Philippe Ombredanne
614 posts

Philippe Ombredanne
@pombr
My mission: make it easy to reuse #FOSS #licensed & #secured #FOSS-on-FOSS SCA with ScanCode, https://t.co/GnSVZFAG1u & Package URL CTO @nexB @DejaCode
CA, USA 가입일 Ağustos 2009
1.3K 팔로잉317 팔로워

@Sh1bumi @stevespringett @lorenc_dan @Sh1bumi Hey! ... that's awesome. Let me review the PR and discuss there
@stevespringett thanks for the ping!
@ashcrow ^
English

@stevespringett @lorenc_dan The Go implementation seems to be very outdated. Do you mind adding me to the package url organisation or contacting the current maintainer? There are a few open issues and PRs ..
English
Philippe Ombredanne 리트윗함

Hola Everyone!!!
@gdscheritageit had an amazing session "Guild to GSoC and Opensource" by @MrHritik.
If you are interested about @gsoc and #OpenSource make sure to Check it Out!!!😇
Special Thanks to @pombr and @rachejazz .
Event - bit.ly/GDSCOpen
#GrowWithGDSCHIT #GSOC




English

@OpenSourcePilot on looking first for #FOSS license evidence matters most opensource.com/article/21/7/o… (with a decent #FOSS tool ;) )
English
Philippe Ombredanne 리트윗함

Switzerland plans to anchor public services’ contribution to open source in law
joinup.ec.europa.eu/collection/ope… | OSOR

English

@gpooc @dirkriehle @scancode @fossology @osrgroup @anulman @bitandbang gpooc See github.com/maxhbr/License… and lsc.maxhbr.de that ran some benchmark on license detection that included Ninka for evidence .. this in particular lsc.maxhbr.de/spdx-testfiles…
English

@pombr @dirkriehle @scancode @fossology @osrgroup @anulman @bitandbang Do you have any evidence to back up "mostly out of date"?
It is not like there are new licenses every day.
English

@gpooc @dirkriehle @scancode @fossology @osrgroup @anulman @bitandbang I have some evidence, but there have been no license updates in Ninka for about 4 years. I discover or get report of new FOSS or proprietary license notices or new licenses at least once a week or more on average. 4 years is like a century is this domain.
English

@gpooc @dirkriehle @scancode @fossology @osrgroup @anulman @bitandbang There are (possibly unfortunately) new licenses often enough and even more so many new way to state existing licenses that pop up that Ninka is mostly out of date for any practical use today.
English

@gpooc @dirkriehle @scancode @fossology @osrgroup @anulman @bitandbang Ninka is not maintained and mostly out of date
English

@dirkriehle @scancode @fossology @osrgroup @anulman @bitandbang it might worth to consider Ninka ninka.turingmachine.org to identify licenses in the source code (even though it is in the references, the tool does not seem to be used)
English

@dirkriehle @scancode @fossology @osrgroup @anulman @bitandbang As a maintainer for scancode this is a fascinating read!
I may not agree on some of the conclusions, in particular random sampling, but what is missing is reproducibility. Which tools versions and scanned code version? Where are the scripts to redo this?
English

@scancode @fossology @osrgroup The final thesis is here osr.cs.fau.de/2019/08/07/fin… and a paper is in the works based on extended data @anulman @bitandbang
English

#ScanCode and #AboutCode FOSS projects are a #GSoC mentoring org for the @gsoc 2019 ... Students can sign up until April 9th with their proposals #6118953540124672" target="_blank" rel="nofollow noopener">summerofcode.withgoogle.com/organizations/… 😎Help us scan #code better for origin, #license, #packages and deps and more!
English
Philippe Ombredanne 리트윗함

When it comes to licence identification, @pombr 's Scancode accuracy is hard to beat. Thanks for enterprise.dejacode.com/licenses/publi… #Compliance
English

See also youtube.com/watch?v=Pc1Hof… for the talk video. I had the privilege to chat with @edward_j_kearns and this was great: from satellites to nuclear power plant cooling to solar system climate to submarine drones to the everglades and more: #fascinating person, mission and job! twitter.com/jeffborek/stat…

YouTube
Jeffrey Borek 🇺🇦@jeffborek
Now Edward Kearns, Chief Data Officer @NOAA talking #opensource use and data sharing for public good. Industry and government balance. Modern data licensing. #cloud #policy #CDLA @linuxfoundation @mdolan @NOAAResearch @oceanexplorer
English

@lsaiz BTW, there are now #packageurl (aka. purl github.com/package-url ) #FLOSS implementations that have been contributed in #golang @golang, #java and #python .... Help wanted for #javascript #ruby and others. 😇
English

that's great. I wished CPE would do it, but there is somewhat of a gap between CPEs and the actual reality of packages as used today IMHO... I tried to capture this in this FAQ entry #can-i-use-a-cpe-instead-of-a-purl" target="_blank" rel="nofollow noopener">github.com/package-url/pu…
github.com/package-url twitter.com/stevespringett…
English

@lsaiz I still think CPEs are essential, and #packageurl (aka. purl github.com/package-url ) are a way to bridge the gap between software packages as we know of it and use and officially tracked vulnerable packages in the national vulnerability database #NVD and at @MITREcorp
English

I modestly help there! We are embarking on an idealistic open #FLOSS data journey to help each and every #FLOSS project provide #OpenSource license clarity and more. Join us if you care about this @OpenSourceOrg github.com/clearlydefined/ twitter.com/clearlydefd/st…
ClearlyDefined@clearlydefd
Well, its official. ClearlyDefined (@clearlydefd) is a thing! @opensourceorg just announced (opensource.org/clearlydefined) our status as an Incubator project. Congrats to everyone from across the community for getting to this important milestone. Check out clearlydefined.io.
English
Philippe Ombredanne 리트윗함
Philippe Ombredanne 리트윗함




