<?xml version="1.0"?>
<?xml-stylesheet type="text/css" href="https://wiki.spdx.org/skins/common/feed.css?303"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.spdx.org/index.php?action=history&amp;feed=atom&amp;title=Technical_Team%2FMinutes%2F2020-08-18</id>
		<title>Technical Team/Minutes/2020-08-18 - Revision history</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.spdx.org/index.php?action=history&amp;feed=atom&amp;title=Technical_Team%2FMinutes%2F2020-08-18"/>
		<link rel="alternate" type="text/html" href="https://wiki.spdx.org/index.php?title=Technical_Team/Minutes/2020-08-18&amp;action=history"/>
		<updated>2026-05-07T15:36:54Z</updated>
		<subtitle>Revision history for this page on the wiki</subtitle>
		<generator>MediaWiki 1.23.13</generator>

	<entry>
		<id>https://wiki.spdx.org/index.php?title=Technical_Team/Minutes/2020-08-18&amp;diff=4871&amp;oldid=prev</id>
		<title>Goneall: Created page with &quot;August 18, 2020 == Attendees == * Kate Stewart * Thomas Steenbergen	 * John Horan * Gary O’Neall * Peter Shin * Philippe Ombredanne  Topics: * Google Summer of Code * Legal...&quot;</title>
		<link rel="alternate" type="text/html" href="https://wiki.spdx.org/index.php?title=Technical_Team/Minutes/2020-08-18&amp;diff=4871&amp;oldid=prev"/>
				<updated>2020-08-18T18:06:21Z</updated>
		
		<summary type="html">&lt;p&gt;Created page with &amp;quot;August 18, 2020 == Attendees == * Kate Stewart * Thomas Steenbergen	 * John Horan * Gary O’Neall * Peter Shin * Philippe Ombredanne  Topics: * Google Summer of Code * Legal...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;August 18, 2020&lt;br /&gt;
== Attendees ==&lt;br /&gt;
* Kate Stewart&lt;br /&gt;
* Thomas Steenbergen	&lt;br /&gt;
* John Horan&lt;br /&gt;
* Gary O’Neall&lt;br /&gt;
* Peter Shin&lt;br /&gt;
* Philippe Ombredanne&lt;br /&gt;
&lt;br /&gt;
Topics:&lt;br /&gt;
* Google Summer of Code&lt;br /&gt;
* Legal profile – continuing discussion&lt;br /&gt;
* Gitlab support of SPDX&lt;br /&gt;
&lt;br /&gt;
==GSoC==&lt;br /&gt;
* Philip’s project should be able to present next General meeting – Kate will arrange&lt;br /&gt;
* Philippe will meet with Philip and check on progress&lt;br /&gt;
&lt;br /&gt;
==Legal Profile==&lt;br /&gt;
* Communicating between tools&lt;br /&gt;
** Example: How well was the match to the license – would be helpful for a tool to tool relationship&lt;br /&gt;
** Issue – loss of information detail&lt;br /&gt;
** Snippets don’t really work – will capture the line range, but isn’t always correct&lt;br /&gt;
** Should it be simplified or include a lot of detail?&lt;br /&gt;
** Thomas: I found this license in this file at this line number&lt;br /&gt;
** Would like to communicate scanning results from Scancode to SW360&lt;br /&gt;
** Would help with audits and detecting errors/bugs&lt;br /&gt;
** All on the call it would be useful&lt;br /&gt;
** Kate created a Google doc to track the license scanning tooling profile: https://docs.google.com/document/d/1p24qf2uNk5b1rU0m_Tvj2cD-lioFaaeJKh9PmnPbhwo/edit&lt;br /&gt;
** Kate also added a dependency tree profiles: https://docs.google.com/document/d/1IfcSlrDou-8KLqkLr568DKGaQiHXmt_EFsZRfcf0Ej8/edit&lt;br /&gt;
** Kate also created a Google doc for the vulnerabilities profile: https://docs.google.com/document/d/11S8FTG5zSwmH-o_Conp9-mkzWyOuxC_KXx3VNHlhbws/edit&lt;br /&gt;
** Will also create an issue&lt;br /&gt;
* Question on how to represent a source file:  I have a question on how to handle declared license.  If it's a short reference to a license, for example, how should SPDX or tool handle &amp;quot;See the license file&amp;quot; snippet.  Should the SPDX handle it as a declared and none?&lt;br /&gt;
** Thomas, Gary and Philippe think it would be declared, but the discussion in legal was interpreted as “None” or “LicenseRef-“ with the text found in the file&lt;br /&gt;
* Discussion on having a primary license for a package&lt;br /&gt;
** Philippe will propose an extension to the license expression&lt;br /&gt;
** Introduce “PLUS” operator with the same semantics as AND except the expression to the left of the operator is the primary license for the package&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Gitlab==&lt;br /&gt;
* Gitlab jobs do not support SPDX&lt;br /&gt;
* Issue logged at https://gitlab.com/gitlab-org/gitlab/-/issues/218521&lt;br /&gt;
* Thomas requested support and comments on the issue in support of SPDX&lt;br /&gt;
* Steve is active with Gitlab and should be able to help&lt;br /&gt;
* Kate will add some pointers in the issue&lt;br /&gt;
&lt;br /&gt;
==DCO signoff on SPDX Spec==&lt;br /&gt;
* Currently not enabled for the spec&lt;br /&gt;
* Agreed we will enable the DCO BOT&lt;br /&gt;
* Will be turn on Sept. 1&lt;br /&gt;
* Kate will send out an email&lt;br /&gt;
* Thomas will submit a PR&lt;br /&gt;
&lt;br /&gt;
==Next Week==&lt;br /&gt;
* Vulnerabilities Profile&lt;br /&gt;
&lt;br /&gt;
 [[Category:Technical|Minutes]]&lt;/div&gt;</summary>
		<author><name>Goneall</name></author>	</entry>

	</feed>