<?xml version="1.0"?>
<?xml-stylesheet type="text/css" href="https://wiki.spdx.org/skins/common/feed.css?303"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.spdx.org/index.php?action=history&amp;feed=atom&amp;title=Technical_Team%2FMinutes%2F2020-08-25</id>
		<title>Technical Team/Minutes/2020-08-25 - Revision history</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.spdx.org/index.php?action=history&amp;feed=atom&amp;title=Technical_Team%2FMinutes%2F2020-08-25"/>
		<link rel="alternate" type="text/html" href="https://wiki.spdx.org/index.php?title=Technical_Team/Minutes/2020-08-25&amp;action=history"/>
		<updated>2026-05-07T15:37:10Z</updated>
		<subtitle>Revision history for this page on the wiki</subtitle>
		<generator>MediaWiki 1.23.13</generator>

	<entry>
		<id>https://wiki.spdx.org/index.php?title=Technical_Team/Minutes/2020-08-25&amp;diff=4872&amp;oldid=prev</id>
		<title>Goneall: Created page with &quot;August 25, 2020 == Attendees == * Kate Stewart * Thomas Steenbergen	 * Nisha Kumar * Gary O’Neall * Peter Shin * William Bartholomew * Jim Hutchison * Philippe Ombredanne  T...&quot;</title>
		<link rel="alternate" type="text/html" href="https://wiki.spdx.org/index.php?title=Technical_Team/Minutes/2020-08-25&amp;diff=4872&amp;oldid=prev"/>
				<updated>2020-08-25T18:04:44Z</updated>
		
		<summary type="html">&lt;p&gt;Created page with &amp;quot;August 25, 2020 == Attendees == * Kate Stewart * Thomas Steenbergen	 * Nisha Kumar * Gary O’Neall * Peter Shin * William Bartholomew * Jim Hutchison * Philippe Ombredanne  T...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;August 25, 2020&lt;br /&gt;
== Attendees ==&lt;br /&gt;
* Kate Stewart&lt;br /&gt;
* Thomas Steenbergen	&lt;br /&gt;
* Nisha Kumar&lt;br /&gt;
* Gary O’Neall&lt;br /&gt;
* Peter Shin&lt;br /&gt;
* William Bartholomew&lt;br /&gt;
* Jim Hutchison&lt;br /&gt;
* Philippe Ombredanne&lt;br /&gt;
&lt;br /&gt;
Topics:&lt;br /&gt;
* Vulnerability Profiles&lt;br /&gt;
* Identity&lt;br /&gt;
* OpenChain Licensing group update – SPDX 3.0&lt;br /&gt;
&lt;br /&gt;
==Call with OpenChain Automotive Workgroup==&lt;br /&gt;
* Thomas attended a meeting with the OpenChain Automotive Workgroup&lt;br /&gt;
* Led my Endo-san&lt;br /&gt;
* Proposal to create an automotive profile&lt;br /&gt;
* Created a PR: PR #468 https://github.com/spdx/spdx-spec/pull/468&lt;br /&gt;
* Several updates are in progress for the PR&lt;br /&gt;
* Several enhancements to 3.0 requested&lt;br /&gt;
** Need a product entity&lt;br /&gt;
** Need a condition entity&lt;br /&gt;
** Need defects&lt;br /&gt;
*** Defects go against conditions&lt;br /&gt;
** Which product is involved&lt;br /&gt;
** Where in the lifecycle (e.g. prototype)&lt;br /&gt;
* Questions on scope&lt;br /&gt;
** Initial proposal would use SPDX for specifications communications back to supplier&lt;br /&gt;
** Should that be in scope for SPDX?&lt;br /&gt;
* Discussion on defects&lt;br /&gt;
** Should we expand vulnerabilities to include functional defects, others?&lt;br /&gt;
** Thomas suggested vulnerabilities are very similar to other types of defects&lt;br /&gt;
** Relationship to patches&lt;br /&gt;
* Desire to communicate document expiration or other way to include the concept of time&lt;br /&gt;
** Should we have a time profile?&lt;br /&gt;
** Stating a future expectation like “I will release a new version on xxx” may violate the principle of stating facts&lt;br /&gt;
** would like to avoid modeling contractual relationship&lt;br /&gt;
* Audience – who is the intended recipient?&lt;br /&gt;
** Example OEM supplier may document information which is not intended to be communicated to end users&lt;br /&gt;
** Steve suggested that the process used for communicating documents may provide the mechanism for what is communicated to whom&lt;br /&gt;
&lt;br /&gt;
==Identity==&lt;br /&gt;
* Came out of the 3T SBOM comparison to SPDX&lt;br /&gt;
* Current SPDX identity is a structured string (e.g. PERSON: (email))&lt;br /&gt;
* Proposal to structure this as a separate class in SPDX 3.0 using person, organization and tool as subclasses&lt;br /&gt;
** name and email would be properties&lt;br /&gt;
** There may have been an identity type in the linking profile&lt;br /&gt;
*** Nisha will check with Santiago&lt;br /&gt;
* Nisha asked if there was a process to propose promoting a field from a profile to the base profile&lt;br /&gt;
** Those proposals can be raised in the SPDX tech meeting&lt;br /&gt;
** Wait until we see commonalities between profiles before promoting&lt;br /&gt;
** This could be used for identity properties used in linking profile and perhaps vulnerabilities&lt;br /&gt;
* No concerns about adding structure to the identity&lt;br /&gt;
&lt;br /&gt;
==Vulnerability Profiles==&lt;br /&gt;
* 3T SBOM put vulnerabilities in the defects&lt;br /&gt;
* Thomas presented the 3T defects spec&lt;br /&gt;
** Similar structure to SPDX&lt;br /&gt;
** Additional relationships&lt;br /&gt;
* Proposal to use defects rather than vulnerabilities&lt;br /&gt;
* Question on having defect types or subclasses&lt;br /&gt;
* Could use different profiles for security defects vs. other types of defects&lt;br /&gt;
* DefectRepsonse&lt;br /&gt;
** Not necessarily a fact like a defect is a fact&lt;br /&gt;
** Should have a relationship to defect&lt;br /&gt;
** Examples – isAffectedBy – this would be a relationship and more fact based&lt;br /&gt;
* Should state SPDX 3.0 design principles&lt;br /&gt;
** Could start with the spec statements about scope for SPDX 2.2&lt;br /&gt;
* Should Vulnerabilities be their own element or a “type” of defect?&lt;br /&gt;
* Source – specify the source&lt;br /&gt;
** Rating is likely related to the source&lt;br /&gt;
** Suggestion to move the rating to the source&lt;br /&gt;
** Score may change over time&lt;br /&gt;
** Vulnerability creation time may be different than document creating time&lt;br /&gt;
** From Peter: CVSS has an equation under the hood - Weight_for_base * base + weight_for_impact * impact + ….&lt;br /&gt;
* Dependency Tree Profile proposal&lt;br /&gt;
&lt;br /&gt;
==Next Week==&lt;br /&gt;
* SPDX 3.0 design principles (e.g. facts based, scope related)&lt;br /&gt;
* Dependency Tree Profile proposal – or template&lt;br /&gt;
&lt;br /&gt;
 [[Category:Technical|Minutes]]&lt;/div&gt;</summary>
		<author><name>Goneall</name></author>	</entry>

	</feed>