🏳️SPDX – Linux Foundation Projects Site

Website faviconspdx.org

[](https://www.linuxfoundation.org/projects?__hstc=74513741.53b852f6e8e06f695b30572182eda598.1741971051277.1741971051277.1741971051277.1&__hssc=74513741.1.1741971051277&__hsfp=1451268799)

[Skip to main content](#ajax-content-wrap)

[Close Search](#)

System Package Data Exchange (SPDX®)

====================================

An open standard capable of representing systems with software components in as SBOMs (Software Bill of Materials) and other AI, data and security references supporting a range of risk management use cases.

The SPDX specification is a freely available international open standard (ISO/IEC 5692:2021).

[Learn More](/about/overview/)

### Learn

Learn more about the structure of SPDX and how to participate.

[ABOUT SPDX](/about/overview/)

### Use

Explore the ways that you can engage with SPDX.

[USE SPDX](/use/overview/)

### Tools

SPDX workgroup tools and others you can use.

[SPDX TOOLS](/use/spdx-tools/)

Areas of Interest

-----------------

SPDX is organized in areas of interest or profiles focused on specific user needs.

[](/learn/areas-of-interest/security/)

[](/learn/areas-of-interest/licensing/)

[](/learn/areas-of-interest/ai/)

[](/learn/areas-of-interest/dataset/)

[](/learn/areas-of-interest/build/)

[](/learn/areas-of-interest/lite/)

Supported by These Foundations

------------------------------

[](/learn/areas-of-interest/core/)

[](/learn/areas-of-interest/software/)

Latest SPDX News

----------------

[In the News](https://spdx.dev/category/in-the-news/)

Mar 5, 2025

[Kudos for Yocto support of SPDX SBOMs](https://spdx.dev/kudos-for-yocto-support-of-spdx-sboms/)

Check out this posting and the accompanying article that give a shout out to the Yocto SBOM work that Joshua Watt briefed us on at the last General Meeting. https://www.linkedin.com/posts/vpetersson\_im-excited-by-yoctos-sbom-capabilities-activity-7298791001526063106-qqsc/#?lipi=urn%3Ali%3Apage%3Ad\_flagship3\_detail\_base%3Brv%2FCdMTgS36PFZd4RZTQPg%3D%3D https://sbomify.com/2025/02/21/mastering-sbom-generation-with-yocto/

[READ MORE](https://spdx.dev/kudos-for-yocto-support-of-spdx-sboms/)

[In the News](https://spdx.dev/category/in-the-news/)

Jan 27, 2025

[SPDX Podcast](https://spdx.dev/spdx-podcast/)

New podcast episode of Nerding Out with Viktor is now live! In Viktor's words: I spoke with Kate Stewart from the The Linux Foundation and Gary ONeall about the evolution of SPDX and its role in software transparency. We covered how SPDX grew from a license compliance tool into a…

[READ MORE](https://spdx.dev/spdx-podcast/)

SPDX Supporters

---------------

[](https://aws.amazon.com/)

[](https://anchore.com/)

[](https://antmicro.com/)

[](https://apiiro.com/)

[](https://www.arm.com/)

[](https://bitergia.com/)

[](https://www.bosch.us/)

[](http://www.caict.ac.cn/)

[](https://canvasslabs.com/)

[](https://cariad.technology/)

[](https://www.castsoftware.com/)

[](https://chainguard.dev/)

[](https://cisco.com/)

[](https://www.cybertrust.co.jp/english/)

[](https://www.dpdk.org/?__hstc=74513741.53b852f6e8e06f695b30572182eda598.1741971051277.1741971051277.1741971051277.1&__hssc=74513741.1.1741971051277&__hsfp=1451268799)

[](https://www.dynatrace.com/)

[](https://www.eclipse.org/)

[](https://www.epam.com/)

[](https://www.ericsson.com/en)

[](https://www.fortressinfosec.com/home)

[](https://fossa.com/)

[](https://foundries.io/)

[](https://about.google/)

[](https://guide-rails.io/)

[](https://here.com/)

[](https://www.hpe.com/us/en/home.html)

[](https://www.hitachi.com/)

[](https://www.huawei.com/en/)

[](https://www.ibm.com/us-en)

[](https://intel.com/?__hstc=74513741.53b852f6e8e06f695b30572182eda598.1741971051277.1741971051277.1741971051277.1&__hssc=74513741.1.1741971051277&__hsfp=1451268799)

[](https://www.kusari.dev/)

[](https://www.lairdconnect.com/)

[](https://www.manifestcyber.com/)

