Tern is a software composition analysis tool and Python library that generates a Software Bill of Materials for container images and Dockerfiles. The SBOM that Tern generates will give you a layer-by-layer view of what's inside your container in a variety of formats including human-readable, JSON, HTML, SPDX and more.
We now have SPDX 2.2 (the ISO version) and SPDX 2.3, and soon we will have SPDX 3.0.
It would be good to be able to specify in which version of SPDX we want the result.
Some users are required to use the ISO version, and some have tools that require a specific version of SPDX.
Syft has planned to implement it: Export specific format versions (SPDX)
We could use the same syntax to specify the version.