Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Question - SPDX Document and Software Bill of Material metrics #161

Open
klumb opened this issue Apr 10, 2022 · 0 comments
Open

Question - SPDX Document and Software Bill of Material metrics #161

klumb opened this issue Apr 10, 2022 · 0 comments

Comments

@klumb
Copy link
Member

klumb commented Apr 10, 2022

Do we want both of these metrics published as part of the release?

I am asking this again because I notice that while they are similar, they exist in different focus areas.

When the SPDX Document metric was released, I was told that it was replacing Software Bill of Materials so we removed it from the release.

While Software Bill of Materials is not part of the release currently it had gone through review and still has a markdown page. Do we want to delete it or add it back to the release? Does it need edits to distinguish it from the SPDX Document metric?

https://github.com/chaoss/wg-risk/blob/main/focus-areas/licensing/spdx-document.md
https://github.com/chaoss/wg-risk/blob/main/focus-areas/transparency/software-bill-of-materials.md

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant