SPDX and Software Bill of Materials ISO/IEC 5962L 2021

Kate Stewart · 2022

Abstract This chapter discusses the Software Package Data Exchange (‘SPDX’) specification. SPDX defines a common language for communicating the components, licenses, security information, and copyrights associated with software. The SPDX specification describes the necessary sections and fields to produce a valid SPDX document. This grass-roots effort has had participation over the years from a wide variety of software developers, systems and tool vendors, foundations, and the legal community — all committed to creating a common language for products, components, and software packages to be able to exchange Software Bill of Materials (‘SBOM’) data efficiently and effectively. By providing a common syntax and vocabulary for organisations and communities to share this software bill of materials data, compliance can be automated, and this improved transparency facilitates vulnerability identification and remediation.

Read the paper · More papers on PaperTik