THE SPDX WIKI IS NO LONGER ACTIVE. ALL CONTENT HAS BEEN MOVED TO https://github.com/spdx
Difference between revisions of "Technical Team/SPDX RDF Vocabularies and Terms/1.1/Terms"
Line 1: | Line 1: | ||
− | + | <h1>SPDX® Vocabulary Specification</h1><dl><dt>Version:</dt><dd>1.1 (Final)</dd><dt>Latest Version:</dt><dd><a href="http://spdx.org/rdf/terms">http://spdx.org/rdf/terms</a></dd></dl><p>Copyright © 2010-2012 Linux Foundation and its Contributors. All other rights are expressly reserved.</p><p>Licensed under the <a href="http://creativecommons.org/licenses/by/3.0/">Creative Commons Attribution License 3.0 unported</a>.</p><h2>Introduction</h2><div><p>This specification describes the SPDX® language, defined as a dictionary of named properties and classes using W3C's RDF Technology.</p><p>SPDX® is a designed to allow the exchange of data about software packages. This information includes general information about the package, licensing information about the package as a whole, a manifest of files contained in the package and licensing information related to the contained files.</p></div><h3>About this document</h3><p>This is an RDFa annotated HTML document that defines the SPDX® RDF vocabulary using the Web Ontology Language. It is RDFa 1.0 compatible and may be consumed by any RDFa 1.0 compatible parser. The same information is available in <a href="./terms.rdf" rel="owl:sameAs">RDF/XML</a> and <a href="./terms.ttl" rel="owl:sameAs">Turtle</a> formats if those are more convenient.</p><p>RDF it is a widely used data interchange technology which allows heterogeneous systems communicate even when their internal models/implementations are incompatible. For more details on RDF, this <a href="http://notabug.com/2002/rdfprimer/">RDF primer</a> helpful for gaining a basic understanding.</p><h3>Prefixes used in this document</h3><p>The <code>spdx</code> prefix used in this document expands to <code>http://spdx.org/rdf/terms#</code>. Any terms in this document without an explicit prefix may be assumed to be in the <code>spdx</code> namespace.</p><h4>Other vocabularies used by this one</h4><p>In addition to the <code>spdx</code> prefix the following prefixes are also used. Each of these reference another vocabulary imported and used by the SPDX vocabulary.</p><ul><li><span> <a href="http://trac.usefulinc.com/doap">DOAP</a> </span></li><li><span> <a href="http://www.w3.org/TR/rdf-schema">RDFS</a> </span></li></ul><h2>Classes</h2><ul><li><a href="#SpdxDocument"><code>SpdxDocument</code></a></li><li><a href="#CreationInfo"><code>CreationInfo</code></a></li><li><a href="#Package"><code>Package</code></a></li><li><a href="#ExtractedLicensingInfo"><code>ExtractedLicensingInfo</code></a></li><li><a href="#Checksum"><code>Checksum</code></a></li><li><a href="#PackageVerificationCode"><code>PackageVerificationCode</code></a></li><li><a href="#File"><code>File</code></a></li><li><a href="#Review"><code>Review</code></a></li><li><a href="#License"><code>License</code></a></li><li><a href="#ConjunctiveLicenseSet"><code>ConjunctiveLicenseSet</code></a></li><li><a href="#DisjunctiveLicenseSet"><code>DisjunctiveLicenseSet</code></a></li><li><a href="#AnyLicenseInfo"><code>AnyLicenseInfo</code></a></li><li><a href="#SimpleLicenseInfo"><code>SimpleLicenseInfo</code></a></li></ul><div><h3 id="SpdxDocument">Class: <code>SpdxDocument</code></h3><p>An <code>SpdxDocument</code> is a summary of the contents, provenance, ownership and licensing analysis of a specific software package. This is, effectively, the top level of SPDX information.</p><dl><dt>Status:</dt><dd>stable</dd><dt>Properties:</dt><dd><ul><li><p><a href="#specVersion" rel="owl:onProperty"><code>specVersion</code></a> <span class="cardinality">Cardinality: Mandatory, <span>one</span></span></p></li><li><p><a href="#dataLicense" rel="owl:onProperty"><code>dataLicense</code></a> <span class="cardinality">Cardinality: Mandatory, <span>one</span></span></p></li><li><p><a href="http://www.w3.org/TR/rdf-schema/#ch_comment"><code>rdfs:comment</code></a> <span class="cardinality">Cardinality: Optional, <span>zero or one</span></span></p></li><li><p><a href="#creationInfo" rel="owl:onProperty"><code>creationInfo</code></a> <span class="cardinality">Cardinality: Mandatory, <span>one</span></span></p></li><li><p><a href="#describesPackage" rel="owl:onProperty"><code>describesPackage</code></a> <span class="cardinality">Cardinality: Mandatory, <span>one</span></span></p></li><li><p><a href="#hasExtractedLicensingInfo"><code>hasExtractedLicensingInfo</code></a> <span class="cardinality">Cardinality: Optional, zero or more</span></p></li><li><p><a href="#referencesFile" rel="owl:onProperty"><code>referencesFile</code></a> <span class="cardinality">Cardinality: Mandatory, <span>one</span> or more</span></p></li><li><p><a href="#reviewed"><code>reviewed</code></a> <span class="cardinality">Cardinality: Optional, zero or more.</span></p></li></ul></dd></dl></div><div><h3 id="CreationInfo">Class: <code>CreationInfo</code></h3><p>A <code>CreationInfo</code> provides information about the individuals, organizations and tools involved in the creation of an <a href="#SpdxDocument"><code>SpdxDocument</code></a>.</p><dl><dt>Status:</dt><dd>stable</dd><dt>Properties:</dt><dd><ul><li><p><a href="#creator" rel="owl:onProperty"><code>creator</code></a> <span class="cardinality">Cardinality: Mandatory, <span>one or more</span></span></p></li><li><p><a href="#created" rel="owl:onProperty"><code>created</code></a> <span class="cardinality">Cardinality: Mandatory, <span>one</span></span></p></li><li><p><a href="http://www.w3.org/TR/rdf-schema/#ch_comment"><code>rdfs:comment</code></a> <span class="cardinality">Cardinality: Optional, <span>zero or one</span></span></p></li></ul></dd></dl></div><div><h3 id="Package">Class: <code>Package</code></h3><p>A <code>Package</code> represents a collection of software files that are delivered as a single functional component.</p><dl><dt>Status:</dt><dd>stable</dd><dt>Properties:</dt><dd><ul><li><p><a href="#name" rel="owl:onProperty"><code>name</code></a> <span class="cardinality">Cardinality: Mandatory, <span>one</span></span></p></li><li><p><a href="#versionInfo" rel="owl:onProperty"><code>versionInfo</code></a> <span class="cardinality">Cardinality: Optional, <span>zero or one</span></span></p></li><li><p><a href="#packageFileName" rel="owl:onProperty"><code>packageFileName</code></a> <span class="cardinality">Cardinality: Optional, <span>zero or one</span></span></p></li><li><p><a href="#supplier" rel="owl:onProperty"><code>supplier</code></a> <span class="cardinality">Cardinality: Optional, <span>zero or one</span></span></p></li><li><p><a href="#originator" rel="owl:onProperty"><code>originator</code></a> <span class="cardinality">Cardinality: Optional, <span>zero or one</span></span></p></li><li><p><a href="#downloadLocation" rel="owl:onProperty"><code>downloadLocation</code></a> <span class="cardinality">Cardinality: Mandatory, <span>one</span></span></p></li><li><p><a href="#packageVerificationCode" rel="owl:onProperty"><code>packageVerificationCode</code></a> <span class="cardinality">Cardinality: Mandatory, <span>one</span></span></p></li><li><p><a href="#checksum" rel="owl:onProperty"><code>checksum</code></a> <span class="cardinality">Cardinality: Optional, <span>zero or one</span></span></p></li><li><p><a href="#sourceInfo" rel="owl:onProperty"><code>sourceInfo</code></a> <span class="cardinality">Cardinality: Optional, <span>zero or one</span></span></p></li><li><p><a href="#licenseConcluded" rel="owl:onProperty"><code>licenseConcluded</code></a> <span class="cardinality">Cardinality: Mandatory, <span>one</span></span></p></li><li><p><a href="#licenseInfoFromFiles" rel="owl:onProperty"><code>licenseInfoFromFiles</code></a> <span class="cardinality">Cardinality: Mandatory, <span>one or more</span></span></p></li><li><p><a href="#licenseDeclared" rel="owl:onProperty"><code>licenseDeclared</code></a> <span class="cardinality">Cardinality: Mandatory, <span>one</span></span></p></li><li><p><a href="#licenseComments" rel="owl:onProperty"><code>licenseComments</code></a> <span class="cardinality">Cardinality: Optional, <span>zero or one</span> </span></p></li><li><p><a href="#copyrightText" rel="owl:onProperty"><code>copyrightText</code></a> <span class="cardinality">Cardinality: Mandatory, <span>one</span></span></p></li><li><p><a href="#summary" rel="owl:onProperty"><code>summary</code></a> <span class="cardinality">Cardinality: Optional, <span>zero or one</span></span></p></li><li><p><a href="#description" rel="owl:onProperty"><code>description</code></a> <span class="cardinality">Cardinality: Optional, <span>zero or one</span></span></p></li><li><p><a href="#hasFile" rel="owl:onProperty"><code>hasFile</code></a> <span class="cardinality">Cardinality: Mandatory, <span>one or more</span></span></p></li></ul></dd></dl></div><div><h3 id="ExtractedLicensingInfo">Class: <code>ExtractedLicensingInfo</code></h3><p>An <code>ExtractedLicensingInfo</code> represents a license or licensing notice that was found in the package. Any license text that is recognized as a license may be represented as a <a href="#License"><code>License</code></a> rather than an <code>ExtractedLicensingInfo</code>.</p><dl><dt>Status:</dt><dd>stable</dd><dt>Properties:</dt><dd><ul><li><p><a href="#licenseId" rel="owl:onProperty"><code>licenseId</code></a> <span class="cardinality">Cardinality: Mandatory, <span>one</span></span></p></li><li><p><a href="#name" rel="owl:onProperty"><code>name</code></a> <span class="cardinality">Cardinality: Optional, <span>zero or more</span></span></p></li><li><p><a href="#extractedText" rel="owl:onProperty"><code>extractedText</code></a> <span class="cardinality">Cardinality: Mandatory, <span>one</span></span></p></li><li><p><a href="http://www.w3.org/TR/rdf-schema/#ch_comment"><code>rdfs:comment</code></a> <span class="cardinality">Cardinality: Optional, <span>zero or one</span></span></p></li><li><p><a href="http://www.w3.org/TR/rdf-schema/#ch_seealso"><code>rdfs:seeAlso</code></a> <span class="cardinality">Cardinality: Optional, <span>zero</span> or more</span></p></li></ul></dd></dl></div><div><h3 id="File">Class: <code>File</code></h3><p>A <code>File</code> represents a named sequence of information that is contained in a software package.</p><dl><dt>Status:</dt><dd>stable</dd><dt>Properties:</dt><dd><ul><li><p><a href="#fileName" rel="owl:onProperty"><code>fileName</code></a> <span class="cardinality">Cardinality: Mandatory, <span>one</span> </span></p></li><li><p><a href="http://www.w3.org/TR/rdf-schema/#ch_comment"><code>rdfs:comment</code></a> <span class="cardinality">Cardinality: Optional, <span>zero or one</span></span></p></li><li><p><a href="#fileType" rel="owl:onProperty"><code>fileType</code></a> <span class="cardinality">Cardinality: Optional, <span>zero or one</span> </span></p></li><li><p><a href="#checksum" rel="owl:onProperty"><code>checksum</code></a> <span class="cardinality">Cardinality: Mandatory, <span>one</span> </span></p></li><li><p><a href="#licenseConcluded" rel="owl:onProperty"><code>licenseConcluded</code></a> <span class="cardinality">Cardinality: Mandatory, <span>one</span> </span></p></li><li><p><a href="#licenseInfoInFile" rel="owl:onProperty"><code>licenseInfoInFile</code></a> <span class="cardinality">Cardinality: Mandatory, <span>one or more</span> </span></p></li><li><p><a href="#licenseComments" rel="owl:onProperty"><code>licenseComments</code></a> <span class="cardinality">Cardinality: Optional, <span>zero or one</span> </span></p></li><li><p><a href="#copyrightText" rel="owl:onProperty"><code>copyrightText</code></a> <span class="cardinality">Cardinality: Mandatory, <span>one</span></span></p></li><li><p><a href="#artifactOf" rel="owl:onProperty"><code>artifactOf</code></a> <span class="cardinality">Cardinality: Optional, <span>zero or one</span> </span></p></li></ul></dd></dl></div><div><h3 id="Review">Class: <code>Review</code></h3><p>A <code>Review</code> represents an audit and signoff by an individual, organization or tool on the information in an <a href="#SpdxDocument"><code>SpdxDocument</code></a>.</p><dl><dt>Status:</dt><dd>stable</dd><dt>Properties:</dt><dd><ul><li><p><a href="#reviewer" rel="owl:onProperty"><code>reviewer</code></a> <span class="cardinality">Cardinality: Mandatory, <span>one</span></span></p></li><li><p><a href="#reviewDate" rel="owl:onProperty"><code>reviewDate</code></a> <span class="cardinality">Cardinality: Mandatory, <span>one</span></span></p></li><li><p><a href="http://www.w3.org/TR/rdf-schema/#ch_comment"><code>rdfs:comment</code></a> <span class="cardinality">Cardinality: Optional, <span>zero or one</span></span></p></li></ul></dd></dl></div><div><h3 id="License">Class: <code>License</code></h3><p>A <code>License</code> represents a copyright license. The <a href="http://spdx.org/licenses">SPDX license list website</a> is annotated with these properties (using <a href="http://www.w3.org/TR/2008/REC-rdfa-syntax-20081014/">RDFa</a>) to allow license data published there to be easily processed.</p><p>The license list is populated in accordance with the <a href="http://spdx.org/wiki/spdx-license-list">License List fields guidelines</a>. These guidelines are not normative and may change over time. SPDX tooling should not rely on values in the license list conforming to the current guidelines.</p><dl><dt>Status:</dt><dd>stable</dd><dt>Properties:</dt><dd><ul><li><p><a href="#licenseId" rel="owl:onProperty"><code>licenseId</code></a> <span class="cardinality">Cardinality: Mandatory, <span>one</span> </span></p><p>A short human readable unique name for the license.</p><p> </p></li><li><p><a href="#name" rel="owl:onProperty"><code>name</code></a> <span class="cardinality">Cardinality: Optional, <span>zero or one</span> </span></p><p>A full name, including version if applicable, of the license.</p></li><li><p><a href="#licenseText" rel="owl:onProperty"><code>licenseText</code></a> <span class="cardinality">Cardinality: Mandatory, <span>one</span> </span></p><p>Full text of the license.</p><p> </p></li><li><p><a href="#isOsiApproved" rel="owl:onProperty"><code>isOsiApproved</code></a> <span class="cardinality">Cardinality: Mandatory, <span>one</span> </span></p><p>Indicates if the <a href="http://opensource.org/">OSI</a> has approved the license.</p></li><li><p><a href="#standardLicenseHeader" rel="owl:onProperty"><code>standardLicenseHeader</code></a> <span class="cardinality">Cardinality: Optional, <span>zero or one</span> </span></p><p>License author's preferred text to indicated that a file is covered by the license.</p><p></></p></li><li><p><a href="http://www.w3.org/TR/rdf-schema/#ch_comment"><code>rdfs:comment</code></a> <span class="cardinality">Cardinality: Optional, <span>zero or one</span></span></p><p>Factual notes regarding the license such as release date.</p></li><li><p><a href="http://www.w3.org/TR/rdf-schema/#ch_seealso"><code>rdfs:seeAlso</code></a> <span class="cardinality">Cardinality: Optional, <span>zero</span> or more</span></p><p>A link to the license on another website.</p></li></ul></dd></dl></div><div><h3 id="Checksum">Class: <code>Checksum</code></h3><p>A <code>Checksum</code> is value that allows the contents of a file to be authenticated. Even small changes to the content of the file will change it's checksum. This class allows the results of a variety of checksum and cryptographic message digest algorithms to be represented.</p><dl><dt>Status:</dt><dd>stable</dd><dt>Properties:</dt><dd><ul><li><p><a href="#algorithm" rel="owl:onProperty"><code>algorithm</code></a> <span class="cardinality">Cardinality: Mandatory, <span>one</span></span></p></li><li><p><a href="#checksumValue" rel="owl:onProperty"><code>checksumValue</code></a> <span class="cardinality">Cardinality: Mandatory, <span>one</span></span></p></li></ul></dd></dl></div><div><h3 id="PackageVerificationCode">Class: <code>PackageVerificationCode</code></h3><p>A manifest based verification code (the algorithm is defined in section 4.7 of the full specification) of the package. This allows consumers of this data and/or database to determine if a package they have in hand is identical to the package from which the data was produced. This algorithm works even if the SPDX document is included in the package.</p><dl><dt>Status:</dt><dd>stable</dd><dt>Properties:</dt><dd><ul><li><p><a href="#packageVerificationCodeExcludedFile"><code>packageVerificationCodeExcludedFile</code></a> <span class="cardinality">Cardinality: Optional, zero or more</span></p></li><li><p><a href="#packageVerificationCodeValue" rel="owl:onProperty"><code>packageVerificationCodeValue</code></a> <span class="cardinality">Cardinality: Mandatory, <span>one</span></span></p></li></ul></dd></dl></div><div><h3 id="ConjunctiveLicenseSet">Class: <code>ConjunctiveLicenseSet</code></h3><p>A <code>ConjunctiveLicenseSet</code> represents a set of <a href="#AnyLicenseInfo">licensing information</a> all of which apply.</p><p>This class refines <a href="http://www.w3.org/TR/rdf-schema/#ch_container"><code>rdfs:Container</code></a>.</p><dl><dt>Status:</dt><dd>stable</dd><dt>Properties:</dt><dd><ul><li><p><a href="#member" rel="owl:onProperty"><code>member</code></a> <span class="cardinality">Cardinality: Mandatory, <span>two</span> or more.</span></p></li></ul></dd></dl></div><div><h3 id="DisjunctiveLicenseSet">Class: <code>DisjunctiveLicenseSet</code></h3><p>A <code>DisjunctiveLicenseSet</code> represents a set of <a href="#AnyLicenseInfo">licensing information</a> where only one license applies at a time. This class implies that the recipient gets to choose one of these licenses they would prefer to use.</p><p>This class refines <a href="http://www.w3.org/TR/rdf-schema/#ch_container"><code>rdfs:Container</code></a>.</p><dl><dt>Status:</dt><dd>stable</dd><dt>Properties:</dt><dd><ul><li><p><a href="#member" rel="owl:onProperty"><code>member</code></a> <span class="cardinality">Cardinality: Mandatory, <span>two</span> or more.</span></p></li></ul></dd></dl></div><div><h3 id="AnyLicenseInfo">Class: <code>AnyLicenseInfo</code></h3><p>The <code>AnyLicenseInfo</code> class includes all resources that represent licensing information.</p><dl><dt>Status:</dt><dd>stable</dd><dt>Members</dt><dd>All resources in any of the following classes:<ul><li><a href="#License" rel="rdf:first"><code>License</code></a></li><li><a href="#ExtractedLicensingInfo" rel="rdf:first"><code>ExtractedLicensingInfo</code></a></li><li><a href="#ConjunctiveLicenseSet" rel="rdf:first"><code>ConjunctiveLicenseSet</code></a></li><li><a href="#DisjunctiveLicenseSet" rel="rdf:first"><code>DisjunctiveLicenseSet</code></a></li></ul></dd></dl></div><div><h3 id="SimpleLicenseInfo">Class: <code>SimpleLicenseInfo</code></h3><p>The <code>SimpleLicenseInfo</code> class includes all resources that represent simple, atomic, licensing information.</p><dl><dt>Status:</dt><dd>stable</dd><dt>Members</dt><dd>All resources in any of the following classes:<ul><li><a href="#License" rel="rdf:first"><code>License</code></a></li><li><a href="#ExtractedLicensingInfo" rel="rdf:first"><code>ExtractedLicensingInfo</code></a></li></ul></dd></dl></div><h2>Properties</h2><ul><li><a href="#algorithm"><code>algorithm</code></a></li><li><a href="#artifactOf"><code>artifactOf</code></a></li><li><a href="#checksum"><code>checksum</code></a></li><li><a href="#checksumValue"><code>checksumValue</code></a></li><li><a href="#copyrightText"><code>copyrightText</code></a></li><li><a href="#created"><code>created</code></a></li><li><a href="#creationInfo"><code>creationInfo</code></a></li><li><a href="#creator"><code>creator</code></a></li><li><a href="#dataLicense"><code>dataLicense</code></a></li><li><a href="#describesPackage"><code>describesPackage</code></a></li><li><a href="#description"><code>description</code></a></li><li><a href="#downloadLocation"><code>downloadLocation</code></a></li><li><a href="#extractedText"><code>extractedText</code></a></li><li><a href="#fileName"><code>fileName</code></a></li><li><a href="#fileType"><code>fileType</code></a></li><li><a href="#hasExtractedLicensingInfo"><code>hasExtractedLicensingInfo</code></a></li><li><a href="#hasFile"><code>hasFile</code></a></li><li><a href="#isOsiApproved"><code>isOsiApproved</code></a></li><li><a href="#licenseComments"><code>licenseComments</code></a></li><li><a href="#licenseConcluded"><code>licenseConcluded</code></a></li><li><a href="#licenseDeclared"><code>licenseDeclared</code></a></li><li><a href="#licenseId"><code>licenseId</code></a></li><li><a href="#licenseText"><code>licenseText</code></a></li><li><a href="#licenseInfoFromFiles"><code>licenseInfoFromFiles</code></a></li><li><a href="#licenseInfoInFile"><code>licenseInfoInFile</code></a></li><li><a href="#member"><code>member</code></a></li><li><a href="#name"><code>name</code></a></li><li><a href="#originator"><code>originator</code></a></li><li><a href="#packageFileName"><code>packageFileName</code></a></li><li><a href="#packageVerificationCode"><code>packageVerificationCode</code></a></li><li><a href="#packageVerificationCodeExcludedFile"><code>packageVerificationCodeExcludedFile</code></a></li><li><a href="#packageVerificationCodeValue"><code>packageVerificationCodeValue</code></a></li><li><a href="#referencesFile"><code>referencesFile</code></a></li><li><a href="#reviewDate"><code>reviewDate</code></a></li><li><a href="#reviewed"><code>reviewed</code></a></li><li><a href="#reviewer"><code>reviewer</code></a></li><li><a href="#sourceInfo"><code>sourceInfo</code></a></li><li><a href="#specVersion"><code>specVerison</code></a></li><li><a href="#standardLicenseHeader"><code>standardLicenseHeader</code></a></li><li><a href="#summary"><code>summary</code></a></li><li><a href="#supplier"><code>supplier</code></a></li><li><a href="#versionInfo"><code>versionInfo</code></a></li></ul><div id="algorithm"><h3>Property: <code>algorithm</code></h3><p>Identifies the algorithm used to produce the subject <a href="#Checksum"><code>Checksum</code></a>.