<?xml version="1.0"?>
<?xml-stylesheet type="text/css" href="https://wiki.spdx.org/skins/common/feed.css?303"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.spdx.org/index.php?action=history&amp;feed=atom&amp;title=Technical_Team%2FMinutes%2F2018-12-4</id>
		<title>Technical Team/Minutes/2018-12-4 - Revision history</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.spdx.org/index.php?action=history&amp;feed=atom&amp;title=Technical_Team%2FMinutes%2F2018-12-4"/>
		<link rel="alternate" type="text/html" href="https://wiki.spdx.org/index.php?title=Technical_Team/Minutes/2018-12-4&amp;action=history"/>
		<updated>2026-05-07T12:25:48Z</updated>
		<subtitle>Revision history for this page on the wiki</subtitle>
		<generator>MediaWiki 1.23.13</generator>

	<entry>
		<id>https://wiki.spdx.org/index.php?title=Technical_Team/Minutes/2018-12-4&amp;diff=4648&amp;oldid=prev</id>
		<title>Goneall: Created page with &quot;December 4, 2018 == Attendees == * Gary O'Neall * James Neushul * Alexios Zavras  ==SPDX Model Updates for SEVA fields== * Discussed the vulnerability relationship to SpdxItem...&quot;</title>
		<link rel="alternate" type="text/html" href="https://wiki.spdx.org/index.php?title=Technical_Team/Minutes/2018-12-4&amp;diff=4648&amp;oldid=prev"/>
				<updated>2018-12-05T18:38:03Z</updated>
		
		<summary type="html">&lt;p&gt;Created page with &amp;quot;December 4, 2018 == Attendees == * Gary O&amp;#039;Neall * James Neushul * Alexios Zavras  ==SPDX Model Updates for SEVA fields== * Discussed the vulnerability relationship to SpdxItem...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;December 4, 2018&lt;br /&gt;
== Attendees ==&lt;br /&gt;
* Gary O'Neall&lt;br /&gt;
* James Neushul&lt;br /&gt;
* Alexios Zavras&lt;br /&gt;
&lt;br /&gt;
==SPDX Model Updates for SEVA fields==&lt;br /&gt;
* Discussed the vulnerability relationship to SpdxItem, Package, and File&lt;br /&gt;
** Most vulnerabilities will be associated with package&lt;br /&gt;
*** NIST NVD’s can only be associated with packages&lt;br /&gt;
** There are some scanners that will associate vulnerabilities with files&lt;br /&gt;
** Agreed that we should associate the vulnerability to Item so that it can apply to both Package and File&lt;br /&gt;
** vulnerability information is optional (0 to many)&lt;br /&gt;
&lt;br /&gt;
==SEVA Vulnerability inclusion in SPDX==&lt;br /&gt;
* Most of the information is based on the NIST NVD definitions&lt;br /&gt;
** Modeled after the definition documentation&lt;br /&gt;
** A schema for the NVD which includes all of the details (e.g. scoring) does not exist (or at least we could not find one)&lt;br /&gt;
** Names do not match the NVD names to support distinguishing an official NVD schema if one to be found or produced&lt;br /&gt;
* Reviewed the SPDX-SECURITY schema at https://spdx-ccm.specchain.org/xsdccm/home&lt;br /&gt;
* There is also an SPDX-SEC-ISM schema which includes classification information (ISM)&lt;br /&gt;
** We agreed that the ISM information would be valuable to commercial use, but can be a separate decision from the vulnerability information&lt;br /&gt;
* Discussed whether we should include all of the detail present in the SEVA document in the SPDX document or should we somehow reference an external document&lt;br /&gt;
** There are a large number of fields to be reviewed&lt;br /&gt;
** We are not vulnerability experts, and may not have the background to decide on a model and tools of our own&lt;br /&gt;
** Agreed we should reference an external document&lt;br /&gt;
* We agreed that the vulnerability information should be included&lt;br /&gt;
* We discussed having a “proposal” or “working draft” similar to the W3C for the external document&lt;br /&gt;
&lt;br /&gt;
==Next Steps in Vulnerability inclusion in SPDX==&lt;br /&gt;
* Gain a larger consensus on referencing an external document for vulnerabilities&lt;br /&gt;
* Draft the external document reference language&lt;br /&gt;
* Discuss / agree on the external reference content&lt;br /&gt;
&lt;br /&gt;
==Documentation for SPDX including SEVA==&lt;br /&gt;
* James provided a document&lt;br /&gt;
* Produced from the XML document&lt;br /&gt;
* Extension to allow security classifications for each element (e.g. confidential)&lt;br /&gt;
** Uses ISM schema&lt;br /&gt;
* Discussion on approach&lt;br /&gt;
** Document in sections vs get experience with proposed sections prior to specifying&lt;br /&gt;
** Document in sections first is the traditional approach for SPDX, may have “culture shock” switching to a more prototyping approach&lt;br /&gt;
** Danger in specifying first – may create implementation challenges and may create specs that are not widely used&lt;br /&gt;
* Discussion on scope and prioritization&lt;br /&gt;
** Large scope – many new sections and properties&lt;br /&gt;
** Suggestion to prioritize by importance and ease of standardization&lt;br /&gt;
* Discussion on the modeling&lt;br /&gt;
** Agreed modeling will be helpful&lt;br /&gt;
* Plan going forward:&lt;br /&gt;
** Next week Mathew will review some of the new sections/areas being proposed and help prioritize which areas would be most useful&lt;br /&gt;
** Next week’s call will focus on the use cases / prioritization&lt;br /&gt;
** In 2 weeks, Gary will propose an update to the model which will include the higher priority areas/sections&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Technical|Minutes]]&lt;br /&gt;
[[Category:Minutes]]&lt;/div&gt;</summary>
		<author><name>Goneall</name></author>	</entry>

	</feed>