Skip to content

Pyspdxtools fails to parse spdx file #890

Description

@hdxtreeem

Hello!
I am trying to run pyspdxtools on my yocto generated build spdx and fails to run.
I get the following result back from the script:

Generating LALR tables
The document couldn't be parsed; check couldn't be performed.

The following parsing error(s) were raised:

Error while constructing CreationInfo: CreationInfo.__init__() missing 6 required positional arguments: 'spdx_version', 'spdx_id', 'name', 'document_namespace', 'creators', and 'created'

What I could see the files has the designated format but not sure why it fails? Following is the snippet of the begining of the spdx file

{
 "spdxVersion": "SPDX-2.3",
 "dataLicense": "CC0-1.0",
 "SPDXID": "SPDXRef-DOCUMENT",
 "name": "device",
 "documentNamespace": "https://spdx.org/spdxdocs/gateway-f1b13a50-485f-4203-933c-11a3caf3e548",
 "creationInfo": {
  "licenseListVersion": "3.14",
  "creators": [
   "Tool: OpenEmbedded Core create-spdx.bbclass",
   "Organization: OpenEmbedded ()",
   "Person: N/A ()",
   "Tool: sbomasm-v1.0.9"
  ],
  "created": "2026-04-07T09:04:34Z",

Activity

  1. Eljees commented on Jul 29, 2026

    @Eljees

    I tried to reproduce this and the parts visible in your snippet are fine on current main.

    The creators list is the usual suspect for that error, because a failing actor makes creators None
    and the constructor then complains about missing arguments. Yours parse without complaint:

    'Tool: OpenEmbedded Core create-spdx.bbclass' -> Tool: OpenEmbedded Core create-spdx.bbclass
    'Organization: OpenEmbedded ()'               -> Organization: OpenEmbedded
    'Person: N/A ()'                              -> Person: N/A
    'Tool: sbomasm-v1.0.9'                        -> Tool: sbomasm-v1.0.9
    

    (run against ActorParser.parse_actor on main, python 3.12 — the empty () is handled.)

    The message you got lists all six required fields as missing, which means the parser received a
    document dict where spdxVersion, SPDXID, name and documentNamespace were absent too — not just
    the creation info. That does not match the snippet you posted, so the interesting part is elsewhere in
    the file or in the version you ran.

    Could you share:

    1. the output of pip show spdx-tools (or how you installed pyspdxtools), and
    2. the document itself, or at least everything up to the first packages entry — the top-level keys are
      what matter here?

    With that I can turn it into a regression test. If the file is a Yocto/OpenEmbedded output that you
    cannot share, create-spdx.bbclass on a minimal image would probably reproduce it too — knowing the
    Yocto release would help.

  2. added a commit that references this issue on Sep 20, 2026
    3fe000b
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions