News: 0001636557

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Fedora 45 Considering Use Of PURL Metadata For Uniquely Identifying Software Packages

([Fedora] 6 Hours Ago Package-URL)


One of the Fedora 45 change proposals under consideration at the moment is making adding PURL "Package-URL" to Fedora's package metadata for simplifying the mapping between upstream projects and Fedora packages.

The PURL specification aims to serve as a "mostly universal" URL to help in identifying and tracking software packages across diverse ecosystems and tooling. It intends to be as a simple, consistent, and flexible approach for identifying software packages via a standardized URL-based syntax:

PURL can work across different package management solutions / protocols such as npm, Nuget, Gem, Docker Hub, PyPi, and more. It can optionally specify a particular version of the package and more.

PURL is seeing adoption across different open-source projects from SPDX SBOM formats to other tooling and software vulnerability databases. The hope with Fedora beginning to generate PURL metadata can help it map upstream projects to packages.

"This Change aims at making it easier and more reliable to identify which packages contain code from what projects. This allows for more reliable identification of packages affected by security vulnerabilities. Additionally, this metadata might be interesting for generating SBOMs for content included in (container) images."

The change proposal for beginning to generate PURL metadata with Fedora 45 is currently under discussion via [1]this thread and still needs to go through a vote by the Fedora Engineering and Steering Committee.

Those wishing to learn more about the Package-URL "PURL" specification itself can find it on [2]GitHub .



[1] https://discussion.fedoraproject.org/t/f45-change-proposal-adopt-purl-metadata-system-wide/192435

[2] https://github.com/package-url/purl-spec



HOGAN'S HEROES DRINKING GAME --
Take a shot every time:

-- Sergeant Schultz says, "I knoooooowww nooooothing!"
-- General Burkhalter or Major Hochstetter intimidate/insult Colonel Klink.
-- Colonel Klink falls for Colonel Hogan's flattery.
-- One of the prisoners sneaks out of camp (one shot for each prisoner to go).
-- Colonel Klink snaps to attention after answering the phone (two shots
if it's one of our heroes on the other end).
-- One of the Germans is threatened with being sent to the Russian front.
-- Corporal Newkirk calls up a German in his phoney German accent, and
tricks him (two shots if it's Colonel Klink).
-- Hogan has a romantic interlude with a beautiful girl from the underground.
-- Colonel Klink relates how he's never had an escape from Stalag 13.
-- Sergeant Schultz gives up a secret (two shots if he's bribed with food).
-- The prisoners listen to the Germans' conversation by a hidden transmitter.
-- Sergeant Schultz "captures" one of the prisoners after an escape.
-- Lebeau pronounces "colonel" as "cuh-loh-`nell".
-- Carter builds some kind of device (two shots if it's not explosive).
-- Lebeau wears his apron.
-- Hogan says "We've got no choice" when someone claims that the plan is
impossible.
-- The prisoners capture an important German, and sneak him out the tunnel.