User Tools

Site Tools


openchain:sandbox

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revision Previous revision
Next revision
Previous revision
openchain:sandbox [2014/12/02 17:52]
hutch@qti.qualcomm.com
openchain:sandbox [2014/12/09 14:01] (current)
slamons [Yes, some of this matches what I have and/or what I want:]
Line 23: Line 23:
     * Case-by-case scanning of source code for licenses     * Case-by-case scanning of source code for licenses
     * Reputation/​relationship     * Reputation/​relationship
 +
 +*Explaining to developers, managers, and suppliers what their obligations are and what we need from them because many still don't have a clue -- especially some of the smaller vendors and entry level software developers. ​
  
 ==== What do you want to have? ==== ==== What do you want to have? ====
Line 30: Line 32:
       * Policy-compatible,​ suitable to the business/​project goals       * Policy-compatible,​ suitable to the business/​project goals
     * Standard format for reporting license info (SPDX)     * Standard format for reporting license info (SPDX)
 +      * Broadly and well supported (use, tools, knowledge-base,​ advancing)
  
   * Accepted and well understood practices around compliance   * Accepted and well understood practices around compliance
  
   * Trust the upstream chain   * Trust the upstream chain
-    * Minimize the need for [redundant] license scanning/​review +    * Minimized ​need for [redundant] license scanning/​review 
-    * Accepted industry practices +    * Accepted industry practices ​in-use 
-      * Efficient means to satisfy ​to source code availability requirements+      * Efficient means to satisfy source code availability requirements
       * Less critical: upstream contributions,​ not required for trust       * Less critical: upstream contributions,​ not required for trust
-    * Accepted set of "​baseline knowledge"​+    * Accepted set of "​baseline knowledge" ​commonly known 
 + 
 +*Better training for open source in general and suppliers/​developers specifically. ​ It should be concise and easily consumable (e.g. online) with perhaps some questions or interactive Q&A to test understanding. ​  There are a lot of good resources out their already (e.g. great webinars produced by many in this group, LF materials, other materials under CC license or other permissive licenses). ​  We should endeavor to pull the best and create a set of training that we can all leverage for companies to use for internal training and to provide to their suppliers. 
 + 
 +==== Yes, some of this matches what I have and/or what I want: ==== 
 +(please add your ID to this list) 
 + 
 +hutch@qti.qualcomm.com 
 + 
 +spl518@gmail.com
  
openchain/sandbox.1417542742.txt.gz · Last modified: 2014/12/02 17:52 by hutch@qti.qualcomm.com