<?xml version="1.0"?>
<?xml-stylesheet type="text/css" href="https://wiki.spdx.org/skins/common/feed.css?303"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.spdx.org/index.php?action=history&amp;feed=atom&amp;title=Technical_Team%2FMinutes%2F2020-09-08</id>
		<title>Technical Team/Minutes/2020-09-08 - Revision history</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.spdx.org/index.php?action=history&amp;feed=atom&amp;title=Technical_Team%2FMinutes%2F2020-09-08"/>
		<link rel="alternate" type="text/html" href="https://wiki.spdx.org/index.php?title=Technical_Team/Minutes/2020-09-08&amp;action=history"/>
		<updated>2026-05-07T12:20:32Z</updated>
		<subtitle>Revision history for this page on the wiki</subtitle>
		<generator>MediaWiki 1.23.13</generator>

	<entry>
		<id>https://wiki.spdx.org/index.php?title=Technical_Team/Minutes/2020-09-08&amp;diff=4875&amp;oldid=prev</id>
		<title>Goneall: Created page with &quot;September 8, 2020 == Attendees == * Thomas Steenbergen	 * Nisha Kumar * Gary O’Neall * David Kemp * William Bartholomew * Jim Hutchison * Steve Winslow  Topics: * How do we...&quot;</title>
		<link rel="alternate" type="text/html" href="https://wiki.spdx.org/index.php?title=Technical_Team/Minutes/2020-09-08&amp;diff=4875&amp;oldid=prev"/>
				<updated>2020-09-08T18:05:39Z</updated>
		
		<summary type="html">&lt;p&gt;Created page with &amp;quot;September 8, 2020 == Attendees == * Thomas Steenbergen	 * Nisha Kumar * Gary O’Neall * David Kemp * William Bartholomew * Jim Hutchison * Steve Winslow  Topics: * How do we...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;September 8, 2020&lt;br /&gt;
== Attendees ==&lt;br /&gt;
* Thomas Steenbergen	&lt;br /&gt;
* Nisha Kumar&lt;br /&gt;
* Gary O’Neall&lt;br /&gt;
* David Kemp&lt;br /&gt;
* William Bartholomew&lt;br /&gt;
* Jim Hutchison&lt;br /&gt;
* Steve Winslow&lt;br /&gt;
&lt;br /&gt;
Topics:&lt;br /&gt;
* How do we best proceed on documenting the different profiles&lt;br /&gt;
* Core 3T SBOM comparison&lt;br /&gt;
&lt;br /&gt;
== Core 3T SBOM comparison ==&lt;br /&gt;
* Comparison of Core 3T model to Core SPDX model&lt;br /&gt;
* Slides available at https://docs.google.com/presentation/d/1dvGeCAbOUSD5qFQ6mt1WsnBEZvatnonYpKGdAQCIWZg/edit#slide=id.g95424fd354_0_0 (NOTE: presentation starts a slide 8)&lt;br /&gt;
* Similar models&lt;br /&gt;
* Proposed changes to SPDX&lt;br /&gt;
** Identity – add structured email field, add structured tool information&lt;br /&gt;
* Relationship&lt;br /&gt;
** Subclass of element – adds ID&lt;br /&gt;
** add completeness enum&lt;br /&gt;
*** Should completeness be put in a separate profile?&lt;br /&gt;
*** General consensus on the call 95% of use cases will not use this so should be added as a profile&lt;br /&gt;
*** Agreed to defer the decision until Kate is on the call – Kate has been working with NTIA on this&lt;br /&gt;
*** David raised the point that completeness is an optional enumeration and may not complicate the model&lt;br /&gt;
*** Desire to simplify by reducing the number of field definitions&lt;br /&gt;
** Make the object independent of the 2 items being related&lt;br /&gt;
*  Package URL more fundamental – mandatory unique identifier&lt;br /&gt;
** Expanded the URL to be and ArtifactURL – superset of PackageURL which can include other types of artifacts including hardware etc.&lt;br /&gt;
** concern about representing non-public package distribution; PURL may not be mature enough for all use cases&lt;br /&gt;
*** add to the PURL or ArtifactURL if it is missing&lt;br /&gt;
*** Software heritage approach could be another alternative – less human readable&lt;br /&gt;
*** Could we use the SPDX reference ID as a package URL&lt;br /&gt;
* Additional HASH algorithms&lt;br /&gt;
* Suggestion to create examples for various scenarios (e.g. here’s the source repository a binary artifact was built from)&lt;br /&gt;
* Suggest that we also have “bad examples”&lt;br /&gt;
* Nisha created a mock-up for a container as part of defining the linking profile&lt;br /&gt;
** Describing the relationships between layers, manifests can be complicated&lt;br /&gt;
** Difficulty in representing URL for container metadata&lt;br /&gt;
** Dynamic systems that re-generate the artifacts&lt;br /&gt;
** Proposal that the SBOM travel with the artifacts in the distributed systems&lt;br /&gt;
&lt;br /&gt;
==How to document different profiles==&lt;br /&gt;
* ran out of time for this topic – moved to next week&lt;br /&gt;
&lt;br /&gt;
==Next Week==&lt;br /&gt;
* Linkage profile update&lt;br /&gt;
* Nisha to present challenges with adapting to the container / container registry work&lt;br /&gt;
* How to document different profiles&lt;br /&gt;
&lt;br /&gt;
 [[Category:Technical|Minutes]]&lt;/div&gt;</summary>
		<author><name>Goneall</name></author>	</entry>

	</feed>