#SPDX

pmonks (330ppm)pmonks@sfba.social
2025-05-27

@afreytes A while back I #AskFedi’ed about a “license exception” (e.g. as defined by SPDX) for this, but got no answers at that time.

I’d love to declare my stuff as being licensed something like `MPL-2.0 WITH No-AI-exception-1.0`. #SPDX #Licensing #FOSS

[edit] oh and ofc someone somewhere will likely whine about this “nOt bEiNg OpEN sOURcE” then point to @osi OSD item #6 as a reference, to which I’d respond: “I don’t care - I don’t want my creative works going into these dumpster fire systems”

Till Kamppetertill@ubuntu.social
2025-05-08

The #LinuxFoundation will mentor 21 contributors in the Google Summer of Code 2025!! #GSoC

Despite having lined up many more proposals than last year we got the same amount of slots.

11 for #OpenPrinting, 3 for #AGL (Automotive Grade Linux, 2 for each of #SPDX and #IIO (Industrial I/O), and 1 for each of #SOF (Sound Open Firmware), #Zephyr, and #KWorkflow.

See Google's announcements of the projects:

summerofcode.withgoogle.com/pr

Viktor Peterssonvpetersson@hachyderm.io
2025-05-07

What does it really take to build secure, auditable firmware today?

In the latest episode of Nerding Out with Viktor, I sat down with Joshua Watt (Garmin) and Ross Burton (ARM) to dig into how the Yocto Project, SBOMs, and SPDX 3.0 are changing how we ship and maintain embedded Linux at scale.

We get into:
*Why SBOMs need to be generated at build-time, not after
*How SPDX 3.0 helps with license clarity and deep package tracking
*Why VEX metadata matters when it’s time to triage real vulnerabilities
*Build determinism, OTA failures, and surviving 15-year product lifecycles
*What the Cyber Resilience Act means for your toolchain

Whether you’re deep in firmware or just trying to ship connected products without getting buried in compliance debt, this one’s worth a listen.

Listen here: vpetersson.com/podcast/S02E09.

#Yocto #EmbeddedLinux #SBOM #SPDX #FirmwareSecurity

John Vaccaro (johniac)johniac
2025-05-02

SciTech Chronicles. . . . . . .May 2nd, 2025

bit.ly/stc050225

#"moment of inertia" #"6.14 kernel" #"geological history" #"Stac Fada Member" #"gastrointestinal diseases"

Frank Hofmannhofmannedv
2025-04-25

I have added SPDX license classifiers to my Lua examples:

github.com/hofmannedv/learning

dawid paćkowski :BlobhajReach:DawPac
2025-04-06

105 QSOs in SP DX Contest as a club station SP7PBC, thank you all, 73

Dziękujemy za uczestnictwo w zawodach SP DX CONTEST 2025!
Otrzymaliśmy wysłany przez Ciebie dziennik stacji SP7PBC w kategorii MOAB MIXED .
Twój log zawiera 105 łączności.
Fabian Kurz, DJ5CW/SO5CWDJ5CW@social.darc.de
2025-04-06

Snow on the SO5CW webcam this morning! 425 QSOs in the #SPDX #Contest so far. Come join the contest: spdxcontest.pzk.org.pl/2025/ #hamradio

A webcam view of the SO5CW antennas: A triband yagi on a small tower and a vertical antenna (that used to be more straight) in the back of the yard. A barn and an old auxillary building are visible around the yard. There is a little snow on the ground and the roofs, the sky is covered in clouds.
2025-03-14

How do #SBOMs fit into #AI, hardware, and critical infrastructure?
SBOMs transformed from static documents to dynamic, database-driven knowledge systems that can scale with today's complex software ecosystems. This session will provide a forward-looking perspective on where SBOM technology is heading, focusing on recent developments in SPDX 3.0 and upcoming features in SPDX 3.1.
Kate Stewart (#SPDX) and Alan Pope (Anchore) discuss the expanding role of SBOMs in modern ... get.anchore.com/future-of-sbom

