ntia_conformance_checker.adapters package

Submodules

ntia_conformance_checker.adapters.adapter_interface module

Blueprint interface for SBOM adapters.

class ntia_conformance_checker.adapters.adapter_interface.SbomAdapter[source]

Bases: ABC

Abstract base class defining the standard interface for all SBOM adapters.

abstractmethod check_author() → bool[source]

Check if the author of SBOM data exists.

abstractmethod check_dependency_relationships() → bool[source]

Check if the SBOM document declares dependency information.

check_doc_version() → bool[source]

Check if the document’s specification version exists.

abstractmethod check_timestamp() → bool[source]

Check if the SBOM creation timestamp exists.

abstractmethod get_components_without_concluded_licenses(reachable_ids: set[str]) → list[tuple[str, str]][source]

Retrieve components missing a concluded license.

Returns:

A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.

Return type:

list[tuple[str, str]]

Retrieve components missing a copyright text.

Returns:

A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.

Return type:

list[tuple[str, str]]

abstractmethod get_components_without_identifiers(reachable_ids: set[str]) → list[tuple[str, str]][source]

Retrieve components missing unique identifiers (SPDX IDs).

Returns:

A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.

Return type:

list[tuple[str, str]]

abstractmethod get_components_without_names(reachable_ids: set[str]) → list[tuple[str, str]][source]

Retrieve components missing a name.

Returns:

A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.

Return type:

list[tuple[str, str]]

abstractmethod get_components_without_suppliers(reachable_ids: set[str]) → list[tuple[str, str]][source]

Retrieve components missing supplier information.

Returns:

A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.

Return type:

list[tuple[str, str]]

abstractmethod get_components_without_versions(reachable_ids: set[str]) → list[tuple[str, str]][source]

Retrieve components missing version information.

Returns:

A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.

Return type:

list[tuple[str, str]]

abstractmethod get_doc_spec_version() → str | None[source]

Retrieve the document’s specification version.

abstractmethod get_sbom_name() → str[source]

Retrieve the name of the SBOM.

abstractmethod get_sbom_types(conformance_messages: list[ValidationMessage]) → list[str][source]

Get SBOM types from the rootElement of the SpdxDocument.

CISA Framing Software Component Transparency (2024) listed “SBOM type” as one of baseline attributes, see Table 1 (p. 22) in: https://www.cisa.gov/resources-tools/resources/framing-software-component-transparency-2024

abstractmethod get_total_number_components() → int[source]

Retrieve total number of components.

Returns:

The total number of components.

Return type:

int

ntia_conformance_checker.adapters.adapter_interface.is_blank_string(value: object, noassertion: bool = False) → bool[source]

Check whether a value is a blank string.

Blank means whitespace-only, or NOASSERTION (any case) when noassertion is set. Use noassertion only for fields where the SPDX specification defines it (supplier, license, copyright). NONE is a statement, so it is not blank.

Parameters:
  • value – The value to check.

  • noassertion – Whether NOASSERTION counts as blank.

Returns:

True if value is a blank string.

Return type:

bool

ntia_conformance_checker.adapters.null_adapter module

Adapter for when parsing fails.

class ntia_conformance_checker.adapters.null_adapter.NullAdapter[source]

Bases: SbomAdapter

Adapter returning defaults, used when parsing fails.

check_author() → bool[source]

Check if the author of SBOM data exists.

check_dependency_relationships() → bool[source]

Check if the SBOM document declares dependency information.

check_timestamp() → bool[source]

Check if the SBOM creation timestamp exists.

get_components_without_concluded_licenses(reachable_ids: set[str]) → list[tuple[str, str]][source]

Retrieve components missing a concluded license.

Returns:

A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.

Return type:

list[tuple[str, str]]

Retrieve components missing a copyright text.

Returns:

A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.

Return type:

list[tuple[str, str]]

get_components_without_identifiers(reachable_ids: set[str]) → list[tuple[str, str]][source]

Retrieve components missing unique identifiers (SPDX IDs).

Returns:

A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.

Return type:

list[tuple[str, str]]

get_components_without_names(reachable_ids: set[str]) → list[tuple[str, str]][source]

Retrieve components missing a name.

Returns:

A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.

Return type:

list[tuple[str, str]]

get_components_without_suppliers(reachable_ids: set[str]) → list[tuple[str, str]][source]

Retrieve components missing supplier information.

Returns:

A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.

Return type:

list[tuple[str, str]]

get_components_without_versions(reachable_ids: set[str]) → list[tuple[str, str]][source]

Retrieve components missing version information.

Returns:

A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.

