Open Source Compliance

Open Source Compliance Tools

SPDX expression validators, license compatibility checkers, CycloneDX SBOM validators, and supply chain reference tools that run entirely in your browser.

๐Ÿ”’ Browser-only โ€” no data sent โšก Zero account required ๐Ÿ“ฆ 10 free tools
spdx
SPDX Expression Validatorโ†’
Validate SPDX license expression syntax โ€” AND, OR, WITH operators and LicenseRef identifiers.
licensing
License Compatibility Checkerโ†’
Check whether two open source licenses are compatible for your use case.
sbom
CycloneDX SBOM Validatorโ†’
Validate CycloneDX SBOM structure against v1.4 and v1.5 JSON schema.
supplychain
SLSA Level Referenceโ†’
Look up SLSA level requirements, provenance format, and implementation guidance.
licensing
npm License Auditorโ†’
Audit npm package licenses for compliance risk before adding dependencies.
spdx
REUSE Compliance Checkerโ†’
Validate REUSE specification file header format for SPDX copyright and license identifiers.
licensing
OSI License Referenceโ†’
Search all OSI-approved licenses with type, GPL compatibility, and patent clause status.
supplychain
Go Module Path Validatorโ†’
Validate Go module paths and check major version suffix requirements.
supplychain
Supply Chain Risk Referenceโ†’
Reference guide to software supply chain attack types, mitigations, and tooling.
sbom
SBOM Format Comparatorโ†’
Compare CycloneDX and SPDX SBOM formats for NTIA, EU CRA, and VEX compliance.