v1

latestOpenAPI 3.0.32026-07-26233989.2 KB
Analysis

Get SBOM Results

Retrieves the Software Bill of Materials (SBOM) results for a specific repository and commit

post/api/analysis/results/sbom

Request body

repostring required

Repository identifier (format varies by service)

commit_idstring

Git commit SHA or identifier. Either commit_id or branch is required. If both are provided, commit_id takes precedence.

branchstring

Git branch name. When provided without commit_id, the service resolves the latest commit from scan history for this branch. Either commit_id or branch is required.

access_tokenstring required

Authentication token for the service

service'github' | 'azuredevops' | 'gitlab' | 'bitbucket' required

Version control service provider

gitlab_base_urlstring

Base URL for the service (optional for GitHub, required for GitLab)

Example request

{
  "repo": "owner/repository",
  "commit_id": "abc123def456",
  "branch": "main",
  "access_token": "ghp_xxxxxxxxxxxx",
  "service": "github",
  "gitlab_base_url": "https://gitlab.com"
}

Response

SBOM results retrieved successfully

status'pending' | 'processing' | 'done' | 'failed'

Status of the SBOM analysis

commit_idstring

Git commit SHA that was analyzed

Example response

{
  "results": {
    "rootFolder": "/mnt/lambda/owner/repository/abc123def456",
    "sboms": [
      {
        "language": "Python",
        "sourceFile": "/tmp/superRequirements.txt",
        "packages": [
          {
            "name": "@alloc/quick-lru",
            "version": "5.2.0",
            "licenseDeclared": "MIT",
            "licenseConcluded": "MIT",
            "licenseReason": "NOASSERTION",
            "licenseStandard": true,
            "copyleftStrength": "permissive",
            "policyLevel": "allow",
            "policyNote": "Permissive license: keep license and notices",
            "spdxId": "MIT",
            "badTerms": [
              {
                "tag": "modifications_must_be_public",
                "start": 246,
                "end": 268,
                "evidence": "out limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell co"
              }
            ]
          }
        ],
        "packagesCount": 1
      }
    ]
  },
  "status": "done",
  "commit_id": "abc123def456"
}