Building Trust Through Transparency: Why SPDX Is Foundational for Software Supply Chain Integrity