mastodon.world is one of the many independent Mastodon servers you can use to participate in the fediverse.
Generic Mastodon server for anyone to use.

Server stats:

11K
active users

#spdx

2 posts2 participants0 posts today

How do #SBOMs fit into #AI, hardware, and critical infrastructure?
SBOMs transformed from static documents to dynamic, database-driven knowledge systems that can scale with today's complex software ecosystems. This session will provide a forward-looking perspective on where SBOM technology is heading, focusing on recent developments in SPDX 3.0 and upcoming features in SPDX 3.1.
Kate Stewart (#SPDX) and Alan Pope (Anchore) discuss the expanding role of SBOMs in modern ... get.anchore.com/future-of-sbom

The #LinuxFoundation is accepted as mentoring organization in the Google Summer of Code #GSoC #GSoC2025!

Amazing project ideas are waiting for awesome contributors: From #OpenPrinting, #Zephyr, Automotive Grade Linux #AGL, Industrial I/O #IIO, Sound Open Firmware #SOF, #SPDX, Automating Linux kernel workflows #kworkflow

summerofcode.withgoogle.com/pr

Project ideas and how to apply:
wiki.linuxfoundation.org/gsoc/

If interested to be a contributor or mentor contact us ASAP! Do not wait for the deadline.

summerofcode.withgoogle.comGoogle Summer of CodeGoogle Summer of Code is a global program focused on bringing more developers into open source software development.
Replied in thread

@sam I’m personally a fan of the #SPDX approach - have a base license that can be modified “WITH” a “license exception”. In fact I’ve been casually on the hunt for a “no AI usage of any kind” license exception that I can add on to my (mostly MPL-2.0) licensed projects.

🐍📦📜 All the pieces (that I use) are now in place for PEP 639 ("Improving License Clarity with Better Package Metadata")!

I made sure to use latest Hatchling 1.27, added `license-files = [ "LICENSE" ]`, and deleted the deprecated licence Trove classifier.

Thanks to contributors and maintainers of PyPI, packaging, Hatchling, Twine, PyPI publish GitHub Action, build-and-inspect-python-package and of course @karo for the PEP+spec!

discuss.python.org/t/pep-639-r

#Python#PEP639#PyPI

After our first webinar introduction on #SBOM basics, we are continuing our educational series with a deeper dive "Understanding SBOMs: Deep Dive with Kate Stewart". Topics include:
- History of SBOM and the development of #SPDX
- Are SBOMs only for #license #compliance?
- What role do SBOMs play when building systems with safety-critical considerations
- How emerging tech like #OSS #LLMs can impact SBOM generation and analysis?

Register Now get.anchore.com/deep-dive-with