2025-03-10

#SPDX 3.0 and the Future of #SBOMs—What's Next? Kate Stewart, a leading force behind SPDX, and Alan Pope of Anchore discuss the latest advancements in SBOMs, regulatory shifts, and integration strategies. Live on March 24 at 10 AM PT. Secure your spot: get.anchore.com/future-of-sbom get.anchore.com/future-of-sbom

2025-03-07

#SBOMs are evolving—are you ready? Join Kate Stewart (#SPDX) and Alan Pope (Anchore) on March 24 at 10 AM PT as they explore the next phase of SBOM adoption, including SPDX 3.0/3.1, AI/ML applications, and deeper CI/CD integration. Register now: get.anchore.com/future-of-sbom

Jürgenelbosso
2025-03-07

... Und schon wieder eine Idee für einen Artikel für die im . Dieses Mal , , , und ...

2025-03-01

SBOMs are more than an inventory—they're a critical tool for securing modern software development. Our latest guide breaks down @SBOM fundamentals, key standards like #SPDX and #CycloneDX, and real-world use cases for security, compliance, and DevSecOps. Download now get.anchore.com/sbom101-guide-

Till Kamppetertill@ubuntu.social
2025-02-27

The #LinuxFoundation is accepted as mentoring organization in the Google Summer of Code #GSoC #GSoC2025!

Amazing project ideas are waiting for awesome contributors: From #OpenPrinting, #Zephyr, Automotive Grade Linux #AGL, Industrial I/O #IIO, Sound Open Firmware #SOF, #SPDX, Automating Linux kernel workflows #kworkflow

summerofcode.withgoogle.com/pr

Project ideas and how to apply:
wiki.linuxfoundation.org/gsoc/

If interested to be a contributor or mentor contact us ASAP! Do not wait for the deadline.

2025-02-25

New in Syft v1.20.0: Bitnami embedded #SBOM support for maximum accuracy + smarter license detection that preserves original text even when #SPDX matching fails. Get the most accurate SBOMs possible! #CyberSecurity
anchore.com/blog/syft-1-20-fas

Orhun Parmaksız 👾orhun@fosstodon.org
2025-02-09

Want to parse/validate open source licenses in Rust? 🦀 Check this out.

🆔 **spdx**: Helper crate for SPDX expressions.

📚 Docs: docs.rs/spdx

⭐ GitHub: github.com/EmbarkStudios/spdx

#rustlang #library #spdx #license #parsing #opensource #validation

Veit Schieleveit
2025-02-01

I’ve just seen that pip now supports License-Expression in pip show: pip.pypa.io/en/stable/news/#fe

Miro Hrončok :fedora: :python:hroncok@floss.social
2025-02-01
Hugo van Kemenadehugovk.dev@bsky.brid.gy
2025-01-24

🐍📦📜 All the pieces (I use) are now in place for PEP 639 ("Improving License Clarity with Better Package Metadata"). Thanks to contributors and maintainers of at least 6 projects and of course Karolina Surma for the PEP! discuss.python.org/t/pep-639-ro... #Python #PEP639 #PyPI #SPDX #licensing

PyPI metadata showing "License Expression: BSD-3-Clause" with links to more info about SPDX and about License Expressions.
Hugo van Kemenadehugovk
2025-01-24

🐍📦📜 All the pieces (that I use) are now in place for PEP 639 ("Improving License Clarity with Better Package Metadata")!

I made sure to use latest Hatchling 1.27, added `license-files = [ "LICENSE" ]`, and deleted the deprecated licence Trove classifier.

Thanks to contributors and maintainers of PyPI, packaging, Hatchling, Twine, PyPI publish GitHub Action, build-and-inspect-python-package and of course @karo for the PEP+spec!

discuss.python.org/t/pep-639-r

PyPI metadata showing "License Expression: BSD-3-Clause" with links to more info about SPDX and about License Expressions.

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst