SPDX Vocabulary Specification

Version:
DRAFT (09 Aug 2011 16:05 UTC master 7e28d2)
Latest Version:
http://spdx.org/rdf/terms

Copyright © 2010-2011 Linux Foundation and its Contributors. All other rights are expressly reserved.

Abstract

This specification describes the SPDX language, defined as a dictionary of named properties and classes using W3C's RDF Technology.

SPDX is a designed to allow the exchange of data about software packages. This information includes general information about the package, licensing information about the package as a whole, a manifest of files contained in the package and licensing information related to the contained files.

The spdx prefix used in this document expands to http://spdx.org/rdf/terms#. Any terms in this document without an explicit prefix may be assumed to be in the spdx namespace.

Other vocabularies used by this one

Classes

Class: SpdxDocument

An SdpxDocument is a summary of the contents, provenance, ownership and licensing analysis of a specific software package. This is, effectively, the top level of SPDX information.

Status:
testing
Properties:

Class: CreationInfo

A CreationInfo provides information about the individuals, organizations and tools involved in the creation of an SpdxDocument.

Status:
testing
Properties:

Class: Package

A Package represents a collection of software files that are delivered as a single functional component.

Status:
testing
Properties:

Class: ExtractedLicensingInfo

An ExtractedLicensingInfo represents a license or licensing notice that was found in the package. Any license text that is recognized as a license may be represented as a License rather than an ExtractedLicensingInfo.

Status:
testing
Properties:

Class: File

A File represents a named sequence of information that is contained in a software package.

Status:
testing
Properties:

Class: Review

A Review represents an audit and signoff by an individual, organization or tool on the information in an SpdxDocument.

Status:
testing
Properties:

Class: License

A License represents a software copyright license. This class is used by the SPDX license list to represent standard licenses.

Status:
testing
Properties:

Class: Checksum

A Checksum is simple value that allows the contents of a file to be authenticated. Even small changes to the content of the file will change it's checksum value.

Status:
testing
Properties:

Class: PackageVerificationCode

A PackageVerificationCode is a value that allows authentication of the package. This differs from the Checksum in that it uses an algorithm that allows the SPDX file to be embedded in the package. This verification code is produced using a cryptographic hash algorithm applied to a manifest of the package. Some files in the package (e.g. the SPDX files) are explicitly excluded from the verification code. This allows those excluded files to not impact the verification code.

Status:
testing
Properties:

Class: ConjunctiveLicenseSet

A ConjunctiveLicenseSet represents a set of licensing information all of which apply.

This class refines rdfs:Container.

Status:
testing
Properties:
  • member
    Cardinality: Mandatory, two or more.

Class: DisjunctiveLicenseSet

A DisjunctiveLicenseSet represents a set of licensing information where only one license applies at a time. This class implies that the recipient gets to choose one of these licenses they would prefer to use.

This class refines rdfs:Container.

Status:
testing
Properties:
  • member
    Cardinality: Mandatory, two or more.

Class: AnyLicenseInfo

The AnyLicenseInfo class includes all resources that represent licensing information.

Status:
testing
Members
All resources in any of the following classes:

Class: SimpleLicenseInfo

The SimpleLicenseInfo class includes all resources that represent simple, atomic, licensing information.

Status:
testing
Members
All resources in any of the following classes:

Properties

Property: algorithm

Identifies the algorithm used to produce the subject Checksum.

Currently, SHA-1 is the only supported algorithm. It is anticipated that other algorithms will be supported at a later time.

Status:
testing
Domain:
Checksum
Range:
spdx:checksumAlgorithm_sha1

Property: artifactOf

Indicates the project in which the file originated.

Tools must preserve doap:hompage and doap:name properties and the URI (if one is known) of doap:Project resources that are values of this property. All other properties of doap:Projects are not directly supported by SPDX and may be dropped when translating to or from some SPDX formats.

Status:
testing
Domain:
File
Range:
doap:Project

Property: checksum

The checksum property provides a mechanism that can be used to verify that the contents of a File or Package have not changed.

