WEBVTT

00:00.000 --> 00:10.080
Remember in the morning that I said there is flu going around that COVID going around, our

00:10.080 --> 00:17.400
next presenter has COVID and has asked the organizer to give that all-constellar.

00:17.400 --> 00:19.480
And we're doing everything in this room.

00:19.480 --> 00:29.720
So Kate Grayson takes over and will be presenting what's new in SPDX 3.1.

00:29.720 --> 00:39.560
So this presentation is put together by Karen, who is the co-chair of the SPDX AI and

00:39.560 --> 00:43.080
data set working groups.

00:43.080 --> 00:46.880
And so this is a little bit more AI slanted on this and most of them happen.

00:46.880 --> 00:53.920
But she is also a member of the ISO and the IEEE AI committee and has been working in

00:53.920 --> 00:55.760
open source for over 30 years.

00:55.760 --> 01:01.240
In fact, she was, when I used to work at IBM back in the 90s, she was my boss.

01:01.240 --> 01:02.240
Okay.

01:02.240 --> 01:04.760
So that's how far back we go.

01:04.760 --> 01:09.360
And in about, I guess it was about five years ago, she came up to me and says, I think we're

01:09.360 --> 01:10.960
going to need a new I-bomb.

01:10.960 --> 01:12.600
And I went, yeah, you're right.

01:12.600 --> 01:16.200
We are going to need something like this because we're going to have to start tracking data.

01:16.200 --> 01:20.280
And we're going to have to start tracking things beyond just software.

01:20.280 --> 01:26.640
Because as AI and models are happening, realistically, what's informing them is the data.

01:26.640 --> 01:30.320
And so if you don't track the data, the poison data sets, the other things like that,

01:30.320 --> 01:33.280
these are vulnerabilities that are going to be happening to us.

01:33.280 --> 01:39.800
And so what's there right now for tracking the software and understanding bugs, we're

01:39.800 --> 01:43.640
going to be seeing this coming up more and more with data.

01:43.640 --> 01:46.280
And then we start going like, hold it.

01:46.280 --> 01:50.080
And there's all this virtual hardware out there, is that software or is it hardware?

01:50.080 --> 01:52.720
And we're starting to see systems emerging.

01:52.720 --> 01:57.760
And so we start realizing that more and more on the SPF community, we need to start looking

01:57.760 --> 02:04.680
at things as a system and be able to map model an entire system so that we could actually

02:04.680 --> 02:10.720
handle all the vulnerabilities as well as a lot of the other use cases that are out there.

02:10.720 --> 02:15.120
Because sometimes a certain microchip when it's processing something and it's interacting

02:15.120 --> 02:17.280
with the software, we'll have a vulnerability.

02:17.280 --> 02:20.840
We saw this a lot with the Linux kernel for instance and various other things with some

02:20.840 --> 02:23.480
of the Intel stuff about four years ago.

02:23.480 --> 02:31.040
So moving things towards a knowledge graph with all of these elements, software, hardware,

02:31.040 --> 02:36.600
data has been what's been happening in the SPF world in the last bit.

02:36.600 --> 02:41.840
And we've started moving effectively from set of documents to something that can be represented

02:41.840 --> 02:49.400
in databases, in color operations, and then exported at slices at points in time based

02:49.400 --> 02:52.440
on what you need to talk to people with and communicate with.

02:52.440 --> 02:58.440
It's for data exchange, that SPDX is system package data exchange and packages can be hardware

02:58.440 --> 03:00.320
or software and so forth.

03:00.320 --> 03:08.800
So what we're looking at here with the RC1 release that just happened last weekend, nothing

03:08.800 --> 03:12.160
like falls to them to motivate, actually people to sit and work on weekends to actually

03:12.160 --> 03:14.520
get things done as we do.

03:14.520 --> 03:20.240
So we actually put our release candidate out and it's there for testing and validation.

03:20.240 --> 03:24.160
I don't think we've got completely right yet.

