skip to content

In an SPDX SBOM, what is the difference between NOASSERTION and NONE in a license field?

level: juniorimportance: should knowfreq 45%

answer

  1. two reserved words, not one
  2. SPDX forbids the silent blank
  3. found nothing versus did not look
  4. declared field versus concluded field
  5. a placeholder is not a pass

basics

~20 s

NONE is a positive claim that nothing is there: the producer looked and found no license. NOASSERTION means the producer makes no claim at all, whether undetermined or withheld. Neither is the same as an empty field.

solid answer

~50 s

SPDX requires many fields to be present even when the answer is unknown, so it defines two reserved values instead of letting a tool leave a blank. `NONE` asserts the absence of the thing: the producer examined the package and there is no license there. `NOASSERTION` asserts nothing at all: the producer could not determine it, did not look, or deliberately withheld it. The practical consequence is that `NOASSERTION` is a hole in the document, not a clean result. A BOM whose packages are mostly `NOASSERTION` is structurally valid and still tells you almost nothing, so the first thing I do with a supplier BOM is count how many fields carry it. SPDX uses the same value well beyond licensing, in supplier, originator and download-location fields, so the count is a decent proxy for how much of the document was actually produced from evidence rather than left as a placeholder.

go deeper

for a junior

Be ready to say plainly that NONE means the producer found nothing and NOASSERTION means the producer is not claiming anything, and that neither is an empty field.

for a middle

Explain why SPDX needs reserved values at all: mandatory fields cannot be blank, and a blank would hide the difference between looked-and-found-nothing and did-not-look. Mention declared versus concluded licensing.

for a senior

Show that you use the count of NOASSERTION values as a quality metric on a supplier document, and that you never let unasserted fields be reported downstream as a clean scan result.

for a principal

Own the supplier conversation: the contractual ask is which fields will be asserted from evidence, not merely that an SBOM will be delivered, because a document of placeholders satisfies a delivery clause and tells you nothing.

## The problem SPDX is solving An SBOM is a claim made by one party and read by another. If a field is simply missing, the reader cannot tell whether the producer looked and found nothing, looked and could not decide, or never looked at all. Those three states have completely different consequences downstream, so SPDX refuses to let a blank stand in for any of them. Many SPDX fields are mandatory, and where the real answer is unavailable the producer must say so explicitly using one of two reserved values. ## The two values **`NONE`** is an assertion of absence. It says: I examined this, and the thing you are asking about does not exist here. In a license field, `NONE` means the producer determined that there is no licensing information present in the package. **`NOASSERTION`** is a refusal to assert. It says: I am not making a claim. It covers several real situations that the format deliberately does not distinguish between: the producer had no efficient way to determine the value, the analysis was inconclusive, the producer chose not to state it, or the value simply was not collected. The distinction is the difference between *nothing is there* and *I am not telling you what is there*, and conflating them is the classic first-week mistake with SPDX. ## Where the values show up Licensing is the field where people meet these values first, and SPDX splits licensing into two questions: - **`PackageLicenseDeclared`** — what the package itself declares, for example in its own metadata. - **`PackageLicenseConcluded`** — what the producer of the SBOM concludes after analysis, which may differ from the declaration. A generator that only reads package metadata typically emits a declared value and `NOASSERTION` for the concluded value, because concluding requires human or tool analysis it did not perform. That is honest behaviour, not a bug, and reading it as *unlicensed* is wrong. The same reserved values appear in supplier, originator, download-location and copyright-text fields, which is why they are best understood as a general grammar for uncertainty rather than a licensing quirk. There is also a related completeness signal: a package can be marked as having had its files analysed or not, and a package whose files were never analysed cannot honestly carry file-level conclusions. ## How CycloneDX handles the same situation CycloneDX takes the opposite approach: most fields are optional, so unknown values are usually expressed by omitting the field. That is more compact but genuinely more ambiguous, because absence collapses *unknown*, *not collected* and *not applicable* into one state. CycloneDX addresses completeness at the document level instead, with a compositions construct that lets a producer declare how complete an assembly or dependency listing is, including that it is incomplete or unknown. This asymmetry matters the moment documents move between the formats. Converting SPDX to CycloneDX naively turns `NOASSERTION` into a missing field, which reads as ordinary optional-field absence and loses the fact that the producer explicitly declined to assert. Converting CycloneDX to SPDX has the mirror problem: the converter must fill mandatory fields for values that were merely absent, and the only honest filler is `NOASSERTION` — which is correct, but means the SPDX document now looks emptier than the original felt. ## Reading a BOM in practice Treat `NOASSERTION` as a quality measurement of the document, not as a property of the software. Useful habits: - Count `NOASSERTION` occurrences per field and per package; a supplier BOM that is 90% placeholders has not been produced from real evidence. - Never let *no disallowed value found* be reported as *no risk found* when the underlying fields are unasserted. That converts document incompleteness into a green light. - Ask the supplier which fields they intend to assert, rather than which values they intend to send. Getting a supplier to move a field from `NOASSERTION` to a real value is a concrete, checkable ask. ## Why interviewers ask it The NTIA minimum elements for an SBOM name a small set of baseline data fields — supplier name, component name, component version, other unique identifiers, dependency relationship, author of the SBOM data, and a timestamp — and the whole point of a baseline is that the fields are *stated*. A candidate who knows that SPDX makes the unknown explicit, and that the explicit unknown is not a pass, is reading SBOMs as documents with provenance rather than as inventories that happen to be machine-readable.

  • A team reports zero licensing risk from a supplier SPDX BOM whose packages are almost all NOASSERTION. What went wrong?
    They read an unasserted field as a clean field. `NOASSERTION` means the producer made no claim, so the report is measuring the emptiness of the document rather than the content of the software. The correct output is a coverage figure — what fraction of packages carry a real value — plus an ask back to the supplier, not a pass.
  • Besides licensing, where else does SPDX use NOASSERTION?
    It is a general value for `no claim made`, so it also appears in supplier, originator, download-location and copyright-text fields. That is why a structurally valid SPDX document can still convey almost nothing: every mandatory field is present, and most of them decline to say anything.
  • How does CycloneDX express the same unknown state?
    Usually by omitting the optional field, which is more ambiguous because absence covers unknown, not collected and not applicable at once. CycloneDX handles completeness at document level instead, through a compositions construct where a producer states how complete an assembly or dependency listing is.

NONE is a doctor writing no allergies on the form. NOASSERTION is the doctor writing not tested. Both are legible; only one is reassuring.

saying these in an interview costs you the question

  • Treats NOASSERTION as no license found, therefore no obligation
  • Says NOASSERTION and NONE mean the same thing
  • Assumes an omitted field and NOASSERTION are equivalent
  • Reads a BOM full of placeholders as a clean result
  • Thinks a declared license and a concluded license must match

context