v1

latestOpenAPI 3.0.02026-07-249055687.1 KB
full-scans

Export CycloneDX SBOM (Beta)

Export a Socket SBOM as a CycloneDX SBOM

Supported ecosystems:

  • crates
  • go
  • maven
  • npm
  • nuget
  • pypi
  • rubygems
  • spdx
  • cdx

Unsupported ecosystems are filtered from the export.

This endpoint consumes 1 unit of your quota.

This endpoint requires the following org token scopes:

  • report:read
get/orgs/{org_slug}/export/cdx/{id}

Path parameters

org_slugstring required

The slug of the organization

idstring required

The full scan OR sbom report ID

Query parameters

authorstring

The person(s) who created the BOM. Set this value if you're intending the modify the BOM and claim authorship.

project_groupstring

Dependency track project group

project_namestring

Dependency track project name. Default use the directory name

project_versionstring

Dependency track project version

project_idstring

Dependency track project id. Either provide the id or the project name and version together

include_vulnerabilitiesstring

Include vulnerability information in the SBOM. Also includes reachability/VEX if available

Response

CycloneDX SBOM

bomFormatstring required
specVersionstring required
serialNumberstring required
versionnumber required