03:24.160 --> 03:29.400
I want to make sure that actually all the release, you know, all the tech team wants

03:29.400 --> 03:33.760
to make sure we do this right, but we do have new profiles now.

03:33.760 --> 03:36.800
In particular, we have a safety profile.

03:36.800 --> 03:43.320
Because the big challenge with security is we need to keep the safety profiles up to date.

03:43.320 --> 03:48.720
So if you've got open source being used in something that is safety critical and there's

03:48.720 --> 03:57.240
a security fix, right now it's really, really manual, it's spreadsheets if you're lucky.

03:57.240 --> 04:03.240
And Nicole will be talking more about the safety profile in a couple of sessions, but

04:03.240 --> 04:10.560
going forward, that is one of the things that is now being finally introduced in here.

04:10.560 --> 04:15.600
And being able to automate the safety use cases is going to require the hardware, the

04:15.600 --> 04:18.680
services, the supply chains and the operations.

04:18.680 --> 04:23.320
And so these are the new profiles that are making their way in that will be available to

04:23.320 --> 04:29.160
be used as part of the SPDX language to express various concepts.

04:29.160 --> 04:35.440
We've updated our security profile, the AI1s plus changes as this data software and core.

04:35.440 --> 04:39.000
We have some more relationships that have been added to again map out of this complex

04:39.000 --> 04:41.680
world we live in.

04:41.680 --> 04:47.480
And then we also are introducing a cryptographic list.

04:47.480 --> 04:50.800
Basically there's a lot of cryptographic elements that are coming in.

04:50.800 --> 04:55.800
And these are similar to the SPDX license list, there's a group that's working on standardizing

04:55.800 --> 05:00.680
the naming for cryptographic elements so that these things can be shared effectively.

05:00.680 --> 05:07.160
And so that's SPDX-31 in a nutshell, okay, I'm done, but not really.

05:07.160 --> 05:14.040
The reason that this is a motivating diagram that I've been using and Karen adopted actually

05:14.040 --> 05:16.760
think about what's happening in a modern car, okay?

05:16.760 --> 05:19.720
And think about all the places that things can go wrong.

05:19.720 --> 05:25.240
You could do the same exercise on a factory floor with a robot, to a large extent, or in

05:25.240 --> 05:27.400
other places.

05:27.400 --> 05:33.240
In these cars, we have software running your dashboard, your infotainments together, but

05:33.240 --> 05:36.480
then you also have a lot of sensors now showing up.

05:36.480 --> 05:42.440
Doing processing on the AI level, being trained to know if I have certain conditions, interact

05:42.440 --> 05:43.440
with the system.

05:43.440 --> 05:52.440
Oh, you're going from point A to point B. Do you have, how many people here don't turn

05:52.440 --> 05:58.840
on their GP, that basically are using a GPS map when they're driving somewhere now?

05:58.840 --> 06:01.080
Right, that think about what's happening there.

06:01.080 --> 06:06.720
It's communicating up to a remote service, to match your position on what's happening,

06:06.720 --> 06:08.440
and you know where you are.

06:08.440 --> 06:12.920
Those sorts of things are functions, and if someone had had something there, that could

06:12.920 --> 06:13.920
be problematic.

06:13.920 --> 06:15.720
You might go in the wrong place.

06:15.720 --> 06:20.680
But, and then the other thing too, especially when you put Mary that, with the fact that

06:20.680 --> 06:25.240
you're starting to see the self-driving, and assisted driving scenarios, and the amount

06:25.240 --> 06:28.880
of training, the data that goes into those, those are all parts of these systems that

06:28.880 --> 06:30.600
we're going towards.

06:30.600 --> 06:35.080
So we want to have transparency and clarity on this type of information and be able to

06:35.080 --> 06:40.400
pull it all together, and that's kind of why we're so saying it has to be more than just

06:40.400 --> 06:45.160
the software, and we have to be able to do a system.