Status:
testing
Domain:
Any of:
Range:
Checksum

Property: checksumValue

The checksumValue property provides a hex encoded digest value produced using a specific algorithm.

Status:
testing
Domain:
Checksum
Range:
xsd:hexBinary

Property: created

The date and time at which the SpdxDocument was created. This value must in UTC and have 'Z' as its timezone indicator.

Status:
testing
Domain:
CreationInfo
Range:
xsd:dateTime

Property: copyrightText

The text of copyright declarations recited in the Package or File.

Status:
testing
Domain:
Any of:
Range:
Any of:

Property: creationInfo

The creationInfo property relates an SpdxDocument to a set of information about the creation of the SpdxDocument.

Status:
testing
Domain:
SpdxDocument
Range:
CreationInfo

Property: creator

The name and, optionally, contact information of a person, organization or tool that created, or was used to create, the SpdxDocument.

Status:
testing
Domain:
CreationInfo
Range:
xsd:string

Property: dataLicense

The licensing under which the creator of this SPDX document allows related data and/or database to be used. By default this is PDDL.

Status:
testing
Domain:
SpdxDocument
Range:
AnyLicenseInfo

Property: describesPackage

The describesPackage property relates an SpdxDocument to the package which it describes.

Status:
testing
Domain:
SpdxDocument
Range:
Package

Property: description

Provides a detailed description of the package.

Status:
testing
Domain:
Package
Range:
xsd:string

Property: downloadLocation

The URI at which this package is available for download. Private (i.e., not publicly reachable) URIs are acceptable as values of this property.

The values http://spdx.org/rdf/terms#none and http://spdx.org/rdf/terms#noassertion may be used to specify that the package is not downloadable or that no attempt was made to determine its download location, respectively.

Status:
testing
Domain:
Package
Range:
xsd:anyURI

Property: extractedText

Verbatim license or licensing notice text that was discovered.

Status:
testing
Domain:
ExtractedLicensingInfo
Range:
xsd:string

Property: fileName

The name of the file relative to the root of the package.

Status:
testing
Domain:
File
Range:
xsd:string

Property: fileType

The type of the file.

Status:
testing
Domain:
File
Range:
One of:

Property: hasExtractedLicensingInfo

Indicates that a particular ExtractedLicensingInfo was defined in the subject SpdxDocument.

Status:
testing
Domain:
SpdxDocument
Range:
ExtractedLicensingInfo

Property: hasFile

Indicates that a particular file belongs to a package.

Status:
testing
Domain:
Package
Range:
File

Property: licenseComments

The licenseComments property allows the preparer of the SPDX document to describe why the licensing in spdx:licenseConcluded was chosen.

Status:
testing
Domain:
Any of:
Range:
xsd:string

Property: licenseConcluded

The licensing that the preparer of this SPDX document has concluded, based on the evidence, actually applies to the package.

Status:
testing
Domain:
Any of:
Range:
Any of:

Property: licenseDeclared

The licensing that the creators of the software in the package, or the packager, have declared. Declarations by the original software creator should be preferred, if they exist.

Status:
testing
Domain:
Package
Range:
Any of:

Property: licenseId

A short name for the license that is at least 3 characters long and made up of the characters from the set 'a'-'z', 'A'-'Z', '0'-'9', '+', '_', '.', and '-'. Formally, all licenseId values must match the regular expression: [-+_.a-zA-Z0-9]{3,}

Status:
testing
Domain:
Range:
xsd:string

Property: licenseText

The full text of the license.

Status:
testing
Domain:
License
Range:
xsd:string

Property: licenseInfoFromFiles

The licensing information that was discovered directly within the package. There will be an instance of this property for each distinct value of all licenseInfoInFile properties of all files contained in the package.

Status:
testing
Domain:
Package
Range:
Any of:

Property: licenseInfoInFile

Licensing information that was discovered directly in the subject file.

