Skip to content

Import SBOM and create a new project (Dependencies - SCA)

Request

Imports an SBOM and creates a new project as part of the process. The SBOM scan is queued for asynchronous processing. Supported formats: SPDX (JSON/XML), CycloneDX (JSON/XML).

Security
bearer-key
Path
applicationUuidstringrequired

Application UUID (Administration > Applications)

Bodymultipart/form-data
projectNamestringrequired

Name of the project to create under this application

projectDescriptionstring

Optional project description

sbomFilestring, (binary)required

The SBOM file to upload (SPDX or CycloneDX). Only one file per request.

POST
/api/v3.0/applications/{applicationUuid}/dependencies/projects/importSbom
{
  "projectName": "string",
  "projectDescription": "string",
  "sbomFile": "string"
}

Responses

SBOM scan successfully created and queued

Bodyapplication/json
supportTokenstring

Support token for tracking

Example:"1171c60d"
projectobject(ProjectDTOV3)

Project information

scanobject(SbomScanInfoDTO)

Scan information

Response
{ "supportToken": "1171c60d", "project": { "uuid": "123e4567-e89b-12d3-a456-426655440000", "name": "My Project", "path": "My Application", "applicationName": "My Application", "applicationUuid": "123e4567-e89b-12d3-a456-426655440000" }, "scan": { "scanUuid": "45e0c7f0-2a64-4a1c-bb2b-22e1c4f02126", "createdAt": "2025-10-27T18:50:05Z" }, "link": { "logs": "/api/v3.0/projects/{projectUuid}/scans/{scanUuid}/dependencies/SBOM/logs" } }