06:45.160 --> 06:48.920
Now, we want to export S-bombs whenever they need to be done, or we want, but we

06:48.920 --> 06:52.040
want to export a data bomb, or an I-bombs.

06:52.040 --> 06:57.040
These are all pieces of this story.

06:57.040 --> 07:03.880
Earlier, I guess last year, Honda did a really nice job because Khabi-san and in Juji-san

07:03.880 --> 07:07.680
went through what Honda is doing and how much open source they're doing and so forth, and

07:07.680 --> 07:15.080
you can sort of see that, you know, about 60% of their products coming in from the stuff

07:15.080 --> 07:18.040
that they were looking at, are working from open source.

07:18.040 --> 07:22.680
So it's definitely there, and it's definitely part of your car today.

07:22.680 --> 07:30.280
I actually have a Honda car, so I'm paying particular interest in this sort of thing.

07:30.280 --> 07:35.000
And so Karen went in, was basically creating a knowledge graph, just to sort of show the

07:35.000 --> 07:38.000
information that they provided and how it all might relate to each other.

07:38.000 --> 07:41.960
And this is a type of information we can now serve capture.

07:41.960 --> 07:47.240
The supply chain is another factor that's building up, and we need to understand people

07:47.320 --> 07:52.560
and organizations because as things go through international supply chains, you want to know

07:52.560 --> 07:56.760
when there may be weaknesses, and that may impact your system.

07:56.760 --> 08:02.000
Similarly, on the hardware side, again, seeing my earlier comments about, you know,

08:02.000 --> 08:06.560
if you've got a bad chip, like I've known chip with, you know, this prediction in your

08:06.560 --> 08:10.040
multi, and some of your microcodes, something like that, you're going to potentially

08:10.040 --> 08:15.080
need to have it updated and work about it, or put it hack in the software and make sure

08:15.160 --> 08:18.160
you can track the two things together.

08:18.160 --> 08:25.480
And so being able to actually encompass hardware, as well as virtual hardware, and have

08:25.480 --> 08:30.640
that tied to the software in your knowledge graph, is what's going to enable you to

08:30.640 --> 08:38.040
bake a lot more clarity in your decisions and track things through your supply chains.

08:38.040 --> 08:46.760
So pulling all of this together is where we're sort of heading with this.

08:46.760 --> 08:59.800
And then, we had one of our companies that we work with, arm, was one of the first ones

08:59.800 --> 09:02.600
that was sort of tracking things and telling us about what we've been to track this stuff

09:02.600 --> 09:06.680
in databases and so forth, but they wanted to track some of their business information

09:06.680 --> 09:09.640
with the software simultaneously.

09:09.640 --> 09:16.040
And so with Bosch and Deloitte, they basically got together, and I guess, I think we've

09:16.040 --> 09:20.040
got a couple of the people here who are doing that in a row, and Marcel, you guys want

09:20.040 --> 09:21.040
to raise your hands.

09:21.040 --> 09:23.040
Oh, yeah, there's a millennial.

09:23.040 --> 09:26.920
So, feel free to come and chat with him about this, but they wanted to track some of

09:26.920 --> 09:30.720
the businesses care about and have it tied with the software rather than having another

09:30.720 --> 09:33.880
system off to the side and trying to put the linkage back in.

09:33.880 --> 09:37.360
So we've provided that piece of the language.

09:37.360 --> 09:41.920
The thing to understand about SPDX is it's a language, okay?

09:41.920 --> 09:46.920
It has various verbs and nouns and ways of representing metadata.

09:46.920 --> 09:51.160
And so we now have the way of having a standard feel to put this information in, so you can

09:51.160 --> 09:52.160
capture it.

09:52.160 --> 09:57.520
Whether you're exported out or not, or share it out wider, it's completely up to you as an

09:57.520 --> 10:00.840
organization, but you have the ability to do it in a standardized way and then share

10:00.840 --> 10:03.960
within organizations.

