Following up on our discussion in today's tech team call, here's my take on the primary use case which is driving the need to "copy" rather than reference SPDX elements.
I created a Github repo in my with a proposed use case description: https://github.com/goneall/spdx-use-cases/blob/main/create-micro-sbom.md Please review and add any pull requests for suggested changes. Note that I tried to generalize the use case to apply to several different scenarios, but I would want to make sure we covered the container use cases since that was a focus of the Docfest discussion. Nisha and Rose - I'm especially interested in any suggested changes from the Tern/Container perspective. Here is what I would propose in terms of process for taking the use case through to a model proposal: * Review and agree on the use case description itself * Create a list of criteria for judging various model solutions * Collect possible solutions * Select the best (or least worse ;) solution Gary ------------------------------------------------- Gary O'Neall Principal Consultant Source Auditor Inc. Mobile: 408.805.0586 Email: <mailto:[email protected]> [email protected] CONFIDENTIALITY NOTE: The information transmitted, including attachments, is intended only for the person(s) or entity to which it is addressed and may contain confidential and/or privileged material. Any review, re-transmission, dissemination or other use of, or taking of any action in reliance upon this information by persons or entities other than the intended recipient is prohibited. If you received this in error, please contact the sender and destroy any copies of this information. -=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#4200): https://lists.spdx.org/g/Spdx-tech/message/4200 Mute This Topic: https://lists.spdx.org/mt/85772839/21656 Group Owner: [email protected] Unsubscribe: https://lists.spdx.org/g/Spdx-tech/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
