This summer the SPDX Cryptography Group agreed on how to describe algorithm parameters, tightened its contribution and release processes, and opened the discussion on post-quantum cryptography. Where this report comes from This is an update of the work we do at the SPDX Cryptography Group. SPDX stands for Software Package Data Exchange. Our group is … Continue reading SPDX Cryptographic Algorithm List: summer 2026 update
Tag: open source
Evaluating the EU Open Source Strategy: Strengths and Weaknesses
A summary of my three-part analysis of the EU Open Source Strategy on Tagoross. Real strengths, real design flaws. The sovereignty definition does not fit open source. The legislation, CADA and Chips Act 2.0, encourages or stays silent rather than requires.
SPDX Cryptographic Algorithm List: Spring 2026 Update
The SPDX Cryptographic Algorithm List keeps growing. New cryptoClass values, a structured docs folder, PQC as a new property, and SCANOSS as our first user-contributor. Here is what happened in the past months.
SWHID in Practice: SBOM Verification, CRA Compliance, and Traceability Use Cases
Explore how SWHID is applied in real-world scenarios to improve SBOMs, support Cyber Resilience Act compliance, and enable software traceability. Discover practical use cases across telecom and automotive industries, based on insights from recent industry talks.
SWHID is an open standard, governed under open governance
SWHID is an open ISO standard with transparent governance and free access to its specification. It includes a reference implementation and several tools that developers can use or extend. The community is open, and anyone can join the discussion to help shape the next version of the standard. Read more in this new blog post
Embedded World 2026: Open Source Everywhere, and Two New Topics Dominating the Conversation
Embedded World 2026 in Nuremberg showcased the growing dominance of open source technologies and ecosystems. Various stacks, tools, and frameworks saw increased adoption in embedded systems. Discussions heavily focused on two emerging topics: cybersecurity regulations and artificial intelligence, pointing to major future investments despite some hype.
Description of SWHID: syntax
This article explains the syntax of SWHIDs, describing how the core identifier and optional qualifiers are structured. It shows how SWHIDs can reference software artifacts such as files, directories, revisions, and releases, and how their design enables precise comparison of software
What is the best way to identify software? Introducing SWHID
Modern software is assembled from hundreds of components that organizations often did not write and do not fully control. Identifying those components reliably is becoming a legal requirement. This article introduces SWHID, an open standard for identifying software artifacts.
SPDX Cryptographic Algorithm List: February 2026 Update
The SPDX Cryptographic Algorithm List now includes 120+ algorithms and 7 properties. The community is growing, the roadmap is clear, and the list is moving toward the SPDX website. Here is the February 2026 update.
AGL’s Business Intelligence Journey – Understanding Activity
Measuring activity is not about producing more metrics. It is about supporting better decisions and enabling continuous improvement. We restricted our analysis to main/master to observe validated flow and kept visualizations simple to promote adoption across the community.