
SPDX 2.3 SBOM With Snippet Ranges
An SPDX 2.3 JSON SBOM that uses the snippet section to attribute a fictional vendored fragment inside a file to a different licence, with both byte-offset and line-number ranges. Every package, version, hash and licence is fictional: the tree describes nothing real.
- File
- JSON · Sbom
- Use case
- JSON parsingSchema validation+1· Conversion set






















