SPDX and Software Bill of Materials ISO/IEC 5962L 2021
Kate Stewart · 2022
Abstract This chapter discusses the Software Package Data Exchange (‘SPDX’) specification. SPDX defines a common language for communicating the components, licenses, security information, and copyrights associated with software. The SPDX specification describes the necessary sections and fields to produce a valid SPDX document. This grass-roots effort has had participation over the years from a wide variety of software developers, systems and tool vendors, foundations, and the legal community — all committed to creating a common language for products, components, and software packages to be able to exchange Software Bill of Materials (‘SBOM’) data efficiently and effectively. By providing a common syntax and vocabulary for organisations and communities to share this software bill of materials data, compliance can be automated, and this improved transparency facilitates vulnerability identification and remediation.