fosstodon.org is one of the many independent Mastodon servers you can use to participate in the fediverse.
Fosstodon is an invite only Mastodon instance that is open to those who are interested in technology; particularly free & open source software. If you wish to join, contact us for an invite.

Administered by:

Server stats:

10K
active users

#spdx

0 posts0 participants0 posts today
Fabian Kurz, DJ5CW/SO5CW<p>Snow on the SO5CW webcam this morning! 425 QSOs in the <a href="https://social.darc.de/tags/SPDX" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SPDX</span></a> <a href="https://social.darc.de/tags/Contest" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Contest</span></a> so far. Come join the contest: <a href="https://spdxcontest.pzk.org.pl/2025/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">spdxcontest.pzk.org.pl/2025/</span><span class="invisible"></span></a> <a href="https://social.darc.de/tags/hamradio" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>hamradio</span></a></p>
anchore<p>How do <a href="https://mstdn.business/tags/SBOMs" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SBOMs</span></a> fit into <a href="https://mstdn.business/tags/AI" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>AI</span></a>, hardware, and critical infrastructure?<br>SBOMs transformed from static documents to dynamic, database-driven knowledge systems that can scale with today's complex software ecosystems. This session will provide a forward-looking perspective on where SBOM technology is heading, focusing on recent developments in SPDX 3.0 and upcoming features in SPDX 3.1.<br>Kate Stewart (<a href="https://mstdn.business/tags/SPDX" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SPDX</span></a>) and Alan Pope (Anchore) discuss the expanding role of SBOMs in modern ... <a href="https://get.anchore.com/future-of-sboms-with-kate-stewart/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">get.anchore.com/future-of-sbom</span><span class="invisible">s-with-kate-stewart/</span></a></p>
anchore<p><a href="https://mstdn.business/tags/SPDX" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SPDX</span></a> 3.0 and the Future of <a href="https://mstdn.business/tags/SBOMs" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SBOMs</span></a>—What's Next? Kate Stewart, a leading force behind SPDX, and Alan Pope of Anchore discuss the latest advancements in SBOMs, regulatory shifts, and integration strategies. Live on March 24 at 10 AM PT. Secure your spot: <a href="https://get.anchore.com/future-of-sboms-with-kate-stewart/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">get.anchore.com/future-of-sbom</span><span class="invisible">s-with-kate-stewart/</span></a> <a href="https://get.anchore.com/future-of-sboms-with-kate-stewart/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">get.anchore.com/future-of-sbom</span><span class="invisible">s-with-kate-stewart/</span></a></p>
anchore<p><a href="https://mstdn.business/tags/SBOMs" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SBOMs</span></a> are evolving—are you ready? Join Kate Stewart (<a href="https://mstdn.business/tags/SPDX" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SPDX</span></a>) and Alan Pope (Anchore) on March 24 at 10 AM PT as they explore the next phase of SBOM adoption, including SPDX 3.0/3.1, AI/ML applications, and deeper CI/CD integration. Register now: <a href="https://get.anchore.com/future-of-sboms-with-kate-stewart/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">get.anchore.com/future-of-sbom</span><span class="invisible">s-with-kate-stewart/</span></a></p>
Jürgen<p>... Und schon wieder eine Idee für einen Artikel für die <a href="https://mastodon.social/tags/heimatseite" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>heimatseite</span></a> im <a href="https://mastodon.social/tags/zwischennetz" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>zwischennetz</span></a>. Dieses Mal <a href="https://mastodon.social/tags/java" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>java</span></a>, <a href="https://mastodon.social/tags/sbom" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>sbom</span></a>, <a href="https://mastodon.social/tags/spdx" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>spdx</span></a> <a href="https://mastodon.social/tags/apacheant" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>apacheant</span></a> , <a href="https://mastodon.social/tags/apacheivy" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>apacheivy</span></a> und <a href="https://mastodon.social/tags/maven" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>maven</span></a> ...</p>
