ABCDEFGHIJKLMNOPQRSTUVWXYZAA
1
CategoryField nameStandardSPDX 3.0 field ID
SPDX 3.0 field name
Mapping justificationComment
2
Automation supportSBOM specification name
Implied to be SPDX from file extension
3
SBOM specification version
Sbom.creationInfo.specVersion
Spec version
4
5
SBOM data fieldsSBOM author
Sbom.creationInfo.createdBy
Created by
6
SBOM tool name
Sbom.creationInfo.createdUsing
Created using
7
SBOM timestamp
Sbom.creationInfo.created
Created
created data type is exactly timestamp and it is for this purpose
8
SBOM type (generation context)Sbom.sbomTypeSBOM typeExact match
9
SBOM primary componentSbom.rootElementRoot element
10
11
Component data fieldsComponent nameElement.nameName
12
Component version string
Package.packageVersion
Package version
13
Component supplier/producer name
Package.suppliedBy
Supplied by
14
Component cryptographic hash
Package.verifiedUsing
Verified using
15
Component unique identifier
Artifact.spdxId, SoftwareArtifact.contentIdentifier, Element.externalIdentifier
16
Component relationships
Relationship (with relation types like dependsOn, hasStaticLink, hasDynamicLink, hasProvidedDependency, hasOptionalDependency, etc)
17
Component license
Relationship (with relation types hasConcludedLicense and hasDeclaredLicense)
18
Component copyright holder
SoftwareArtifact.copyrightText
Copyright text
SPDX 3.0 does not have the exact slot for copyright holder name but as copyright text will contain this information, this SPDX 3.0 property is used here.
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100