LWN.net's Journal
 
[Most Recent Entries] [Calendar View]

Friday, September 10th, 2021

    Time Event
    2:10p
    Security updates for Friday
    Security updates have been issued by Debian (firefox-esr, ghostscript, ntfs-3g, and postorius), Fedora (java-1.8.0-openjdk-aarch32, libtpms, and salt), openSUSE (libaom, libtpms, and openssl-1_0_0), Red Hat (openstack-neutron), SUSE (grilo, java-1_7_0-openjdk, libaom, libtpms, mariadb, openssl-1_0_0, openssl-1_1, and php74-pear), and Ubuntu (firefox and ghostscript).
    2:27p
    [$] The folio pull-request pushback
    When we last caught up with the page folio patch set, it appeared to be on
    track to be pulled into the mainline during the 5.15 merge window. Matthew
    Wilcox duly sent a pull
    request
    in August to make that happen. While it is possible that
    folios could still end up in 5.15, that has not happened as of this writing
    and appears increasingly unlikely. What we got instead was a lengthy
    discussion on the merits of the folio approach.
    4:31p
    SPDX Becomes Internationally Recognized Standard for Software Bill of Materials
    The Linux Foundation has announced that Software Package Data Exchange (SPDX) has become an international standard (ISO/IEC 5962:2021). SPDX has been used in the kernel and other projects to identify the licenses and attach other metadata to software components.
    Between eighty and ninety percent (80%-90%) of a modern application is assembled from open source software components. An SBOM [software bill of materials] accounts for the software components contained in an application — open source, proprietary, or third-party — and details their provenance, license, and security attributes. SBOMs are used as a part of a foundational practice to track and trace components across software supply chains. SBOMs also help to proactively identify software issues and risks and establish a starting point for their remediation.

    SPDX results from ten years of collaboration from representatives across industries, including the leading Software Composition Analysis (SCA) vendors – making it the most robust, mature, and adopted SBOM standard.

    << Previous Day 2021/09/10
    [Calendar]
    Next Day >>

LWN.net   About LJ.Rossia.org