Problem Statement
Which statement about S B O M formats is most accurate today?
Explanation
Both SPDX and CycloneDX are widely used and overlapping. CycloneDX is popular in AppSec and component analysis; SPDX is strong for compliance metadata. Many teams support both and even convert between them. (Sources: Sonatype and other comparisons.)
Code Solution
SolutionRead Only
Tools: syft, cyclonedx-cli, spdx-sbom-generator; convert between formats as needed