10:03.960 --> 10:11.080
The other piece that was asked for, and I guess we've started working on it, pre-3O, coming

10:11.080 --> 10:15.760
out, we finally finished it off enough that we're comfortable with it going out is our

10:15.760 --> 10:23.720
software's service, and having ways of basically looking at expressing these remote services

10:23.720 --> 10:26.720
and how they're being used and pulled in.

10:26.720 --> 10:33.600
So those are the pieces that are showing up as fairly new.

10:33.600 --> 10:37.800
And the last piece, which I'm not going to do too much talking because Nicole will be going

10:37.800 --> 10:42.000
to a lot more detail about it shortly, is the safety case.

10:42.000 --> 10:46.800
And this is something that with my day hat on with Zephyr project, as well as the Alyssa

10:46.800 --> 10:52.160
project, I care about a lot so that we can actually make sure that we can get the automation.

10:52.160 --> 10:57.280
And then there's a variety of tooling that is experimenting with us on this.

10:57.280 --> 11:04.600
In particular, I'll show it out to the strict.tool, as well as to the Basel tool, where we're

11:04.600 --> 11:08.120
using SPDX to express this information.

11:08.120 --> 11:11.000
And we'll have two tools that will be able to interchange things and exchange things

11:11.000 --> 11:14.520
so we can get rid of some of the content we can make sure you have things actually work

11:14.520 --> 11:16.800
in a supply chain properly.

11:17.800 --> 11:23.600
And one of the things I sort of talked about at the start was the fact that we now

11:23.600 --> 11:29.320
have over 130 crypto algorithms that have been encompassed and expressed.

11:29.320 --> 11:36.400
This is a standard way of referring to them and we are encoding this enemeration.

11:36.400 --> 11:43.520
We all have our sets of, you know, 512, et cetera, and things like that, but we've just

11:43.600 --> 11:48.520
basically been very precise and so if people have a crypto algorithm, they want to see added,

11:48.520 --> 11:52.520
please reach out to this group, have it added to our master list, and then this is a nice

11:52.520 --> 11:56.840
standard way to refer to all these as we are trying to make sure we have the properties going

11:56.840 --> 11:59.840
forward.

11:59.840 --> 12:06.480
So the rest of the profile hasn't stayed, profiles haven't stayed stable, static, I should

12:06.480 --> 12:07.480
say, they are stable.

12:07.480 --> 12:09.280
The fields are there.

12:09.280 --> 12:12.160
We did do a little bit of clean up on some consistencies that people have pointed

12:12.160 --> 12:19.160
out to us and made things a little bit clear on a few place in our descriptions.

12:19.160 --> 12:22.560
There is also some more examples showing up.

12:22.560 --> 12:28.000
We had an exploiter property that you would be clarified.

12:28.000 --> 12:34.200
Things that people have gotten confused about, we have been trying to fix in the specification.

12:34.200 --> 12:37.840
We also did a bit more work on working with our regulatory alignment.

12:38.840 --> 12:44.240
You'll find there's tables out there that map all the fields at the UAI Act is asking

12:44.240 --> 12:50.560
for, as well as ISO 42.01, so forth to the fields to be used for SPDX to capture this

12:50.560 --> 12:52.560
type of metadata.

12:52.560 --> 12:58.360
And we also are obviously working on improving the provenance and basically traceability.

12:58.360 --> 13:06.000
So obviously here, CRA is a big topic.

13:07.000 --> 13:13.680
We started looking at what's needs to be done for CRA readiness, metadata we need to capture

13:13.680 --> 13:16.680
so that we can actually do it efficiently.

13:16.680 --> 13:22.880
We've also got one of the community volunteers working on doing an example of conformance

13:22.880 --> 13:25.280
to it with SPDX.

13:25.280 --> 13:29.760
So this is very much a work in progress and he would love people to collaborate with.

