> In text use:  SPDX-License-ID: LicenseRef-.com.amazon.-.ASL-2.0
>
> Then if someone shipping a SBOM with the information in it
> and wanted to record the license contents as well, they could cut/paste
> into the document.
>
> LicenseID: LicenseRef-.com.amazon.-.ASL-2.0
> LicenseName: Amazon Software License version 2.0
> ExtractedText: <text>
> insert here info
> </text>
>
> and still be able to represent the known state of the source code without
> relying completely on the web sites to stay stable over time.
>
> Thoughts?

Well, my immediate thought was that this combination of dots and dashes looks 
*very* awkward. Why not just "LicenseRef-com.amazon-ASL-2.0"? That would also 
go nicely with Philippe's approach to use a "scancode" namespace for 
ScanCode-specific license findings that have no SPDX identifier: In this case 
the namespace would be "com.amazon", i.e. the reverse domain just like in a 
Maven group name, to denote an Amazon-specific license.

Regards,
Sebastian


-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.

View/Reply Online (#3653): https://lists.spdx.org/g/Spdx-tech/message/3653
Mute This Topic: https://lists.spdx.org/mt/29560818/21656
Group Owner: [email protected]
Unsubscribe: https://lists.spdx.org/g/Spdx-tech/unsub  
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to