@malwarejake replying only to add some hopefully relevant hashtags that capture more eyeballs: #SBOM #SPDX #CycloneDX
If you never did a Linux contribution, there's a cool #fedora #hackfest happening on the 26 of April. The hackfest will be conducted by #fedoralegal.
It's a great occasion to start understanding how contributions and licenses work. The Hackfest will focus on migrating licenses to the standardized SPDX format.
If you are shy, please don't be. We are always glad to help.
Any questions?
#fedora #hackfest #fedoralegal #fedoradevel #spdx #linux #freesoftware
Folks from Fedora and Red Hat have been working together on SPDX - "an open standard for communicating software bill of material information." Here's their presentation to the Fedora Council!
https://www.youtube.com/watch?v=be0jfUCZM1M
This is important to Fedora because of our commitment to shipping only FOSS out of the box, but it also has implications in the enterprise. Good stuff!
#Fedora #OpenSource #SPDX
New Export SBOM capability allows SBOM generation with one click on @GitHub https://www.fosslife.org/generate-sboms-one-click-github #SBOM #SPDX #security #SoftwareSupplyChain #tools
#SBOM #spdx #security #softwaresupplychain #tools
So apparently the `+` #SPDX license expression syntax is "deprecated" except it isn't deprecated in the spec, so new projects are using it. Ofc their uses are absolutely meaningless but they're permitted to, so…
https://github.com/nexB/license-expression/issues/9#issuecomment-1493462932
SBOM Everywhere Update and Python SPDX-Tools https://openssf.org/blog/2023/03/27/sbom-everywhere-update-and-python-spdx-tools/ #SBOM #SPDX #Python #OSS #OpenSource #OSSsecurity
#sbom #spdx #python #oss #opensource #osssecurity
SBOM Everywhere Update and Python SPDX-Tools https://twitter.com/theopenssf/status/1640470630511304707 #SBOM #SPDX #Python #OSS #OpenSource #OSSsecurity
#sbom #spdx #python #oss #opensource #osssecurity
🐣🗃️🔍 Interlynk is closing out the week with a little gift of #sbomex - Interlynk's #SBOM Explorer - for the SBOM curious.
The CLI-tool helps search and pull Interlynk's public SBOM repository of thousands and increasing #SPDX #CycloneDX SBOMs.
#sbomex #SBOM #spdx #CycloneDX
Did you copy and paste the GPLv2? Which variation did you copy? 40+ variations exist on http://fsf.org alone. This is another key reason to use #SPDX Short Identifiers.
Why you should use #SPDX for #security https://www.linux.com/featured/why-you-should-use-spdx-for-security/ #opensource
For folks who are interested in the #SPDX discussion about adding identifiers for the Open RAIL-M licenses, it's here.
This is really cool – finally a public collaboratively maintained repo of #SPDX documents about #FOSS components. If it takes off and people actually contribute to it too, this could make FOSS license compliance much easier.
Sharing is caring, and reusing is a must :)
#spdx #foss #licensecompliance
Come share knowledge among #OSPO's at the two day #OSPOlogy Live 🇳🇱 #event 23-24 January in Amsterdam. Focus on Program and signup at https://community.linuxfoundation.org/events/details/lfhq-ospology-european-chapter-presents-ospologylive-share-learn-netherlands/ #OpenSource event hosted at #Alliander and co-organized with #TODOGroup, #LFEnergy, #OpenChain, #SPDX, #CHAOSS #InnersourceCommons and #OpenSSF.
#OpenSSF #innersourcecommons #chaoss #spdx #openchain #lfenergy #todogroup #alliander #opensource #event #ospology #ospo
RFC: Using standard SPDX license expressions in PKGBUILDs
https://gitlab.archlinux.org/archlinux/rfcs/-/merge_requests/16
#archlinux #linux #spdx #licensing