Use when checking a dependency's license, license compatibility, copyleft obligations, generating or reading an SBOM, SPDX identifiers, or whether a package's provenance/existence is trustworthy before adding it.