13:29.760 --> 13:34.040
On it, he tends to work on, it tends to be on the Friday meeting.

13:34.040 --> 13:40.840
On the Friday meetings, we tend to have discussions about it, but it's up in the get-up repo.

13:40.840 --> 13:44.720
And he is basically popular in his example at a very detailed.

13:44.720 --> 13:47.920
His background is in doing product line management.

13:47.920 --> 13:54.120
So managing sets of things at scale as they evolve is what he has been focusing on.

13:54.120 --> 14:00.400
And so he's looking at seeing where the holes are for us so that we can evolve the spec

14:00.400 --> 14:01.400
for that.

14:01.400 --> 14:03.400
And I think we've got most of what we need right now.

14:03.400 --> 14:08.640
The other thing is mapping of the SPDX fields to the CRA clauses.

14:08.640 --> 14:12.600
When these slides are up there, if you click on that link, you'll go to a spreadsheet and

14:12.600 --> 14:14.680
we've been basically going clause by clause.

14:14.680 --> 14:15.680
This is a property and so forth.

14:15.680 --> 14:19.920
And he's sort of using that type of thing with guidance.

14:19.920 --> 14:24.080
There's also a white paper where we've been talking about this that came out last month,

14:24.080 --> 14:29.760
a month before, and it was in the last couple of months that's probably worth looking.

14:29.760 --> 14:33.160
And like I say, we've got our eyes pretty much fixed and focused on this and we want

14:33.160 --> 14:36.560
to basically build it up from there.

14:36.560 --> 14:41.640
So as you hear, tooling is important here for people to actually use this stuff.

14:41.640 --> 14:45.720
This is a language, how do we work with the tools?

14:45.720 --> 14:49.680
One of the things that was coming in is the fact that we need to start looking at the

14:49.680 --> 14:52.520
knowledge graph exploration.

14:52.520 --> 14:59.680
And so one of the other accepted speakers was going to come and demonstrate this tool.

14:59.920 --> 15:00.920
For people.

15:00.920 --> 15:04.760
Unfortunately, they couldn't get a visa.

15:04.760 --> 15:10.560
Fuzzdom doesn't write letters for visas, so they couldn't manage to get over here.

15:10.560 --> 15:14.160
I'm hoping in future that that problem will be resolved and we'll have some more visibility

15:14.160 --> 15:15.160
on that.

15:15.160 --> 15:19.080
But there's a couple of screenshots here from this tool, which will start to let you

15:19.080 --> 15:23.880
actually import the SPDX and then start to explore the knowledge graph and do some of the

15:23.880 --> 15:26.880
conflict resolutions and checking.

15:26.880 --> 15:28.520
And there's a demo available.

15:28.520 --> 15:33.160
If you're interested in the demo show up on the Wednesday call or reach out to me, I'll

15:33.160 --> 15:36.920
put you in touch with GoP and I'll yes, because they've been doing the work and what they're

15:36.920 --> 15:42.600
trying to do is basically have this type of generation and show the derivations as things

15:42.600 --> 15:46.600
move so you can start to work and explore and track.

15:46.600 --> 15:48.880
Because like I say, these things are very, very complex.

15:48.880 --> 15:52.800
We need to have it in a way that's in databases that people couldn't then reason about

15:52.800 --> 15:56.840
it query about it and start to work with these things as scale.

15:56.840 --> 16:00.040
Because it's a lot of data here.

16:00.040 --> 16:06.400
The other piece that's come out of this one of the other members in the project is this

16:06.400 --> 16:12.560
sis auditor tool suite and what they're trying to do is looking at more, these are the

16:12.560 --> 16:15.360
guys that have been behind the hardware side because of their business cases and so

16:15.360 --> 16:19.560
of course, so they've got this tool that they've been basically looking up and making

16:19.560 --> 16:20.560
available.

16:20.560 --> 16:23.720
So check that one out as well.

