Standard · 3.0.1

SPDX 3.0 System Bill of Materials

Maintained by SPDX Project · Linux Foundation

What it helps you do

SPDX supports a system bill of materials spanning software, builds, AI models, datasets, identities, provenance, integrity, licenses, security findings, and relationships.

  • AI / ML
  • Cross-cutting
PlanAcquireHarmonizeExchangeLearn + reuse

01

Where it fits and where it does not

Use these four checks before committing implementation time.

Use it when
Reproducible and reviewable supply-chain records for an AI release that combines scientific data, preprocessing code, dependencies, models, and licenses.
Limits
It is a broad BOM model rather than a scientific metadata profile; generated inventories require verification, and license metadata does not authorize use of sensitive human data.
Best for
AI / ML and Cross-cutting teams working across Exchange → Learn + reuse.
Maturity
ScalingUsable now, but adoption or tooling is still developing. Pilot the exact stack first.

02

See it in the workflow

This view shows the input, the change the standard introduces, and the resulting output.

  1. InputWhat starts

    AI / ML and Cross-cutting source data, metadata, and local mappings

  2. SPDXWhat changes

    Use SPDX as a pinned standard across Exchange → Learn + reuse

  3. OutputWhat becomes possible

    A handoff the next system or team can validate against the same release

Readiness gateIt is a broad BOM model rather than a scientific metadata profile; generated inventories require verification, and license metadata does not authorize use of sensitive human data.

03

A concrete example

A release publishes an SPDX 3.0.1 document linking the dataset, model, source code, build inputs, dependencies, integrity evidence, licenses, and their relationships, then validates the JSON-LD representation.

Why it matters: Makes the data-model-software supply chain inspectable by tools and agents, while scientific validity, consent, bias, and model performance need separate evidence.

04

What it fits with

Complements RO-Crate research context, Croissant dataset loading metadata, and PROV-O or OpenLineage process history.

05

Implementation starter

Start with one bounded handoff. Pin, test, and review it before scaling.

  1. Define one handoff, its accountable owner, and the decision SPDX must support.

  2. Pin the exact version and companion artifacts: 3.0.1.

  3. Map one representative input to the required standard artifacts.

  4. Test the result against the canonical source and record every exception.

  5. Preserve the source data, mappings, and review evidence before scaling.

06

Test the main limitation

Risk

It is a broad BOM model rather than a scientific metadata profile; generated inventories require verification, and license metadata does not authorize use of sensitive human data.

Test

Run one representative end-to-end pilot and record exactly where SPDX loses context, needs an extension, or depends on another standard.

Risk

Machine-readable output may still be unfit for analysis or ML.

Test

Test the output for missing context, provenance, terminology alignment, time leakage, and the intended downstream decision. Makes the data-model-software supply chain inspectable by tools and agents, while scientific validity, consent, bias, and model performance need separate evidence.

07

Official resources

Specifications, diagrams, examples, and guides from the organizations that maintain them.

  • Primary source3.0.1

    SPDX Specification 3.0.1

    Official publisher or steward guidance for this standard profile.

    Publisher
    SPDX Project · Linux Foundation
    Open official source

Next action

Put this profile in context

Compare its role with adjacent standards or place it inside an end-to-end data pathway before choosing an implementation.