Safeguard
Tag

spdx

Safeguard articles tagged "spdx" — guides, analysis, and best practices for software supply chain and application security.

57 articles

Open Source Security

SPDX vs CycloneDX: comparing SBOM formats

SPDX and CycloneDX both satisfy federal SBOM rules, but they solve different problems. Here's how they actually differ — with real specs, dates, and tooling.

May 8, 20267 min read
Compliance

Software License Examples and Why They Matter for Security

A software license example is more than boilerplate — it defines your obligations and your risk. Here is how to read common licenses and enforce them at scale.

May 6, 20265 min read
Compliance

Software Licensing Options Explained: A Security and Compliance Guide

Your software licensing options fall into a handful of families, and each one carries obligations that show up in audits. Here is how to read a license before it reads you.

May 2, 20266 min read
SBOM

CycloneDX vs SPDX: SBOM Format Comparison 2026

A practical CycloneDX vs SPDX comparison for 2026 buyers: schema depth, tool support, regulatory alignment, and which format to pick for which use case.

Apr 14, 20265 min read
SBOM

How to Read a CycloneDX SBOM: A Line-by-Line Walkthrough

A walkthrough of a CycloneDX 1.6 JSON document — metadata, components, services, dependencies, and vulnerabilities — with a real snippet and what to check first.

Apr 13, 20267 min read
Compliance

How Does Software Licensing Work? A Practical Guide for Developers

Software licensing works by granting usage rights under specific terms. Here is how open-source and commercial licenses differ, and how to stay compliant in your dependency tree.

Apr 12, 20266 min read
Supply Chain

SBOM File Formats, Explained

An SBOM file is only useful if the tools reading it agree on its structure — here's what CycloneDX, SPDX, and SWID actually look like and when each one fits.

Apr 5, 20265 min read
Software Supply Chain Security

CycloneDX vs SPDX: SBOM Formats Compared

CycloneDX vs SPDX: how the two SBOM formats differ in vulnerability data, licensing, regulatory recognition, and conversion — and which to pick.

Apr 5, 20266 min read
Supply Chain

SBOM Example: Reading a Real CycloneDX and SPDX Document

One component, two formats: a field-by-field walkthrough of a real CycloneDX and SPDX SBOM — purls, licenses, hashes, dependency graphs, and how to validate your own.

Apr 4, 20266 min read
SBOM

SPDX 3.0 Feature Overview for 2026

What changed in SPDX 3.0 and the 3.0.1 patch release: the profile model, AI and dataset profiles, serialization choices, and what to migrate first.

Mar 19, 20265 min read
Standards

SPDX 3.0.1: The Patch Release That Cleared ISO and OMG Submission

SPDX 3.0.1 was announced on December 27, 2024, bundling fixes from 3.0.0 implementation and the edits required for OMG SPDX/3.0 and ISO/IEC submission.

Mar 19, 20265 min read
AI Security

AI Bill of Materials (ML-BOM) Standards in 2026

A senior engineer's survey of AI-BOM and ML-BOM standards in 2026, from CycloneDX ML components to SPDX 3.0 AI profile, and what to actually ship.

Mar 18, 20267 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.

spdx (Page 3) — Safeguard Blog