</p><p>Currently, <a href="http://www.itl.nist.gov/fipspubs/fip180-1.htm">SHA-1</a> is the only supported algorithm. It is anticipated that other algorithms will be supported at a later time.</p><dl><dt>Status:</dt><dd>stable</dd><dt>Domain:</dt><dd><a href="#Checksum" rel="rdfs:domain"><code>Checksum</code></a></dd><dt>Range:</dt><dd><span> <span> <span> <span> <a href="#checksumAlgorithm_sha1"><code>spdx:checksumAlgorithm_sha1</code></a> </span> </span> </span> </span></dd></dl></div><div id="artifactOf"><h3>Property: <code>artifactOf</code></h3><div><p>Indicates the project in which the file originated.</p><p>Tools must preserve <code>doap:hompage</code> and <code>doap:name</code> properties and the URI (if one is known) of <code>doap:Project</code> resources that are values of this property. All other properties of <code>doap:Projects</code> are not directly supported by SPDX and may be dropped when translating to or from some SPDX formats.</p></div><dl><dt>Status:</dt><dd>stable</dd><dt>Domain:</dt><dd><a href="#File" rel="rdfs:domain"><code>File</code></a></dd><dt>Range:</dt><dd><a href="http://usefulinc.com/ns/doap#Project" rel="rdfs:range"><code>doap:Project</code></a></dd></dl></div><div id="checksum"><h3>Property: <code>checksum</code></h3><p>The <code>checksum</code> property provides a mechanism that can be used to verify that the contents of a <a href="#File"><code>File</code></a> or <a href="#Package"><code>Package</code></a> have not changed.</p><dl><dt>Status:</dt><dd>stable</dd><dt>Domain:</dt><dd>Any of:<div><ul><li><a href="#Package" rel="rdf:first"><code>Package</code></a></li><li><a href="#File" rel="rdf:first"><code>File</code></a></li></ul></div></dd><dt>Range:</dt><dd><a href="#Checksum" rel="rdfs:range">Checksum</a></dd></dl></div><div id="checksumValue"><h3>Property: <code>checksumValue</code></h3><p>The <code>checksumValue</code> property provides a lower case hexidecimal encoded digest value produced using a specific algorithm.</p><dl><dt>Status:</dt><dd>stable</dd><dt>Domain:</dt><dd><a href="#Checksum" rel="rdfs:domain"><code>Checksum</code></a></dd><dt>Range:</dt><dd><a href="http://www.w3.org/TR/xmlschema-2/#hexBinary"><code>xsd:hexBinary</code></a></dd></dl></div><div id="created"><h3>Property: <code>created</code></h3><p>The date and time at which the <a href="#SpdxDocument"><code>SpdxDocument</code></a> was created. This value must in UTC and have 'Z' as its timezone indicator.</p><dl><dt>Status:</dt><dd>stable</dd><dt>Domain:</dt><dd><a href="#CreationInfo" rel="rdfs:domain"><code>CreationInfo</code></a></dd><dt>Range:</dt><dd><a href="http://www.w3.org/TR/xmlschema-2/#dateTime"><code>xsd:dateTime</code></a></dd></dl></div><div id="copyrightText"><h3>Property: <code>copyrightText</code></h3><p>The text of copyright declarations recited in the <a href="#Package"><code>Package</code></a> or <a href="#File"><code>File</code></a>.</p><dl><dt>Status:</dt><dd>stable</dd><dt>Domain:</dt><dd>Any of:<div><ul><li><a href="#Package" rel="rdf:first"><code>Package</code></a></li><li><a href="#File" rel="rdf:first"><code>File</code></a></li></ul></div></dd><dt>Range:</dt><dd>Any of:<div><ul><li><a href="http://www.w3.org/TR/rdf-schema/#ch_literal"><code>rdfs:Literal</code></a></li><li><a href="#none"><code>spdx:none</code></a></li><li><a href="#noassertion"><code>spdx:noassertion</code></a></li></ul></div></dd></dl></div><div id="creationInfo"><h3>Property: <code>creationInfo</code></h3><p>The <code>creationInfo</code> property relates an <a href="#SpdxDocument"><code>SpdxDocument</code></a> to a set of information about the creation of the <a href="#SpdxDocument"><code>SpdxDocument</code></a>.</p><dl><dt>Status:</dt><dd>stable</dd><dt>Domain:</dt><dd><a href="#SpdxDocument" rel="rdfs:domain"><code>SpdxDocument</code></a></dd><dt>Range:</dt><dd><a href="#CreationInfo" rel="rdfs:range"><code>CreationInfo</code></a></dd></dl></div><div id="creator"><h3>Property: <code>creator</code></h3><div><p>The name and, optionally, contact information of a person, organization or tool that created, or was used to create, the <a href="#SpdxDocument"><code>SpdxDocument</code></a>.</p><p>Values of this property must conform to the <a href="#agent-syntax">agent and tool syntax</a>.</p></div><dl><dt>Status:</dt><dd>stable</dd><dt>Domain:</dt><dd><a href="#CreationInfo" rel="rdfs:domain"><code>CreationInfo</code></a></dd><dt>Range:</dt><dd><a href="http://www.w3.org/TR/xmlschema-2/#string"><code>xsd:string</code></a></dd></dl></div><div id="dataLicense"><h3>Property: <code>dataLicense</code></h3><div><p>The licensing under which the <a href="#creator"><code>creator</code></a> of this SPDX document allows related data to be reproduced.</p><p>The only valid value for this property is <code>http://spdx.org/licenses/CC0-1.0</code>. This is to alleviate any concern that content (the data) in an SPDX file is subject to any form of intellectual property right that could restrict the re-use of the information or the creation of another SPDX file for the same project(s). This approach avoids intellectual property and related restrictions over the SPDX file, however individuals can still contract one to one to restrict release of specific collections of SPDX files (which map to software bill of materials) and the identification of the supplier of SPDX files.</p></div><dl><dt>Status:</dt><dd>stable</dd><dt>Domain:</dt><dd><a href="#SpdxDocument" rel="rdfs:domain"><code>SpdxDocument</code></a></dd><dt>Range:</dt><dd><div><div><div><a href="http://spdx.org/licenses/CC0-1.0" rel="rdf:first"><code>http://spdx.org/licenses/CC0-1.0</code></a></div></div></div></dd></dl></div><div id="describesPackage"><h3>Property: <code>describesPackage</code></h3><p>The <code>describesPackage</code> property relates an <code>SpdxDocument</code> to the package which it describes.</p><dl><dt>Status:</dt><dd>stable</dd><dt>Domain:</dt><dd><a href="#SpdxDocument" rel="rdfs:domain"><code>SpdxDocument</code></a></dd><dt>Range:</dt><dd><a href="#Package" rel="rdfs:range"><code>Package</code></a></dd></dl></div><div id="description"><h3>Property: <code>description</code></h3><p>Provides a detailed description of the package.</p><dl><dt>Status:</dt><dd>stable</dd><dt>Domain:</dt><dd><a href="#Package" rel="rdfs:domain"><code>Package</code></a></dd><dt>Range:</dt><dd><a href="http://www.w3.org/TR/xmlschema-2/#string"><code>xsd:string</code></a></dd></dl></div><div id="downloadLocation"><h3>Property: <code>downloadLocation</code></h3><p>The URI at which this package is available for download. Private (i.e., not publicly reachable) URIs are acceptable as values of this property.</p><p>The values <a href="#none"><code>http://spdx.org/rdf/terms#none</code></a> and <a href="#noassertion"><code>http://spdx.org/rdf/terms#noassertion</code></a> may be used to specify that the package is not downloadable or that no attempt was made to determine its download location, respectively.</p><dl><dt>Status:</dt><dd>stable</dd><dt>Domain:</dt><dd><a href="#Package" rel="rdfs:domain"><code>Package</code></a></dd><dt>Range:</dt><dd><a href="http://www.w3.org/TR/xmlschema-2/#anyURI"><code>xsd:anyURI</code></a></dd></dl></div><div id="extractedText"><h3>Property: <code>extractedText</code></h3><p>Verbatim license or licensing notice text that was discovered.</p><dl><dt>Status:</dt><dd>stable</dd><dt>Domain:</dt><dd><a href="#ExtractedLicensingInfo" rel="rdfs:domain"><code>ExtractedLicensingInfo</code></a></dd><dt>Range:</dt><dd><a href="http://www.w3.org/TR/xmlschema-2/#string"><code>xsd:string</code></a></dd></dl></div><div id="fileName"><h3>Property: <code>fileName</code></h3><p>The name of the file relative to the root of the package.</p><dl><dt>Status:</dt><dd>stable</dd><dt>Domain:</dt><dd><a href="#File" rel="rdfs:domain"><code>File</code></a></dd><dt>Range:</dt><dd><a href="http://www.w3.org/TR/xmlschema-2/#string"><code>xsd:string</code></a></dd></dl></div><div id="fileType"><h3>Property: <code>fileType</code></h3><p>The type of the file.</p><dl><dt>Status:</dt><dd>stable</dd><dt>Domain:</dt><dd><a href="#File" rel="rdfs:domain"><code>File</code></a></dd><dt>Range:</dt><dd>One of:<div><ul><li><span> <a href="#fileType_source"> <code>spdx:fileType_source</code> </a> </span><p>Indicates the file is a source code file.</p></li><li><span> <a href="#fileType_archive"> <code>spdx:fileType_archive</code> </a> </span><p>Indicates the file is an archive file.</p></li><li><span> <a href="#fileType_binary"> <code>spdx:fileType_binary</code></a> </span><p>Indicates the file is not a text file. <code>filetype_archive</code> is preferred for archive files even though they are binary.</p></li><li><span> <a href="#fileType_other"> <code>spdx:fileType_other</code></a> </span><p>Indicates the file did not fall into any of the other categories.</p></li></ul></div></dd></dl></div><div id="hasExtractedLicensingInfo"><h3>Property: <code>hasExtractedLicensingInfo</code></h3><p>Indicates that a particular <a href="#ExtractedLicensingInfo"><code>ExtractedLicensingInfo</code></a> was defined in the subject <a href="#SpdxDocument"><code>SpdxDocument</code></a>.</p><dl><dt>Status:</dt><dd>stable</dd><dt>Domain:</dt><dd><a href="#SpdxDocument" rel="rdfs:domain"><code>SpdxDocument</code></a></dd><dt>Range:</dt><dd><a href="#ExtractedLicensingInfo" rel="rdfs:range"><code>ExtractedLicensingInfo</code></a></dd></dl></div><div id="hasFile"><h3>Property: <code>hasFile</code></h3><p>Indicates that a particular <a href="#File">file</a> belongs to a <a href="#Package">package</a>.</p><dl><dt>Status:</dt><dd>stable</dd><dt>Domain:</dt><dd><a href="#Package" rel="rdfs:domain"><code>Package</code></a></dd><dt>Range:</dt><dd><a href="#File" rel="rdfs:range"><code>File</code></a></dd></dl></div><div id="isOsiApproved"><h3>Property: <code>isOsiApproved</code></h3><p>Indicates that a particular <a href="#License">license</a> has been approved by the <a href="http://opensource.org/">OSI</a> as an open source licenses. If this property is true there <em>should</em> be a <code>seeAlso</code> property linking to the OSI version of the license.</p><dl><dt>Status:</dt><dd>stable</dd><dt>Domain:</dt><dd><a href="#License" rel="rdfs:domain"><code>License</code></a></dd><dt>Range:</dt><dd><a href="http://www.w3.org/TR/xmlschema-2/#boolean"><code>xsd:boolean</code></a></dd></dl></div><div id="licenseComments"><h3>Property: <code>licenseComments</code></h3><p>The <code>licenseComments</code> property allows the preparer of the SPDX document to describe why the licensing in <a href="#licenseConcluded"><code>spdx:licenseConcluded</code></a> was chosen.