skip to content

CycloneDX vs SPDX — what are these SBOM formats and how do they relate to the Maven plugin?

level: seniorimportance: should knowfreq 35%

answer

  1. CycloneDX = OWASP, security/VEX
  2. SPDX = Linux Foundation, ISO, licensing
  3. plugin emits CycloneDX only
  4. convert via CLI/syft for SPDX
  5. format != serialization

basics

~10 s

Both are standard SBOM formats. CycloneDX (OWASP) is security-focused and is what cyclonedx-maven-plugin emits natively (xml/json). SPDX (Linux Foundation) is license/compliance-focused; for SPDX in Maven you use a different plugin or convert.

solid answer

~40 s

CycloneDX and SPDX are the two dominant SBOM standards. **CycloneDX** is an OWASP project, lightweight, with a security/vulnerability bent (components, PURLs, VEX, dependency relationships) and is what the `cyclonedx-maven-plugin` produces directly in XML or JSON. **SPDX** is a Linux Foundation / ISO standard originally centered on license compliance, with rich file-level and licensing metadata; it is common in OSS legal workflows and tools like FOSSology. The Maven `cyclonedx-maven-plugin` only emits CycloneDX; to get SPDX you use the `spdx-maven-plugin` or convert a CycloneDX BOM with a tool (e.g., the CycloneDX CLI or syft). Choice depends on your consumers: pick CycloneDX if your scanners (Dependency-Track, Grype) are CycloneDX-native, SPDX if your compliance toolchain or a regulatory mandate requires it. Many orgs generate CycloneDX and convert to SPDX on demand.

go deeper

for a junior

Knows there are two SBOM formats and the plugin makes CycloneDX.

for a middle

Can set outputFormat/schemaVersion and knows SPDX needs a different tool.

for a senior

Weighs CycloneDX vs SPDX by consumer (security vs legal) and chooses a generate-then-convert strategy.

for a principal

Sets org format policy, handles regulatory mandates, and owns conversion/round-trip-loss tradeoffs.

## Two competing standards An SBOM needs a **serialization format** — an agreed schema so tools can parse it. The two widely adopted standards are CycloneDX and SPDX. ### CycloneDX - Maintained by **OWASP**. - Designed primarily for **application security and supply-chain risk**. - Emphasizes: components with **PURLs**, dependency relationships, vulnerability data, and **VEX** (Vulnerability Exploitability eXchange — statements about whether a CVE actually affects you). - Serializations: **XML and JSON** (and Protobuf). - This is the **native and only** output of the `org.cyclonedx:cyclonedx-maven-plugin`. ### SPDX - Maintained by the **Linux Foundation**; it is an **ISO/IEC standard (5962)**. - Originated for **license compliance** — strong on file-level provenance, copyright, and a controlled list of SPDX **license identifiers** (e.g., `Apache-2.0`, `GPL-3.0-only`). - Serializations: tag-value, JSON, YAML, RDF. - Common in OSS legal/compliance tooling (FOSSology, many corporate compliance pipelines). ## How they map to Maven - `cyclonedx-maven-plugin` → CycloneDX only. Control format via `<outputFormat>` = `xml`, `json`, or `all`, and `<schemaVersion>` (e.g., `1.5`). - For **SPDX** you reach for a separate plugin (`org.spdx:spdx-maven-plugin`) or **convert** an existing CycloneDX BOM using the CycloneDX CLI or `syft`. ```xml <configuration> <outputFormat>all</outputFormat> <!-- bom.xml AND bom.json --> <schemaVersion>1.5</schemaVersion> <outputName>bom</outputName> </configuration> ``` ## Choosing - **Security-driven monitoring** (Dependency-Track, Grype, Trivy): CycloneDX is the path of least resistance. - **License/legal compliance or a mandate** (some government/regulatory requirements name SPDX): produce or convert to SPDX. - Pragmatic pattern: **generate CycloneDX in the build**, convert to SPDX on demand for whoever needs it. Don't maintain two hand-written sources of truth. ## Common confusion - They are **not interchangeable byte-for-byte** but cover overlapping data; conversion is lossy in places (e.g., VEX and file-level details may not survive a round trip). - 'JSON vs XML' is a serialization choice **within** a format, not a format choice itself.

  • Can the cyclonedx-maven-plugin emit SPDX directly?
    No. It only emits CycloneDX (XML/JSON). For SPDX you use the spdx-maven-plugin or convert a CycloneDX BOM with a tool like the CycloneDX CLI or syft.
  • What is VEX and which format emphasizes it?
    VEX (Vulnerability Exploitability eXchange) records whether a known CVE actually affects your product. CycloneDX has first-class support for it.

saying these in an interview costs you the question

  • Saying the cyclonedx-maven-plugin can output SPDX
  • Treating 'JSON vs XML' as the format distinction (it's serialization within CycloneDX)
  • Assuming CycloneDX↔SPDX conversion is perfectly lossless

context