Open Source Compliance
Open Source Compliance Tools
SPDX expression validators, license compatibility checkers, CycloneDX SBOM validators, and supply chain reference tools that run entirely in your browser.
๐ Browser-only โ no data sent
โก Zero account required
๐ฆ 10 free tools
spdx
SPDX Expression Validatorโ
Validate SPDX license expression syntax โ AND, OR, WITH operators and LicenseRef identifiers.
licensing
License Compatibility Checkerโ
Check whether two open source licenses are compatible for your use case.
sbom
CycloneDX SBOM Validatorโ
Validate CycloneDX SBOM structure against v1.4 and v1.5 JSON schema.
supplychain
SLSA Level Referenceโ
Look up SLSA level requirements, provenance format, and implementation guidance.
licensing
npm License Auditorโ
Audit npm package licenses for compliance risk before adding dependencies.
spdx
REUSE Compliance Checkerโ
Validate REUSE specification file header format for SPDX copyright and license identifiers.
licensing
OSI License Referenceโ
Search all OSI-approved licenses with type, GPL compatibility, and patent clause status.
supplychain
Go Module Path Validatorโ
Validate Go module paths and check major version suffix requirements.
supplychain
Supply Chain Risk Referenceโ
Reference guide to software supply chain attack types, mitigations, and tooling.
sbom
SBOM Format Comparatorโ
Compare CycloneDX and SPDX SBOM formats for NTIA, EU CRA, and VEX compliance.