PUT/v1/bom

Upload a Base64-encoded CycloneDX BOM

Uploads a Base64-encoded CycloneDX bill of materials (BOM) and associates it with a project. Supply project, projectName, and projectVersion as required by the schema, and use autoCreate to create a project when it does not exist. Processing is asynchronous; use the returned token to check progress, and send large BOMs through the POST upload endpoint to avoid the 20,000,000-character limit.

11 body fields

Base64-encoded CycloneDX BOM upload and project details. The schema requires bom, project, projectName, and projectVersion.

autoCreatebooleanoptional
Whether to create the project if it does not exist. Project creation requires PORTFOLIO_MANAGEMENT, PORTFOLIO_MANAGEMENT_CREATE, or PROJECT_CREATION_UPLOAD permission.
bomstringrequired
Base64 encoded BOM
isActivebooleanoptional
The project's active state. If provided, this changes the state even when the project already exists; send it only when you intend to change that state.
isLatestbooleanoptional
Whether to mark the project as the latest version when creating it.
parentNamestringoptional
The name of the parent project when creating a project under a parent.
parentUUIDstringoptional
The UUID of the parent project when creating a project under a parent. Must use UUID format.
parentVersionstringoptional
The version of the parent project when creating a project under a parent.
projectstringrequired
The project UUID to upload the BOM for. Must use UUID format.
projectNamestringrequired
The project name. Must contain at least one character.
projectTagsarray<object>optional
Tags to apply to the project when creating it; each tag object must include a `name` of 1 to 255 characters.
projectVersionstringrequired
The project version. Must contain at least one character.

5 status codes
200Returns the project UUID and a processing token to use when checking BOM processing progress.
projectUuidstringrequired
UUID of the project the BOM was uploaded for
tokenstringrequired
Token used to check task progress
400Returned when the uploaded BOM is invalid, including when it fails CycloneDX schema validation.
401Returned when the request is unauthorized.
403Returned when access to the requested project is forbidden or the authenticated user lacks permission for the requested operation.
detailstringrequired
Human-readable explanation specific to this occurrence of the problem
instancestringoptional
Reference URI that identifies the specific occurrence of the problem
statusintegerrequired
HTTP status code generated by the origin server for this occurrence of the problem
titlestringrequired
Short, human-readable summary of the problem type
typestringoptional
A URI reference that identifies the problem type
404Returned when the project cannot be found.

Error handling

A 400 is returned when the BOM is invalid, including when it fails CycloneDX schema validation. A 401 is returned when the request is unauthorized; a 403 is returned when the authenticated user lacks access to the project or the permission required for project creation. A 404 is returned when the project cannot be found. bom must be valid Base64 and no longer than 20,000,000 characters; project must be a UUID, and projectName and projectVersion must each contain at least one character.