From fa0c98b2f59c82e91b6eb5963c0680fd126a623c Mon Sep 17 00:00:00 2001 From: shwetha729 Date: Tue, 18 Jul 2023 10:26:43 -0400 Subject: [PATCH] Updated: 2023-07-18 10:26:42 + 4 --- enter/SPDX.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/enter/SPDX.md b/enter/SPDX.md index 529f186..0d344bc 100644 --- a/enter/SPDX.md +++ b/enter/SPDX.md @@ -3,4 +3,4 @@ Software Package Data Exchange (SPDX) is **an open standard for communicating software Bill of Materials (SBOM) information, including components, licenses, copyrights, and security references**. It is used to create Software Bill of Material lists (SBOMs), encapsulate licensing and copyright details, and provide package metadata such as version identifiers and known vulnerabilities.0 SPDX reduces redundant work by providing a common format for companies and communities to share important data, thereby streamlining and improving compliance, security, and dependability.Its original purpose was to improve license compliance, but it has since been expanded to facilitate additional use-cases, such as supply-chain transparency and security. SPDX has a rich ecosystem of existing tools that provides a common format for companies and communities to share important data to streamline and improve the identification and monitoring of software. Organized by the Linux Foundation -visit the full list on their site [here](https://spdx.dev/). \ No newline at end of file +For a quick [overview](https://spdx.dev/wp-content/uploads/sites/41/2020/04/easier_than_you_think.pdf) or visit the full list on their site [here](https://spdx.dev/). \ No newline at end of file