Hello SPDX Technical Team,

I maintain the Rawafid Arabic/RTL Accessibility & Localization Toolkit, a 
public Apache-2.0 TypeScript project focused on Arabic/RTL web engineering, 
localization, accessibility, Unicode/bidi safety, and browser-level 
verification.

Repository: https://github.com/khaledaltheeb/rawafid-arabic-rtl-a11y-toolkit

The project already includes release-policy controls and SPDX SBOM generation 
in its release design. I am writing with a narrow interoperability question: 
for a small TypeScript library publishing npm tarballs and GitHub releases, is 
there a currently preferred SPDX version/profile or validation path you would 
recommend so that generated SBOMs remain maximally portable across downstream 
security and package-analysis tools?

We are not asking for certification or endorsement. The goal is to align our 
public machine-readable release artifacts with current SPDX technical guidance 
and avoid introducing Rawafid-specific conventions where a standards-backed 
representation already exists.

If there is a more appropriate issue tracker, working-group channel, or current 
validation tool for this question, a pointer would be appreciated.

Best regards,
Khaled Altheeb
Rawafid
https://healthrenewal.org/


-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#6232): https://lists.spdx.org/g/Spdx-tech/message/6232
Mute This Topic: https://lists.spdx.org/mt/120946254/21656
Group Owner: [email protected]
Unsubscribe: https://lists.spdx.org/g/Spdx-tech/unsub [[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-


Reply via email to