openapi: 3.1.0 info: title: Anchore Enterprise Images SBOM API description: REST API for Anchore Enterprise providing image analysis, vulnerability scanning, policy evaluation, SBOM generation, and subscription management for enterprise container security workflows. version: '2.0' contact: name: Anchore Support url: https://anchore.com/support/ license: name: Apache 2.0 url: https://www.apache.org/licenses/LICENSE-2.0 servers: - url: https://anchore.example.com/v2 description: Anchore Enterprise API security: - basicAuth: [] - bearerAuth: [] tags: - name: SBOM paths: /images/{imageDigest}/sbom: get: operationId: getImageSbom summary: Anchore Enterprise Get Image SBOM description: Retrieve the Software Bill of Materials for an analyzed image tags: - SBOM parameters: - name: imageDigest in: path required: true schema: type: string responses: '200': description: Image SBOM in CycloneDX format content: application/json: schema: $ref: '#/components/schemas/SBOM' components: schemas: SBOMComponent: type: object properties: type: type: string enum: - application - framework - library - container - device - firmware name: type: string version: type: string purl: type: string licenses: type: array items: type: object properties: license: type: object properties: id: type: string hashes: type: array items: type: object properties: alg: type: string content: type: string SBOM: type: object description: Software Bill of Materials in CycloneDX format properties: bomFormat: type: string specVersion: type: string serialNumber: type: string version: type: integer metadata: type: object components: type: array items: $ref: '#/components/schemas/SBOMComponent' securitySchemes: basicAuth: type: http scheme: basic bearerAuth: type: http scheme: bearer