Comment by Tomte

Comment by Tomte 6 hours ago

0 replies

Software licensing information is the big use case where SPDX originated from.

In CycloneDX you can also express things like attestations/certifications, possibly down to the code review level (although I think nobody does that).