Return type:

list[tuple[str, str]]

get_doc_spec_version() → str | None[source]

Retrieve the document’s specification version.

get_sbom_name() → str[source]

Retrieve the name of the SBOM.

get_sbom_types(conformance_messages: list[ValidationMessage]) → list[str][source]

Get SBOM types from the rootElement of the SpdxDocument.

CISA Framing Software Component Transparency (2024) listed “SBOM type” as one of baseline attributes, see Table 1 (p. 22) in: https://www.cisa.gov/resources-tools/resources/framing-software-component-transparency-2024

get_total_number_components() → int[source]

Retrieve total number of components.

Returns:

The total number of components.

Return type:

int

ntia_conformance_checker.adapters.spdx2_adapter module

SPDX 2.x specific data extraction adapter.

class ntia_conformance_checker.adapters.spdx2_adapter.Spdx2Adapter(doc: Document)[source]

Bases: SbomAdapter

Adapter for extracting data from SPDX 2.x documents.

check_author() → bool[source]

Check if the author of SBOM data exists.

check_dependency_relationships() → bool[source]

In SPDX 2, this checks for a DESCRIBES relationship

check_timestamp() → bool[source]

Check if the SBOM creation timestamp exists.

get_components_without_concluded_licenses(reachable_ids: set[str]) → list[tuple[str, str]][source]

Retrieve components missing a concluded license.

Returns:

A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.

Return type:

list[tuple[str, str]]

Retrieve components missing a copyright text.

Returns:

A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.

Return type:

list[tuple[str, str]]

get_components_without_identifiers(reachable_ids: set[str]) → list[tuple[str, str]][source]

Retrieve components missing unique identifiers (SPDX IDs).

Returns:

A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.

Return type:

list[tuple[str, str]]

get_components_without_names(reachable_ids: set[str]) → list[tuple[str, str]][source]

Retrieve components missing a name.

Returns:

A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.

Return type:

list[tuple[str, str]]

get_components_without_suppliers(reachable_ids: set[str]) → list[tuple[str, str]][source]

Retrieve components missing supplier information.

Returns:

A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.

Return type:

list[tuple[str, str]]

get_components_without_versions(reachable_ids: set[str]) → list[tuple[str, str]][source]

Retrieve components missing version information.

Returns:

A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.

Return type:

list[tuple[str, str]]

get_doc_spec_version() → str | None[source]

Retrieve the document’s specification version.

get_sbom_name() → str[source]

Retrieve the name of the SBOM.

get_sbom_types(conformance_messages: list[ValidationMessage]) → list[str][source]

Get SBOM types from the rootElement of the SpdxDocument.

CISA Framing Software Component Transparency (2024) listed “SBOM type” as one of baseline attributes, see Table 1 (p. 22) in: https://www.cisa.gov/resources-tools/resources/framing-software-component-transparency-2024

get_total_number_components() → int[source]

In SPDX 2, this returns the total count of packages.

ntia_conformance_checker.adapters.spdx3_adapter module

SPDX 3.x specific data extraction adapter.

class ntia_conformance_checker.adapters.spdx3_adapter.Spdx3Adapter(object_set: SHACLObjectSet, spdx3_doc: SpdxDocument | None)[source]

Bases: SbomAdapter

Adapter for extracting data from SPDX 3.x documents.

check_author() → bool[source]

Check if the author of SBOM data exists.

check_dependency_relationships() → bool[source]

In SPDX 3, this checks package-level dependency relationships.

check_timestamp() → bool[source]

Check if the SBOM creation timestamp exists.

get_components_without_concluded_licenses(reachable_ids: set[str]) → list[tuple[str, str]][source]

Retrieve components missing a concluded license.

Returns:

A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.

Return type:

list[tuple[str, str]]

Retrieve components missing a copyright text.

Returns:

A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.

Return type:

list[tuple[str, str]]

get_components_without_identifiers(reachable_ids: set[str]) → list[tuple[str, str]][source]

Note that SPDX 3 requires identifiers for all elements, so this should not happen in a valid SPDX 3 document. The spdx-python-model JSON deserializer will raise a ValueError if any element is missing an identifier.

get_components_without_names(reachable_ids: set[str]) → list[tuple[str, str]][source]

Retrieve components missing a name.

Returns:

A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.

Return type:

list[tuple[str, str]]

get_components_without_suppliers(reachable_ids: set[str]) → list[tuple[str, str]][source]

Retrieve components missing supplier information.

Returns:

A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.

Return type:

list[tuple[str, str]]

get_components_without_versions(reachable_ids: set[str]) → list[tuple[str, str]][source]

Retrieve components missing version information.

Returns:

A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.

Return type:

list[tuple[str, str]]

get_doc_spec_version() → str | None[source]

Retrieve the document’s specification version.

get_sbom_name() → str[source]

Retrieve the name of the SBOM.

get_sbom_types(conformance_messages: list[ValidationMessage]) → list[str][source]

In SPDX 3, SBOM type is only available in /Software/Sbom class.

get_total_number_components() → int[source]

In SPDX 3, this returns the total count of packages and package subclasses (including AIPackage and DatasetPackage).

ntia_conformance_checker.adapters.spdx3_adapter.is_blank_license_expression(obj: object) → bool[source]

Check whether an object is a license expression without license information.

Parameters:

obj – The object to check, e.g. a relationship target.

Returns:

True if obj is a simplelicensing_LicenseExpression whose text is blank, NOASSERTION, or names the NoAssertionLicense individual.

Return type:

bool

Module contents

Adapter package for handling multiple SBOM specifications.

class ntia_conformance_checker.adapters.NullAdapter[source]

Bases: SbomAdapter

Adapter returning defaults, used when parsing fails.

check_author() → bool[source]

Check if the author of SBOM data exists.

check_dependency_relationships() → bool[source]

Check if the SBOM document declares dependency information.

check_timestamp() → bool[source]

Check if the SBOM creation timestamp exists.

get_components_without_concluded_licenses(reachable_ids: set[str]) → list[tuple[str, str]][source]

Retrieve components missing a concluded license.

Returns:

A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.

Return type:

list[tuple[str, str]]

Retrieve components missing a copyright text.

Returns:

A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.

Return type:

list[tuple[str, str]]

get_components_without_identifiers(reachable_ids: set[str]) → list[tuple[str, str]][source]

Retrieve components missing unique identifiers (SPDX IDs).

Returns:

A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.

Return type:

list[tuple[str, str]]

get_components_without_names(reachable_ids: set[str]) → list[tuple[str, str]][source]

Retrieve components missing a name.

Returns:

A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.

Return type:

list[tuple[str, str]]

get_components_without_suppliers(reachable_ids: set[str]) → list[tuple[str, str]][source]

Retrieve components missing supplier information.

Returns:

A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.

Return type:

list[tuple[str, str]]

get_components_without_versions(reachable_ids: set[str]) → list[tuple[str, str]][source]

Retrieve components missing version information.

Returns:

A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.

Return type:

list[tuple[str, str]]

get_doc_spec_version() → str | None[source]

Retrieve the document’s specification version.

get_sbom_name() → str[source]

Retrieve the name of the SBOM.

get_sbom_types(conformance_messages: list[ValidationMessage]) → list[str][source]

Get SBOM types from the rootElement of the SpdxDocument.

CISA Framing Software Component Transparency (2024) listed “SBOM type” as one of baseline attributes, see Table 1 (p. 22) in: https://www.cisa.gov/resources-tools/resources/framing-software-component-transparency-2024

get_total_number_components() → int[source]

Retrieve total number of components.

Returns:

The total number of components.

Return type:

int

class ntia_conformance_checker.adapters.SbomAdapter[source]

Bases: ABC

Abstract base class defining the standard interface for all SBOM adapters.

abstractmethod check_author() → bool[source]

Check if the author of SBOM data exists.

abstractmethod check_dependency_relationships() → bool[source]

Check if the SBOM document declares dependency information.

check_doc_version() → bool[source]

Check if the document’s specification version exists.

abstractmethod check_timestamp() → bool[source]

Check if the SBOM creation timestamp exists.

abstractmethod get_components_without_concluded_licenses(reachable_ids: set[str]) → list[tuple[str, str]][source]

Retrieve components missing a concluded license.

Returns:

A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.

Return type:

list[tuple[str, str]]

Retrieve components missing a copyright text.

Returns:

A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.

Return type:

list[tuple[str, str]]

abstractmethod get_components_without_identifiers(reachable_ids: set[str]) → list[tuple[str, str]][source]

Retrieve components missing unique identifiers (SPDX IDs).

Returns:

A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.

Return type:

list[tuple[str, str]]

abstractmethod get_components_without_names(reachable_ids: set[str]) → list[tuple[str, str]][source]

Retrieve components missing a name.

Returns:

A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.

Return type:

list[tuple[str, str]]

abstractmethod get_components_without_suppliers(reachable_ids: set[str]) → list[tuple[str, str]][source]

Retrieve components missing supplier information.

Returns:

A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.

Return type:

list[tuple[str, str]]

abstractmethod get_components_without_versions(reachable_ids: set[str]) → list[tuple[str, str]][source]

Retrieve components missing version information.

Returns:

A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.

Return type:

list[tuple[str, str]]

abstractmethod get_doc_spec_version() → str | None[source]

Retrieve the document’s specification version.

abstractmethod get_sbom_name() → str[source]

Retrieve the name of the SBOM.

abstractmethod get_sbom_types(conformance_messages: list[ValidationMessage]) → list[str][source]

Get SBOM types from the rootElement of the SpdxDocument.

