Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
196 changes: 196 additions & 0 deletions hardware/2026/2026-07-31.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,196 @@
# SPDX Hardware Team Meeting — 2026-07-31

**PR:**

## Attendees

* [x] Alfred Strauch
* [x] Steven Carbno
* [x] Bob Martin (MITRE)
* [ ] Dishoung White II
* [ ] Kate Stewart
* [ ] Victor Lu
* [x] Jim Vitrano
* [ ] Amit Kumar
* [ ] Issac Asay
* [ ] Lucas Tate
* [ ] Apoorav Trehan
* [ ] Alex Volykin
* [ ] Allan Friedman
* [ ] Cassie Crossley
* [ ] Felix Reichmanna
* [ ] Makki Elfatih
* [x] Greg Shue
* [ ] Riley Barello-Myers
* [ ] Henk Berkholz
* [ ] Dan Hopkins
* [ ] Courtney Ng
* [ ] Andrew Viater
* [ ] Raymond Sheh
* [ ] Stanislav Pankevich
* [ ] Karen Bennet
* [ ] Marcel Kurzamann
* [ ] Raymond Sheh
* [ ] Michael Pease (NIST Standards)
* [ ] Jenn Power (Red Hat)
* [ ] Arthit Suriyawongkul

## Agenda

### Previous Minutes

* Approve the previous meeting minutes:

* [SPDX Meetings PR #1131](https://github.com/spdx/meetings/pull/1131)

### SPDX Changes Merged During the Previous Week

* `ProjectOwner` and `productAgent`: Apply consistent language and expand abbreviations.

* [SPDX 3 Model PR #1296](https://github.com/spdx/spdx-3-model/pull/1296)

### Hardware and Software Profile Topics

* The Zephyr project has a custom action for CO2. Bulk hardware may require an SPDX enhancement to better capture CO2 produced during an action.

* [SPDX 3 Visualization](https://kartben.github.io/spdx3_viz/)
* A theoretical firmware class would need to be defined by the Software Profile.

* This is a crossover issue that should be brought to the Tech Team.

### Pull Request for Review

* Conformance Example 1 preliminary system requirements:

* [SPDX Examples PR #155](https://github.com/spdx/spdx-examples/pull/155)

### Issues from Microsoft’s SPDX Review Document

* **[3.1-RC1] Editorial cleanup: clarity-only naming and description suggestions (7.6)**

* [Issue #1403](https://github.com/spdx/spdx-3-model/issues/1403)
* **Rename vague SupplyChain property names (`current*`, `previous*`, and `planned*`)**

* [Issue #1390](https://github.com/spdx/spdx-3-model/issues/1390)
* **[3.1-RC1] Scope the `CreateProcess` description to software, datasets, and models**

* [Issue #1389](https://github.com/spdx/spdx-3-model/issues/1389)
* **[3.1-RC1] Add a redacted or opaque element type for supply-chain black-boxing**

* [Issue #1388](https://github.com/spdx/spdx-3-model/issues/1388)
* **[3.1-RC1] Restore `suppliedBy` and `releaseTime` on Hardware for traceability**

* [Issue #1384](https://github.com/spdx/spdx-3-model/issues/1384)
* **[3.1-RC1] Relax `Hardware.partNumber` for `BulkHardware` commodities**

* [Issue #1383](https://github.com/spdx/spdx-3-model/issues/1383)
* **[3.1-RC1] Add a Firmware class linked to its hardware**

* [Issue #1382](https://github.com/spdx/spdx-3-model/issues/1382)
* **[3.1-RC1] Add `RepairAction` and `ReturnAction` to the SupplyChain namespace**

* [Issue #1371](https://github.com/spdx/spdx-3-model/issues/1371)
* **[3.1-RC1] Add Incoterms and customs-role modeling to `TransportAction`**

* [Issue #1372](https://github.com/spdx/spdx-3-model/issues/1372)
* **[3.1-RC1] Editorial cleanup: Model Operations, Functional Safety, and Hardware (7.4)**

