Hi,
We are still using SPDX 2 since it is an ISO standard and we have tooling 
around it. We have also some custom merge scripts. SPDX 3 is still not an ISO 
standard yet.

Been said that, we will be ok to have it in the mixins as extra meta-layer, to 
reduce the maintenance burden for oe-core while keeping it working for the LTS.

Best regards,
Daniel
________________________________
From: [email protected] 
<[email protected]> on behalf of Richard Purdie 
via lists.openembedded.org 
<[email protected]>
Sent: Thursday, March 12, 2026 4:47 PM
To: [email protected] <[email protected]>; Joshua Watt 
<[email protected]>
Cc: OpenEmbedded Architecture <[email protected]>
Subject: Re: [Openembedded-architecture] Proposal to drop SPDX 2.2 support for 
6.0 LTS

On Thu, 2026-03-12 at 16:41 +0100, Marta Rybczynska via lists.openembedded.org 
wrote:
> Unfortunately SPDX 3.x support isn't mature in most of the tooling I
> know of and you can't import it there (no support in timelines in
> many cases too). The only way to use YP SBOM there is to do a custom
> merge script for 2.2 files and then use that.
>
> In my opinion it's too early to drop yet.

The trouble is that the SPDX 2.2 output is sub optimal with known
issues and we'd be committing to keeping it going for 4 years into a
scenario where people are even likely going to want things added to it
for various reasons.

I'm really worried about the support burden this is going to place on
us, I'd rather get behind SPDX 3 and support that as our output format.
If you need anything else, you could convert from that since all the
information should be there, even if 2.2 can't support all of it.

I appreciate this isn't the answer people want to hear with the tools
situation right now but I don't think keeping going with 2.2 is going
to really help people in the long run either.

Put another way, I'd rather do one thing well and right rather than
have multiple things with known issues.

Cheers,

Richard

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#2301): 
https://lists.openembedded.org/g/openembedded-architecture/message/2301
Mute This Topic: https://lists.openembedded.org/mt/118281203/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-architecture/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to