$npx skillfedfor your agent

pyspdx

Validate SPDX expressions

With conditionsPyPI Quality AssuranceReleased Feb 202595.3K downloads / moGPL-2.0-onlyPure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — pyspdx-1.2.0-py3-none-any.whl
v1.2.0 · released 2025-02-10 · Python <4.0,>=3.9 · 1 runtime deps: pyparsing

Yes, if your project is copyleft-licensed or can accommodate GPL-2.0-only. The package is lightweight, has no security vulnerabilities, and solves a specific problem (SPDX expression validation) with a minimal API. Dormant maintenance is acceptable for a narrow, stable utility. If your project is proprietary or permissively licensed, the copyleft license makes this a blocker.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.9 or later (supports 3.9–3.13); GPL-2.0-only license means consuming code must be copyleft-compatible.
  • Low install friction with a single lightweight dependency (pyparsing).
  • Repository is dormant but not archived; last commit was recent (2025-02-10), suggesting minimal maintenance rather than abandonment.

License · maintenance · safety

GPL-2.0-only (copyleft) — Licensed under GPL-2.0-only (copyleft). Any code that imports this library must be distributed under compatible copyleft terms; proprietary or permissive-licensed projects cannot use it without license conflict.

last release 2025-02-10 (550 days) · last repo commit 2025-02-10 · 4 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 95,325 downloads/mo, #13,271 on PyPI

Verify before relying

pip install pyspdx

from pyspdx import validate, tokenize

validate("MIT")  # Valid, does nothing
validate("(Apache-2.0 OR MIT) AND BSD-3-Clause")  # Valid
tokenize("MIT")  # Returns ["MIT"]
  • Whether the package handles all SPDX v2.3 license expression edge cases or has known limitations beyond what the description states.
  • Performance characteristics when parsing very large or deeply nested license expressions.
  • Whether the tokenize function output format is stable across versions or documented beyond the single example shown.
Same gist for agents: .md · .json

What it is and what it does

pyspdx is a small Python library that validates and tokenizes SPDX license expressions—the standardized format for describing software licenses and their combinations. It exposes two functions: validate() checks whether a license expression conforms to the SPDX v2.3 specification and raises ValueError if it does not, while tokenize() breaks an expression into its constituent license identifiers. The library handles complex expressions with logical operators (OR, AND, WITH) and document references, relying on pyparsing for the underlying grammar implementation.

The package is useful for tools that need to parse or validate license metadata in software bills of materials, dependency manifests, or compliance workflows. It is dormant but recently maintained; however, its GPL-2.0-only copyleft license means it can only be used in projects that are themselves distributed under compatible copyleft terms.

Use it for

  • Validate license expressions in SBOM (software bill of materials) files before processing or storing them.
  • Parse complex license combinations in dependency metadata to extract individual license identifiers for compliance audits.
  • Build license compliance tooling that needs to reject malformed or non-standard SPDX expressions early.
  • Tokenize license strings to feed into downstream license compatibility or risk analysis systems.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, if your project is copyleft-licensed or can accommodate GPL-2.0-only.

The package is lightweight, has no security vulnerabilities, and solves a specific problem (SPDX expression validation) with a minimal API. Dormant maintenance is acceptable for a narrow, stable utility. If your project is proprietary or permissively licensed, the copyleft license makes this a blocker.

Install

pyspdx on PyPI

Before you install

Low install friction with a single lightweight dependency (pyparsing). Repository is dormant but not archived; last commit was recent (2025-02-10), suggesting minimal maintenance rather than abandonment.

Requires Python 3.9 or later (supports 3.9–3.13); GPL-2.0-only license means consuming code must be copyleft-compatible.

License in practice

Licensed under GPL-2.0-only (copyleft). Any code that imports this library must be distributed under compatible copyleft terms; proprietary or permissive-licensed projects cannot use it without license conflict.

Quickstart

pip install pyspdx

from pyspdx import validate, tokenize

validate("MIT")  # Valid, does nothing
validate("(Apache-2.0 OR MIT) AND BSD-3-Clause")  # Valid
tokenize("MIT")  # Returns ["MIT"]

Verify before relying

  • Whether the package handles all SPDX v2.3 license expression edge cases or has known limitations beyond what the description states.
  • Performance characteristics when parsing very large or deeply nested license expressions.
  • Whether the tokenize function output format is stable across versions or documented beyond the single example shown.

Package facts

LicenseGPL-2.0-only copyleft
Python supportSupports the current Python release <4.0,>=3.9
Install frictionLow. Pure-Python wheel
Runtime dependencies
1 package
pyparsing
MaintenanceDormant 550 days since the last release
Last repo commit
First released
Downloads95,325 / month, #13,271 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
License :: OSI Approved :: GNU General Public License v2 (GPLv2)Programming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.9Typing :: Typed

Evidence: pyspdx-1.2.0-py3-none-any.whl

Tags

Capabilities
spdx license expression validationparse spdx license stringsvalidate license expressionsspdx expression parserlicense compliance checking
Topics
license-compliancespdx

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “spdx license expression validation”

  • pyspdxValidates and tokenizes SPDX license expressions according to the…
  • license-expressionParses, validates, simplifies, and normalizes license expressions…
  • spdx-toolsParse, validate, create, and convert SPDX software license documents…

Give your agent the search over MCP, or paste the wish link into any chat.

More Quality Assurance packages

coverage Worth it
PyPI · Testing · released Aug 2026

Coverage.py measures which lines of Python code are executed during test runs, reporting coverage percentages and identifying untested code paths.

Install it if you want to measure test completeness or enforce coverage thresholds in your project.

permissive licensepure Python · 3.10+
335.8Mdownloads / mo
ruff Worth it
PyPI · Python Modules · released Aug 2026

Ruff is a Python linter and code formatter written in Rust that combines linting, formatting, and code fixing into a single tool, replacing Flake8, Black, isort, and related utilities.

MITcompiled wheel · 3.7+
316.1Mdownloads / mo
pexpect With conditions
PyPI · Software Development · released Nov 2023

Pexpect spawns and controls interactive console applications by sending input and matching output patterns, automating tasks that would otherwise require manual interaction.

ISCpure Pythonaging
200.8Mdownloads / mo
black Worth it
PyPI · Python Modules · released May 2026

Black reformats Python source code to a consistent style by parsing entire files and rewriting them according to an opinionated, deterministic set of rules, eliminating manual formatting decisions.

MITpure Python · 3.10+
179.9Mdownloads / mo
pytest-xdist Worth it
PyPI · Utilities · released Jul 2025

pytest-xdist distributes pytest tests across multiple CPU cores or machines to speed up test execution, with the simplest usage being `pytest -n auto` to spawn workers equal to available CPUs.

Install it if your test suite takes long enough that parallelization would save meaningful time.

MITpure Python · 3.9+
177.1Mdownloads / mo
cfn-lint Worth it
PyPI · Quality Assurance · released Aug 2026

Validates AWS CloudFormation templates in YAML or JSON format against resource provider schemas and best practices, checking property values and configuration correctness.

Install it if you work with CloudFormation templates.

MIT-0pure Python
114.9Mdownloads / mo

See also license-expression · spdx-tools · spdx3-validate · boolean.py · spdx-python-model · stix2-patterns · aws-cron-expression-validator · cel-expr-python · iregexp-check · pip-licenses-cli