[media-types] [IANA #1450117] application/spdx3+json reg istration request
"Amanda Baber via RT" <[email protected]> Wed, 15 Apr 2026 00:50:01 +0000
| Newsgroups | gmane.ietf.types |
|---|---|
| Message-ID | <[email protected]> |
Hi Alexey, Would it be possible to review this request from the Linux Foundation by April 28th? It looks like you reviewed application/spdx+json and text/spdx 4-6 years ago. The submitter added the following notes: === This is similar to the two existing SPDX media types and aligned with SPDX principles to be vendor-neutral. Btw, we are aware of the possibility of using a "version" parameter to extend the existing "application/spdx+json" to accommodate multiple SPDX versions. At the same time, we see quite a big differences between the JSON formats of SPDX 3 and prior SPDX versions. We are also aware of the implications of putting a version number inside the media type string itself (spdx3+json) and question if this means we will have to register another media type in the future when SPDX version 4 is released. If IANA can further share its best practices and advice with us, it would be greatly appreciated. We track the application/spdx3+json media type registration here: https://github.com/spdx/spdx-spec/issues/1359 Thank you again for your help, we are much appreciated. === thanks, Amanda ===== Name: Arthit Suriyawongkul Email: [email protected] Media type name: application Media subtype name: spdx3+json Required parameters: N/A Optional parameters: version The version parameter refers to the SPDX specification version in use. version = 1*DIGIT "." 1*DIGIT ["." 1*DIGIT] Encoding considerations: binary This media type has all of the same encoding considerations of application/json as described in [RFC8259] Section 8.1. Security considerations: The format supports the ExternalRef and ExternalIdentifier classes, which provide links to external databases such as the National Vulnerability Database (NVD) and various security advisories. Users should be aware that following these links involves interacting with external systems. SPDX 3 documents do not allow embedding executable content. Additionally, this media inherits the interoperability security considerations of application/json as described in [RFC8259] Section 12. Interoperability considerations: The application/spdx3+json media type can be distributed free of external systems or processors. Internet text-processing applications will likely consume these documents. The application/spdx3+json media type is a strict subset of JSON-LD 1.1 (https://www.w3.org/TR/json-ld11/). Additionally, this media type inherits the interoperability considerations of application/json as described in [RFC8259]. Published specification: Current versions of the specification are available at https://spdx.github.io/spdx-spec/. Historical versions can be found at https://spdx.org/specifications. The current SPDX 3 JSON schema version is available at https://spdx.org/schema/3.0/spdx-json-schema.json. The current SPDX 3 JSON serialization details is available at https://spdx.github.io/spdx-spec/v3.0/serializations/. Applications which use this media: This media is intended to represent a bill of materials (BOM), including but not limited to a software bill of materials (SBOM), and will be used by tools that produce or consume BOMs as part of their supply chain. Fragment identifier considerations: N/A Restrictions on usage: N/A Provisional registration? (standards tree only): No Additional information: 1. Deprecated alias names for this type: N/A 2. Magic number(s): N/A 3. File extension(s): .spdx3.json 4. Macintosh file type code: N/A 5. Object Identifiers: N/A Person to contact for further information: 1. Name: Arthit Suriyawongkul 2. Email: [email protected] Intended usage: COMMON SPDX is an open standard. It is intended to be used to enable companies and organizations to share human-readable and machine-processable software package metadata to facilitate secure and compliant software supply chain processes. An SPDX 3 JSON media type will be associated with a particular software package or set of packages and will contain information about it in the SPDX 3 JSON format. Author/Change controller: Kate Stewart <[email protected]> - The Linux Foundation _______________________________________________ media-types mailing list -- [email protected] To unsubscribe send an email to [email protected]