16:23.760 --> 16:31.040
So what we're doing right now in the SPX-31 phase is we're looking for your feedback.

16:31.040 --> 16:35.160
We're working with some of the OS groups as well as addressing some of the community

16:35.160 --> 16:37.880
feedback that's come in so date.

16:37.880 --> 16:42.560
We are making sure that we're going to line up with the MITRE attack and defend frameworks

16:42.560 --> 16:46.440
and starting to talk about the threats and controls.

16:46.440 --> 16:50.400
So we're trying to take it to the stage where we can get this operationalized in places

16:50.400 --> 16:53.240
where it's going to manage.

16:53.240 --> 17:00.160
Agentic AI is on getting that captured properly with the Trump's and trainings and so

17:00.160 --> 17:05.600
forth in the agents, getting that reflected, making sure we've got what we've got there

17:05.600 --> 17:06.600
is there.

17:06.600 --> 17:10.400
And the other thing we were finding as we were working through the safety side is

17:10.400 --> 17:13.560
a lot of this is just system engineering.

17:13.560 --> 17:16.480
And so they'll be seeing some changes emerging.

17:16.480 --> 17:23.160
Probably around some of those classes we may refactor a little bit of this going forward.

17:23.160 --> 17:27.080
And then there's additional use cases for manufacturers for CRA.

17:27.080 --> 17:31.800
So that's the whiteboard exercises we're doing right now.

17:31.800 --> 17:36.960
In our examples repo, we'll make sure we can handle it cleanly for the CRA and like any

17:36.960 --> 17:42.000
fields that are coming out for things like the Linux kernel generation and so forth.

17:42.000 --> 17:45.560
If there's things that people are having to put in comments or doing a send-up, I'll probably

17:45.560 --> 17:50.640
look at trying to get them included before we hit this release.

17:50.960 --> 17:51.960
I think that's it.

17:51.960 --> 17:57.280
So you'll probably see more work on the procurement and audit as well as gain the hardware

17:57.280 --> 18:01.320
and logistics and so forth and gain these examples up in these areas.

18:01.320 --> 18:06.320
So people can see examples to work from because the feedback has been received that our

18:06.320 --> 18:07.960
documentation sucks.

18:07.960 --> 18:10.720
I don't disagree.

18:10.720 --> 18:16.480
But the best thing is to be examples of what people want to work with.

18:16.480 --> 18:25.120
And if you want to join us, and you're interested in things like threats and controls,

18:25.120 --> 18:29.000
there's a meeting on Monday, Tuesdays, the main tech team meeting and that's where we try

18:29.000 --> 18:34.120
to make all these profiles work together with each other and not conflict too badly.

18:34.120 --> 18:39.240
Wednesdays got the INDATA Sets Network and that's kind of what you're going to be seeing

18:39.240 --> 18:43.600
some of the visualizations on the AI, bomb signs, so forth.

18:43.600 --> 18:49.680
Friday is got the regulatory compliance as well as some functional safety.

18:49.680 --> 18:57.680
And I'm sorry, I will fix that before these slides go up, operations also meets on Friday.

18:57.680 --> 19:03.280
So ended the week tends to be a busy time because other meetings are not happening, I guess.

19:03.280 --> 19:04.680
And that's when the people want to meet.

19:04.680 --> 19:10.840
So these are some basic resources for you, you know, you're here with OpenChain project

19:10.840 --> 19:15.520
for some of these things as well as, you know, there is a white paper on implementing

19:15.520 --> 19:21.520
an AI bomb with SPDX3, if AI is in your radar in Horizon, where we pretty much document

19:21.520 --> 19:24.080
as much as we can there.

19:24.080 --> 19:29.200
And then the general information is there, there's a link to all the main meetings.

19:29.200 --> 19:37.200
And I guess the key takeaways for this are SPDX3 family is a knowledge graph and we're

19:37.200 --> 19:40.600
just building onto the things we can put into these knowledge graphs so we can reason

19:40.600 --> 19:44.160
about them over time.

