Export SPDX, CycloneDX, PDF, and NOTICE from one reviewed snapshot
THIRD_PARTY_LICENSES.md, NOTICE, JSON, PDF, CycloneDX, SPDX, and more, all tied to the same reviewed inventory as your attestation page.
Last updated: July 19, 2026
What do you need the data for?
Two SBOM standards, selectable spec versions, procurement-ready.
The same reviewed snapshot answers an engineer, a lawyer, and a regulator. When a contract cites the EU Cyber Resilience Act or US Executive Order 14028, you pick the standard and the spec version they name, and download.
CycloneDX 1.5, 1.6, or 1.7
JSON or XML, selected in the download dialog. The version a procurement checklist names is the version you hand over.
SPDX 2.3 or 3.0.1
Including 3.0.1 JSON-LD for pipelines that consume linked data.
Provenance on every file
Each export states which published revision it matches, and warns when your inventory is ahead with unpublished changes. Deliverables trace back to the snapshot.
This export matches revision 8 on the public attestation page
Nine formats from one review
THIRD_PARTY_LICENSES.md, NOTICE, JSON, CSV, standalone HTML, an Xcode Acknowledgements.plist, both SBOMs, and a branded PDF. Nothing is re-reviewed per format, so they can never disagree.
Exports
Ship-ready files from the same reviewed snapshot
Questionnaires may ask for a URL; engineering may need files in git or a release bundle. Every export comes from the same frozen publish snapshot as your attestation page, with provenance tying the file to a specific revision.
Human-readable disclosure
THIRD_PARTY_LICENSES.md, NOTICE, and HTML bundles with copyright notices, license names, and attribution copy suitable for repository roots and release packages.
Machine-readable records
JSON and CSV exports for CI checks and internal tooling. Includes provenance metadata and the public page URL when published.
Platform-specific formats
Apple plist for iOS/macOS distributions. Generated from the same approved inventory as your compliance page.
SBOM variants when asked
CycloneDX (v1.5–1.7 JSON or XML) and SPDX (2.3 / 3.0.1) exports from the reviewed snapshot, for teams that need a machine-readable bundle without publishing a raw vulnerability-correlatable SBOM publicly.
Send SPDX to procurement; keep the attestation URL as the primary proof.
Branded PDF
Download a branded license disclosure PDF from any published snapshot; useful when a buyer wants an attachment instead of a link.
01
The page is the deliverable; exports are the escort
The attestation page is the primary deliverable, a maintained, buyer-readable record. Exports are there when engineering or procurement needs files in-repo, in a release bundle, or as an attachment. Same reviewed inventory either way.
02
Can I generate SPDX or CycloneDX from the same inventory?
Yes. When exports come from the same frozen publish snapshot as your attestation page, SPDX, CycloneDX, PDF, and NOTICE files describe the same reviewed inventory. That is what keeps questionnaires and engineering packages aligned.
03
When should you send a PDF instead of a URL?
Send a PDF when the buyer’s process requires an attachment. Prefer the URL when they will reopen the record later. Either way, generate the file from the approved publish, not from an unreviewed import.
04
What does provenance on an export mean?
Provenance ties the file to a specific publish revision and, when published, to the public page URL. It answers which snapshot this export came from, so diligence does not mix files from different reviews.
Continue reading
Related topics
One idea per page: Follow the path that matches your next question.
Set up a project for each repo, review your obligations, publish when ready, and keep the record aligned with every release. Download license and attribution files when engineering needs them, with pipeline checks so the next update does not undo what you already approved. Your SOC report is not a substitute.
We use essential cookies for security, including abuse prevention on our site scan and walkthrough request form. With your permission, we also use optional analytics and diagnostics (Google Tag Manager on this site, and the Sentry browser SDK on the SourceTrust application when configured). See our cookie policy.