About SPDX and Black Duck

Document and Share BOMs

The Software Package Data Exchange® (SPDX®) is an evolving standard for communicating the open source content, licenses and copyrights associated with a software package. The purpose of the standard is to help companies in a software supply chain more easily comply with software licensing obligations. 

Software Package Data Exchange (SPDX)

SPDX provides a uniform approach to documenting and sharing a software bill of materials (BOM), making it more efficient for supply chain partners to communicate. The standard is developed and maintained by the SPDX workgroup of the Linux Foundation and is a critical element of the foundation’s Open Compliance Program.
 
Black Duck’s Support of SPDX
Black Duck has been instrumental in developing SPDX through participation in the SPDX workgroup. Our involvement includes:
  • Chairing the SPDX workgroup
  • Actively participating in the three SPDX teams: Technical, Business and Legal
  • Authoring the first SPDX whitepaper
  • Developing and evolving the structure of the spdx.org website and supporting the SPDX beta process
  • Implementing SPDX software BOM in the Black Duck® Suite at no additional cost to customers
 
For More Information:

Product Integrations Learn About
Our Product Integrations

Latest Tweets

Black Duck Software (8 hours ago)
Free and open source compliance: action steps | DLA Piper's @LawandLifeSV via JDSupra http://t.co/lZFcNmnoDL #GPL #opensource
Black Duck Software (9 hours ago)
How healthy is your code? Are you running old versions of #opensource code? Start your free risk profile assessment: http://t.co/zTw5ddyucS
Black Duck Software (10 hours ago)
RT @jfrog: We welcome @black_duck_sw on board as Rose Sponsors for #swampUP JFrog User Conference http://t.co/dyRtsVtTZg
Black Duck Software (11 hours ago)
“With Shellshock, you didn’t have many eyes” @LinuxPundit on the critical #vulnerability & the state of OSS security http://t.co/k5pqviOMtY
Black Duck Software (12 hours ago)
RT @megandegruttola: Are you arming your security team w/the info and tools needed to secure your use of open source? http://t.co/Db28bA50Th

Black Duck Software
8 New England Executive Park
Burlington, MA 01803

Contact Us

Legal Notices | Privacy Policy | Site map
Open Source Delivers | Open HUB
Open Source Think Tank