Skip to content

SPDX

Software Package Data Exchange

SPDX is an SBOM format developed by the Linux Foundation and published as ISO/IEC 5962:2021 — a standard jointly issued by the International Organization for Standardization and the International Electrotechnical Commission, the two bodies behind most international technical standards. It is the older of the two dominant formats, and it originated in license compliance — the problem of knowing precisely which licenses apply to which components in a shipped product, and under what obligations.

That heritage remains visible. SPDX’s license expression syntax (the identifiers you see as Apache-2.0 or GPL-2.0-only) is used far beyond SPDX documents themselves, including by package managers that have never emitted an SBOM.

Later versions broadened well past licensing to cover the security and supply-chain ground that CycloneDX was built for, and the two formats now overlap substantially.

Its ISO status matters in procurement. Where a contract or regulator names a standard, SPDX is the one likely to be named — which is a large part of why organizations that have standardized on CycloneDX internally still publish SPDX alongside it.

Machine-readable:/glossary/spdx.md

Get started now.

Request access, describe the image you want, and have your first hardened image in about 15 minutes — a typical estimate, before publishing to your clouds. Primcoat builds, hardens, scans, signs, and publishes it, on the operating systems you already run.