-
-
Notifications
You must be signed in to change notification settings - Fork 587
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Remove support for SPDX #1053
Labels
p2
Non-critical bugs, and features that help organizations to identify and reduce risk
pending release
technical debt
Milestone
Comments
stevespringett
added
technical debt
p2
Non-critical bugs, and features that help organizations to identify and reduce risk
labels
May 25, 2021
Clarification. This only applies to SPDX SBOMs, not SPDX license IDs or expressions. |
stevespringett
added a commit
that referenced
this issue
May 29, 2021
…egacy SPDX Tools library. Added Apache Commons Compress that previously came in through a dependency of SPDX Tools. Updated documentation to reflect this change.
stevespringett
added a commit
that referenced
this issue
May 30, 2021
stevespringett
added a commit
to DependencyTrack/frontend
that referenced
this issue
May 30, 2021
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Labels
p2
Non-critical bugs, and features that help organizations to identify and reduce risk
pending release
technical debt
In a recent draft response to NIST regarding the Executive Order, OpenSSF (Linux Foundation) had an initial statement from David Wheeler that they would pay to write SPDX plugins. SPDX is over ten years old, has fewer tools that other SBOM standards and LF has entertained the idea of paying others to support it.
The text was subsequently changed, however, David Wheeler is the Director of Open Source Supply Chain Security at the Linux Foundation, and is in a position of knowing strategically what the foundation is doing
https://docs.google.com/document/d/13SS6u2bQswfRYNi-WXm4dJZkgGHZK7slYZQ75HXTVns/edit?disco=AAAAIlxfpo4
This type of forced standard does not align to the values of the Dependency-Track project.
Support for SPDX will be removed from a future version.
https://docs.google.com/document/d/13SS6u2bQswfRYNi-WXm4dJZkgGHZK7slYZQ75HXTVns/edit
The text was updated successfully, but these errors were encountered: