CtrlK
BlogDocsLog inGet started
Tessl Logo

testland/spdx-format

Reference for the SPDX (Software Package Data Exchange) v2.3 + v3.0 SBOM specification - Linux Foundation-curated, license-focused format covering packages, files, snippets, relationships, license declarations, and (in 3.0) AI / dataset / build / security profiles; supports Tag-Value / JSON / YAML / RDF / Spreadsheet encodings; preferred by US Federal procurement (NIST guidance) and Linux distros. Use when the team's SBOM consumer requires SPDX format (federal procurement, Linux Foundation members, license-compliance focus).

75

Quality

94%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Overview
Quality
Evals
Security
Files

spdx3-profiles-and-tooling.mdreferences/

SPDX 3.0 profiles and tooling

Extended reference extracted from spdx-format. See spdx.dev/specifications for the source spec.

SPDX 3.0 profiles

SPDX 3.0 (2024 release) restructures into composable profiles:

ProfileUse
coreMinimum BOM model
softwareSoftware-specific extensions (approx. SPDX 2.3 packages)
licensingLicense identification + expressions
securityVulnerability + VEX statements
aiAI/ML models, datasets, hyperparameters
datasetDataset-specific metadata
buildBuild provenance (similar to in-toto attestations)

JSON-LD is the primary encoding; tooling support is growing but less mature than 2.3 as of 2026. For most teams, stay on SPDX 2.3 unless 3.0 features are required - 2.3 has broader tooling.

Tooling

ToolUse
syftGenerates SPDX 2.3 (JSON / Tag-Value); cross-source
spdx-toolsReference impl (Python); validation + conversion
spdx-tools-javaJava reference impl
ORT (OSS Review Toolkit)License compliance scanning + SPDX reporting
spdx-sbom-generatorPer-language native generation
ternContainer image SPDX generation
TrivyCross-purpose scanner with SPDX output

SKILL.md

tile.json