</p><dl><dt>Status:</dt><dd>stable</dd><dt>Domain:</dt><dd>Any of:<ul><li><a href="#Package" rel="rdf:first"><code>Package</code></a></li><li><a href="#File" rel="rdf:first"><code>File</code></a></li></ul></dd><dt>Range:</dt><dd><a href="http://www.w3.org/TR/xmlschema-2/#string"><code>xsd:string</code></a></dd></dl></div><div id="licenseConcluded"><h3>Property: <code>licenseConcluded</code></h3><p>The licensing that the preparer of this SPDX document has concluded, based on the evidence, actually applies to the package.</p><dl><dt>Status:</dt><dd>stable</dd><dt>Domain:</dt><dd>Any of:<div><ul><li><a href="#Package" rel="rdf:first"><code>Package</code></a></li><li><a href="#File" rel="rdf:first"><code>File</code></a></li></ul></div></dd><dt>Range:</dt><dd>Any of:<div><ul><li><a href="#AnyLicenseInfo" rel="rdf:first"><code>AnyLicenseInfo</code></a></li><li><a href="#none"><code>spdx:none</code></a></li><li><a href="#noassertion"><code>spdx:noassertion</code></a></li></ul></div></dd></dl></div><div id="licenseDeclared"><h3>Property: <code>licenseDeclared</code></h3><p>The licensing that the creators of the software in the package, or the packager, have declared. Declarations by the original software creator should be preferred, if they exist.</p><dl><dt>Status:</dt><dd>stable</dd><dt>Domain:</dt><dd><a href="#Package" rel="rdfs:domain"><code>Package</code></a></dd><dt>Range:</dt><dd>Any of:<div><ul><li><a href="#AnyLicenseInfo" rel="rdf:first"><code>AnyLicenseInfo</code></a></li><li><a href="#none"><code>spdx:none</code></a></li><li><a href="#noassertion"><code>spdx:noassertion</code></a></li></ul></div></dd></dl></div><div id="licenseId"><h3>Property: <code>licenseId</code></h3><p>A short name for the license that is at least 3 characters long and made up of the characters from the set 'a'-'z', 'A'-'Z', '0'-'9', '+', '_', '.', and '-'. Formally, all <code>licenseId</code> values must match the regular expression: <code>[-+_.a-zA-Z0-9]{3,}</code></p><dl><dt>Status:</dt><dd>stable</dd><dt>Domain:</dt><dd><ul><li><a href="#License" rel="rdf:first"><code>License</code></a></li><li><a href="#ExtractedLicensingInfo" rel="rdf:first"><code>ExtractedLicensingInfo</code></a></li></ul></dd><dt>Range:</dt><dd><a href="http://www.w3.org/TR/xmlschema-2/#string"><code>xsd:string</code></a></dd></dl></div><div id="licenseText"><h3>Property: <code>licenseText</code></h3><p>The full text of the license.</p><dl><dt>Status:</dt><dd>stable</dd><dt>Domain:</dt><dd><a href="#License" rel="rdfs:domain"><code>License</code></a></dd><dt>Range:</dt><dd><a href="http://www.w3.org/TR/xmlschema-2/#string"><code>xsd:string</code></a></dd></dl></div><div id="licenseInfoFromFiles"><h3>Property: <code>licenseInfoFromFiles</code></h3><p>The licensing information that was discovered directly within the package. There will be an instance of this property for each distinct value of all <a href="#licenseInfoInFile"><code>licenseInfoInFile</code></a> properties of all files contained in the package.</p><dl><dt>Status:</dt><dd>stable</dd><dt>Domain:</dt><dd><a href="#Package" rel="rdfs:domain"><code>Package</code></a></dd><dt>Range:</dt><dd>Any of:<div><ul><li><a href="#SimpleLicenseInfo" rel="rdf:first"><code>SimpleLicenseInfo</code></a></li><li><a href="#none"><code>spdx:none</code></a></li><li><a href="#noassertion"><code>spdx:noassertion</code></a></li></ul></div></dd></dl></div><div id="licenseInfoInFile"><h3>Property: <code>licenseInfoInFile</code></h3><p>Licensing information that was discovered directly in the subject file.</p><dl><dt>Status:</dt><dd>stable</dd><dt>Domain:</dt><dd><a href="#File" rel="rdfs:domain"><code>File</code></a></dd><dt>Range:</dt><dd>Any of:<div><ul><li><a href="#SimpleLicenseInfo" rel="rdf:first"><code>SimpleLicenseInfo</code></a></li><li><a href="#none"><code>spdx:none</code></a></li><li><a href="#noassertion"><code>spdx:noassertion</code></a></li></ul></div></dd></dl></div><div id="member"><h3>Property: <code>member</code></h3><p>A <a href="#License">license</a>, or other licensing information, that is a member of the subject license set.</p><dl><dt>Status:</dt><dd>stable</dd><dt>Domain:</dt><dd>Any of:<div><ul><li><a href="#ConjunctiveLicenseSet" rel="rdf:first"><code>ConjunctiveLicenseSet</code></a></li><li><a href="#DisjunctiveLicenseSet" rel="rdf:first"><code>DisjunctiveLicenseSet</code></a></li></ul></div></dd><dt>Range:</dt><dd><a href="#AnyLicenseInfo" rel="rdfs:range"><code>AnyLicenseInfo</code></a></dd><dt>Refines:</dt><dd><span> <a href="http://www.w3.org/TR/rdf-schema/#ch_member"><code>rdfs:member</code></a> </span></dd></dl></div><div id="name"><h3>Property: <code>name</code></h3><p>The full human readable name of the item. This should include version information when applicable.</p><dl><dt>Status:</dt><dd>stable</dd><dt>Domain:</dt><dd>Any of:<div><ul><li><a href="#Package" rel="rdf:first"><code>Package</code></a></li><li><a href="#ExtractedLicensingInfo" rel="rdf:first"><code>ExtractedLicensingInfo</code></a></li><li><a href="#License" rel="rdf:first"><code>License</code></a></li></ul></div></dd><dt>Range:</dt><dd><a href="http://www.w3.org/TR/xmlschema-2/#string"><code>xsd:string</code></a></dd><dt>Refines:</dt><dd><span> <a href="http://www.w3.org/TR/rdf-schema/#ch_label"><code>rdfs:label</code></a> </span></dd></dl></div><div id="originator"><h3>Property: <code>originator</code></h3><div><p>The name and, optionally, contact information of the person or organization that originally created the package.</p><p>Values of this property must conform to the <a href="#agent-syntax">agent and tool syntax</a>.</p></div><dl><dt>Status:</dt><dd>stable</dd><dt>Domain:</dt><dd><a href="#Package" rel="rdfs:domain"><code>Package</code></a></dd><dt>Range:</dt><dd><span> <span> <span> <a href="http://www.w3.org/TR/xmlschema-2/#string"><code>xsd:string</code></a> </span> or the individual <span> <a href="#noassertion"><code>spdx:noassertion</code></a> </span> </span> </span></dd></dl></div><div id="packageFileName"><h3>Property: <code>packageFileName</code></h3><p>The base name of the package file name. For example, <code>zlib-1.2.5.tar.gz</code>.</p><dl><dt>Status:</dt><dd>stable</dd><dt>Domain:</dt><dd><a href="#Package" rel="rdfs:domain"><code>Package</code></a></dd><dt>Range:</dt><dd><a href="http://www.w3.org/TR/xmlschema-2/#string"><code>xsd:string</code></a></dd></dl></div><div id="packageVerificationCode"><h3>Property: <code>packageVerificationCode</code></h3><div><p>A manifest based authentication code for the package. This allows consumers of this data to determine if a package they have in hand is identical to the package from which the data was produced. This algorithm works even if the SPDX document is included in the package. This algorithm is described in detail in the SPDX specification.</p><p>The package verification code algorithm is defined in section 4.7 of the full specification.</p></div><dl><dt>Status:</dt><dd>stable</dd><dt>Domain:</dt><dd><a href="#Package" rel="rdfs:domain"><code>Package</code></a></dd><dt>Range:</dt><dd><a href="#PackageVerificationCode" rel="rdfs:range"><code>PackageVerificationCode</code></a></dd></dl></div><div id="packageVerificationCodeExcludedFile"><h3>Property: <code>packageVerificationCodeExcludedFile</code></h3><p>A file that was excluded when calculating the <a href="#packageVerificationCode">package verification code</a>. This is usually a file containing SPDX data regarding the package. If a package contains more than one SPDX file all SPDX files must be excluded from the package verification code. If this is not done it would be impossible to correctly calculate the verification codes in both files.</p><dl><dt>Status:</dt><dd>stable</dd><dt>Domain:</dt><dd><a href="#PackageVerificationCode" rel="rdfs:domain"><code>PackageVerificationCode</code></a></dd><dt>Range:</dt><dd><a href="http://www.w3.org/TR/xmlschema-2/#string"><code>xsd:string</code></a></dd></dl></div><div id="packageVerificationCodeValue"><h3>Property: <code>packageVerificationCodeValue</code></h3><p>The actual package verification code as a hex encoded value.</p><dl><dt>Status:</dt><dd>stable</dd><dt>Domain:</dt><dd><a href="#PackageVerificationCode" rel="rdfs:domain"><code>PackageVerificationCode</code></a></dd><dt>Range:</dt><dd><a href="http://www.w3.org/TR/xmlschema-2/#hexBinary"><code>xsd:hexBinary</code></a></dd></dl></div><div id="referencesFile"><h3>Property: <code>referencesFile</code></h3><p>Indicates that a particular file belongs as part of the set of analyzed files in the <a href="#SpdxDocument"><code>SpdxDocument</code></a>.</p><dl><dt>Status:</dt><dd>stable</dd><dt>Domain:</dt><dd><a href="#SpdxDocument" rel="rdfs:domain"><code>SpdxDocument</code></a></dd><dt>Range:</dt><dd><a href="#File" rel="rdfs:range"><code>File</code></a></dd></dl></div><div id="reviewDate"><h3>Property: <code>reviewDate</code></h3><p>The date and time at which the <a href="#SpdxDocument"><code>SpdxDocument</code></a> was reviewed. This value must be in UTC and have 'Z' as its timezone indicator.</p><dl><dt>Status:</dt><dd>stable</dd><dt>Domain:</dt><dd><a href="#Review" rel="rdfs:domain"><code>Review</code></a></dd><dt>Range:</dt><dd><a href="http://www.w3.org/TR/xmlschema-2/#dateTime"><code>xsd:dateTime</code></a></dd></dl></div><div id="reviewed"><h3>Property: <code>reviewed</code></h3><p>The <code>review</code> property relates a <code>SpdxDocument</code> to the review history.</p><dl><dt>Status:</dt><dd>stable</dd><dt>Domain:</dt><dd><a href="#SpdxDocument" rel="rdfs:domain"><code>SpdxDocument</code></a></dd><dt>Range:</dt><dd><a href="#Review" rel="rdfs:range"><code>Review</code></a></dd></dl></div><div id="reviewer"><h3>Property: <code>reviewer</code></h3><div><p>The name and, optionally, contact information of the person who performed the review.</p><p>Values of this property must conform to the <a href="#agent-syntax">agent and tool syntax</a>.</p></div><dl><dt>Status:</dt><dd>stable</dd><dt>Domain:</dt><dd><a href="#Review" rel="rdfs:domain"><code>Review</code></a></dd><dt>Range:</dt><dd><a href="http://www.w3.org/TR/xmlschema-2/#string"><code>xsd:string</code></a></dd></dl></div><div id="sourceInfo"><h3>Property: <code>sourceInfo</code></h3><p>Allows the producer(s) of the SPDX document to describe how the package was acquired and/or changed from the original source.</p><dl><dt>Status:</dt><dd>stable</dd><dt>Domain:</dt><dd><a href="#Package" rel="rdfs:domain"><code>Package</code></a></dd><dt>Range:</dt><dd><a href="http://www.w3.org/TR/xmlschema-2/#string"><code>xsd:string</code></a></dd></dl></div><div id="specVersion"><h3>Property: <code>specVersion</code></h3><p>Identifies the version of this specification that was used to produce this SPDX document. The value for this version of the spec is <code>SPDX-1.1</code>. The value <code>SPDX-1.0</code> may also be supported by SPDX tools for backwards compatibility purposes.</p><dl><dt>Status:</dt><dd>stable</dd><dt>Domain:</dt><dd><a href="#SpdxDocument" rel="rdfs:domain"><code>SpdxDocument</code></a></dd><dt>Range:</dt><dd><a href="http://www.w3.org/TR/xmlschema-2/#string"><code>xsd:string</code></a></dd></dl></div><div id="standardLicenseHeader"><h3>Property: <code>standardLicenseHeader</code></h3><p>Text specifically delineated by the license, or license appendix, as the preferred way to indicate that a source, or other, file is copyable under the license.</p><dl><dt>Status:</dt><dd>stable</dd><dt>Domain:</dt><dd><a href="#License" rel="rdfs:domain"><code>License</code></a></dd><dt>Range:</dt><dd><a href="http://www.w3.org/TR/xmlschema-2/#string"><code>xsd:string</code></a></dd></dl></div><div id="summary"><h3>Property: <code>summary</code></h3><p>Provides a short description of the package.</p><dl><dt>Status:</dt><dd>stable</dd><dt>Domain:</dt><dd><a href="#Package" rel="rdfs:domain"><code>Package</code></a></dd><dt>Range:</dt><dd><a href="http://www.w3.org/TR/xmlschema-2/#string"><code>xsd:string</code></a></dd></dl></div><div id="supplier"><h3>Property: <code>supplier</code></h3><div><p>The name and, optionally, contact information of the person or organization who was the immediate supplier of this package to the recipient. The supplier may be different than <a href="#originator"><code>originator</code></a> when the software has been repackaged.</p><p>Values of this property must conform to the <a href="#agent-syntax">agent and tool syntax</a>.</p></div><dl><dt>Status:</dt><dd>stable</dd><dt>Domain:</dt><dd><a href="#Package" rel="rdfs:domain"><code>Package</code></a></dd><dt>Range:</dt><dd><span> <span> <span> <a href="http://www.w3.org/TR/xmlschema-2/#string"><code>xsd:string</code></a> </span> or the individual <span> <a href="#noassertion"><code>spdx:noassertion</code></a> </span> </span> </span></dd></dl></div><div id="versionInfo"><h3>Property: <code>versionInfo</code></h3><p>Provides an indication of the version of the package that is described by this <a href="#SpdxDocument"><code>SpdxDocument</code></a>.</p><dl><dt>Status:</dt><dd>stable</dd><dt>Domain:</dt><dd><a href="#Package" rel="rdfs:domain"><code>Package</code></a></dd><dt>Range:</dt><dd><a href="http://www.w3.org/TR/xmlschema-2/#string"><code>xsd:string</code></a></dd></dl></div><div style="display: none;"> </div><h2>Individuals</h2><ul><li><a href="#checksumAlgorithm_sha1"><code>checksumAlgorithm_sha1</code></a></li><li><a href="#fileType_archive"><code>fileType_archive</code></a></li><li><a href="#fileType_binary"><code>fileType_binary</code></a></li><li><a href="#fileType_other"><code>fileType_other</code></a></li><li><a href="#fileType_source"><code>fileType_source</code></a></li><li><a href="#noassertion"><code>noassertion</code></a></li><li><a href="#none"><code>none</code></a></li></ul><div id="checksumAlgorithm_sha1"><h3>Individual: <code>checksumAlgorithm_sha1</code></h3><p>Indicates the algorithm used was <a href="http://www.itl.nist.gov/fipspubs/fip180-1.htm">SHA-1</a></p><dl><dt>Status:</dt><dd>stable</dd></dl></div><div id="fileType_archive"><h3>Individual: <code>fileType_archive</code></h3><p>Indicates the file is an archive file.</p><dl><dt>Status:</dt><dd>stable</dd></dl></div><div id="fileType_binary"><h3>Individual: <code>fileType_binary</code></h3><p>Indicates the file is not a text file. <a href="#fileType_archive"><code>spdx:filetype_archive</code></a> is preferred for archive files even though they are binary.</p><dl><dt>Status:</dt><dd>stable</dd></dl></div><div id="fileType_other"><h3>Individual: <code>fileType_other</code></h3><p>Indicates the file is not a <a href="#fileType_source">source</a>, <a href="#fileType_archive">archive</a> or <a href="#fileType_binary">binary</a> file.</p><dl><dt>Status:</dt><dd>stable</dd></dl></div><div id="fileType_source"><h3>Individual: <code>fileType_source</code></h3><p>Indicates the file is a source code file.</p><dl><dt>Status:</dt><dd>stable</dd></dl></div><div id="noassertion"><h3>Individual: <code>noassertion</code></h3><p>Indicates that the preparer of the SPDX document is not making any assertion regarding the value of this field.</p><dl><dt>Status:</dt><dd>stable</dd></dl><div> </div></div><div id="none"><h3>Individual: <code>none</code></h3><p>When this value is used as the object of a property it indicates that the preparer of the <a href="#SpdxDocument"><code>SpdxDocument</code></a> believes that there is no value for the property. This value should only be used if there is sufficient evidence to support this assertion.</p><dl><dt>Status:</dt><dd>stable</dd></dl><div> </div></div><h2 id="agent-syntax">Agent and Tool Identifiers</h2><p>Fields that identify entities that have acted in relation to the SPDX file are single line of text which name the agent or tool and, optionally, provide contact information. For example, "Person: Jane Doe (jane.doe@example.com)", "Organization: ExampleCodeInspect (contact@example.com)" and "Tool: LicenseFind - 1.0". The exact syntax of agent and tool identifications is described below in <a href="http://tools.ietf.org/html/rfc5234">ABNF</a>.</p><pre><code> agent = person / organization tool = "Tool: " name 0*1( " " DASH " " version) person = "Person: " name 0*1contact-info organization = "Organization: " name 0*1contact-info name = 1*( UNRESERVED ) / U+0022 1*( VCHAR-SANS-QUOTE ) U+0022 contact-info = " (" email-addr ")" email-addr = local-name-atom *( "." local-name-atom ) "@" domain-name-atom 1*( "." domain-name-atom ) version = 1*VCHAR-SANS-QUOTE local-name-atom = 1*( ALPHA / DIGIT / ; Printable US-ASCII "!" / "#" / ; characters not including "$" / "%" / ; specials. "&" / "'" / "*" / "+" / "-" / "/" / "=" / "?" / "^" / "_" / "`" / "{" / "|" / "}" / "~" ) domain-name-atom = 1*( ALPHA / DIGIT / "-" ) DASH = U+2010 / U+2212 / ; hyphen, minus, em dash and U+2013 / U+2014 ; en dash UNRESERVED = U+0020-U+0027 / ; visible unicode characters U+0029-U+0080 / ; except '(' and dashes U+00A0-U+200F / U+2011-U+2027 / U+202A-U+2211 / U+2213-U+E01EF VCHAR-SANS-QUOTE = U+0020-U+0021 / ; visible unicode characters U+0023-U+0080 / ; except quotation mark U+00a0-U+E01EF </code></pre> |
Revision as of 17:26, 20 September 2012
Contents
- 1 SPDX® Vocabulary Specification
- 1.1 Introduction
- 1.2 Classes
- 1.2.1 Class: SpdxDocument
- 1.2.2 Class: CreationInfo
- 1.2.3 Class: Package
- 1.2.4 Class: ExtractedLicensingInfo
- 1.2.5 Class: File
- 1.2.6 Class: Review
- 1.2.7 Class: License
- 1.2.8 Class: Checksum
- 1.2.9 Class: PackageVerificationCode
- 1.2.10 Class: ConjunctiveLicenseSet
- 1.2.11 Class: DisjunctiveLicenseSet
- 1.2.12 Class: AnyLicenseInfo
- 1.2.13 Class: SimpleLicenseInfo
- 1.3 Properties
- 1.3.1 Property: algorithm
- 1.3.2 Property: artifactOf
- 1.3.3 Property: checksum
- 1.3.4 Property: checksumValue
- 1.3.5 Property: created
- 1.3.6 Property: copyrightText
- 1.3.7 Property: creationInfo
- 1.3.8 Property: creator
- 1.3.9 Property: dataLicense
- 1.3.10 Property: describesPackage
- 1.3.11 Property: description
- 1.3.12 Property: downloadLocation
- 1.3.13 Property: extractedText
- 1.3.14 Property: fileName
- 1.3.15 Property: fileType
- 1.3.16 Property: hasExtractedLicensingInfo
- 1.3.17 Property: hasFile
- 1.3.18 Property: isOsiApproved
- 1.3.19 Property: licenseComments
- 1.3.20 Property: licenseConcluded
- 1.3.21 Property: licenseDeclared
- 1.3.22 Property: licenseId
- 1.3.23 Property: licenseText
- 1.3.24 Property: licenseInfoFromFiles
- 1.3.25 Property: licenseInfoInFile
- 1.3.26 Property: member
- 1.3.27 Property: name
- 1.3.28 Property: originator
- 1.3.29 Property: packageFileName
- 1.3.30 Property: packageVerificationCode
- 1.3.31 Property: packageVerificationCodeExcludedFile
- 1.3.32 Property: packageVerificationCodeValue
- 1.3.33 Property: referencesFile
- 1.3.34 Property: reviewDate
- 1.3.35 Property: reviewed
- 1.3.36 Property: reviewer
- 1.3.37 Property: sourceInfo
- 1.3.38 Property: specVersion
- 1.3.39 Property: standardLicenseHeader
- 1.3.40 Property: summary
- 1.3.41 Property: supplier
- 1.3.42 Property: versionInfo
- 1.4 Individuals
- 1.5 Agent and Tool Identifiers
SPDX® Vocabulary Specification
- Version:
- 1.1 (Final)
- Latest Version:
- <a href="http://spdx.org/rdf/terms">http://spdx.org/rdf/terms</a>
Copyright © 2010-2012 Linux Foundation and its Contributors. All other rights are expressly reserved.
Licensed under the <a href="http://creativecommons.org/licenses/by/3.0/">Creative Commons Attribution License 3.0 unported</a>.
Introduction
This specification describes the SPDX® language, defined as a dictionary of named properties and classes using W3C's RDF Technology.
SPDX® is a designed to allow the exchange of data about software packages. This information includes general information about the package, licensing information about the package as a whole, a manifest of files contained in the package and licensing information related to the contained files.
About this document
This is an RDFa annotated HTML document that defines the SPDX® RDF vocabulary using the Web Ontology Language. It is RDFa 1.0 compatible and may be consumed by any RDFa 1.0 compatible parser. The same information is available in <a href="./terms.rdf" rel="owl:sameAs">RDF/XML</a> and <a href="./terms.ttl" rel="owl:sameAs">Turtle</a> formats if those are more convenient.
RDF it is a widely used data interchange technology which allows heterogeneous systems communicate even when their internal models/implementations are incompatible. For more details on RDF, this <a href="http://notabug.com/2002/rdfprimer/">RDF primer</a> helpful for gaining a basic understanding.
Prefixes used in this document
The spdx
prefix used in this document expands to http://spdx.org/rdf/terms#
. Any terms in this document without an explicit prefix may be assumed to be in the spdx
namespace.
Other vocabularies used by this one
In addition to the spdx
prefix the following prefixes are also used. Each of these reference another vocabulary imported and used by the SPDX vocabulary.
- <a href="http://trac.usefulinc.com/doap">DOAP</a>
- <a href="http://www.w3.org/TR/rdf-schema">RDFS</a>
Classes
- <a href="#SpdxDocument">
SpdxDocument
</a> - <a href="#CreationInfo">
CreationInfo
</a> - <a href="#Package">
Package
</a> - <a href="#ExtractedLicensingInfo">
ExtractedLicensingInfo
</a> - <a href="#Checksum">
Checksum
</a> - <a href="#PackageVerificationCode">
PackageVerificationCode
</a> - <a href="#File">
File
</a> - <a href="#Review">
Review
</a> - <a href="#License">
License
</a> - <a href="#ConjunctiveLicenseSet">
ConjunctiveLicenseSet
</a> - <a href="#DisjunctiveLicenseSet">
DisjunctiveLicenseSet
</a> - <a href="#AnyLicenseInfo">
AnyLicenseInfo
</a> - <a href="#SimpleLicenseInfo">
SimpleLicenseInfo
</a>
Class: SpdxDocument
An SpdxDocument
is a summary of the contents, provenance, ownership and licensing analysis of a specific software package. This is, effectively, the top level of SPDX information.
- Status:
- stable
- Properties:
<a href="#specVersion" rel="owl:onProperty">
specVersion
</a> Cardinality: Mandatory, one<a href="#dataLicense" rel="owl:onProperty">
dataLicense
</a> Cardinality: Mandatory, one<a href="http://www.w3.org/TR/rdf-schema/#ch_comment">
rdfs:comment
</a> Cardinality: Optional, zero or one<a href="#creationInfo" rel="owl:onProperty">
creationInfo
</a> Cardinality: Mandatory, one<a href="#describesPackage" rel="owl:onProperty">
describesPackage
</a> Cardinality: Mandatory, one<a href="#hasExtractedLicensingInfo">
hasExtractedLicensingInfo
</a> Cardinality: Optional, zero or more<a href="#referencesFile" rel="owl:onProperty">
referencesFile
</a> Cardinality: Mandatory, one or more<a href="#reviewed">
reviewed
</a> Cardinality: Optional, zero or more.
Class: CreationInfo
A CreationInfo
provides information about the individuals, organizations and tools involved in the creation of an <a href="#SpdxDocument">SpdxDocument
</a>.
- Status:
- stable
- Properties:
<a href="#creator" rel="owl:onProperty">
creator
</a> Cardinality: Mandatory, one or more<a href="#created" rel="owl:onProperty">
created
</a> Cardinality: Mandatory, one<a href="http://www.w3.org/TR/rdf-schema/#ch_comment">
rdfs:comment
</a> Cardinality: Optional, zero or one
Class: Package
A Package
represents a collection of software files that are delivered as a single functional component.
- Status:
- stable
- Properties:
<a href="#name" rel="owl:onProperty">
name
</a> Cardinality: Mandatory, one<a href="#versionInfo" rel="owl:onProperty">
versionInfo
</a> Cardinality: Optional, zero or one<a href="#packageFileName" rel="owl:onProperty">
packageFileName
</a> Cardinality: Optional, zero or one<a href="#supplier" rel="owl:onProperty">
supplier
</a> Cardinality: Optional, zero or one<a href="#originator" rel="owl:onProperty">
originator
</a> Cardinality: Optional, zero or one<a href="#downloadLocation" rel="owl:onProperty">
downloadLocation
</a> Cardinality: Mandatory, one<a href="#packageVerificationCode" rel="owl:onProperty">
packageVerificationCode
</a> Cardinality: Mandatory, one<a href="#checksum" rel="owl:onProperty">
checksum
</a> Cardinality: Optional, zero or one<a href="#sourceInfo" rel="owl:onProperty">
sourceInfo
</a> Cardinality: Optional, zero or one<a href="#licenseConcluded" rel="owl:onProperty">
licenseConcluded
</a> Cardinality: Mandatory, one<a href="#licenseInfoFromFiles" rel="owl:onProperty">
licenseInfoFromFiles
</a> Cardinality: Mandatory, one or more<a href="#licenseDeclared" rel="owl:onProperty">
licenseDeclared
</a> Cardinality: Mandatory, one<a href="#licenseComments" rel="owl:onProperty">
licenseComments
</a> Cardinality: Optional, zero or one<a href="#copyrightText" rel="owl:onProperty">
copyrightText
</a> Cardinality: Mandatory, one<a href="#summary" rel="owl:onProperty">
summary
</a> Cardinality: Optional, zero or one<a href="#description" rel="owl:onProperty">
description
</a> Cardinality: Optional, zero or one<a href="#hasFile" rel="owl:onProperty">
hasFile
</a> Cardinality: Mandatory, one or more
Class: ExtractedLicensingInfo
An ExtractedLicensingInfo
represents a license or licensing notice that was found in the package. Any license text that is recognized as a license may be represented as a <a href="#License">License
</a> rather than an ExtractedLicensingInfo
.
- Status:
- stable
- Properties:
<a href="#licenseId" rel="owl:onProperty">
licenseId
</a> Cardinality: Mandatory, one<a href="#name" rel="owl:onProperty">
name
</a> Cardinality: Optional, zero or more<a href="#extractedText" rel="owl:onProperty">
extractedText
</a> Cardinality: Mandatory, one<a href="http://www.w3.org/TR/rdf-schema/#ch_comment">
rdfs:comment
</a> Cardinality: Optional, zero or one<a href="http://www.w3.org/TR/rdf-schema/#ch_seealso">
rdfs:seeAlso
</a> Cardinality: Optional, zero or more
Class: File
A File
represents a named sequence of information that is contained in a software package.
- Status:
- stable
- Properties:
<a href="#fileName" rel="owl:onProperty">
fileName
</a> Cardinality: Mandatory, one<a href="http://www.w3.org/TR/rdf-schema/#ch_comment">
rdfs:comment
</a> Cardinality: Optional, zero or one<a href="#fileType" rel="owl:onProperty">
fileType
</a> Cardinality: Optional, zero or one<a href="#checksum" rel="owl:onProperty">
checksum
</a> Cardinality: Mandatory, one<a href="#licenseConcluded" rel="owl:onProperty">
licenseConcluded
</a> Cardinality: Mandatory, one<a href="#licenseInfoInFile" rel="owl:onProperty">
licenseInfoInFile
</a> Cardinality: Mandatory, one or more<a href="#licenseComments" rel="owl:onProperty">
licenseComments
</a> Cardinality: Optional, zero or one<a href="#copyrightText" rel="owl:onProperty">
copyrightText
</a> Cardinality: Mandatory, one<a href="#artifactOf" rel="owl:onProperty">
artifactOf
</a> Cardinality: Optional, zero or one
Class: Review
A Review
represents an audit and signoff by an individual, organization or tool on the information in an <a href="#SpdxDocument">SpdxDocument
</a>.
- Status:
- stable
- Properties:
<a href="#reviewer" rel="owl:onProperty">
reviewer
</a> Cardinality: Mandatory, one<a href="#reviewDate" rel="owl:onProperty">
reviewDate
</a> Cardinality: Mandatory, one<a href="http://www.w3.org/TR/rdf-schema/#ch_comment">
rdfs:comment
</a> Cardinality: Optional, zero or one
Class: License
A License
represents a copyright license. The <a href="http://spdx.org/licenses">SPDX license list website</a> is annotated with these properties (using <a href="http://www.w3.org/TR/2008/REC-rdfa-syntax-20081014/">RDFa</a>) to allow license data published there to be easily processed.
The license list is populated in accordance with the <a href="http://spdx.org/wiki/spdx-license-list">License List fields guidelines</a>. These guidelines are not normative and may change over time. SPDX tooling should not rely on values in the license list conforming to the current guidelines.
- Status:
- stable
- Properties:
<a href="#licenseId" rel="owl:onProperty">
licenseId
</a> Cardinality: Mandatory, oneA short human readable unique name for the license.
<a href="#name" rel="owl:onProperty">
name
</a> Cardinality: Optional, zero or oneA full name, including version if applicable, of the license.
<a href="#licenseText" rel="owl:onProperty">
licenseText
</a> Cardinality: Mandatory, oneFull text of the license.
<a href="#isOsiApproved" rel="owl:onProperty">
isOsiApproved
</a> Cardinality: Mandatory, oneIndicates if the <a href="http://opensource.org/">OSI</a> has approved the license.
<a href="#standardLicenseHeader" rel="owl:onProperty">
standardLicenseHeader
</a> Cardinality: Optional, zero or oneLicense author's preferred text to indicated that a file is covered by the license.
</>
<a href="http://www.w3.org/TR/rdf-schema/#ch_comment">
rdfs:comment
</a> Cardinality: Optional, zero or oneFactual notes regarding the license such as release date.
<a href="http://www.w3.org/TR/rdf-schema/#ch_seealso">
rdfs:seeAlso
</a> Cardinality: Optional, zero or moreA link to the license on another website.
Class: Checksum
A Checksum
is value that allows the contents of a file to be authenticated. Even small changes to the content of the file will change it's checksum. This class allows the results of a variety of checksum and cryptographic message digest algorithms to be represented.
- Status:
- stable
- Properties:
<a href="#algorithm" rel="owl:onProperty">
algorithm
</a> Cardinality: Mandatory, one<a href="#checksumValue" rel="owl:onProperty">
checksumValue
</a> Cardinality: Mandatory, one
Class: PackageVerificationCode
A manifest based verification code (the algorithm is defined in section 4.7 of the full specification) of the package. This allows consumers of this data and/or database to determine if a package they have in hand is identical to the package from which the data was produced. This algorithm works even if the SPDX document is included in the package.
- Status:
- stable
- Properties:
<a href="#packageVerificationCodeExcludedFile">
packageVerificationCodeExcludedFile
</a> Cardinality: Optional, zero or more<a href="#packageVerificationCodeValue" rel="owl:onProperty">
packageVerificationCodeValue
</a> Cardinality: Mandatory, one
Class: ConjunctiveLicenseSet
A ConjunctiveLicenseSet
represents a set of <a href="#AnyLicenseInfo">licensing information</a> all of which apply.
This class refines <a href="http://www.w3.org/TR/rdf-schema/#ch_container">rdfs:Container
</a>.
- Status:
- stable
- Properties:
<a href="#member" rel="owl:onProperty">
member
</a> Cardinality: Mandatory, two or more.
Class: DisjunctiveLicenseSet
A DisjunctiveLicenseSet
represents a set of <a href="#AnyLicenseInfo">licensing information</a> where only one license applies at a time. This class implies that the recipient gets to choose one of these licenses they would prefer to use.
This class refines <a href="http://www.w3.org/TR/rdf-schema/#ch_container">rdfs:Container
</a>.
- Status:
- stable
- Properties:
<a href="#member" rel="owl:onProperty">
member
</a> Cardinality: Mandatory, two or more.
Class: AnyLicenseInfo
The AnyLicenseInfo
class includes all resources that represent licensing information.
- Status:
- stable
- Members
- All resources in any of the following classes:
- <a href="#License" rel="rdf:first">
License
</a> - <a href="#ExtractedLicensingInfo" rel="rdf:first">
ExtractedLicensingInfo
</a> - <a href="#ConjunctiveLicenseSet" rel="rdf:first">
ConjunctiveLicenseSet
</a> - <a href="#DisjunctiveLicenseSet" rel="rdf:first">
DisjunctiveLicenseSet
</a>
- <a href="#License" rel="rdf:first">
Class: SimpleLicenseInfo
The SimpleLicenseInfo
class includes all resources that represent simple, atomic, licensing information.
