<?xml version="1.0"?>
<?xml-stylesheet type="text/css" href="https://wiki.spdx.org/skins/common/feed.css?303"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.spdx.org/index.php?action=history&amp;feed=atom&amp;title=Technical_Team%2FMinutes%2F2020-05-26</id>
		<title>Technical Team/Minutes/2020-05-26 - Revision history</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.spdx.org/index.php?action=history&amp;feed=atom&amp;title=Technical_Team%2FMinutes%2F2020-05-26"/>
		<link rel="alternate" type="text/html" href="https://wiki.spdx.org/index.php?title=Technical_Team/Minutes/2020-05-26&amp;action=history"/>
		<updated>2026-05-07T12:33:16Z</updated>
		<subtitle>Revision history for this page on the wiki</subtitle>
		<generator>MediaWiki 1.23.13</generator>

	<entry>
		<id>https://wiki.spdx.org/index.php?title=Technical_Team/Minutes/2020-05-26&amp;diff=4834&amp;oldid=prev</id>
		<title>Swinslow: posted minutes for Gary</title>
		<link rel="alternate" type="text/html" href="https://wiki.spdx.org/index.php?title=Technical_Team/Minutes/2020-05-26&amp;diff=4834&amp;oldid=prev"/>
				<updated>2020-05-28T13:28:33Z</updated>
		
		<summary type="html">&lt;p&gt;posted minutes for Gary&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;May 26, 2020&lt;br /&gt;
== Attendees ==&lt;br /&gt;
* Rex Jaeschke&lt;br /&gt;
* Kate Stewart&lt;br /&gt;
* William Bartholomew&lt;br /&gt;
* Gary O’Neall&lt;br /&gt;
* Nisha Kumar&lt;br /&gt;
* Steve Winslow&lt;br /&gt;
* John Mudge&lt;br /&gt;
* Takashi Ninjouji&lt;br /&gt;
* Peter Shin&lt;br /&gt;
* Rose Judge&lt;br /&gt;
* Thomas Steenbergen&lt;br /&gt;
* Jim Hutchison&lt;br /&gt;
* GogginsS&lt;br /&gt;
* Santiago Torres&lt;br /&gt;
* Vicky Brasseur&lt;br /&gt;
* Rishabh Bhatnagar&lt;br /&gt;
&lt;br /&gt;
Topics:&lt;br /&gt;
&lt;br /&gt;
Document namespaces and download URL’s using PUURL – issue https://github.com/spdx/spdx-spec/issues/372&lt;br /&gt;
&lt;br /&gt;
==SPDX 2.2==&lt;br /&gt;
&lt;br /&gt;
==SPDX 2.2.1==&lt;br /&gt;
* Update from Rex&lt;br /&gt;
** Steady progress&lt;br /&gt;
** a few issues still open&lt;br /&gt;
** John updating template so that there is no requirement for formatting&lt;br /&gt;
* Discussion on proposal to add footnotes for XML&lt;br /&gt;
** Agreed to remove the tables for the examples rather than go to footnotes&lt;br /&gt;
** Still an issue with conciseness of the examples&lt;br /&gt;
** Agree to keep the metadata as tables&lt;br /&gt;
&lt;br /&gt;
==GSoC==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==SPDX 3.0 Security Profile==&lt;br /&gt;
* Thomas provided an overview of the proposal: https://docs.google.com/document/d/1GyUMEcv4G8ZUGbXB8T_-pkDFxYUAbP0W0Tuts2cpZiw/edit#heading=h.szfwkkflaxx2&lt;br /&gt;
* Proposal to focus scope on Vulnerability information&lt;br /&gt;
** Create separate proposals for Virus information and other areas of security&lt;br /&gt;
** William and Gary agreed with proposal, no objections&lt;br /&gt;
* Do we need a data provider identity?&lt;br /&gt;
** Tradeoff of complexity vs additional data&lt;br /&gt;
** having a data provider may be useful for other profiles&lt;br /&gt;
** useful at the vulnerability level&lt;br /&gt;
** potentially useful at the document level&lt;br /&gt;
** need an identity object &lt;br /&gt;
** can be a field for vulnerability&lt;br /&gt;
** can also be used as in a relationship&lt;br /&gt;
* Do we want to include a remediation field?&lt;br /&gt;
** Proposal to include a “first patched version” field&lt;br /&gt;
** Proposal to use the description field to capture the remediation suggestion&lt;br /&gt;
** Steve suggested we stick to the facts – similar to legal profile&lt;br /&gt;
** Consensus to not include a remediation field (other than the first patched version field which will be included)&lt;br /&gt;
* Discussion on filtering&lt;br /&gt;
* Do we want to include any formatting for the description (e.g. HTML)?&lt;br /&gt;
* Identifier Aliasing&lt;br /&gt;
** Agreed to use ExternalRef approach under the security category&lt;br /&gt;
* What do we do with packages that don’t maintain standard version&lt;br /&gt;
** The fields that refer to version is a string – added many possible format&lt;br /&gt;
* Aligning with CycloneDX&lt;br /&gt;
** Agreed that we want to have common terms etc.&lt;br /&gt;
** Briefly reviewed differences&lt;br /&gt;
*** ExternalRef is on area of difference&lt;br /&gt;
*** Description vs. summary is another area&lt;br /&gt;
**** Suggestion to change SPDX to use description for the summary and details &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Next Week’s Agenda==&lt;br /&gt;
* How do we specify the profiles in use for 3.0&lt;br /&gt;
* Legal update – suggest this would be a joint legal/tech call&lt;br /&gt;
&lt;br /&gt;
 [[Category:Technical|Minutes]]&lt;/div&gt;</summary>
		<author><name>Swinslow</name></author>	</entry>

	</feed>