;br /&gt;
LicenseConcluded: (LicenseRef-FSF-MIT AND GPL-2.0+ WITH Autoconf-exception-2.0)&lt;br /&gt;
LicenseInfoInFile: LicenseRef-FSF-MIT &lt;br /&gt;
LicenseInfoInFile: GPL-2.0+&lt;br /&gt;
&lt;br /&gt;
Q5: Can one do custom license exceptions for LicenseRefs in SPDX? &lt;br /&gt;
&lt;br /&gt;
Answer: Use LicenseRef e.g. LicenseRef-MIT-WITH-Happy-Bunny&lt;br /&gt;
&lt;br /&gt;
Q6: What are your ideas on modeling package managers in SPDX?&lt;br /&gt;
The current way we do it is to create a SPDX-FILE on the pom.xml and then use ExternalDocumentRef and Relationship tags to link to separate SPDX files for each dependency. PackageLicenseConcluded are per package.&lt;br /&gt;
&lt;br /&gt;
Answer: @Gary: This is how I am currently doing it. @Thomas to provide some example for Wiki for various languages. Contact Jack Manbeck to get Wiki access.&lt;br /&gt;
&lt;br /&gt;
Q7:  Is it Ok to use “cvs” within PackageDownloadLocation? e.g. Is it Ok to extend &amp;lt;vcs_tool&amp;gt; with other version control systems other than the ones listed in  https://pip.pypa.io/en/latest/reference/pip_install.html#vcs-support?&lt;br /&gt;
&lt;br /&gt;
Answer: @Gary: Yes this is the correct way. We should look into adding cvs to the spec.   TODO: Follow-up with Bill&lt;br /&gt;
[[Category:Technical|Minutes]]&lt;br /&gt;
[[Category:Minutes]]&lt;/div&gt;</summary>
		<author><name>Goneall</name></author>	</entry>

	</feed>