CISA Framing Software Component Transparency (2024) listed “SBOM type” as one of baseline attributes, see Table 1 (p. 22) in: https://www.cisa.gov/resources-tools/resources/framing-software-component-transparency-2024

abstractmethod get_total_number_components() → int[source]

Retrieve total number of components.

Returns:

The total number of components.

Return type:

int

class ntia_conformance_checker.adapters.Spdx2Adapter(doc: Document)[source]

Bases: SbomAdapter

Adapter for extracting data from SPDX 2.x documents.

check_author() → bool[source]

Check if the author of SBOM data exists.

check_dependency_relationships() → bool[source]

In SPDX 2, this checks for a DESCRIBES relationship

check_timestamp() → bool[source]

Check if the SBOM creation timestamp exists.

get_components_without_concluded_licenses(reachable_ids: set[str]) → list[tuple[str, str]][source]

Retrieve components missing a concluded license.

Returns:

A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.

Return type:

list[tuple[str, str]]

Retrieve components missing a copyright text.

Returns:

A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.

Return type:

list[tuple[str, str]]

get_components_without_identifiers(reachable_ids: set[str]) → list[tuple[str, str]][source]

Retrieve components missing unique identifiers (SPDX IDs).

Returns:

A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.

Return type:

list[tuple[str, str]]

get_components_without_names(reachable_ids: set[str]) → list[tuple[str, str]][source]

Retrieve components missing a name.

Returns:

A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.

Return type:

list[tuple[str, str]]

get_components_without_suppliers(reachable_ids: set[str]) → list[tuple[str, str]][source]

Retrieve components missing supplier information.

Returns:

A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.

Return type:

list[tuple[str, str]]

get_components_without_versions(reachable_ids: set[str]) → list[tuple[str, str]][source]

Retrieve components missing version information.

Returns:

A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.

Return type:

list[tuple[str, str]]

get_doc_spec_version() → str | None[source]

Retrieve the document’s specification version.

get_sbom_name() → str[source]

Retrieve the name of the SBOM.

get_sbom_types(conformance_messages: list[ValidationMessage]) → list[str][source]

Get SBOM types from the rootElement of the SpdxDocument.

CISA Framing Software Component Transparency (2024) listed “SBOM type” as one of baseline attributes, see Table 1 (p. 22) in: https://www.cisa.gov/resources-tools/resources/framing-software-component-transparency-2024

get_total_number_components() → int[source]

In SPDX 2, this returns the total count of packages.

class ntia_conformance_checker.adapters.Spdx3Adapter(object_set: SHACLObjectSet, spdx3_doc: SpdxDocument | None)[source]

Bases: SbomAdapter

Adapter for extracting data from SPDX 3.x documents.

check_author() → bool[source]

Check if the author of SBOM data exists.

check_dependency_relationships() → bool[source]

In SPDX 3, this checks package-level dependency relationships.

check_timestamp() → bool[source]

Check if the SBOM creation timestamp exists.

get_components_without_concluded_licenses(reachable_ids: set[str]) → list[tuple[str, str]][source]

Retrieve components missing a concluded license.

Returns:

A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.

Return type:

list[tuple[str, str]]

Retrieve components missing a copyright text.

Returns:

A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.

Return type:

list[tuple[str, str]]

get_components_without_identifiers(reachable_ids: set[str]) → list[tuple[str, str]][source]

Note that SPDX 3 requires identifiers for all elements, so this should not happen in a valid SPDX 3 document. The spdx-python-model JSON deserializer will raise a ValueError if any element is missing an identifier.

get_components_without_names(reachable_ids: set[str]) → list[tuple[str, str]][source]

Retrieve components missing a name.

Returns:

A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.

Return type:

list[tuple[str, str]]

get_components_without_suppliers(reachable_ids: set[str]) → list[tuple[str, str]][source]

Retrieve components missing supplier information.

Returns:

A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.

Return type:

list[tuple[str, str]]

get_components_without_versions(reachable_ids: set[str]) → list[tuple[str, str]][source]

Retrieve components missing version information.

Returns:

A list of tuples of the form (component_name, spdx_id). Consumers should extract the preferred value (name or SPDX ID) as needed.

Return type:

list[tuple[str, str]]

get_doc_spec_version() → str | None[source]

Retrieve the document’s specification version.

get_sbom_name() → str[source]

Retrieve the name of the SBOM.

get_sbom_types(conformance_messages: list[ValidationMessage]) → list[str][source]

In SPDX 3, SBOM type is only available in /Software/Sbom class.

get_total_number_components() → int[source]

In SPDX 3, this returns the total count of packages and package subclasses (including AIPackage and DatasetPackage).