ilva
> Chairperson of the Supervisory Board: Nicole Lau
> Registered Office: Munich
> Commercial Register: Amtsgericht Muenchen HRB 186928
>
>
--
Cordially
Philippe Ombredanne
+1 650 799 0949 | pombreda...@nexb.com
AboutCode - Open source for open source - https://www.aboutcode.org
V
FOSS events.
We're also looking for generous sponsors to help fund the venue and
catering - you can contribute online directly or email me directly at
pombreda...@nexb.com
I look forward to seeing you there.
--
Cordially
Philippe Ombredanne
+1 650 799 0949 | pombreda...@nexb.com
AboutCode - Open
detected?
Can you share some concrete examples?
--
Cordially
Philippe Ombredanne
+1 650 799 0949 | pombreda...@nexb.com
AboutCode - Open source for open source - https://www.aboutcode.org
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#5042): https
Philippe Ombredanne
+1 650 799 0949 | pombreda...@nexb.com
AboutCode - Open source for open source - https://www.aboutcode.org
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#4913): https://lists.spdx.org/g/Spdx-tech/message/4913
Mute This Topic
an_copyright.py
and here:
https://github.com/nexB/scancode-toolkit/blob/develop/src/packagedcode/debian.py
And this is used also in ScanCode.io for Debian/Ubuntu for VM and
docker image scanning in
https://scancodeio.readthedocs.io/en/latest/
Please tell me how I can help so this becomes easy enough f
listed at
https://www.itic.org/about/membership/iti-members
to reach out to this organization and/or their internal contact to
apply pressure and sort out this mess.
--
Cordially
Philippe Ombredanne
+1 650 799 0949 | pombreda...@nexb.com
DejaCode - What's in your code?! - http://www.dejacode.com
A
. I do not know your background, but it is clear that you
have experience in this domain. So please do not stop!
--
Cordially
Philippe Ombredanne
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#4584): https://lists.spdx.org/g/Spdx-tech/message/4584
Mute This
of license identifiers maintained at
SPDX and assigned on a first-come-first-served basis. And with a
simple rule that no two ids conflict ignoring case and no two ids
point to the same text (say using SPDX matching guidelines).
If this is what you suggest, I couldn't agree more and I would support
ion and identifier representation are either all
lowercase or all uppercase and be done with this topic for good.
--
Cordially
Philippe Ombredanne
+1 650 799 0949 | pombreda...@nexb.com
DejaCode - What's in your code?! - http://www.dejacode.com
AboutCode - Open source for open source - https:/
://www.python.org/dev/peps/pep-0639/
Comments and feedback are welcomed at:
https://discuss.python.org/t/2154
--
Cordially
Philippe Ombredanne
+1 650 799 0949 | pombreda...@nexb.com
DejaCode - What's in your code?! - http://www.dejacode.com
AboutCode - Open source for open source - https://www.aboutcode.org
ocument/d/1UphruKKAlsoUEidPCwTF2LCcHFnQkvQCQ9luTXfDupw/edit#
--
Cordially
Philippe Ombredanne
+1 650 799 0949 | pombreda...@nexb.com
DejaCode - What's in your code?! - http://www.dejacode.com
AboutCode - Open source for open source - https://www.aboutcode.org
nexB Inc. - http://www.nexb.com
-=-=-=-=-=-=-=-=-=-=-=-
Links: Yo
document/d/1UphruKKAlsoUEidPCwTF2LCcHFnQkvQCQ9luTXfDupw/edit#heading=h.p2d7mni4lrcu
for details.
To "register", just add you name to this document! (alternatively you
can reply to me off list too)
I look forward to seeing you there!