Status:
testing
Domain:
File
Range:
Any of:

Property: member

A license, or other licensing information, that is a member of the subject license set.

Status:
testing
Domain:
Any of:
Range:
AnyLicenseInfo
Refines:
rdfs:member

Property: name

The full name of the package including version information.

Status:
testing
Domain:
Package
Range:
xsd:string

Property: packageFileName

The base name of the package file name. For example, zlib-1.2.5.tar.gz.

Status:
testing
Domain:
Package
Range:
xsd:string

Property: packageVerificationCode

A manifest based checksum (the algorithm is defined in section 4.7 of the full specification) of the package. This allows consumers of this data to determine if a package they have in hand is identical to the package from which the data was produced. This algorithm works even if the SPDX document is included in the package. This algorithm is described in detail in the SPDX specification.

Status:
testing
Domain:
Package
Range:
PackageVerificationCode

Property: packageVerificationCodeExcludedFile

A file that was excluded when calculating the package verification code. This is usually a file containing SPDX data regarding the package. If a package contains more than one SPDX file all SPDX files must be excluded from the package verification code. If this is not done each recalculation of the package verification code in one file will require the other to be recalculated to be valid which will require the original which will require the original file's be recalculated, ad infinitum.

Status:
testing
Domain:
PackageVerificationCode
Range:
xsd:string

Property: packageVerificationCodeValue

The actual package verification code as a hex encoded value.

Status:
testing
Domain:
PackageVerificationCode
Range:
xsd:hexBinary

Property: originator

The name and, optionally, contact information of the person or organization that originally created the package.

Status:
testing
Domain:
Package
Range:
Any of:

Property: referencesFile

Indicates that a particular file belongs as part of the set of analyzed files in the SpdxDocument.

Status:
testing
Domain:
SpdxDocument
Range:
File

Property: reviewDate

The date and time at which the SpdxDocument was reviewed. This value must be in UTC and have 'Z' as its timezone indicator.

Status:
testing
Domain:
Review
Range:
xsd:dateTime

Property: reviewed

The review property relates a SpdxDocument to the review history.

Status:
testing
Domain:
SpdxDocument
Range:
Review

Property: reviewer

The name and, optionally, contact information of the person who performed the review.

Status:
testing
Domain:
Review
Range:
xsd:string

Property: sourceInfo

Allows the producer(s) of the SPDX document to describe how the package was acquired and/or changed from the original source.

Status:
testing
Domain:
Package
Range:
xsd:string

Property: specVersion

Identifies the version of this specification that was used to produce this SPDX document. Currently the only supported value is SPDX-1.0.

Status:
testing
Domain:
SpdxDocument
Range:
xsd:string

Property: summary

Provides a short description of the package.

Status:
testing
Domain:
Package
Range:
xsd:string

Property: supplier

The name and, optionally, contact information of the person or organization that is the immediate supplier of this package. The supplier may be different than originator when the software has been repackaged. For example if you get glibc from RedHat, RedHat is the Package Supplier, but FSF is the originator.

Status:
testing
Domain:
Package
Range:
Any of:

Property: versionInfo

Provides an indication of the version of the package that is described by this SpdxDocument.

Status:
testing
Domain:
Package
Range:
xsd:string

Individuals

Individual: checksumAlgorithm_sha1

Indicates the algorithm used was SHA-1

Status:
testing

Individual: fileType_archive

Indicates the file is an archive file.

Status:
testing

Individual: fileType_binary

Indicates the file is not a text file. spdx:filetype_archive is preferred for archive files even though they are binary.

Status:
testing

Individual: fileType_other

Indicates the file is not a source, archive or binary file.

Status:
testing

Individual: fileType_source

Indicates the file is a source code file.

Status:
testing

Individual: noassertion

Indicates that the preparer of the SPDX document is not making any assertion regarding the value of this field.

Status:
testing

Individual: none

When this value is used as the object of a property it indicates that the preparer of the SpdxDocument believes that there is no value for the property. This value should only be used if there is sufficient evidence to support this assertion.

Status:
testing