* [Issue #1401](https://github.com/spdx/spdx-3-model/issues/1401)

### Additional Review Topics

* Review Microsoft’s SPDX Review document:

* [Microsoft SPDX Review](https://docs.google.com/document/d/1WU1V-8LbmB0uMhKpKIri7qiBdU40GEG8XwZHyOXrJcM/edit?tab=t.0)
* Model certificate and root-of-trust annotations.
* OpenChain has parallel Cyber Resilience Act and functional-safety initiatives:

* [OpenChain Document](https://docs.google.com/document/d/1Wog28BZ9NQhY3tN9Wc2NDml2phBDuvYu9zkXSON5z5o/edit?tab=t.0)
* [CRA Checklist Requirement PA 1.0](https://github.com/OpenChain-Project/CRA-Compliance/blob/main/CRA_Checklist_Requirement_PA%201.0.md)

## Notes

### Announcements and Previous Business

* A vertical standard related to interfaces is expected to be released in September 2026.
* The previous meeting minutes were approved.
* The group reviewed and approved items and pull requests from the previous week.
* The definition of `productAgent` was improved.

### Digital Product Passport and CO2 Units

* Based on Digital Product Passport requirements, an addition related to CO2 and units of measure may be needed.
* The information may need to be attached to lifecycle data and represented hop by hop.
* The group will check with the Digital Product Passport initiative regarding units of measure for CO2.

### Zephyr and Firmware

* The group discussed the Zephyr use case.
* The group discussed whether firmware should be treated as hardware or software.
* A bit pattern has logical behavior; therefore, firmware may be considered a combination of hardware and software, similar to a CD-ROM.
* Data in firmware is not self-modifying.
* The applicable subset or classification remains to be determined.
* The terms “product” and “system” need to be defined.
* This may require discussion during a Tech Team meeting.

### Microsoft Review Issues

#### Issue #1384 — Hardware Traceability

* The issue concerns the SupplyChain Profile.
* The use of Hardware in the profile is intentional.
* Close the issue.

#### Issue #1388 — Supply-Chain Black-Boxing

* The issue extends beyond the SupplyChain Profile.
* It is a Core Profile issue.
* Consider it for SPDX 3.2.

#### Issue #1390 — SupplyChain Property Names

* The property descriptions need clarification.
* The issue requires discussion by a larger group.

#### Issue #1389 — `CreateProcess` Scope

* The SupplyChain Profile is intended to apply to both hardware and software.
* Close the issue.

#### Issue #1372 — Incoterms and Customs Roles

* Custody transfer is addressed through the responsibility category.
* Custody remains the relevant concept.

### Bulk Hardware and Part Numbers

* Bulk hardware requires some form of part number.
* The description and summary of `partNumber` need improvement.
* The group discussed which agency or party is responsible for defining the category or type of an item.
* Using a third-party taxonomy may complicate citations.
* Every item needs a part number that can function as a stock-keeping unit.
* A part number is related to the quantity or specific unit, such as a bottle or truck.
* The relevant unit type must be identified.
* CO2 is a poor part number because it does not meaningfully represent a part number or SKU.
* The definition of `partNumber` should be improved to describe a specific good.
* The original equipment manufacturer provides the definition.
* `TransportAction` may require a unit for the distance traveled.
* The group discussed an appropriate measure for bulk products:

* What constitutes a unit of bulk product?
* Does the absence of a serial number indicate a bulk product measured by volume?
* The `productAgent` is responsible for defining the product, unit, and identifying number.
* The group discussed whether bulk products require a specification, description, or measurement.

## Action Items

* Check with the Digital Product Passport initiative regarding units of measure for CO2:

* [UN Transparency Protocol Overview](https://unctad.org/news/unlocking-transparency-promise-un-transparency-protocol-global-trade)
* [UN Transparency Protocol Repository](https://github.com/uncefact/spec-untp)
* Review the identified pull requests and submit suggestions or approvals.

## Decision and Follow-Up Items

* Continue the discussion of bulk-product part numbers at the next meeting.
* Review the Digital Product Passport materials.