--
Cordially
Philippe Ombredanne
+1 650 799 0949 | pombreda...@nexb.c
-metadata/2154/57
And see, comment and propose updates to the draft PEP here:
https://github.com/pombredanne/spdx-pypi-pep/pull/2
--
Cordially
Philippe Ombredanne
+1 650 799 0949 | pombreda...@nexb.com
DejaCode - What's in your code?! - http://www.dejacode.com
AboutCode - Open source for open source
Hi David:
On Mon, Jul 1, 2019 at 9:00 PM Wheeler, David A wrote:
> Philippe Ombredanne wrote:
>> What looks as a version number in an SPDX license identifier is NOT
>> like a software version number. This is purely indicative and is not
>> something that is specifie
ak them in parts: they have no parts, no part
separator, no prefix, no suffix and no version (even though it may
look like it).
--
Cordially
Philippe Ombredanne
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#3739): https://lists.spdx.org/g/Spdx-tec
tance you could track that EPL-1.0
next version is EPL-2.0 and so on. But this becomes an explicitly
stored relationship and not something vaguely inferred from opaque
ids.
And in the same way, the -only and -or-later suffixes applied to some
ids have no meaning whatsoever of their own. They just
have one though)
--
Cordially
Philippe Ombredanne
+1 650 799 0949 | pombreda...@nexb.com
DejaCode - What's in your code?! - http://www.dejacode.com
AboutCode - Open source for open source - https://www.aboutcode.org
nexB Inc. - http://www.nexb.com
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all
putes
Thankyou: that's all valuable things to consider indeed and hard
earned from the leftpad issues.
Though I doubt mere licenses will ever be as successful as npm!
--
Cordially
Philippe Ombredanne
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online
on, the SPDX legal team can use not only direct
requests for license additions but also can funnel selected public
registrations as candidates for inclusion in the main SPDX
non-namespaced License List.
Done.
--
Cordially
Philippe Ombredanne
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages
best achieved by license detection with a full diff (which
is what scancode does FWIW).
Let me follow up with my suggestion.
--
Cordially
Philippe Ombredanne
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#3668): https://lists.spdx.org/g/Spdx-tech/
censes as being a funnel for actual additions to the SPDX
list proper. Some may be worthy of that addition while some may not
make the cut.
--
Cordially
Philippe Ombredanne
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#3666): https://lists
Hi Mark:
On Mon, Feb 4, 2019 at 9:57 PM Mark Atwood wrote:
> Just following up, does anyone have any comments or suggestions for my
> proposal for SPDX Private License Identifiers?
We surely could use a way to have namespaces of sorts for extra, non
SPDX-listed license identifiers. This is
All:
I am not able to join this week due to a conflicting appointment.
--
Cordially
Philippe
On Tue, May 1, 2018 at 4:35 PM, Kate Stewart
wrote:
> Hi,
> Just a reminder that we'll be having our weekly tech call in a couple
> of hours, and the topic for today is
hings...
You positively rock!
My only comment is that I did not see a GPL license in the expression
animation ;)
BTW, I just pushed an update to Scancode the other day that at last
detects all these correctly.
And deals with less well formed variants too.
--
Cordially
Philippe Ombredanne
. (Again, provided that this wouldn't actually break any
> active users)
Dropping 1.x support would make 100% sense. I would not even
contemplate using and supporting 1.x at this stage.
And again that's what version control is used for. So no worries.
And as a side note: great to know that yo
here for a Python reference and not
Go ;)
https://github.com/spdx/tools-go
--
Cordially
Philippe Ombredanne
+1 650 799 0949 | pombreda...@nexb.com
DejaCode - What's in your code?! - http://www.dejacode.com
AboutCode - Open source for open source - https://w
thon
[2]
https://github.com/spdx/tools-python/blob/a48022e65a8897d0e4f2e93d8e53695d2c13ea23/spdx/package.py#L233
--
Cordially
Philippe Ombredanne
+1 650 799 0949 | pombreda...@nexb.com
DejaCode - What's in your code?! - http://www.dejacode.com
AboutCode - Open source for open source - https:
code-toolkit
--
Cordially
Philippe Ombredanne
___
Spdx-tech mailing list
Spdx-tech@lists.spdx.org
https://lists.spdx.org/mailman/listinfo/spdx-tech
talks to use a macro instead of a comment.
