Exports
The right files for every handoff.
Download license notices, reports and machine-readable SBOMs from one reviewed snapshot.
Exports
Pick a format. Get a matched file.
Questionnaires may ask for a URL; engineering may need files in git or a release bundle. Every export comes from the same frozen publish snapshot as your attestation page, with provenance tying the file to a specific revision.
SBOM variants when asked
Human-readable disclosure
Machine-readable records
Platform-specific formats
Branded PDF
SPDX 2.3 or 3.0.1
CycloneDX (v1.5–1.7 JSON or XML) and SPDX (2.3 / 3.0.1) exports from the reviewed snapshot, for teams that need a machine-readable bundle without publishing a raw vulnerability-correlatable SBOM publicly.
Including 3.0.1 JSON-LD for pipelines that consume linked data.
What do you need the data for?
Two standards. The version your contract names.
- SPDX 2.3 or 3.0.1
- Including 3.0.1 JSON-LD for pipelines that consume linked data.
- CycloneDX 1.5, 1.6, or 1.7
- JSON or XML, selected in the download dialog. The version a procurement checklist names is the version you hand over.
Contract and regulatory context
The same reviewed snapshot answers an engineer, a lawyer, and a regulator. When a contract cites the EU Cyber Resilience Act or US Executive Order 14028, you pick the standard and the spec version they name, and download.
Exports
Export questions
The page is the deliverable; exports are the escort
The attestation page is the primary deliverable, a maintained, buyer-readable record. Exports are there when engineering or procurement needs files in-repo, in a release bundle, or as an attachment. Same reviewed inventory either way.
Can I generate SPDX or CycloneDX from the same inventory?
Yes. When exports come from the same frozen publish snapshot as your attestation page, SPDX, CycloneDX, PDF, and NOTICE files describe the same reviewed inventory. That is what keeps questionnaires and engineering packages aligned.
When should you send a PDF instead of a URL?
Send a PDF when the buyer’s process requires an attachment. Prefer the URL when they will reopen the record later. Either way, generate the file from the approved publish, not from an unreviewed import.
What does provenance on an export mean?
Provenance ties the file to a specific publish revision and, when published, to the public page URL. It answers which snapshot this export came from, so diligence does not mix files from different reviews.
Start with the files you already have.
Free to import and review. No credit card needed.
