spdx-python-model
SPDX Model Python Bindings
Decision gist · record as of 2026-08-14
Yes, if you need to work with SPDX 3 documents in Python. The library has low install friction, no runtime dependencies, active maintenance, and permissive licensing. It is the canonical bindings for SPDX 3 and supports modern Python versions. Caveat: it is low-level and lacks convenience helpers—suitable for direct manipulation but not for rapid prototyping of SPDX workflows.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.9 or later.
- Building from source with local SPDX model files requires setting SHACL2CODE_SPDX_DIR environment variable.
- Low installation friction with no runtime dependencies.
License · maintenance · safety
Apache-2.0 (permissive) — Apache-2.0 permissive license allows use in most commercial and open-source projects with minimal restrictions.
last release 2026-06-23 (52 days) · last repo commit 2026-07-01 · 5 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 173,470 downloads/mo, #10,307 on PyPI
Alternatives
Verify before relying
pip install spdx-python-model
import spdx_python_model
p = spdx_python_model.v3_0_1.Person()
# Or load from an SPDX file
from pathlib import Path
model, objset = spdx_python_model.load(Path("/path/to/file.spdx3.json"))- Whether the low-level bindings are suitable for typical SPDX document creation workflows without higher-level helpers
- Performance characteristics when working with large or complex SPDX documents
What it is and what it does
spdx-python-model is a Python library that provides direct bindings to the SPDX 3 specification through auto-generated classes. The bindings are created from the official RDF and SHACL definitions of SPDX 3 using shacl2code during package build, ensuring they stay synchronized with the specification. It exposes low-level, direct access to SPDX data structures organized by version (e.g., v3_0_1), allowing you to instantiate and manipulate SPDX objects programmatically.
The library is intended for developers who need to work directly with SPDX files or build SPDX documents from code. It includes a load() API that can automatically detect and deserialize SPDX documents from disk. However, the bindings are intentionally low-level—they lack higher-level convenience functions for common SPDX creation tasks. If you need a more ergonomic API, the SPDX Python Tools project offers a higher-level interface, though it does not yet support SPDX 3.
Use it for
- Parse and deserialize existing SPDX 3 JSON documents into Python objects for inspection or modification
- Programmatically construct SPDX 3 documents from scratch by instantiating model classes like Person, Package, or Bundle
- Build software bill-of-materials (SBOM) generation tools that emit valid SPDX 3 output
- Integrate SPDX 3 data handling into build systems or CI/CD pipelines that need to work with standardized software metadata
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you need to work with SPDX 3 documents in Python.
The library has low install friction, no runtime dependencies, active maintenance, and permissive licensing. It is the canonical bindings for SPDX 3 and supports modern Python versions. Caveat: it is low-level and lacks convenience helpers—suitable for direct manipulation but not for rapid prototyping of SPDX workflows.
Install
spdx-python-model on PyPI
Before you install
Low installation friction with no runtime dependencies. Active maintenance with a release 52 days ago and recent commits. Supports Python 3.9 through 3.14.
Requires Python 3.9 or later. Building from source with local SPDX model files requires setting SHACL2CODE_SPDX_DIR environment variable.
License in practice
Apache-2.0 permissive license allows use in most commercial and open-source projects with minimal restrictions.
Quickstart
pip install spdx-python-model
import spdx_python_model
p = spdx_python_model.v3_0_1.Person()
# Or load from an SPDX file
from pathlib import Path
model, objset = spdx_python_model.load(Path("/path/to/file.spdx3.json"))
Verify before relying
- Whether the low-level bindings are suitable for typical SPDX document creation workflows without higher-level helpers
- Performance characteristics when working with large or complex SPDX documents
Package facts
| License | Apache-2.0 permissive |
| Python support | Supports the current Python release >=3.9 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | None |
| Maintenance | Actively maintained 52 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 173,470 / month, #10,307 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 4 - BetaIntended Audience :: DevelopersProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Programming Language :: Python :: 3.9Topic :: Software Development :: Libraries :: Python Modules |
Evidence: spdx_python_model-0.0.6-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “spdx 3 python bindings”
- spdx-python-modelProvides Python bindings for the SPDX 3 data model, enabling direct…
- spdx3-validateValidates SPDX 3 documents with context-aware checks for external…
- spdx-toolsParse, validate, create, and convert SPDX software license documents…
Give your agent the search over MCP, or paste the wish link into any chat.
More Python Modules packages
Converts domain names between Unicode and ASCII-compatible encoding (Punycode) according to IDNA 2008 and Unicode Technical Standard 46, with security validation and broader script coverage than the standard library.
Install it if you work with internationalized domain names, need to validate domains, or use HTTP clients that depend on it transitively.
Setuptools is a Python build backend and package management tool that handles building, distributing, and installing Python packages, including support for C/C++ extension modules.
PyYAML parses and emits YAML 1.1 data format, enabling serialization and deserialization of configuration files and Python objects to and from human-readable YAML text.
Pydantic validates Python data structures against type hints, coercing and checking input at runtime to ensure it matches a declared schema.
Provides reusable metadata objects for use with PEP-593 `typing.Annotated` to express common constraints like bounds, collection sizes, and predicates on types.
Install it if you use or build libraries that need to express type constraints in a standardized, inspectable way—or if you want to annotate your own types with…
Provides runtime tools to inspect and introspect Python type annotations, enabling programmatic examination of type hints at execution time.
See also spdx3-validate · lib4sbom · spdx-tools · pyshacl · cyclonedx-python-lib · pyspdx · distro2sbom · cyclonedx-bom · cyclonedx-py · PyShEx