THE LINUX FOUNDATION PROJECTS

News & Announcements

Sep 17, 2025

SBOM Vision

In collaboration with NSA and a number of foreign cybersecurity agencies, CISA just just published this easily consumable SBOM vision document. https://www.cisa.gov/sites/default/files/2025-09/joint-guidance-a-shared-vision-of-software-bill-of-materials-for-cybersecurity_508c.pdf

Jul 29, 2025

A Guide to the GitHub SPDX Repo

We just published a readme file at the top level of the repository that provides a great overview of the contents and where to find what. https://github.com/spdx

Mar 5, 2025

Kudos for Yocto support of SPDX SBOMs

Check out this posting and the accompanying article that give a shout out to the Yocto SBOM work that Joshua Watt briefed us on at the last General Meeting. https://www.linkedin.com/posts/vpetersson_im-excited-by-yoctos-sbom-capabilities-activity-7298791001526063106-qqsc/#?lipi=urn%3Ali%3Apage%3Ad_flagship3_detail_base%3Brv%2FCdMTgS36PFZd4RZTQPg%3D%3D https://sbomify.com/2025/02/21/mastering-sbom-generation-with-yocto/

Jan 27, 2025

SPDX Podcast

New podcast episode of Nerding Out with Viktor is now live! In Viktor's words: I spoke with Kate Stewart from the The Linux Foundation and Gary ONeall about the evolution of SPDX and its role in software transparency. We covered how SPDX grew from a license compliance tool into a…

Nov 13, 2024

Implementing an AI BOM

As global regulations on AI software tighten, developers face a complex set of new, ambiguous rules. The AI Software Bill of Materials (AI BOM), especially the new SPDX 3.0 with AI and dataset profiles, offers a promising solution for compliance, providing detailed, machine-readable documentation of AI systems. Despite its benefits,…