POST/v1/vex

Upload a VEX document

Uploads a CycloneDX VEX document for a project using multipart form data. Identify the project with project, or provide projectName and projectVersion; the VEX is validated against the CycloneDX schema. The authenticated user needs VULNERABILITY_ANALYSIS or VULNERABILITY_ANALYSIS_UPDATE permission, and the response includes a token for checking processing progress.

  • IdempotentThe SDK sends Idempotency-Key, so a retried request is only applied once.

4 body fields

Multipart form data containing a VEX document and project identification details.

projectstringoptional
The UUID of the project for which to upload the VEX document.
projectNamestringoptional
The project name to use to identify the project when `project` is not specified.
projectVersionstringoptional
The project version to use with `projectName` when `project` is not specified.
vexstringoptional
The CycloneDX VEX document to validate and process.

5 status codes
200Returns the project UUID and a token you can use to check VEX processing progress.
projectUuidstringrequired
UUID of the project the BOM was uploaded for
tokenstringrequired
Token used to check task progress
400Returned when the VEX document is invalid or fails CycloneDX schema validation.
detailstringrequired
Human-readable explanation specific to this occurrence of the problem
instancestringoptional
Reference URI that identifies the specific occurrence of the problem
statusintegerrequired
HTTP status code generated by the origin server for this occurrence of the problem
titlestringrequired
Short, human-readable summary of the problem type
typestringoptional
A URI reference that identifies the problem type
errorsarray<string>optional
Errors identified during schema validation
401Returned when the request is unauthorized.
403Returned when access to the requested project is forbidden.
detailstringrequired
Human-readable explanation specific to this occurrence of the problem
instancestringoptional
Reference URI that identifies the specific occurrence of the problem
statusintegerrequired
HTTP status code generated by the origin server for this occurrence of the problem
titlestringrequired
Short, human-readable summary of the problem type
typestringoptional
A URI reference that identifies the problem type
404Returned when the project cannot be found.

Error handling

A 400 is returned when the VEX is invalid or fails CycloneDX schema validation; identify the project with project or with both projectName and projectVersion. A 401 indicates an unauthorized request, and a 403 indicates that the authenticated user lacks permission or access to the project. A 404 is returned when the project cannot be found.