19:44.160 --> 19:49.160
You can't always so export things into a flat file to share with someone else.

19:49.160 --> 19:53.320
We have actually are trying to make sure that our profiles now can capture the full lifecycle

19:53.320 --> 20:02.200
from design through development, through build, through productization, through end of life.

20:02.200 --> 20:04.200
Because that's what happens in the real world.

20:04.200 --> 20:06.760
We've got to be able to capture that whole spectrum.

20:06.760 --> 20:10.560
So the languages are there for that now.

20:10.560 --> 20:17.560
You need to have the evidence traceability so we can automate four compliance.

20:17.560 --> 20:18.720
Okay?

20:18.720 --> 20:26.160
So we can basically, as a security vulnerability happens, either, you know, something

20:26.160 --> 20:29.920
just new exploited that's in the Linux kernel that's running someone who's software in

20:29.920 --> 20:34.640
your car, the people who are manufacturing it have a way of knowing and then can figure

20:34.640 --> 20:38.920
out whether you have to have an update or not so that your car doesn't get taken over.

20:38.920 --> 20:46.600
It comes down to in some of these cases literally people and not letting people get hurt.

20:46.600 --> 20:49.440
And the traceability is what's going to make this possible.

20:49.440 --> 20:55.720
The other side too is we need to have more tools for automating the metadata capturing.

20:55.720 --> 20:58.760
We are adding more and we'll probably continue to add more.

20:58.760 --> 21:03.360
But capturing the metadata when it's created rather than investigating it after the fact

21:03.360 --> 21:06.080
is going to increase the accuracy.

21:06.080 --> 21:10.720
And I think you've sort of seen some of that from some of the other talks today too.

21:10.720 --> 21:16.320
And getting more examples and guidelines to help manufacturers be ready for the use

21:16.320 --> 21:17.320
CRA.

21:17.320 --> 21:22.680
So these are the things that 3.1 is probably going to be making sure that when we put

21:22.680 --> 21:26.320
out our final release that's hopefully a better picture.

21:26.320 --> 21:31.000
And with that I will wrap it up and ask if anyone has any questions.

21:31.000 --> 21:32.000
Okay, Anthony.

21:32.000 --> 21:41.720
I've got an extension bill that I'll keep us after that.

21:41.720 --> 21:48.320
The crypto list, Cyclone DX had that from IBM and they gave a crypto list for the C-bombs.

21:48.320 --> 21:49.720
And you've got one.

21:49.720 --> 21:52.120
How do we ensure we only have one?

21:52.120 --> 21:55.480
Because I'd be able to donate it to this and work with us.

21:55.480 --> 21:56.480
So they've done it well.

21:56.480 --> 21:57.480
They've done it.

21:57.480 --> 21:58.480
But they can donate.

21:58.480 --> 22:01.040
That's copyright owners so they can basically get.

22:01.040 --> 22:02.040
So why are we okay?

22:02.040 --> 22:03.040
Okay.

22:03.040 --> 22:04.040
But it's okay.

22:04.040 --> 22:05.040
Could we need to try and make sure we have one?

22:05.040 --> 22:06.040
Yes.

22:06.040 --> 22:07.040
I tried to have it.

22:07.040 --> 22:08.040
I tried to.

22:08.040 --> 22:09.040
Yeah.

22:09.040 --> 22:10.040
But we can't start.

22:10.040 --> 22:13.040
So the second thing is we're moving towards risk management.

22:13.040 --> 22:15.040
This is all like a bit of risk management.

22:15.040 --> 22:19.040
So if you start being in business context as well as technical context, we're very

22:19.040 --> 22:23.040
into third part of this management, which is a very different way away from the technical

22:23.040 --> 22:24.040
community.

22:24.040 --> 22:29.040
Are we trying to do too much?

22:30.040 --> 22:32.040
In the real world, we have to do it today.

22:32.040 --> 22:36.040
Are we as efficient as we need to be?

22:36.040 --> 22:38.040
Because we're having different systems.

22:38.040 --> 22:42.040
The same way you might want to keep vulnerabilities with your software.

22:42.040 --> 22:45.040
You might want to be keeping some of the business risk stuff with your software so you can

22:45.040 --> 22:46.040
find it.

22:46.040 --> 22:47.040
Okay.

22:47.040 --> 22:51.040
It's all about can you be practical and can you be efficient as a business?

22:51.040 --> 22:54.040
Whether you want to do it or not, it's all up to your organization.

22:54.040 --> 22:55.040
Okay.

22:55.040 --> 22:57.040
We just want to make sure there's a language to make it happen.

22:58.040 --> 22:59.040
It needs to be done.

22:59.040 --> 23:01.040
Can we make it as simple as possible?

23:01.040 --> 23:03.040
Can we automate as possible to make it efficient?

23:03.040 --> 23:04.040
Any other questions?

23:04.040 --> 23:05.040
Oh, boy.

23:05.040 --> 23:06.040
Okay.

23:06.040 --> 23:07.040
Shout it out.

23:07.040 --> 23:08.040
I have a thing.

23:08.040 --> 23:10.040
You know that slower than that push out.

23:10.040 --> 23:11.040
Yeah?

23:11.040 --> 23:13.040
Is this V3?

23:13.040 --> 23:14.040
Yeah.

23:14.040 --> 23:15.040
Okay.

23:15.040 --> 23:27.040
So for the note, the note explorer thing is right now it's currently V3.

23:27.040 --> 23:32.040
And there are ways of converting from SPDX2 to SPDX3.

23:32.040 --> 23:34.040
There are conversion tools out there.

23:34.040 --> 23:40.040
And so you can convert it to SPDX2 data thing into a 3 and then feed it in.

23:40.040 --> 23:42.040
I should be able to work.

23:42.040 --> 23:47.040
I don't know if they've tested those paths, efficiently but in theory it should work.

23:47.040 --> 23:51.040
We should have the pieces to pull it together.

23:51.040 --> 23:52.040
Okay.

23:52.040 --> 23:55.040
I have enough of questions.

23:55.040 --> 23:56.040
Go for it.

23:56.040 --> 23:58.040
I'm going to publish the graph exploration tool.

23:58.040 --> 24:01.040
The graph exploration tool is being published.

24:01.040 --> 24:07.040
I don't have the basically it's being done as a company.

24:07.040 --> 24:14.040
Gopies working very, very hard with LES to get.

24:14.040 --> 24:16.040
Oh, that's a frame.

24:16.040 --> 24:17.040
Okay.

24:17.040 --> 24:18.040
Sorry.

24:18.040 --> 24:19.040
Yes.

24:19.040 --> 24:22.040
The full intention is to have a public and I was hoping it would be public before here.

24:22.040 --> 24:26.040
They're just having to deal with internal issues inside their corporation.

24:26.040 --> 24:29.040
They're working with.

24:29.040 --> 24:30.040
Yeah.

24:30.040 --> 24:31.040
No.

24:31.040 --> 24:36.040
Like I say, I think we'll probably try to get them to come and do a full

24:36.040 --> 24:41.040
talk at one of the one of the SPDX monthly meetings.

24:41.040 --> 24:46.040
And so I keep an eye open for that and then you can ask all the questions in.

24:46.040 --> 24:48.040
Hopefully it'll be up and get them to look at it shortly.

24:48.040 --> 24:51.040
Sure.

24:51.040 --> 24:54.040
Anything else?

24:54.040 --> 24:55.040
Okay.

24:55.040 --> 24:56.040
Thank you.

24:56.040 --> 25:00.040
Well, thank you.

25:00.040 --> 25:03.040
And thank you to Karen for putting the slides together.

25:06.040 --> 25:08.040
Thank you.