- Status:
- stable
- Members
- All resources in any of the following classes:
- <a href="#License" rel="rdf:first">
License
</a> - <a href="#ExtractedLicensingInfo" rel="rdf:first">
ExtractedLicensingInfo
</a>
- <a href="#License" rel="rdf:first">
Properties
- <a href="#algorithm">
algorithm
</a> - <a href="#artifactOf">
artifactOf
</a> - <a href="#checksum">
checksum
</a> - <a href="#checksumValue">
checksumValue
</a> - <a href="#copyrightText">
copyrightText
</a> - <a href="#created">
created
</a> - <a href="#creationInfo">
creationInfo
</a> - <a href="#creator">
creator
</a> - <a href="#dataLicense">
dataLicense
</a> - <a href="#describesPackage">
describesPackage
</a> - <a href="#description">
description
</a> - <a href="#downloadLocation">
downloadLocation
</a> - <a href="#extractedText">
extractedText
</a> - <a href="#fileName">
fileName
</a> - <a href="#fileType">
fileType
</a> - <a href="#hasExtractedLicensingInfo">
hasExtractedLicensingInfo
</a> - <a href="#hasFile">
hasFile
</a> - <a href="#isOsiApproved">
isOsiApproved
</a> - <a href="#licenseComments">
licenseComments
</a> - <a href="#licenseConcluded">
licenseConcluded
</a> - <a href="#licenseDeclared">
licenseDeclared
</a> - <a href="#licenseId">
licenseId
</a> - <a href="#licenseText">
licenseText
</a> - <a href="#licenseInfoFromFiles">
licenseInfoFromFiles
</a> - <a href="#licenseInfoInFile">
licenseInfoInFile
</a> - <a href="#member">
member
</a> - <a href="#name">
name
</a> - <a href="#originator">
originator
</a> - <a href="#packageFileName">
packageFileName
</a> - <a href="#packageVerificationCode">
packageVerificationCode
</a> - <a href="#packageVerificationCodeExcludedFile">
packageVerificationCodeExcludedFile
</a> - <a href="#packageVerificationCodeValue">
packageVerificationCodeValue
</a> - <a href="#referencesFile">
referencesFile
</a> - <a href="#reviewDate">
reviewDate
</a> - <a href="#reviewed">
reviewed
</a> - <a href="#reviewer">
reviewer
</a> - <a href="#sourceInfo">
sourceInfo
</a> - <a href="#specVersion">
specVerison
</a> - <a href="#standardLicenseHeader">
standardLicenseHeader
</a> - <a href="#summary">
summary
</a> - <a href="#supplier">
supplier
</a> - <a href="#versionInfo">
versionInfo
</a>
Property: algorithm
Identifies the algorithm used to produce the subject <a href="#Checksum">Checksum
</a>.
Currently, <a href="http://www.itl.nist.gov/fipspubs/fip180-1.htm">SHA-1</a> is the only supported algorithm. It is anticipated that other algorithms will be supported at a later time.
- Status:
- stable
- Domain:
- <a href="#Checksum" rel="rdfs:domain">
Checksum
</a> - Range:
- <a href="#checksumAlgorithm_sha1">
spdx:checksumAlgorithm_sha1
</a>
Property: artifactOf
Indicates the project in which the file originated.
Tools must preserve doap:hompage
and doap:name
properties and the URI (if one is known) of doap:Project
resources that are values of this property. All other properties of doap:Projects
are not directly supported by SPDX and may be dropped when translating to or from some SPDX formats.
- Status:
- stable
- Domain:
- <a href="#File" rel="rdfs:domain">
File
</a> - Range:
- <a href="http://usefulinc.com/ns/doap#Project" rel="rdfs:range">
doap:Project
</a>
Property: checksum
The checksum
property provides a mechanism that can be used to verify that the contents of a <a href="#File">File
</a> or <a href="#Package">Package
</a> have not changed.
- Status:
- stable
- Domain:
- Any of:
- <a href="#Package" rel="rdf:first">
Package
</a> - <a href="#File" rel="rdf:first">
File
</a>
- <a href="#Package" rel="rdf:first">
- Range:
- <a href="#Checksum" rel="rdfs:range">Checksum</a>
Property: checksumValue
The checksumValue
property provides a lower case hexidecimal encoded digest value produced using a specific algorithm.
- Status:
- stable
- Domain:
- <a href="#Checksum" rel="rdfs:domain">
Checksum
</a> - Range:
- <a href="http://www.w3.org/TR/xmlschema-2/#hexBinary">
xsd:hexBinary
</a>
Property: created
The date and time at which the <a href="#SpdxDocument">SpdxDocument
</a> was created. This value must in UTC and have 'Z' as its timezone indicator.
- Status:
- stable
- Domain:
- <a href="#CreationInfo" rel="rdfs:domain">
CreationInfo
</a> - Range:
- <a href="http://www.w3.org/TR/xmlschema-2/#dateTime">
xsd:dateTime
</a>
Property: copyrightText
The text of copyright declarations recited in the <a href="#Package">Package
</a> or <a href="#File">File
</a>.
- Status:
- stable
- Domain:
- Any of:
- <a href="#Package" rel="rdf:first">
Package
</a> - <a href="#File" rel="rdf:first">
File
</a>
- <a href="#Package" rel="rdf:first">
- Range:
- Any of:
- <a href="http://www.w3.org/TR/rdf-schema/#ch_literal">
rdfs:Literal
</a> - <a href="#none">
spdx:none
</a> - <a href="#noassertion">
spdx:noassertion
</a>
- <a href="http://www.w3.org/TR/rdf-schema/#ch_literal">
Property: creationInfo
The creationInfo
property relates an <a href="#SpdxDocument">SpdxDocument
</a> to a set of information about the creation of the <a href="#SpdxDocument">SpdxDocument
</a>.
- Status:
- stable
- Domain:
- <a href="#SpdxDocument" rel="rdfs:domain">
SpdxDocument
</a> - Range:
- <a href="#CreationInfo" rel="rdfs:range">
CreationInfo
</a>
Property: creator
The name and, optionally, contact information of a person, organization or tool that created, or was used to create, the <a href="#SpdxDocument">SpdxDocument
</a>.
Values of this property must conform to the <a href="#agent-syntax">agent and tool syntax</a>.
- Status:
- stable
- Domain:
- <a href="#CreationInfo" rel="rdfs:domain">
CreationInfo
</a> - Range:
- <a href="http://www.w3.org/TR/xmlschema-2/#string">
xsd:string
</a>
Property: dataLicense
The licensing under which the <a href="#creator">creator
</a> of this SPDX document allows related data to be reproduced.
The only valid value for this property is http://spdx.org/licenses/CC0-1.0
. This is to alleviate any concern that content (the data) in an SPDX file is subject to any form of intellectual property right that could restrict the re-use of the information or the creation of another SPDX file for the same project(s). This approach avoids intellectual property and related restrictions over the SPDX file, however individuals can still contract one to one to restrict release of specific collections of SPDX files (which map to software bill of materials) and the identification of the supplier of SPDX files.
- Status:
- stable
- Domain:
- <a href="#SpdxDocument" rel="rdfs:domain">
SpdxDocument
</a> - Range:
- <a href="http://spdx.org/licenses/CC0-1.0" rel="rdf:first">
http://spdx.org/licenses/CC0-1.0
</a>
Property: describesPackage
The describesPackage
property relates an SpdxDocument
to the package which it describes.
- Status:
- stable
- Domain:
- <a href="#SpdxDocument" rel="rdfs:domain">
SpdxDocument
</a> - Range:
- <a href="#Package" rel="rdfs:range">
Package
</a>
Property: description
Provides a detailed description of the package.
- Status:
- stable
- Domain:
- <a href="#Package" rel="rdfs:domain">
Package
</a> - Range:
- <a href="http://www.w3.org/TR/xmlschema-2/#string">
xsd:string
</a>
Property: downloadLocation
The URI at which this package is available for download. Private (i.e., not publicly reachable) URIs are acceptable as values of this property.
The values <a href="#none">http://spdx.org/rdf/terms#none
</a> and <a href="#noassertion">http://spdx.org/rdf/terms#noassertion
</a> may be used to specify that the package is not downloadable or that no attempt was made to determine its download location, respectively.
- Status:
- stable
- Domain:
- <a href="#Package" rel="rdfs:domain">
Package
</a> - Range:
- <a href="http://www.w3.org/TR/xmlschema-2/#anyURI">
xsd:anyURI
</a>
Property: extractedText
Verbatim license or licensing notice text that was discovered.
- Status:
- stable
- Domain:
- <a href="#ExtractedLicensingInfo" rel="rdfs:domain">
ExtractedLicensingInfo
</a> - Range:
- <a href="http://www.w3.org/TR/xmlschema-2/#string">
xsd:string
</a>
Property: fileName
The name of the file relative to the root of the package.
- Status:
- stable
- Domain:
- <a href="#File" rel="rdfs:domain">
File
</a> - Range:
- <a href="http://www.w3.org/TR/xmlschema-2/#string">
xsd:string
</a>
Property: fileType
The type of the file.
- Status:
- stable
- Domain:
- <a href="#File" rel="rdfs:domain">
File
</a> - Range:
- One of:
- <a href="#fileType_source">
spdx:fileType_source
</a>Indicates the file is a source code file.
- <a href="#fileType_archive">
spdx:fileType_archive
</a>Indicates the file is an archive file.
- <a href="#fileType_binary">
spdx:fileType_binary
</a>Indicates the file is not a text file.
filetype_archive
is preferred for archive files even though they are binary. - <a href="#fileType_other">
spdx:fileType_other
</a>Indicates the file did not fall into any of the other categories.
- <a href="#fileType_source">
Property: hasExtractedLicensingInfo
Indicates that a particular <a href="#ExtractedLicensingInfo">ExtractedLicensingInfo
</a> was defined in the subject <a href="#SpdxDocument">SpdxDocument
</a>.
- Status:
- stable
- Domain:
- <a href="#SpdxDocument" rel="rdfs:domain">
SpdxDocument
</a> - Range:
- <a href="#ExtractedLicensingInfo" rel="rdfs:range">
ExtractedLicensingInfo
</a>
Property: hasFile
Indicates that a particular <a href="#File">file</a> belongs to a <a href="#Package">package</a>.
- Status:
- stable
- Domain:
- <a href="#Package" rel="rdfs:domain">
Package
</a> - Range:
- <a href="#File" rel="rdfs:range">
File
</a>
Property: isOsiApproved
Indicates that a particular <a href="#License">license</a> has been approved by the <a href="http://opensource.org/">OSI</a> as an open source licenses. If this property is true there should be a seeAlso
property linking to the OSI version of the license.
- Status:
- stable
- Domain:
- <a href="#License" rel="rdfs:domain">
License
</a> - Range:
- <a href="http://www.w3.org/TR/xmlschema-2/#boolean">
xsd:boolean
</a>
Property: licenseComments
The licenseComments
property allows the preparer of the SPDX document to describe why the licensing in <a href="#licenseConcluded">spdx:licenseConcluded
</a> was chosen.
- Status:
- stable
- Domain:
- Any of:
- <a href="#Package" rel="rdf:first">
Package
</a> - <a href="#File" rel="rdf:first">
File
</a>
- <a href="#Package" rel="rdf:first">
- Range:
- <a href="http://www.w3.org/TR/xmlschema-2/#string">
xsd:string
</a>
Property: licenseConcluded
The licensing that the preparer of this SPDX document has concluded, based on the evidence, actually applies to the package.
- Status:
- stable
- Domain:
- Any of:
- <a href="#Package" rel="rdf:first">
Package
</a> - <a href="#File" rel="rdf:first">
File
</a>
- <a href="#Package" rel="rdf:first">
- Range:
- Any of:
- <a href="#AnyLicenseInfo" rel="rdf:first">
AnyLicenseInfo
</a> - <a href="#none">
spdx:none
</a> - <a href="#noassertion">
spdx:noassertion
</a>
- <a href="#AnyLicenseInfo" rel="rdf:first">
Property: licenseDeclared
The licensing that the creators of the software in the package, or the packager, have declared. Declarations by the original software creator should be preferred, if they exist.
- Status:
- stable
- Domain:
- <a href="#Package" rel="rdfs:domain">
Package
</a> - Range:
- Any of:
- <a href="#AnyLicenseInfo" rel="rdf:first">
AnyLicenseInfo
</a> - <a href="#none">
spdx:none
</a> - <a href="#noassertion">
spdx:noassertion
</a>
- <a href="#AnyLicenseInfo" rel="rdf:first">
Property: licenseId
A short name for the license that is at least 3 characters long and made up of the characters from the set 'a'-'z', 'A'-'Z', '0'-'9', '+', '_', '.', and '-'. Formally, all licenseId
values must match the regular expression: [-+_.a-zA-Z0-9]{3,}
- Status:
- stable
- Domain:
- <a href="#License" rel="rdf:first">
License
</a> - <a href="#ExtractedLicensingInfo" rel="rdf:first">
ExtractedLicensingInfo
</a>
- <a href="#License" rel="rdf:first">
- Range:
- <a href="http://www.w3.org/TR/xmlschema-2/#string">
xsd:string
</a>
Property: licenseText
The full text of the license.
