All of lore.kernel.org
 help / color / mirror / Atom feed
* Is curated SPDX data sharing a thing?
@ 2020-12-18 20:15 Jérôme Carretero
  2020-12-18 20:34 ` Richard Purdie
  0 siblings, 1 reply; 4+ messages in thread
From: Jérôme Carretero @ 2020-12-18 20:15 UTC (permalink / raw)
  To: yocto, Richard Purdie, Joshua Watt

Hi,


Please correct me if I'm wrong but as far as I understand it, as of
today the flow for generating SPDX data to build software BoMs,
documented eg. in:

- https://www.fossology.org/get-started/basic-workflow/
- https://elinux.org/images/2/20/License_Compliance_in_Embedded_Linux_with_the_Yocto_Project.pdf

involves building your own database of SPDX files after reviewing all
the sources, which doesn't look to be something at reach of most
businesses.


I am wondering by extension:

- Whether there are businesses selling pre-masticated SPDX data
  (I can imagine one would be willing to pay a little something to
  obtain a collection of "certified" (or possibly "insured") SPDX);

- Whether there are (plans for having) public, collaborative
  repositories of SPDX data that could be trusted over automatic scans
  of source.


Best regards,

-- 
Jérôme

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2020-12-18 22:23 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2020-12-18 20:15 Is curated SPDX data sharing a thing? Jérôme Carretero
2020-12-18 20:34 ` Richard Purdie
2020-12-18 21:51   ` [yocto] " Jérôme Carretero
2020-12-18 22:23     ` Richard Purdie

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.