BS ISO IEC 18670-2025 PDF

STB BS ISO IEC 18670-2025

Name in English:
STB BS ISO IEC 18670-2025

Name in Russian:
СТБ BS ISO IEC 18670-2025

Description in English:

Original standard BS ISO IEC 18670-2025 in PDF full version. Additional info + preview on request

Description in Russian:
Оригинальный стандарт BS ISO IEC 18670-2025 в PDF полная версия. Дополнительная инфо + превью по запросу
Document status:
Active

Format:
Electronic (PDF)

Delivery time (for English version):
1 business day

Delivery time (for Russian version):
200 business days

SKU:
stbs40851

Choose Document Language:
€50

Full title and description

STB BS ISO IEC 18670-2025 — Information technology — SoftWare Hash IDentifier (SWHID) Specification V1.2. This international standard defines a content-based identifier format and data model for referencing software artefacts (files, trees, revisions, releases and repository status) compatible with modern distributed version control systems. The identifiers are cryptographically derived from the described objects to enable decentralised, independent verification of integrity.

Abstract

ISO/IEC 18670:2025 specifies the SWHID (Software Hash IDentifier) data format and computation rules (based on Merkle acyclic directed graphs) so that software artefacts can be unambiguously referenced and verified by any party holding a copy of those artefacts. The standard documents the object model (file/tree/revision/release), the canonical serialization and the hashing procedures; it explicitly leaves resolution (how to obtain a copy from an identifier) outside its scope.

General information

  • Status: Active / Published international standard (also adopted as national variants such as BS ISO/IEC 18670:2025).
  • Publication date: ISO/IEC publication: 23 April 2025. British national publication (BS ISO/IEC 18670:2025) recorded 6 June 2025.
  • Publisher: ISO/IEC JTC 1 (published jointly under the ISO/IEC framework); national adoptions published by national bodies (example: BSI for the BS designation).
  • ICS / categories: 35.040.10 (Software engineering — Software tools and environments).
  • Edition / version: Edition 1.0 (ISO/IEC 18670:2025); the standard formalises SWHID specification version 1.2.
  • Number of pages: ISO/IEC published document: 14 pages (core international text); some national/adopted copies (BS/etc.) list a longer PDF that can include national forewords—example listings show 24 pages for the BS publication.

Scope

This standard defines a canonical data format and hashing/computation rules for Software Hash IDentifiers (SWHIDs), covering how to represent files, directory trees, source code revisions, releases and the full version-control-system state in a content-addressable model. It enables anyone with a copy of the digital objects to compute the same identifier using the specified algorithms and data model. The standard does not define a resolution service or mandate any particular archival or retrieval infrastructure.

Key topics and requirements

  • Canonical object model for software artefacts (files, directories/trees, revisions, releases and repository metadata).
  • Computation rules for SWHIDs based on Merkle Acyclic Directed Graphs (generalization of Merkle trees).
  • Cryptographic hashing and canonical serialization to ensure identical identifiers across independent implementations.
  • Specification of identifier forms and namespaces for different object kinds (file, directory, revision, release, snapshot, etc.).
  • Requirements for interoperability with version control concepts (branches, tags, commits) and for supporting reproducibility and integrity verification.
  • Explicit separation of identifier computation (in-scope) from identifier resolution and repository access (out of scope).

Typical use and users

Primary users include digital preservation organisations, software archives, package and repository maintainers, cybersecurity and vulnerability-tracking teams, research projects requiring reproducible software citation, and tool authors (build systems, package managers, provenance and SBOM tools) who need stable, content-based identifiers for software artefacts. Standards adopters include archives and registries that want machine-verifiable, decentralized identifiers for stored code.

Related standards

Related specifications and initiatives include the SWHID Publicly Available Specifications (project sources and release notes), SPDX (software bill of materials and metadata formats), and ISO/IEC standards and best practices in software asset identification and digital preservation. Implementers often combine SWHIDs with existing package metadata and SBOM frameworks for vulnerability tracking and archival workflows.

Keywords

SWHID; Software Hash Identifier; content-addressable identifier; Merkle DAG; software provenance; digital preservation; reproducibility; integrity verification; version control; software artefact identification.

FAQ

Q: What is this standard?

A: ISO/IEC 18670:2025 is the international standard that formalises the SoftWare Hash IDentifier (SWHID) specification (V1.2), providing a content-based identifier format and computation rules for software artefacts. It was published on 23 April 2025.

Q: What does it cover?

A: It covers the canonical object model and hashing/serialization rules to compute SWHIDs for files, directory trees, revisions, releases and repository snapshots; it ensures identical identifiers can be independently computed from the same objects. Resolution (how to fetch artefacts from an identifier) is explicitly out of scope.

Q: Who typically uses it?

A: Archives, software heritage projects, repository and package maintainers, cybersecurity teams (for tracing vulnerable code), researchers needing reproducible software citation, and tool developers (SBOM, provenance, build and packaging tools) are typical users.

Q: Is it current or superseded?

A: This standard was published as ISO/IEC 18670:2025 on 23 April 2025 and is an active (current) standard; national adoptions such as BS ISO/IEC 18670:2025 were published in national catalogues (example date: 6 June 2025). There is no indication of supersession as of 23 February 2026.

Q: Is it part of a series?

A: ISO/IEC 18670 is a standalone international standard formalising the SWHID specification; it complements other standards and specifications in the software identification, asset management and provenance space (for example SPDX and ISO/IEC software-management work), but it is not listed as a numbered multi-part series under the same base number.

Q: What are the key keywords?

A: SWHID, Software Hash Identifier, content-addressable, Merkle DAG, software provenance, digital preservation, reproducibility, integrity verification, version control.