anchore<p>SBOMs are more than an inventory—they're a critical tool for securing modern software development. Our latest guide breaks down @SBOM fundamentals, key standards like <a href="https://mstdn.business/tags/SPDX" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SPDX</span></a> and <a href="https://mstdn.business/tags/CycloneDX" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CycloneDX</span></a>, and real-world use cases for security, compliance, and DevSecOps. Download now <a href="https://get.anchore.com/sbom101-guide-for-devsecops-community/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">get.anchore.com/sbom101-guide-</span><span class="invisible">for-devsecops-community/</span></a></p>
Till Kamppeter<p>The <a href="https://ubuntu.social/tags/LinuxFoundation" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LinuxFoundation</span></a> is accepted as mentoring organization in the Google Summer of Code <a href="https://ubuntu.social/tags/GSoC" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>GSoC</span></a> <a href="https://ubuntu.social/tags/GSoC2025" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>GSoC2025</span></a>!</p><p>Amazing project ideas are waiting for awesome contributors: From <a href="https://ubuntu.social/tags/OpenPrinting" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OpenPrinting</span></a>, <a href="https://ubuntu.social/tags/Zephyr" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Zephyr</span></a>, Automotive Grade Linux <a href="https://ubuntu.social/tags/AGL" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>AGL</span></a>, Industrial I/O <a href="https://ubuntu.social/tags/IIO" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>IIO</span></a>, Sound Open Firmware <a href="https://ubuntu.social/tags/SOF" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SOF</span></a>, <a href="https://ubuntu.social/tags/SPDX" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SPDX</span></a>, Automating Linux kernel workflows <a href="https://ubuntu.social/tags/kworkflow" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>kworkflow</span></a> </p><p><a href="https://summerofcode.withgoogle.com/programs/2025-ao/organizations/the-linux-foundation" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">summerofcode.withgoogle.com/pr</span><span class="invisible">ograms/2025-ao/organizations/the-linux-foundation</span></a></p><p>Project ideas and how to apply:<br><a href="https://wiki.linuxfoundation.org/gsoc/google-summer-code-2025" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">wiki.linuxfoundation.org/gsoc/</span><span class="invisible">google-summer-code-2025</span></a></p><p>If interested to be a contributor or mentor contact us ASAP! Do not wait for the deadline.</p>
anchore<p>New in Syft v1.20.0: Bitnami embedded <a href="https://mstdn.business/tags/SBOM" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SBOM</span></a> support for maximum accuracy + smarter license detection that preserves original text even when <a href="https://mstdn.business/tags/SPDX" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SPDX</span></a> matching fails. Get the most accurate SBOMs possible! <a href="https://mstdn.business/tags/CyberSecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CyberSecurity</span></a><br><a href="https://anchore.com/blog/syft-1-20-faster-scans-smarter-license-detection-and-enhanced-bitnami-support/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">anchore.com/blog/syft-1-20-fas</span><span class="invisible">ter-scans-smarter-license-detection-and-enhanced-bitnami-support/</span></a></p>
pmonks (330ppm)<p><span class="h-card" translate="no"><a href="https://social.coop/@sam" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>sam</span></a></span> I’m personally a fan of the <a href="https://sfba.social/tags/SPDX" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SPDX</span></a> approach - have a base license that can be modified “WITH” a “license exception”. In fact I’ve been casually on the hunt for a “no AI usage of any kind” license exception that I can add on to my (mostly MPL-2.0) licensed projects.</p>
Orhun Parmaksız 👾<p>Want to parse/validate open source licenses in Rust? 🦀 Check this out.</p><p>🆔 **spdx**: Helper crate for SPDX expressions.</p><p>📚 Docs: <a href="https://docs.rs/spdx" target="_blank" rel="nofollow noopener noreferrer" translate="no"><span class="invisible">https://</span><span class="">docs.rs/spdx</span><span class="invisible"></span></a></p><p>⭐ GitHub: <a href="https://github.com/EmbarkStudios/spdx" target="_blank" rel="nofollow noopener noreferrer" translate="no"><span class="invisible">https://</span><span class="">github.com/EmbarkStudios/spdx</span><span class="invisible"></span></a></p><p><a href="https://fosstodon.org/tags/rustlang" class="mention hashtag" rel="tag">#<span>rustlang</span></a> <a href="https://fosstodon.org/tags/library" class="mention hashtag" rel="tag">#<span>library</span></a> <a href="https://fosstodon.org/tags/spdx" class="mention hashtag" rel="tag">#<span>spdx</span></a> <a href="https://fosstodon.org/tags/license" class="mention hashtag" rel="tag">#<span>license</span></a> <a href="https://fosstodon.org/tags/parsing" class="mention hashtag" rel="tag">#<span>parsing</span></a> <a href="https://fosstodon.org/tags/opensource" class="mention hashtag" rel="tag">#<span>opensource</span></a> <a href="https://fosstodon.org/tags/validation" class="mention hashtag" rel="tag">#<span>validation</span></a></p>
