Gary O'Neall
goneall
Contributor to Linux Foundation @spdx and @OpenChain-Project projects. Consultant providing technical due diligence and open source compliance services.
Source Auditor Inc. San Francisco Bay Area
SPDX
spdx
SPDX is an open standard for communicating SBOM information, including provenance, license, security, and other related information. ISO/IEC 5962:2021
Philippe Ombredanne
pombredanne
Passionate FOSS hacker on a mission: healthy & safe software supply chains with FOSS tools, open data & standards @aboutcode-org @package-url @clearlydefine
@aboutcode-org @package-url @clearlydefined @nexB Earth