Comment by Tomte
6 hours ago
Software licensing information is the big use case where SPDX originated from.
In CycloneDX you can also express things like attestations/certifications, possibly down to the code review level (although I think nobody does that).
No comments yet
Contribute on Hacker News ↗