Skip to main content

SPDX 3 Validation Tool

Validates SPDX 3 documents

While standalone tools like pyshacl and check-jsonschema can be used to validate SPDX 3 documents, there are a few context-aware checks that can be useful. This includes:

  1. Ignored SHACL errors for missing spdxIds if they are defined in an ExternalMap
  2. Validation that any spdxId defined in an ExternalMap are not present in the document
  3. SHACL Validation of merged documents (in this way, if you reference an spdxId from an ExternalMap and then pass the document that provides that spdxId, the type can be validated)
  4. (Hopefully) More useful JSON schema error output

Installation

spdx3-validate can be installed using pip:

python3 -m pip install spdx3-validate

Using as a library

spdx3-validate can also be used programmatically. validate() takes a single source or an iterable of sources (a path or a URL) and returns a ValidationResult:

import spdx3_validate

result = spdx3_validate.validate("doc.spdx3.json")
if not result:
    print(result)  # prints the errors, one per line

# Or inspect the individual findings:
for error in result.errors:
    print(error)
  • The SPDX version is detected from each document's @context; pass version="X.Y" to force one.
  • Set check_merged=True to also validate the merged graph of several documents together.
  • A document that cannot be loaded (missing @context, unknown version, incompatible versions) raises spdx3_validate.SpdxValidateError.

Developing

Developing on spdx3-validate is best done using a virtual environment. You can configure one and install spdx3-validate in editable mode with all necessary development dependencies by running:

python3 -m venv .venv
. .venv/bin/activate
pip install -e ".[dev]"

TODO

  • Option to automatically download dependencies based on locationHint
  • Offline validation?
  • Cache downloaded context

Metadata

Release files for spdx3-validate 0.0.7

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for spdx3-validate 0.0.7
File Size Uploaded
spdx3_validate-0.0.7.tar.gz 13.3 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for spdx3-validate 0.0.7
File Interpreter ABI Platform
spdx3_validate-0.0.7-py3-none-any.whl Python 3 none any Details

Total release size: 25.5 kB

Release files / spdx3_validate-0.0.7.tar.gz

Download URL spdx3_validate-0.0.7.tar.gz
Size 13.3 kB
Tags Source
SHA-256 checksum
How to use checksums
167d4f18ecd643af80290d8b3edde16e9142f528a013b7e45be712e539b5b93a
BLAKE2b-256 checksum
How to use checksums
5297ddfbdf43953f7f284ce4b1b495b86091e1c30253fe5218297d934070e4de
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.13

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 10, 2026.

Transparency log

Release files / spdx3_validate-0.0.7-py3-none-any.whl

Download URL spdx3_validate-0.0.7-py3-none-any.whl
Size 12.2 kB
Tags Python 3
SHA-256 checksum
How to use checksums
722759285636c8e73e6485d5789128e7af1911c0586d7a1bd07c42f8644d091f
BLAKE2b-256 checksum
How to use checksums
3d5c8d091c82061bd96d5bcc3b47edb98810ee9c6adde95910a7f6cb86a233b0
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.13

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 10, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.0.7 This release

2 release files

0.0.5

2 release files

0.0.4

2 release files

0.0.2

2 release files

0.0.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page