Veit Schiele<p>I’ve just seen that pip now supports License-Expression in pip show: <a href="https://pip.pypa.io/en/stable/news/#features" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">pip.pypa.io/en/stable/news/#fe</span><span class="invisible">atures</span></a><br><a href="https://mastodon.social/tags/pip" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>pip</span></a> <a href="https://mastodon.social/tags/spdx" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>spdx</span></a> <a href="https://mastodon.social/tags/Python" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Python</span></a> <a href="https://mastodon.social/tags/Licensing" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Licensing</span></a></p>
Miro Hrončok :fedora: :python:<p>pip can now show SPDX license expressions 🎉 </p><p><a href="https://ichard26.github.io/blog/2025/01/whats-new-in-pip-25.0/#pep-639-spdx-license-expressions" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">ichard26.github.io/blog/2025/0</span><span class="invisible">1/whats-new-in-pip-25.0/#pep-639-spdx-license-expressions</span></a></p><p><a href="https://floss.social/tags/Python" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Python</span></a> <a href="https://floss.social/tags/SPDX" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SPDX</span></a></p>
Hugo van Kemenade<p>🐍📦📜 All the pieces (that I use) are now in place for PEP 639 ("Improving License Clarity with Better Package Metadata")!</p><p>I made sure to use latest Hatchling 1.27, added `license-files = [ "LICENSE" ]`, and deleted the deprecated licence Trove classifier.</p><p>Thanks to contributors and maintainers of PyPI, packaging, Hatchling, Twine, PyPI publish GitHub Action, build-and-inspect-python-package and of course <span class="h-card" translate="no"><a href="https://floss.social/@karo" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>karo</span></a></span> for the PEP+spec!</p><p><a href="https://discuss.python.org/t/pep-639-round-3-improving-license-clarity-with-better-package-metadata/53020/172" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">discuss.python.org/t/pep-639-r</span><span class="invisible">ound-3-improving-license-clarity-with-better-package-metadata/53020/172</span></a></p><p><a href="https://mastodon.social/tags/Python" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Python</span></a> <a href="https://mastodon.social/tags/PEP639" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PEP639</span></a> <a href="https://mastodon.social/tags/PyPI" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PyPI</span></a> <a href="https://mastodon.social/tags/SPDX" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SPDX</span></a> <a href="https://mastodon.social/tags/licensing" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>licensing</span></a></p>
anchore<p>T-1 hour for our 2nd webinar in our <a href="https://mstdn.business/tags/SBOM" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SBOM</span></a> series: Understanding SBOMs: Deep Dive with Kate Stewart. Join us to learn about <a href="https://mstdn.business/tags/SPDX" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SPDX</span></a> format, SBOMs for license compliance and how <a href="https://mstdn.business/tags/OSS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OSS</span></a> <a href="https://mstdn.business/tags/LLMs" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LLMs</span></a> impact SBOM generation and analysis. Sign up <a href="https://get.anchore.com/deep-dive-with-kate-stewart/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">get.anchore.com/deep-dive-with</span><span class="invisible">-kate-stewart/</span></a></p>
anchore<p>TOMORROW 🚨 Join our live <a href="https://mstdn.business/tags/webinar" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>webinar</span></a> with Kate Stewart with crucial insights into <a href="https://mstdn.business/tags/SBOMs" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SBOMs</span></a> and their evolving role in modern <a href="https://mstdn.business/tags/software" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>software</span></a> <a href="https://mstdn.business/tags/development" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>development</span></a>. Learn about <a href="https://mstdn.business/tags/SPDX" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SPDX</span></a> and so much more. Save your seat 👉 <a href="https://get.anchore.com/deep-dive-with-kate-stewart/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">get.anchore.com/deep-dive-with</span><span class="invisible">-kate-stewart/</span></a></p>
