REUSE compliance of open-component-model/ocm-spec

Unfortunately, github.com/open-component-model/ocm-spec is not REUSE compliant and does not fully adopt the recommendations to make software licensing easy for humans and machines alike. Have a look at our tutorial to learn about the three simple steps to become REUSE compliant.

Badge

To add the badge to your project's README.md file, use the following snippet:

[![REUSE status](https://api.reuse.software/badge/github.com/open-component-model/ocm-spec)](https://api.reuse.software/info/github.com/open-component-model/ocm-spec)

Machine-readable information

The API provides machine-readable artifacts for automatic analysis.

  • All information about the latest compliance check can also be accessed via a machine-parsable JSON file.
  • You can gather the automatically generated SPDX SBOM in Tag:Value format, based on the reuse spdx command.

Last lint output

Commit 41ab62f53144702e51df79ad7a2f645cb4ab2ad2 was checked on 11 Sep 2026 00:05:49 UTC with the following result:

# MISSING LICENSES

'CC-BY-4.0' found in:
* 1._Community_Specification_License-v1.md

# SUMMARY

* Bad licenses: 0
* Deprecated licenses: 0
* Licenses without file extension: 0
* Missing licenses: CC-BY-4.0
* Unused licenses: 0
* Used licenses: Apache-2.0, CC-BY-4.0, Community-Spec-1.0
* Read errors: 0
* Invalid SPDX License Expressions: 0
* Files with copyright information: 93 / 93
* Files with license information: 93 / 93

Unfortunately, your project is not compliant with version 3.3 of the REUSE Specification :-(


# RECOMMENDATIONS

* Fix missing licenses: For at least one of the license identifiers provided by
  the 'SPDX-License-Identifier' tags, there is no corresponding license text
  file in the 'LICENSES' directory. For SPDX license identifiers, you can simply
  run 'reuse download --all' to get any missing ones. For custom licenses
  (starting with 'LicenseRef-'), you need to add these files yourself.