Hello SPDX Technical Team, I maintain the Rawafid Arabic/RTL Accessibility & Localization Toolkit, a public Apache-2.0 TypeScript project focused on Arabic/RTL web engineering, localization, accessibility, Unicode/bidi safety, and browser-level verification.
Repository: https://github.com/khaledaltheeb/rawafid-arabic-rtl-a11y-toolkit The project already includes release-policy controls and SPDX SBOM generation in its release design. I am writing with a narrow interoperability question: for a small TypeScript library publishing npm tarballs and GitHub releases, is there a currently preferred SPDX version/profile or validation path you would recommend so that generated SBOMs remain maximally portable across downstream security and package-analysis tools? We are not asking for certification or endorsement. The goal is to align our public machine-readable release artifacts with current SPDX technical guidance and avoid introducing Rawafid-specific conventions where a standards-backed representation already exists. If there is a more appropriate issue tracker, working-group channel, or current validation tool for this question, a pointer would be appreciated. Best regards, Khaled Altheeb Rawafid https://healthrenewal.org/ -=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#6232): https://lists.spdx.org/g/Spdx-tech/message/6232 Mute This Topic: https://lists.spdx.org/mt/120946254/21656 Group Owner: [email protected] Unsubscribe: https://lists.spdx.org/g/Spdx-tech/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
