| SPDXTOOL(1) | General Commands Manual | SPDXTOOL(1) |
NAME
spdxtool — a tool
for generating SPDX Lite 3.0.1 profile software bills of material
document
SYNOPSIS
spdxtool |
[options] module ... |
DESCRIPTION
spdxtool is a program which generates a
JSON-LD formatted SPDX Lite 3.0.1 software bill of materials (SBOM) for a
given set of pkg-config modules. The output of this tool can then be
translated into other SBOM formats as necessary.
More documentation about SDPX 3.0.1 can be found from: https://spdx.github.io/spdx-spec/v3.0.1/
The options are as follows:
--about- Print the version number, the Copyright notice, and the license of the
spdxtoolprogram to standard output and exit. Most other options and all command line arguments are ignored. --version- Print the version number of the
spdxtoolprogram to standard output and exit. Most other options and all command line arguments are ignored. --agent-name- Set agent name-property in /Core/Agent-class. Default is 'Default'
--creation-time- Set create-property time in /Core/CreationInfo-class. SPDX documentation
recommends using ISO 8601-formatted time which is: YYYY-MM-DDThh:mm:ssZ.
Default is document creation time. This takes precedence over the
SOURCE_DATE_EPOCHenvironment variable. --creation-id- Set creation ID in /Core/CreationInfoc-class. As ID in creation info mainly have special format and it's default is '_:creationinfo_1'.
--define-variable=varname=value- Define varname as value. Variables are used in query output, and some modules' results may change based on the presence of a variable definition.
ENVIRONMENT
PKG_CONFIG_DEBUG_SPEW- If set, print debugging messages to stderr.
PKG_CONFIG_IGNORE_CONFLICTS- If set, ignore
Conflictsrules in modules. Has the same effect as the--ignore-conflictsoption in pkgconf(1) PKG_CONFIG_LIBDIR- A colon-separated list of low-priority directories where
pc(5) files are looked up. The
module search path is constructed by appending this list to
PKG_CONFIG_PATH, which enjoys higher priority. IfPKG_CONFIG_LIBDIRis not defined, the default list compiled into thespdxtoolprogram from thePKG_DEFAULT_PATHpreprocessor macro is appended instead. IfPKG_CONFIG_LIBDIRis defined but empty, nothing is appended. PKG_CONFIG_MAXIMUM_TRAVERSE_DEPTH- Impose a limit on the allowed depth in the dependency graph.
PKG_CONFIG_PATH- A colon-separated list of high-priority directories where pc(5) files are looked up.
PKG_CONFIG_PRELOADED_FILES- Colon-separated list of pc(5) files which are loaded before any other pkg-config files. These packages are given highest priority over any other pc(5) files that would otherwise provide a given package.
SOURCE_DATE_EPOCH- If set, and the
--creation-timeoption is not given, the creation time in /Core/CreationInfo-class is derived from this UNIX timestamp instead of the current time, allowing for reproducible SBOM generation.
EXIT STATUS
The spdxtool utility exits 0 on
success, and >0 if an error occurs.
EXAMPLES
Generating an SBOM for the package named foo:
$ spdxtool foo{@graph: [{type: AgentcreationInfo:
_:creationinfo_1name: Default},{type: CreationInfo@id: _:creationinfo_1[...]SEE ALSO
| January 22, 2026 | Linux 7.1.4-arch1-1 |