by Martin Michlmayr
Organisations across the globe are creating and distributing products that include open source software. To ensure compliance with the open source licenses, each company needs to evaluate exactly what open source licenses and copyrights are included – resulting in duplicated effort and redundancy. This talk will provide an overview of the Software Package Data Exchange (SPDX) specification. This specification provides a common format to share information about the open source licenses and copyrights that are included in any software package, with the goal of saving time and improving data accuracy. This talk will review the current status of the initiative; discuss the benefits to organizations using open source and share information