SBOMit/specification

Update specification license to Community Specification License 1.0

Closed this issue · 7 comments

LF started IP/license review of the SBOMit spec and provided feedback that the SBOMit specification needs to be Community Specification License 1.0 licensed per the OpenSSF charter (Section 5, Page 9):
https://cdn.platform.linuxfoundation.org/agreements/openssf.pdf

@JustinCappos, @jeffcshapiro is the reviewer who provided the feedback. I also worked with @hythloda to coordinate the review.

I would use this issue for discussion ossf/tac#191 .

Let's wait and not update the license yet until we resolve the issue of which license is best for you, and see if an exception has been / will be granted if you stay with CC-BY-4.0.

Okay, from our community standpoint, the license that the CNCF uses (see clause 11f https://github.com/cncf/foundation/blob/main/charter.md ) is what several community members are strongly in favor of. So, this is what is best for us.

@jeffcshapiro Are you able to approve this license or if not, can you escalate this to someone who can?

Understood. Keep in mind the CNCF charter is referring to documentation, not a specification.

It's not up to me, most likely the OpenSSF governing board makes the decision. I will follow up with Amanda @hythloda and anyone else necessary to help get this resolved.

Closed by #14