- Status:
- stable
- Domain:
- <a href="#License" rel="rdfs:domain">
License
</a> - Range:
- <a href="http://www.w3.org/TR/xmlschema-2/#string">
xsd:string
</a>
Property: licenseInfoFromFiles
The licensing information that was discovered directly within the package. There will be an instance of this property for each distinct value of all <a href="#licenseInfoInFile">licenseInfoInFile
</a> properties of all files contained in the package.
- Status:
- stable
- Domain:
- <a href="#Package" rel="rdfs:domain">
Package
</a> - Range:
- Any of:
- <a href="#SimpleLicenseInfo" rel="rdf:first">
SimpleLicenseInfo
</a> - <a href="#none">
spdx:none
</a> - <a href="#noassertion">
spdx:noassertion
</a>
- <a href="#SimpleLicenseInfo" rel="rdf:first">
Property: licenseInfoInFile
Licensing information that was discovered directly in the subject file.
- Status:
- stable
- Domain:
- <a href="#File" rel="rdfs:domain">
File
</a> - Range:
- Any of:
- <a href="#SimpleLicenseInfo" rel="rdf:first">
SimpleLicenseInfo
</a> - <a href="#none">
spdx:none
</a> - <a href="#noassertion">
spdx:noassertion
</a>
- <a href="#SimpleLicenseInfo" rel="rdf:first">
Property: member
A <a href="#License">license</a>, or other licensing information, that is a member of the subject license set.
- Status:
- stable
- Domain:
- Any of:
- <a href="#ConjunctiveLicenseSet" rel="rdf:first">
ConjunctiveLicenseSet
</a> - <a href="#DisjunctiveLicenseSet" rel="rdf:first">
DisjunctiveLicenseSet
</a>
- <a href="#ConjunctiveLicenseSet" rel="rdf:first">
- Range:
- <a href="#AnyLicenseInfo" rel="rdfs:range">
AnyLicenseInfo
</a> - Refines:
- <a href="http://www.w3.org/TR/rdf-schema/#ch_member">
rdfs:member
</a>
Property: name
The full human readable name of the item. This should include version information when applicable.
- Status:
- stable
- Domain:
- Any of:
- <a href="#Package" rel="rdf:first">
Package
</a> - <a href="#ExtractedLicensingInfo" rel="rdf:first">
ExtractedLicensingInfo
</a> - <a href="#License" rel="rdf:first">
License
</a>
- <a href="#Package" rel="rdf:first">
- Range:
- <a href="http://www.w3.org/TR/xmlschema-2/#string">
xsd:string
</a> - Refines:
- <a href="http://www.w3.org/TR/rdf-schema/#ch_label">
rdfs:label
</a>
Property: originator
The name and, optionally, contact information of the person or organization that originally created the package.
Values of this property must conform to the <a href="#agent-syntax">agent and tool syntax</a>.
- Status:
- stable
- Domain:
- <a href="#Package" rel="rdfs:domain">
Package
</a> - Range:
- <a href="http://www.w3.org/TR/xmlschema-2/#string">
xsd:string
</a> or the individual <a href="#noassertion">spdx:noassertion
</a>
Property: packageFileName
The base name of the package file name. For example, zlib-1.2.5.tar.gz
.
- Status:
- stable
- Domain:
- <a href="#Package" rel="rdfs:domain">
Package
</a> - Range:
- <a href="http://www.w3.org/TR/xmlschema-2/#string">
xsd:string
</a>
Property: packageVerificationCode
A manifest based authentication code for the package. This allows consumers of this data to determine if a package they have in hand is identical to the package from which the data was produced. This algorithm works even if the SPDX document is included in the package. This algorithm is described in detail in the SPDX specification.
The package verification code algorithm is defined in section 4.7 of the full specification.
- Status:
- stable
- Domain:
- <a href="#Package" rel="rdfs:domain">
Package
</a> - Range:
- <a href="#PackageVerificationCode" rel="rdfs:range">
PackageVerificationCode
</a>
Property: packageVerificationCodeExcludedFile
A file that was excluded when calculating the <a href="#packageVerificationCode">package verification code</a>. This is usually a file containing SPDX data regarding the package. If a package contains more than one SPDX file all SPDX files must be excluded from the package verification code. If this is not done it would be impossible to correctly calculate the verification codes in both files.
- Status:
- stable
- Domain:
- <a href="#PackageVerificationCode" rel="rdfs:domain">
PackageVerificationCode
</a> - Range:
- <a href="http://www.w3.org/TR/xmlschema-2/#string">
xsd:string
</a>
Property: packageVerificationCodeValue
The actual package verification code as a hex encoded value.
- Status:
- stable
- Domain:
- <a href="#PackageVerificationCode" rel="rdfs:domain">
PackageVerificationCode
</a> - Range:
- <a href="http://www.w3.org/TR/xmlschema-2/#hexBinary">
xsd:hexBinary
</a>
Property: referencesFile
Indicates that a particular file belongs as part of the set of analyzed files in the <a href="#SpdxDocument">SpdxDocument
</a>.
- Status:
- stable
- Domain:
- <a href="#SpdxDocument" rel="rdfs:domain">
SpdxDocument
</a> - Range:
- <a href="#File" rel="rdfs:range">
File
</a>
Property: reviewDate
The date and time at which the <a href="#SpdxDocument">SpdxDocument
</a> was reviewed. This value must be in UTC and have 'Z' as its timezone indicator.
- Status:
- stable
- Domain:
- <a href="#Review" rel="rdfs:domain">
Review
</a> - Range:
- <a href="http://www.w3.org/TR/xmlschema-2/#dateTime">
xsd:dateTime
</a>
Property: reviewed
The review
property relates a SpdxDocument
to the review history.
- Status:
- stable
- Domain:
- <a href="#SpdxDocument" rel="rdfs:domain">
SpdxDocument
</a> - Range:
- <a href="#Review" rel="rdfs:range">
Review
</a>
Property: reviewer
The name and, optionally, contact information of the person who performed the review.
Values of this property must conform to the <a href="#agent-syntax">agent and tool syntax</a>.
- Status:
- stable
- Domain:
- <a href="#Review" rel="rdfs:domain">
Review
</a> - Range:
- <a href="http://www.w3.org/TR/xmlschema-2/#string">
xsd:string
</a>
Property: sourceInfo
Allows the producer(s) of the SPDX document to describe how the package was acquired and/or changed from the original source.
- Status:
- stable
- Domain:
- <a href="#Package" rel="rdfs:domain">
Package
</a> - Range:
- <a href="http://www.w3.org/TR/xmlschema-2/#string">
xsd:string
</a>
Property: specVersion
Identifies the version of this specification that was used to produce this SPDX document. The value for this version of the spec is SPDX-1.1
. The value SPDX-1.0
may also be supported by SPDX tools for backwards compatibility purposes.
- Status:
- stable
- Domain:
- <a href="#SpdxDocument" rel="rdfs:domain">
SpdxDocument
</a> - Range:
- <a href="http://www.w3.org/TR/xmlschema-2/#string">
xsd:string
</a>
Property: standardLicenseHeader
Text specifically delineated by the license, or license appendix, as the preferred way to indicate that a source, or other, file is copyable under the license.
- Status:
- stable
- Domain:
- <a href="#License" rel="rdfs:domain">
License
</a> - Range:
- <a href="http://www.w3.org/TR/xmlschema-2/#string">
xsd:string
</a>
Property: summary
Provides a short description of the package.
- Status:
- stable
- Domain:
- <a href="#Package" rel="rdfs:domain">
Package
</a> - Range:
- <a href="http://www.w3.org/TR/xmlschema-2/#string">
xsd:string
</a>
Property: supplier
The name and, optionally, contact information of the person or organization who was the immediate supplier of this package to the recipient. The supplier may be different than <a href="#originator">originator
</a> when the software has been repackaged.
Values of this property must conform to the <a href="#agent-syntax">agent and tool syntax</a>.
- Status:
- stable
- Domain:
- <a href="#Package" rel="rdfs:domain">
Package
</a> - Range:
- <a href="http://www.w3.org/TR/xmlschema-2/#string">
xsd:string
</a> or the individual <a href="#noassertion">spdx:noassertion
</a>
Property: versionInfo
Provides an indication of the version of the package that is described by this <a href="#SpdxDocument">SpdxDocument
</a>.
- Status:
- stable
- Domain:
- <a href="#Package" rel="rdfs:domain">
Package
</a> - Range:
- <a href="http://www.w3.org/TR/xmlschema-2/#string">
xsd:string
</a>
Individuals
- <a href="#checksumAlgorithm_sha1">
checksumAlgorithm_sha1
</a> - <a href="#fileType_archive">
fileType_archive
</a> - <a href="#fileType_binary">
fileType_binary
</a> - <a href="#fileType_other">
fileType_other
</a> - <a href="#fileType_source">
fileType_source
</a> - <a href="#noassertion">
noassertion
</a> - <a href="#none">
none
</a>
Individual: checksumAlgorithm_sha1
Indicates the algorithm used was <a href="http://www.itl.nist.gov/fipspubs/fip180-1.htm">SHA-1</a>
- Status:
- stable
Individual: fileType_archive
Indicates the file is an archive file.
- Status:
- stable
Individual: fileType_binary
Indicates the file is not a text file. <a href="#fileType_archive">spdx:filetype_archive
</a> is preferred for archive files even though they are binary.
- Status:
- stable
Individual: fileType_other
Indicates the file is not a <a href="#fileType_source">source</a>, <a href="#fileType_archive">archive</a> or <a href="#fileType_binary">binary</a> file.
- Status:
- stable
Individual: fileType_source
Indicates the file is a source code file.
- Status:
- stable
Individual: noassertion
Indicates that the preparer of the SPDX document is not making any assertion regarding the value of this field.
- Status:
- stable
Individual: none
When this value is used as the object of a property it indicates that the preparer of the <a href="#SpdxDocument">SpdxDocument
</a> believes that there is no value for the property. This value should only be used if there is sufficient evidence to support this assertion.
- Status:
- stable
Agent and Tool Identifiers
Fields that identify entities that have acted in relation to the SPDX file are single line of text which name the agent or tool and, optionally, provide contact information. For example, "Person: Jane Doe (jane.doe@example.com)", "Organization: ExampleCodeInspect (contact@example.com)" and "Tool: LicenseFind - 1.0". The exact syntax of agent and tool identifications is described below in <a href="http://tools.ietf.org/html/rfc5234">ABNF</a>.
<code> agent = person / organization tool = "Tool: " name 0*1( " " DASH " " version) person = "Person: " name 0*1contact-info organization = "Organization: " name 0*1contact-info name = 1*( UNRESERVED ) / U+0022 1*( VCHAR-SANS-QUOTE ) U+0022 contact-info = " (" email-addr ")" email-addr = local-name-atom *( "." local-name-atom ) "@" domain-name-atom 1*( "." domain-name-atom ) version = 1*VCHAR-SANS-QUOTE local-name-atom = 1*( ALPHA / DIGIT / ; Printable US-ASCII "!" / "#" / ; characters not including "$" / "%" / ; specials. "&" / "'" / "*" / "+" / "-" / "/" / "=" / "?" / "^" / "_" / "`" / "{" / "|" / "}" / "~" ) domain-name-atom = 1*( ALPHA / DIGIT / "-" ) DASH = U+2010 / U+2212 / ; hyphen, minus, em dash and U+2013 / U+2014 ; en dash UNRESERVED = U+0020-U+0027 / ; visible unicode characters U+0029-U+0080 / ; except '(' and dashes U+00A0-U+200F / U+2011-U+2027 / U+202A-U+2211 / U+2213-U+E01EF VCHAR-SANS-QUOTE = U+0020-U+0021 / ; visible unicode characters U+0023-U+0080 / ; except quotation mark U+00a0-U+E01EF </code>