v1

latestOpenAPI 3.0.02026-07-249055687.1 KB
full-scans

Export SPDX SBOM (Beta)

Export a Socket SBOM as a SPDX SBOM

Supported ecosystems:

  • crates
  • go
  • maven
  • npm
  • nuget
  • pypi
  • rubygems
  • spdx
  • cdx

Unsupported ecosystems are filtered from the export.

This endpoint consumes 1 unit of your quota.

This endpoint requires the following org token scopes:

  • report:read
get/orgs/{org_slug}/export/spdx/{id}

Path parameters

org_slugstring required

The slug of the organization

idstring required

The full scan OR sbom report ID

Query parameters

authorstring

The person(s) who created the BOM. Set this value if you're intending the modify the BOM and claim authorship.

project_groupstring

Dependency track project group

project_namestring

Dependency track project name. Default use the directory name

project_versionstring

Dependency track project version

project_idstring

Dependency track project id. Either provide the id or the project name and version together

include_vulnerabilitiesstring

Include vulnerability information in the SBOM. Also includes reachability/VEX if available

Response

SPDX SBOM

spdxVersionstring required
dataLicensestring required
SPDXIDstring required
namestring required
documentNamespacestring required
documentDescribesstring[] required