Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 6 Aug 2025 11:46:27 +0100
From:      Lexi Winter <ivy@freebsd.org>
To:        Ed Maste <emaste@freebsdfoundation.org>
Cc:        freebsd-hackers@freebsd.org
Subject:   Re: RFC: Adopting SPDX for SBOM generation
Message-ID:  <aJMyg1hAGQmSwrlJ@freefall.freebsd.org>
In-Reply-To: <CAAeFWmnnX2=qj53je_nCgRBFG2g_%2BEx2CMxfUhLAahnB3obNQw@mail.gmail.com>
References:  <CAAeFWmnnX2=qj53je_nCgRBFG2g_%2BEx2CMxfUhLAahnB3obNQw@mail.gmail.com>

next in thread | previous in thread | raw e-mail | index | archive | help

[-- Attachment #1 --]
Ed Maste:
> We would appreciate your feedback on:
> [...]
> - Integration with existing FreeBSD development workflows

> Any concerns or suggestions for the proposed approach

this may be too obvious to be worth mentioning, but just in case:
whatever tooling is used should make it possible to correctly populate
the license metadata in pkgbase during build.  at the moment we set this
to BSD2CLAUSE for every package, which is very wrong.

[-- Attachment #2 --]
-----BEGIN PGP SIGNATURE-----

iHUEABYKAB0WIQSyjTg96lp3RifySyn1nT63mIK/YAUCaJMyfwAKCRD1nT63mIK/
YPqTAPwKGe7BssoPhibMEjEJn8okA5jm/pPp4grvie+Vv8S1zAEAwqGiXeBCp22G
ELyZdeMmKC1Gi3y5woiLQiFZR0CLvwM=
=v0/s
-----END PGP SIGNATURE-----

Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?aJMyg1hAGQmSwrlJ>