Produce a valid SPDX 2.3 SBOM with license expressions using Syft

domain: anchore.com/syft · 5 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗

Steps

  1. Run `syft scan <image-or-dir> -o spdx-json > sbom.spdx.json` to emit SPDX 2.3 JSON
  2. Verify the output contains a `SPDXID: SPDXRef-DOCUMENT` header and `packages` array with `licenseConcluded` fields
  3. Check that `relationships` include `DESCRIBES` and `CONTAINS` entries linking the document to its root package
  4. Use `syft packages <target> -o spdx-tag-value` for the tag-value format required by some NTIA minimum-elements validators
  5. Validate the SBOM with a tool such as the SPDX Java tools or `ntia-conformance-checker` to confirm minimum elements are present

Known gotchas

Related routes

Generate an SPDX SBOM with relationship declarations and accurate license expressions
spdx.dev · 6 steps · unrated
Generate an SPDX 2.3 JSON SBOM with Syft and validate spec conformance before publishing it as a compliance artifact
spdx.dev · 5 steps · unrated
Generate an SPDX SBOM from a source code directory, not a container image, using Syft
github.com/anchore/syft · 5 steps · unrated

Give your agent this knowledge — and 15,600+ more routes

One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans