Re: Hello World!
Philip Odence
Hey Jeremiah,
It’s been a while. Forgive me for doing a lousy job educating you on SPDX. Thanks, MarkG for filling in.
Having been involved in SPDX from the outset, I can tell you that there are many issues, but lack of a problem focus really isn’t one. Attached is the high level way we’ve expressed it. We’ve been well-focused, I believe, on providing a lingua franca for
partners in a supply chain to exchange software BoM information. There’s been external pressure, by the way, to expand our focus, for example into OpenChain type activities—thanks, Dave Marr, for starting OC and thereby relieving the pressure.
Adoption is a challenge, a real chicken/egg problem. How do you get people to communicate in your language when it’s hard to find others who are fluent? That said Wind River, TI, Siemens, Samsung, Alcatel-Lucent and others have all started using SPDX internally
and increasingly with partners. I have been heartened this year to learn of a number of companies using SPDX who have never been involved with the group developing the standard. We would love their involvement, but that fact that organizations can get value,
without being in the middle of SPDX specification development, says to me we’ve turned a corner and that the virtuous cycles are starting to spin.
The SPDX group will stay close to the OpenChain activities. As Bogart said, “I think this is the beginning of a beautiful friendship.”
Phil
L. Philip Odence
Chair, Linux Foundation SPDX Workgroup
Vice President and General Manager
Black Duck
8 New England Executive Park, Suite 211, Burlington MA 01803
Phone: 781.810.1819, Mobile: 781.258.9502
Skype: philip.odence
From: Jeremiah Foster <jeremiah.foster@...>
Date: Fri, 29 Aug 2014 09:17:56 +0200 To: Mark Gisi <Mark.Gisi@...> Cc: "openchain@..." <openchain@...> Subject: Re: [OpenChain] Hello World! On Fri, Aug 29, 2014 at 7:37 AM, Gisi, Mark
<Mark.Gisi@...> wrote:
Okay, I confess I view it more as a tool, good to have this clarified for me.
Thanks very much for this email. Puts SPDX into the right perspective for me. I've sort of viewed it from a software engineer's view as this thing I have to add not knowing really why. If it does provide a software Bill of Materials that can effectively
provide assurance in the supply chain then clearly its a solution to a very real problem.
Regards,
Jeremiah
|
|