If you have difficulty in submitting comments on draft standards you can use a commenting template and email it to admin.start@bsigroup.com. The commenting template can be found here.

We use cookies to give you the best experience and to help improve our website

Find out what cookies we use and how to disable them

BS ISO/IEC 5962 ISO/IEC 5962 Information technology. SPDX® Specification V3.0

Source:
ISO/IEC
Committee:
ICT/1 - Information systems co-ordination
Categories:
Software
Comment period start date:
Comment period end date:
Number of comments:
0

Comment by:

Scope

The System Package Data Exchange™ (SPDX®) specification defines an open standard for communicating bill of materials (BOM) information for different topic areas.

SPDX defines an underlying data model as well as multiple serialization formats to encode that data model.

SPDX metadata includes details about creation and distribution, including the following:

• software composition, for collections of

• software (Packages), individual Files, and portions of files (Snippets) software build information

• artificial intelligence (AI) models

• datasets

• creator, supplier and distributor identity information

• provenance and integrity

• licenses and copyrights, including a curated list of licenses and exceptions

• security vulnerabilities, defects, and other quality data

• relationships between system elements

• software usage and lifecycle

• mechanisms to enable annotating SPDX elements and linking between multiple SPDX Documents

Read draft and comment

Comment on proposal

Required form fields are indicated by an asterisk (*) character.


Please email further comments to: debbie.stead@bsigroup.com

Follow standard

You are now following this standard. Weekly digest emails will be sent to update you on the following activities:

You can manage your follow preferences from your Account. Please check your mailbox junk folder if you don't receive the weekly email.

Unfollow standard

You have successfully unsubscribed from weekly updates for this standard.

Error