anchore<p>After our first webinar introduction on <a href="https://mstdn.business/tags/SBOM" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SBOM</span></a> basics, we are continuing our educational series with a deeper dive "Understanding SBOMs: Deep Dive with Kate Stewart". Topics include:<br>- History of SBOM and the development of <a href="https://mstdn.business/tags/SPDX" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SPDX</span></a><br>- Are SBOMs only for <a href="https://mstdn.business/tags/license" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>license</span></a> <a href="https://mstdn.business/tags/compliance" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>compliance</span></a>?<br>- What role do SBOMs play when building systems with safety-critical considerations<br>- How emerging tech like <a href="https://mstdn.business/tags/OSS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OSS</span></a> <a href="https://mstdn.business/tags/LLMs" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LLMs</span></a> can impact SBOM generation and analysis?</p><p>Register Now <a href="https://get.anchore.com/deep-dive-with-kate-stewart/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">get.anchore.com/deep-dive-with</span><span class="invisible">-kate-stewart/</span></a></p>
anchore<p>WEBINAR ALERT 🚨 We're excited to invite you to an exclusive <a href="https://mstdn.business/tags/SBOM" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SBOM</span></a> <a href="https://mstdn.business/tags/webinar" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>webinar</span></a> featuring Kate Stewart, co-founder of <a href="https://mstdn.business/tags/SPDX" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SPDX</span></a> and a leading authority in <a href="https://mstdn.business/tags/software" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>software</span></a> <a href="https://mstdn.business/tags/supplychain" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>supplychain</span></a> <a href="https://mstdn.business/tags/security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>security</span></a>. Save your seat 👉 <a href="https://get.anchore.com/deep-dive-with-kate-stewart/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">get.anchore.com/deep-dive-with</span><span class="invisible">-kate-stewart/</span></a></p>
anchore<p>Kick off 2025 right! Join our weekly <a href="https://mstdn.business/tags/SBOM" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SBOM</span></a> webinar series starting Jan 14. Learn from experts like Kate Stewart (<a href="https://mstdn.business/tags/SPDX" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SPDX</span></a>) &amp; Steve Springett (<a href="https://mstdn.business/tags/CycloneDX" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CycloneDX</span></a>) and master the art of securing your software supply chain. </p><p>Read the blog post to get a sneak peek. ➡️ <a href="https://anchore.com/blog/all-things-sbom-in-2025-a-weekly-webinar-series/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">anchore.com/blog/all-things-sb</span><span class="invisible">om-in-2025-a-weekly-webinar-series/</span></a></p>
Miroslav Suchý<p>Despite the Christmas break, Steve W. released a new <a href="https://rodina-sucha.cz/tags/SPDX" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SPDX</span></a> License List with 19 new licenses. Many of them were found during our work in <a href="https://rodina-sucha.cz/tags/Fedora" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Fedora</span></a>. <a href="https://github.com/spdx/license-list-XML/releases/tag/v3.26.0" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">github.com/spdx/license-list-X</span><span class="invisible">ML/releases/tag/v3.26.0</span></a></p>
anchore<p>WEBINAR ALERT 🚨 We're excited to invite you to an exclusive <a href="https://mstdn.business/tags/SBOM" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SBOM</span></a> <a href="https://mstdn.business/tags/webinar" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>webinar</span></a> featuring Kate Stewart, co-founder of <a href="https://mstdn.business/tags/SPDX" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SPDX</span></a> and a leading authority in <a href="https://mstdn.business/tags/software" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>software</span></a> <a href="https://mstdn.business/tags/supplychain" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>supplychain</span></a> <a href="https://mstdn.business/tags/security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>security</span></a>. Save your seat 👉 <a href="https://get.anchore.com/deep-dive-with-kate-stewart/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">get.anchore.com/deep-dive-with</span><span class="invisible">-kate-stewart/</span></a></p>