/v1/vexUpload a VEX document
Uploads a CycloneDX VEX document for a project using multipart form data. Identify the project with project, or provide projectName and projectVersion; the VEX is validated against the CycloneDX schema. The authenticated user needs VULNERABILITY_ANALYSIS or VULNERABILITY_ANALYSIS_UPDATE permission, and the response includes a token for checking processing progress.
- IdempotentThe SDK sends
Idempotency-Key, so a retried request is only applied once.
Multipart form data containing a VEX document and project identification details.
A 400 is returned when the VEX is invalid or fails CycloneDX schema validation; identify the project with project or with both projectName and projectVersion. A 401 indicates an unauthorized request, and a 403 indicates that the authenticated user lacks permission or access to the project. A 404 is returned when the project cannot be found.