POST/v1/bom

Upload a CycloneDX bill of materials

Uploads a CycloneDX bill of materials (BOM) and starts processing it for a project. Send the BOM as multipart form data; identify the project with project, or supply both projectName and projectVersion, and use autoCreate to create a project when needed. The response includes a token for checking processing progress; BOM uploads require the BOM_UPLOAD permission, and creating a project also requires one of the documented project-creation permissions.

  • IdempotentThe SDK sends Idempotency-Key, so a retried request is only applied once.

11 body fields

Multipart form data containing a CycloneDX BOM and optional project creation and metadata settings.

autoCreatebooleanoptional
Create the project if it does not exist. Defaults to false when omitted.
Default:false
bomstringoptional
The CycloneDX BOM file to upload. Supply an uncompressed XML or JSON file, or a gzip- or zstd-compressed file with a matching media type.
isActivebooleanoptional
Set the active state of the project. When provided, this value also changes the state of an existing project.
isLatestbooleanoptional
Mark the project as the latest version. Defaults to false when omitted.
Default:false
parentNamestringoptional
The name of the parent project under which to place a newly created project.
parentUUIDstringoptional
The UUID of the parent project under which to place a newly created project.
parentVersionstringoptional
The version of the parent project under which to place a newly created project.
projectstringoptional
The UUID of the project to upload the BOM for.
projectNamestringoptional
The project name to use when identifying or creating a project without a UUID.
projectTagsstringoptional
Tags to apply to a newly created project.
projectVersionstringoptional
The project version to use when identifying or creating a project without a UUID.

5 status codes
200Returns the project UUID and a processing token to use when checking BOM processing progress.
projectUuidstringrequired
UUID of the project the BOM was uploaded for
tokenstringrequired
Token used to check task progress
400Returned when the uploaded BOM is invalid.
401Returned when the request is unauthorized.
403Returned when access to the requested project is forbidden.
detailstringrequired
Human-readable explanation specific to this occurrence of the problem
instancestringoptional
Reference URI that identifies the specific occurrence of the problem
statusintegerrequired
HTTP status code generated by the origin server for this occurrence of the problem
titlestringrequired
Short, human-readable summary of the problem type
typestringoptional
A URI reference that identifies the problem type
404Returned when the project could not be found.

Error handling

A 400 is returned when the uploaded BOM is invalid. A 401 is returned when the request is unauthorized. A 403 is returned when access to the project is forbidden or the required permission is missing. A 404 is returned when the project cannot be found. Supply a valid CycloneDX BOM; uncompressed files must use application/xml or application/json, while compressed files must use application/gzip or application/zstd matching the actual compression. Identify the project with project, or provide both projectName and projectVersion.