{ "$schema": "https://json-schema.org/draft/2020-12/schema", "$id": "https://raw.githubusercontent.com/api-evangelist/github/main/json-schema/github-dependency-graph-spdx-sbom-schema.json", "title": "Dependency Graph SPDX SBOM", "description": "A schema for the SPDX JSON format returned by the Dependency Graph.", "x-generated": "2026-10-03", "x-method": "derived", "x-generator": "derive-json-schema.py", "x-source": "openapi/github-dependency-graph-api-openapi.yml#/components/schemas/dependency-graph-spdx-sbom", "type": "object", "properties": { "sbom": { "type": "object", "properties": { "SPDXID": { "type": "string", "description": "The SPDX identifier for the SPDX document." }, "spdxVersion": { "type": "string", "description": "The version of the SPDX specification that this document conforms to." }, "creationInfo": { "type": "object", "properties": { "created": { "type": "string", "description": "The date and time the SPDX document was created." }, "creators": { "type": "array", "items": { "type": "string" }, "description": "The tools that were used to generate the SPDX document." } }, "required": [ "created", "creators" ] }, "name": { "type": "string", "description": "The name of the SPDX document." }, "dataLicense": { "type": "string", "description": "The license under which the SPDX document is licensed." }, "documentDescribes": { "type": "array", "items": { "type": "string" }, "description": "The name of the repository that the SPDX document describes." }, "documentNamespace": { "type": "string", "description": "The namespace for the SPDX document." }, "packages": { "type": "array", "items": { "type": "object", "properties": { "SPDXID": { "type": "string", "description": "A unique SPDX identifier for the package." }, "name": { "type": "string", "description": "The name of the package." }, "versionInfo": { "type": "string", "description": "The version of the package. If the package does not have an exact version specified,\na version range is given." }, "downloadLocation": { "type": "string", "description": "The location where the package can be downloaded,\nor NOASSERTION if this has not been determined." }, "filesAnalyzed": { "type": "boolean", "description": "Whether the package's file content has been subjected to\nanalysis during the creation of the SPDX document." }, "licenseConcluded": { "type": "string", "description": "The license of the package as determined while creating the SPDX document." }, "licenseDeclared": { "type": "string", "description": "The license of the package as declared by its author, or NOASSERTION if this information\nwas not available when the SPDX document was created." }, "supplier": { "type": "string", "description": "The distribution source of this package, or NOASSERTION if this was not determined." }, "externalRefs": { "type": "array", "items": { "type": "object", "properties": { "referenceCategory": { "type": "string", "description": "The category of reference to an external resource this reference refers to." }, "referenceLocator": { "type": "string", "description": "A locator for the particular external resource this reference refers to." }, "referenceType": { "type": "string", "description": "The category of reference to an external resource this reference refers to." } }, "required": [ "referenceCategory", "referenceLocator", "referenceType" ] } } } }, "required": [ "SPDXID", "name", "versionInfo", "downloadLocation", "filesAnalyzed", "licenseConcluded", "licenseDeclared", "supplier" ] } }, "required": [ "SPDXID", "spdxVersion", "creationInfo", "name", "dataLicense", "documentDescribes", "documentNamespace", "packages" ] } }, "required": [ "sbom" ] }