Software Supply Chain
SPDX
System Package Data Exchange
Foundation
Global
Linux Foundation
Since 2011
A bill-of-materials standard for describing software components, licences, copyrights and security references. SPDX 3.0 generalised the model to cover builds, AI models, datasets and services alongside packages.
The dataset and AI profiles matter here: they are the closest thing to a standard way of shipping a machine-readable declaration of what data a model was trained on.
At a glance
- Category
- Software Supply Chain
- Jurisdiction
- Global
- Governance
- Linux Foundation
- Status
- SPDX 3.0 (2024), 3.1 in review; version 2.2.1 published as ISO/IEC 5962:2021
- First released
- 2011
Links
Related frameworks
Other entries under Software Supply Chain.
- CycloneDX: CycloneDX Bill of Materials
- SLSA: Supply-chain Levels for Software Artifacts
- Sigstore
- in-toto: in-toto Attestation Framework
See SPDX in context
Open the interactive Data Landscape for Regulation to compare SPDX against every other framework, or grab the raw JSON. Certification schemes and editions move — follow the source links before relying on this page.