본문 바로가기
  • Home

SPDX Parser and Validator for Software Compliance

  • Journal of Software Forensics
  • Abbr : JSF
  • 2017, 13(1), pp.15~21
  • Publisher : Korea Software Assessment and Valuation Society
  • Research Area : Engineering > Computer Science
  • Received : May 22, 2017
  • Accepted : June 25, 2017
  • Published : June 30, 2017

Ho-Yeong Yun 1,  Yong-Joon Joe 1,  Byung-Ok Jung 1,  Shin DongMyung 2

1엘에스웨어
2엘에스웨어 (주)

ABSTRACT

Analyzing a software package which is consisted of big numbers of files takes enormous costs and time. Therefore, SPDX (Software Package Data Exchange) working group collaborate with Linux Foundation published a software information(metadata) specification: SPDX. On the first half of 2017, the specification contains seven chapters and 66 items, according to Ver 2.1 of SPDX spec. It prefers Tag/Value or RDF forms but also supports spreadsheet form. In this paper, we introduce SPDX parsing & validation tools to check the validity of SPDX document. We'll develop SPDX document generator to manage software package more efficiently for our next target.

Journal Copyright Policy

No CCL information provided

Citation status

* References for papers published after 2025 are currently being built.