It may come back in the future as it would have the added benefit to inject
license ids in the built binaries (the same way a MODULE_LICENSE ends
up in a built LKM)
[0]
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/tree/include/linux/modu
FYI:
In case you missed it: SPDX identifiers have landed in kernel land...
Read the whole thread at https://patchwork.kernel.org/patch/10016189/
And as a side effect, some new patches elsewhere are coming in with
SPDX identifiers right in!
--
Cordially
Philippe Ombredanne
-- Forwarded
ve in mind?
- what is your plan to package and make these installable?
And this for each feature and/or tool you are considering.
And I am not interested in boilerplate parts, but what is
specific to your apps.
As a side note, please try to avoid posting HTML or Rich text o
th
> python-tools and java tools once my exams get over.
Thanks! The goal there is that we can ensure that you can show minimal skills
for doing PR and handling tickets. and that we can see if you have basic code
writing skills.
--
Cordially
Philippe Ombredanne
it was mistakenly written in Python and
not Lisp as it should have. We are working slowly to implement a
messy, incomplete subset of an imperfect Lisp engine as all serious
software projects tend to do eventually.
> Lisp, Jazz, Aïkido: http://www.didierverna.info
A definit
s should be available as a web UI and a REST API.
I hope this helps.
--
Cordially
Philippe Ombredanne
___
Spdx-tech mailing list
Spdx-tech@lists.spdx.org
https://lists.spdx.org/mailman/listinfo/spdx-tech
/blob/bd424eae1dcdbb3f873169bbc01d252e4e20e4f4/AUTHORS.rst
> [2] https://github.com/sschuberth/dev-scripts/blob/master/git/git-hash-blob.sh
[3] https://shattered.it/
[4] https://www.softwareheritage.org/
[5]
https://fosdem.org/2017/schedule/event/software_heritage/attachments/slides/1537/export/events/attachments/software_heritage/slides/1537/fosdem17_software_heritage.pdf
--
Cordially
Philippe Ombredanne
___
Spdx-tech mailing list
Spdx-tech@lists.spdx.org
https://lists.spdx.org/mailman/listinfo/spdx-tech
two files is very small (e.g. 9)
which is the property you want to
exploit to determine that two files are essentially the same except
for very minor changes:
$ bin/tlsh -f foo/foo1.c -c foo/foo2.c
9 foo/foo1.c
As a side note, I have built several alternative lsh fingerprints and
I will push t
organization and we have
several SPDX-related projects ideas there too:
https://github.com/nexB/aboutcode/wiki/GSOC-2017
--
Cordially
Philippe Ombredanne
___
Spdx-tech mailing list
Spdx-tech@lists.spdx.org
https://lists.spdx.org/mailman/listinfo/spdx-tech
comments in this issue Paul entered on keyring [3]
[1] https://pypi.python.org/pypi?:action=list_classifiers
[2] https://github.com/nexB/scancode-toolkit/
[3] https://github.com/jaraco/keyring/issues/263#issuecomment-281035598
--
Cordially
Philippe Ombredanne
+1 650 799 0949 | pombreda...@nexb.com
De
ier
> (8AM Pacific, 4PM GMT) or would prefer to keep the call at its current time
> (10AM Pacific, 6PM GMT).
+1 for moving it earlier with the added benefit that folks in Asia
could join too (though it would still be quite late and in the range
of 11:00PM to 1:00AM in some locales)
--
Cordi
roring. I would then remove all commit
> access on SPDX.org to prevent any accidental commits.
This works for me alright.
You should go head with the the Go tools too and grant me access on
Github as I mentored the initial contribution. There will be some
minor issues with Go import namespaci
be synced from the github repo for
reference.
