CycloneDX Tool Center JSON Reference

Type: object
No Additional Properties

Type: enum (of string)

Must be one of:

  • "2.0"

Type: stringFormat: date-time

Type: array

All items must be unique

No Additional Items

Each item of this array must be:

Type: object
No Additional Properties

Type: string

Must be at least 1 characters long

Type: string

Must be at least 1 characters long

Type: string

Must be at least 10 characters long

Must be at most 250 characters long

Type: stringFormat: iri

Type: stringFormat: iri

Type: array of enum (of string)
No Additional Items

Each item of this array must be:

Type: enum (of string)

Must be one of:

Name Description
"SBOM"

Software Bill of Materials

"SAASBOM"

Software as-a Service Bill of Materials

"CBOM"

Cryptography Bill of Materials

"AI/ML-BOM"

AI/ML Bill of Materials

"HBOM"

Hardware Bill of Materials

"MBOM"

Manufacturing Bill of Materials (Formulation)

"OBOM"

Operations Bill of Materials

"CDXA"

CycloneDX Attestations

"RELEASE_NOTES"

Standardized Release Notes Format

"VDR/VEX"

Vulnerability Disclosure Report and Vulnerability eXploitability Exchange

Type: array of enum (of string)
No Additional Items

Each item of this array must be:

Type: enum (of string)

Must be one of:

Name Description
"OPEN_SOURCE"

Open Source

"FREE_WITH_PAID_UPGRADE"

Free with Paid Upgrade

"OSI_APPROVED"

OSI Approved License

"SUBSCRIPTION"

Subscription

Type: array of enum (of string)
No Additional Items

Each item of this array must be:

Type: enum (of string)

Must be one of:

Name Description
"ANALYSIS"

Analysis

"AUTHOR"

Author

"DISTRIBUTE"

Distribute

"PACKAGE_MANAGER_INTEGRATION"

Package manager integration

"TRANSFORM"

Transform

"SIGNING/NOTARY"

Signing and notary

Type: array of enum (of string)
No Additional Items

Each item of this array must be:

Type: enum (of string)

Must be one of:

Name Description
"SECURITY_VULNERABILITIES"

Security vulnerabilities

"POLICY_EVALUATION"

Policy evaluation

"RESOURCE_REPORTING"

Resource reporting

"LICENSE_REPORTING"

License reporting

Type: array of enum (of string)
No Additional Items

Each item of this array must be:

Type: enum (of string)

Must be one of:

Name Description
"BOM_STANDARD_(CYCLONEDX/SPDX)"

BOM Standard: CycloneDX/SPDX

"BOM_FORMAT_(XML/JSON)"

BOM Serialization Format: JSON / XML

"BOM_VERSION"

BOM version

Type: array of enum (of string)
No Additional Items

Each item of this array must be:

Type: enum (of string)

Must be one of:

Name Description
"APPLICATION"

Application

"COMMAND_LINE_UTILITY"

Command line utility

"CONTAINER_IMAGE"

Container image

"GITHUB_ACTION"

GitHub Action

"GITHUB_APP"

GitHub App

"LIBRARY"

Library

Type: array of enum (of string)
No Additional Items

Each item of this array must be:

Type: enum (of string)

Must be one of:

  • "C/C++"
  • "GO"
  • "JAVA"
  • "JAVASCRIPT_TYPESCRIPT"
  • "DOT_NET"
  • "NODE.JS"
  • "PERL"
  • "PHP"
  • "PYTHON"
  • "RUBY"
  • "RUST"
  • "SWIFT"

Type: array of enum (of string)
No Additional Items

Each item of this array must be:

Type: enum (of string)

Must be one of:

  • "LINUX"
  • "MAC"
  • "WINDOWS"

Type: array of enum (of string)
No Additional Items

Each item of this array must be:

Type: enum (of string)

Must be one of:

  • "DESIGN"
  • "PRE-BUILD"
  • "BUILD"
  • "POST-BUILD"
  • "DEPLOYMENT"
  • "OPERATIONS"
  • "DISCOVERY"
  • "DECOMMISSION"

Type: array of enum (of string)
No Additional Items

Each item of this array must be:

Type: enum (of string)

Must be one of:

  • "CYCLONEDX"
  • "SPDX"
  • "PACKAGE_URL"
  • "CPE"
  • "OMNIBOR"
  • "SWID"

Type: array of enum (of string)
No Additional Items

Each item of this array must be:

Type: enum (of string)

Must be one of:

  • "CYCLONEDX_V1.6"
  • "CYCLONEDX_V1.5"
  • "CYCLONEDX_V1.4"
  • "CYCLONEDX_V1.3"
  • "CYCLONEDX_V1.2"

Type: array of enum (of string)
No Additional Items

Each item of this array must be:

Type: enum (of string)

Must be one of:

  • "C/C++"
  • "GO"
  • "JAVA"
  • "JAVASCRIPT/TYPESCRIPT"
  • ".NET"
  • "NODE.JS"
  • "PERL"
  • "PHP"
  • "PYTHON"
  • "RUBY"
  • "RUST"
  • "SWIFT"