Generate an SPDX SBOM for a software project

Problem and when to use it

Use cd-generate-spdx when you need SPDX tag-value documents describing the project and its third-party dependencies, for example as an input to an OpenChain or licence-compliance process. The tool also creates licence reports; see TPIP reporting.

Inputs and example

Configure pyproject.toml with PROJECT_ROOT, SOURCE_DIR, PROGRAMMING_LANGUAGE, your licence policy and any values required by the selected language plugin. Provide PROJECT_UUID and an [spdx] section for the document namespace; see SPDX document identity. Then provide an existing output directory:

mkdir -p spdx-output
cd-generate-spdx --output-dir spdx-output

The selected language plugin must return project metadata; if it does not, the command returns without a report. The selected plugin uses language-specific tools to obtain dependency and licence information; consult the plugin documentation for its prerequisites and metadata support. For Go projects, CDS downloads module dependencies automatically before running the dependency scan. Pass --skip-dependency-download when the environment already prefetches those dependencies and you want to skip that extra step. SPDX tag-value generation also requires an SDK compatible with this project's writer. Check the output files before treating an audit as complete. Installed packages and platform-specific dependency markers determine what is covered; a Linux run does not audit Windows- or macOS-only dependencies.

Output

The directory contains a .spdx document for the project and each discovered dependency, plus third_party_IP_report.html, .csv and .txt summaries when metadata reporting is available. Documents are separate tag-value files, not a single merged dependency graph.

GitHub Actions example

After checking out the project and installing its dependencies:

- run: mkdir -p spdx-output && cd-generate-spdx --output-dir spdx-output
- uses: actions/upload-artifact@v4
  with:
    name: spdx-report
    path: spdx-output/

See cd-generate-spdx's API for the common reporting interface.