Software Supply Chain

SPDX

System Package Data Exchange

Foundation Global Linux Foundation Since 2011

A bill-of-materials standard for describing software components, licences, copyrights and security references. SPDX 3.0 generalised the model to cover builds, AI models, datasets and services alongside packages.

The dataset and AI profiles matter here: they are the closest thing to a standard way of shipping a machine-readable declaration of what data a model was trained on.

At a glance

Category
Software Supply Chain
Jurisdiction
Global
Governance
Linux Foundation
Status
SPDX 3.0 (2024), 3.1 in review; version 2.2.1 published as ISO/IEC 5962:2021
First released
2011

Links

Related frameworks

Other entries under Software Supply Chain.

See SPDX in context

Open the interactive Data Landscape for Regulation to compare SPDX against every other framework, or grab the raw JSON. Certification schemes and editions move — follow the source links before relying on this page.