Check an SBOM
check_sbomRead-onlyIdempotent
Audit a CycloneDX or SPDX JSON software bill of materials. Components are mapped to tracked products and scored for EOL risk; unmatched components are listed honestly rather than guessed. Pass the SBOM as a JSON string or object. Versions resolve to their release family (python 3.12, php 7.4, ubuntu 20.04). Without a key up to 5 matched components are scored per call; Starter 25; Pro 50. Larger SBOMs return the scored subset plus a note of how many were not checked.
Input Schema
TableJSON Schema
| Name | Required | Description | Default |
|---|---|---|---|
| sbom | Yes | The SBOM document (JSON string or object). CycloneDX (bomFormat/components) or SPDX (spdxVersion/packages). | |
| max_items | No | Optional: return at most this many scored components (the tier cap applies first). |
Output Schema
TableJSON Schema
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||