$npx skillfedfor your agent

spdx3-validate

Validates SPDX 3 data files

With conditionsPyPI Build ToolsReleased Aug 2026133.1K downloads / mopermissive licensePure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — spdx3_validate-0.0.7-py3-none-any.whl
v0.0.7 · released 2026-08-10 · Python >=3.8 · 4 runtime deps: halo, jsonschema, pyshacl, rdflib

Yes, if you need to validate SPDX 3 documents with external reference awareness. The package is actively maintained, has low install friction, carries a permissive MIT license, and adds real value over generic SHACL validation for SPDX-specific use cases. Beta status and early release history suggest caution in production deployments, but the recent activity and zero known vulnerabilities are positive signals.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.8 or later; SPDX documents must include a valid @context field for version detection.
  • Low friction: pure Python wheel with four runtime dependencies (halo, jsonschema, pyshacl, rdflib).
  • Active maintenance with a release within days of the fact sheet date.

License · maintenance · safety

permissive license (permissive) — MIT license (permissive) means you can use, modify, and distribute this package freely in commercial and private projects with minimal restrictions.

last release 2026-08-10 (4 days) · last repo commit 2026-08-10 · 4 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 133,144 downloads/mo, #11,526 on PyPI

Verify before relying

pip install spdx3-validate

import spdx3_validate

result = spdx3_validate.validate("doc.spdx3.json")
if not result:
    print(result)  # prints errors, one per line
  • Whether pyshacl, rdflib, and jsonschema are lightweight or bring significant transitive dependencies.
  • Performance characteristics when validating large or complex SPDX documents.
  • Whether the library is suitable for production use or primarily experimental (beta status).
Same gist for agents: .md · .json

What it is and what it does

spdx3-validate is a Python library that validates SPDX 3 documents with awareness of external references and merged document graphs. While tools like pyshacl and check-jsonschema can validate SPDX 3 files against their schema, this package adds context-specific logic: it ignores SHACL errors for missing spdxIds when they are defined in an ExternalMap, validates that ExternalMap spdxIds are not duplicated in the document itself, and can validate merged document graphs to ensure referenced external spdxIds have compatible types when both documents are provided together.

The package can be used as a command-line tool or imported as a library. The validate() function accepts a single document path or URL, or an iterable of sources, and returns a ValidationResult object containing structured errors. SPDX version is auto-detected from each document's @context, though you can override it. It depends on pyshacl, rdflib, jsonschema, and halo for progress indication.

Use it for

  • Validate SPDX 3 software bill-of-materials documents before submission to compliance systems.
  • Check that external component references in an SPDX document are correctly declared and not duplicated.
  • Validate merged SPDX graphs when combining multiple documents with external references.
  • Programmatically inspect validation errors in a Python application for custom error handling.
  • Detect missing or incompatible @context declarations in SPDX 3 JSON files.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, if you need to validate SPDX 3 documents with external reference awareness.

The package is actively maintained, has low install friction, carries a permissive MIT license, and adds real value over generic SHACL validation for SPDX-specific use cases. Beta status and early release history suggest caution in production deployments, but the recent activity and zero known vulnerabilities are positive signals.

Install

spdx3-validate on PyPI

Before you install

Low friction: pure Python wheel with four runtime dependencies (halo, jsonschema, pyshacl, rdflib). Active maintenance with a release within days of the fact sheet date. Supports Python 3.8 through 3.14.

Requires Python 3.8 or later; SPDX documents must include a valid @context field for version detection.

License in practice

MIT license (permissive) means you can use, modify, and distribute this package freely in commercial and private projects with minimal restrictions.

Quickstart

pip install spdx3-validate

import spdx3_validate

result = spdx3_validate.validate("doc.spdx3.json")
if not result:
    print(result)  # prints errors, one per line

Verify before relying

  • Whether pyshacl, rdflib, and jsonschema are lightweight or bring significant transitive dependencies.
  • Performance characteristics when validating large or complex SPDX documents.
  • Whether the library is suitable for production use or primarily experimental (beta status).

Package facts

Licensepermissive license permissive
Python supportSupports the current Python release >=3.8
Install frictionLow. Pure-Python wheel
Runtime dependencies
4 packages
halojsonschemapyshaclrdflib
MaintenanceActively maintained 4 days since the last release
Last repo commit
First released
Downloads133,144 / month, #11,526 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 4 - BetaIntended Audience :: DevelopersLicense :: OSI Approved :: MIT LicenseProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9Topic :: Software Development :: Build Tools

Evidence: spdx3_validate-0.0.7-py3-none-any.whl

Tags

Capabilities
SPDX 3 validationvalidate SPDX documentsSPDX compliance checkingsoftware bill of materials validationSBOM validatorSHACL validation SPDXexternal map validation
Topics
spdxsbomvalidation

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “SPDX 3 validation”

  • spdx3-validateValidates SPDX 3 documents with context-aware checks for external…
  • pyspdxValidates and tokenizes SPDX license expressions according to the…
  • license-expressionParses, validates, simplifies, and normalizes license expressions…

Give your agent the search over MCP, or paste the wish link into any chat.

More Build Tools packages

packaging Worth it
PyPI · Build Tools · released Aug 2026

Provides reusable utilities for Python packaging interoperability, including version handling, specifiers, markers, requirements, tags, and metadata parsing according to standards like PEP 440 and PEP 425.

Apache-2.0 OR BSD-2-Clausepure Python · 3.9+
2.2Bdownloads / mo
tqdm Worth it
PyPI · Libraries · released Jul 2026

Wraps any iterable to display a real-time progress bar in the terminal or Jupyter notebook, showing iteration count, elapsed time, and estimated time remaining.

copyleftpure Python · 3.8+
648.6Mdownloads / mo
pip Worth it
PyPI · Build Tools · released Aug 2026

pip is the standard installer for Python packages, enabling you to download and install packages from the Python Package Index and other indexes into your Python environment.

MITpure Python · 3.10+
617.5Mdownloads / mo
hatchling Worth it
PyPI · Python Modules · released Aug 2026

Hatchling is a standards-compliant Python build backend that handles packaging, metadata, and distribution of Python projects when configured in a project's pyproject.toml file.

MITpure Python · 3.10+
484.2Mdownloads / mo
grpcio-tools Worth it
PyPI · Build Tools · released Jul 2026

Generates Python gRPC service stubs and message classes from Protocol Buffer definitions, enabling developers to build gRPC clients and servers.

Apache-2.0compiled wheel · 3.10+
278.2Mdownloads / mo
pre-commit Worth it
PyPI · Build Tools · released Aug 2026

pre-commit is a framework for installing and running git hooks written in any language before commits are made, automating code quality and validation checks across multi-language projects.

Install it if your team needs consistent, automated validation at commit time.

permissive licensepure Python · 3.10+
179.9Mdownloads / mo

See also pyshacl · spdx-python-model · spdx-tools · pyspdx · jsonschema · check-jsonschema · kubernetes-validate · validate-docbr · reuse · fastjsonschema