Greetings,

Below are just some very brief follow-up items from today's tech call.

Gary

> -----Original Message-----
> From: [email protected] <[email protected]> On Behalf Of
> Norio Kobota
> Sent: Tuesday, August 1, 2023 7:04 AM
> To: [email protected]
> Cc: [email protected]
> Subject: [spdx-tech] Drafted profile-level.md (Lite.md)
> 
> Dear spdx-tech community,
> 
> Thank you for discussing Lite Profile at the previous meeting.
> 
> We drafted profile-level.md. However, we found some issues, so let me
> discuss them.
> https://github.com/OpenChain-Project/OpenChain-
> JWG/blob/master/subgroups/sbom-sg/outcomes/SPDX-
> Lite/Proposal_v3.0/model/Lite/SPDX-Lite.md
> 
> 1. Which class and element should be used to represent a license with or
> without an SPDX short ID?

[G.O.] Need to wait for the relationship PR to be merged -
https://github.com/spdx/spdx-3-model/pull/448 - 
[G.O.] Update - this was merged yesterday - since concluded and declared
licenses are now relationships, we should remove reference to the
properties.  We should define a restriction that a relationship exists for
the Software Artifiact.  I created issue 463 to track
(https://github.com/spdx/spdx-3-model/issues/463). 
[G.O.] Note that AnyLicenseInfo would be the class to use for any type of
possible license expression

>   It seems to reconfigure Licensing classes in issue#399.
> (https://github.com/spdx/spdx-3-model/pull/399)
> 2. Do we need to list external properties restriction at profile-level.md
that
> already have minCount:1 specified?

[G.O.] From the tech call - no

> 3. How should we write CustomLicense information if we want it to be
> required if it exists and not required if it does not exist?

[G.O.] Same answer as 1. Above

> 4. How should we handle the packageFileName in SPDX2.3 when we receive
> an archived file of an OSS package?
>   This topic appears to be discussed in issue#83.
> (https://github.com/spdx/spdx-3-model/issues/83)

[G.O.] Need to wait for #83 to be resolved - Added to the discussion list
for the tech call

> 
> Best regards,
>   -- Kobota
> 
> 
> 
> 




-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#5276): https://lists.spdx.org/g/Spdx-tech/message/5276
Mute This Topic: https://lists.spdx.org/mt/100484187/21656
Group Owner: [email protected]
Unsubscribe: https://lists.spdx.org/g/Spdx-tech/unsub [[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-


Reply via email to