SPDX 3 Validation Tool
Validates SPDX 3 documents
While standalone tools like pyshacl and check-jsonschema can be used to
validate SPDX 3 documents, there are a few context-aware checks that can be
useful. This includes:
- Ignored SHACL errors for missing
spdxIds if they are defined in anExternalMap - Validation that any
spdxIddefined in anExternalMapare not present in the document - SHACL Validation of merged documents (in this way, if you reference an
spdxIdfrom anExternalMapand then pass the document that provides thatspdxId, the type can be validated) - (Hopefully) More useful JSON schema error output
Installation
spdx3-validate can be installed using pip:
python3 -m pip install spdx3-validate
Using as a library
spdx3-validate can also be used programmatically.
validate() takes a single source or an iterable of sources
(a path or a URL) and returns a ValidationResult:
import spdx3_validate
result = spdx3_validate.validate("doc.spdx3.json")
if not result:
print(result) # prints the errors, one per line
# Or inspect the individual findings:
for error in result.errors:
print(error)
- The SPDX version is detected from each document's
@context; passversion="X.Y"to force one. - Set
check_merged=Trueto also validate the merged graph of several documents together. - A document that cannot be loaded (missing
@context, unknown version, incompatible versions) raisesspdx3_validate.SpdxValidateError.
Developing
Developing on spdx3-validate is best done using a virtual environment. You
can configure one and install spdx3-validate in editable mode with all
necessary development dependencies by running:
python3 -m venv .venv
. .venv/bin/activate
pip install -e ".[dev]"
TODO
- Option to automatically download dependencies based on
locationHint - Offline validation?
- Cache downloaded context
Metadata
Release files for spdx3-validate 0.0.7
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| spdx3_validate-0.0.7.tar.gz | 13.3 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| spdx3_validate-0.0.7-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 25.5 kB
Release files / spdx3_validate-0.0.7.tar.gz
| Download URL | spdx3_validate-0.0.7.tar.gz |
|---|---|
| Size | 13.3 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
167d4f18ecd643af80290d8b3edde16e9142f528a013b7e45be712e539b5b93a
|
|
BLAKE2b-256 checksum How to use checksums |
5297ddfbdf43953f7f284ce4b1b495b86091e1c30253fe5218297d934070e4de
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.13
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 10, 2026.
Transparency logRelease files / spdx3_validate-0.0.7-py3-none-any.whl
| Download URL | spdx3_validate-0.0.7-py3-none-any.whl |
|---|---|
| Size | 12.2 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
722759285636c8e73e6485d5789128e7af1911c0586d7a1bd07c42f8644d091f
|
|
BLAKE2b-256 checksum How to use checksums |
3d5c8d091c82061bd96d5bcc3b47edb98810ee9c6adde95910a7f6cb86a233b0
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.13
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 10, 2026.
Transparency log