This should be rather simple IMHO: just remove any mirroring hooks or
settings from repo @ spdx
(and if needed setup a cron job to pull from github instead.)
Who can make this happen? Kate? Gary?
I would rather have this ASAP.
--
Cordially
Philippe
ent
but equivalent expressions for equality or containment.
--
Cordially
Philippe Ombredanne
+1 650 799 0949 | pombreda...@nexb.com
DejaCode : What's in your code?! at http://www.dejacode.com
nexB Inc. at http://www.nexb.com
___
Spdx-tech mailing list
than a full conditional construct?
e.g. something like:
scope:doc GFDL and MIT
scope:tools GPL-2.0+
scope:library LGPL-2.1+
And if no scope is defined it defaults to global and is overridden if
a scope is defined?
So IMHO this would not be a single expression but an array of expressions.
A
rmat.
[1] https://en.wikipedia.org/wiki/ReStructuredText
--
Cordially
Philippe Ombredanne
___
Spdx-tech mailing list
Spdx-tech@lists.spdx.org
https://lists.spdx.org/mailman/listinfo/spdx-tech
n a separate repo,if that can help I
can pull it out.
There is also Python code to read it [2]
[1]
https://github.com/nexB/scancode-toolkit/tree/develop/src/licensedcode/data/licenses
[2]
https://github.com/nexB/scancode-toolkit/blob/c1e70994abe8ceb18bc99aa6f81ebc40d832fb7f/src/licensedcode/
hon ;)
--
Cordially
Philippe Ombredanne
___
Spdx-tech mailing list
Spdx-tech@lists.spdx.org
https://lists.spdx.org/mailman/listinfo/spdx-tech
On Tue, Nov 3, 2015 at 3:45 AM, Wheeler, David A <dwhee...@ida.org> wrote:
> Philippe Ombredanne wrote:
[...]
>> You say:
>> GPL-2.0 ==> implies GPL 2.0 only
>> GPL-2.0+ ==> implies GPL 2.0 or later
> That's not just what I say. That's what the spec says,
as part of a licenseref:
there is no possible ambiguity.
Then again we would be better off to get rid of the plus entirely!
--
Cordially
Philippe Ombredanne
___
Spdx-tech mailing list
Spdx-tech@lists.spdx.org
https://lists.spdx.org/mailman/listinfo/spdx-tech
On Mon, Nov 2, 2015 at 9:12 PM, Wheeler, David A <dwhee...@ida.org> wrote:
> Philippe Ombredanne:
>> This + is a suffix and not a freestanding character, right?
>> Then again we would be better off to get rid of the plus entirely!
> You may be confusing a SPDX "l
to support this claim ;)
http://www.googlefight.com/free+software+foundation+and+no+other+version-vs-free+software+foundation%3B+either+version+2.php
--
Cordially
Philippe Ombredanne
___
Spdx-tech mailing list
Spdx-tech@lists.spdx.org
https://lists.spdx.org/mailman/listinfo/spdx-tech
art is not clear, let's fix the spec. This is not something frozen.
Now that said, I do not like the plus at all and we should remove entirely from
the spec.
--
Cordially
Philippe Ombredanne
___
Spdx-tech mailing list
Spdx-tech@lists.spdx.org
https://lists.spdx.org/mailman/listinfo/spdx-tech
2015 Myco }} would match up to 5 words
and {{ 10 Copyright (c) 2015 Myco inc.}} would match up to 10 words.
I hope this helps even though this is a slightly different take.
--
Cordially
Philippe Ombredanne
___
Spdx-tech mailing list
Spdx-tech@lists.
?
The compounded complexity of RDF and bytes is unlikely warranted here.
--
Cordially
Philippe Ombredanne
___
Spdx-tech mailing list
Spdx-tech@lists.spdx.org
https://lists.spdx.org/mailman/listinfo/spdx-tech
punct = - / .
The difference is that an identifier is defined as starting with a
letter or digit and this is specified for refs, id and an exception
ids.
--
Cordially
Philippe Ombredanne
___
Spdx-tech mailing list
Spdx-tech@lists.spdx.org
could be anything, but we could have the convention for SPDX-provided
exceptions IDs to suffix them with
-exception for clarity, though that would not be needed just a nice to
have. IMHO adding the keyword exception would be redundant with the
with keyword.
--
Cordially
Philippe Ombredanne
or additional thoughts on the tools
session.
I look forward to the face to face!
--
Cordially
Philippe Ombredanne
+1 650 799 0949 | pombreda...@nexb.com
DejaCode : What's in your code?! at http://www.dejacode.com
nexB Inc. at http://www.nexb.com
On Mon, Jun 16, 2014 at 8:17 PM, Vlad Velici vlad.vel...@gmail.com wrote:
I probably should have written a few status reports by now and I apologise
for that.
My progress can be easily tracked on both the git.spdx.org repository[1] and,
with a bit more details, on the issue tracker of the
experiences
seem quite different from your negative ones.
--
Cordially
Philippe Ombredanne
___
Spdx-tech mailing list
Spdx-tech@lists.spdx.org
https://lists.spdx.org/mailman/listinfo/spdx-tech
?
One or more, yes. This is a major change in 2.0
--
Cordially
Philippe Ombredanne
___
Spdx-tech mailing list
Spdx-tech@lists.spdx.org
https://lists.spdx.org/mailman/listinfo/spdx-tech
: full paths in SPDX
vs. patterns in DEP5.
Which would create likely bloated DEP5 files.
--
Philippe Ombredanne
___
Spdx-tech mailing list
Spdx-tech@lists.spdx.org
https://lists.spdx.org/mailman/listinfo/spdx-tech
On Mon, Mar 10, 2014 at 7:22 PM, Jeremiah Foster
jeremiah.fos...@pelagicore.com wrote:
On Mon, Mar 10, 2014 at 4:02 PM, Philippe Ombredanne pombreda...@nexb.com
wrote:
As for SPDX to DEP5 conversion, there are probably several
difficulties ahead, one of them being the files: full paths in SPDX
partially as the spec is expected to be release in august and by
then the summer of code will be at its end.
Yes that would work best.
Now which language would you have in mind?
Hint: Java is already covered.
My choices would be Python, Go, JavaScript and Ruby in this order.
Cordially
--
Philippe
.
Visit this group at http://groups.google.com/group/gsoc-mentors-announce.
For more options, visit https://groups.google.com/groups/opt_out.
--
Philippe Ombredanne
___
Spdx-tech mailing list
Spdx-tech@lists.spdx.org
https://lists.spdx.org/mailman/listinfo
thread to use SPDX license keys.
--
Philippe Ombredanne
+1 650 799 0949 | pombreda...@nexb.com
DejaCode Enterprise at http://www.dejacode.com
nexB Inc. at http://www.nexb.com
___
Spdx-tech mailing list
Spdx-tech@lists.spdx.org
https://lists.spdx.org
organizations and different counsels may look at things slightly
differently and come to different conclusions based on the same
original materials.
I hope we can encourage others to present situations they believe the current
SPDX licensing mechanism does not easily support.
+1!
--
Philippe
single component.
I think that SPDX does and should in spirit and letter support both approaches.
--
Philippe Ombredanne
+1 650 799 0949 | pombreda...@nexb.com
DejaCode Enterprise at http://www.dejacode.com
nexB Inc. at http://www.nexb.com
___
Spdx-tech
properly or mark them such that they are not recognized by a
template engine. And angle brackets would likely have the same issues
wrt to HTML/XML.
--
Philippe Ombredanne
___
Spdx-tech mailing list
Spdx-tech@lists.spdx.org
https://lists.spdx.org/mailman
67 matches
Mail list logo