[](https://microsoft.com/)

[](https://connection.mit.edu/home-mission-leadership-and-latest-news)

[](https://www.mitre.org/)

[](https://www.nexb.com/)

[](https://www.paloaltonetworks.com/)

[](https://qosi.kz/)

[](https://www.redhat.com/)

[](https://www.rezilion.com/)

[](https://riscv.org/?__hstc=74513741.53b852f6e8e06f695b30572182eda598.1741971051277.1741971051277.1741971051277.1&__hssc=74513741.1.1741971051277&__hsfp=1451268799)

[](https://www.sap.com/)

[](https://www.scania.com/)

[](https://blog.shebash.io/)

[](https://siemens.com/)

[](https://snyk.io/)

[](https://www.sonatype.com/)

[](https://www.sony.com/en/)

[](https://sourceauditor.com/)

[](https://synopsys.com/)

[](https://www.ti.com/)

[](https://tidelift.com/)

[](https://www.tngtech.com/en/)

[](https://vmware.com/)

[](https://windriver.com/)

[](https://wipro.com/)

[](https://www.xilinx.com/)

[](https://yoctoproject.org/?__hstc=74513741.53b852f6e8e06f695b30572182eda598.1741971051277.1741971051277.1741971051277.1&__hssc=74513741.1.1741971051277&__hsfp=1451268799)

Copyright © 2023 The Linux Foundation® . All rights reserved. The Linux Foundation has registered trademarks and uses trademarks. For a list of trademarks of The Linux Foundation, please see our [Trademark Usage](https://www.linuxfoundation.org/trademark-usage?__hstc=74513741.53b852f6e8e06f695b30572182eda598.1741971051277.1741971051277.1741971051277.1&__hssc=74513741.1.1741971051277&__hsfp=1451268799) page. Linux is a registered trademark of Linus Torvalds. [Privacy Policy](http://www.linuxfoundation.org/privacy?__hstc=74513741.53b852f6e8e06f695b30572182eda598.1741971051277.1741971051277.1741971051277.1&__hssc=74513741.1.1741971051277&__hsfp=1451268799) and [Terms of Use](http://www.linuxfoundation.org/terms?__hstc=74513741.53b852f6e8e06f695b30572182eda598.1741971051277.1741971051277.1741971051277.1&__hssc=74513741.1.1741971051277&__hsfp=1451268799).

[Close Menu](#)

*   [About](#)

    *   [Overview](https://spdx.dev/about/overview/)

    *   [Governance](https://spdx.dev/about/governance/)

    *   [Legal Notices](https://spdx.dev/about/legal-notices/)

*   [Learn](#)

    *   [Overview](https://spdx.dev/learn/overview/)

    *   [Areas of Interest](https://spdx.dev/learn/areas-of-interest/)

        *   [Security](https://spdx.dev/learn/areas-of-interest/security/)

        *   [Licensing](https://spdx.dev/learn/areas-of-interest/licensing/)

        *   [AI](https://spdx.dev/learn/areas-of-interest/ai/)

        *   [Dataset](https://spdx.dev/learn/areas-of-interest/dataset/)

        *   [Build](https://spdx.dev/learn/areas-of-interest/build/)

        *   [Lite](https://spdx.dev/learn/areas-of-interest/lite/)

        *   [Core](https://spdx.dev/learn/areas-of-interest/core/)

        *   [Software](https://spdx.dev/learn/areas-of-interest/software/)

    *   [Handling License Info](https://spdx.dev/learn/handling-license-info/)

*   [Engage](#)

    *   [Participate](https://spdx.dev/engage/participate/)

        *   [Technical Team](https://spdx.dev/engage/participate/technical-team/)

        *   [Legal Team](https://spdx.dev/engage/participate/legal-team/)

        *   [Outreach Team](https://spdx.dev/engage/participate/outreach-team/)

    *   [Join](https://spdx.dev/engage/join/)

*   [Use](#)

    *   [Overview](https://spdx.dev/use/overview/)

    *   [Examples](https://spdx.dev/use/examples/)

    *   [Specifications](https://spdx.dev/use/specifications/)

    *   [License List](https://spdx.org/licenses/)

    *   [Tools](https://spdx.dev/use/spdx-tools/)

*   [News](https://spdx.dev/news/)

*   [Join](https://enrollment.lfx.linuxfoundation.org/?project=spdx&__hstc=74513741.53b852f6e8e06f695b30572182eda598.1741971051277.1741971051277.1741971051277.1&__hssc=74513741.1.1741971051277&__hsfp=1451268799)

Notifications