openapi: 3.2.0 info: version: v3 title: Fortify on Demand Web API Explorer Open Source Components… servers: - url: https://api.ams.fortify.com tags: - name: Open Source Components paths: /api/v3/applications/open-source-components: get: tags: - Open Source Components summary: Retrieve a collection of open source components description: 'Allowed Scopes: api-tenant, view-tenant-data' operationId: OpenSourceComponentsV3_GetOpenSourceComponents parameters: - name: openSourceScanType in: query description: The source of component data. required: false schema: type: string enum: - Sonatype - CycloneDx - Debricked - name: filters in: query description: 'A delimited list of field filters.

Field name and value should be separated by a colon (:).

Multiple fields should be separated by a plus (+). Multiple fields are treated as an AND condition. Example, fieldname1:value+fieldname2:value

Multiple values for a field should be separated by a pipe (|). Mulitple values for a field are treated as an OR condition. Example, fieldname1:value1|value2

Filtering is not supported for the following fields: licenses, packageUrl, vulnerabilityCounts' required: false schema: type: string - name: orderBy in: query description: The field name to order the results by. required: false schema: type: string - name: orderByDirection in: query description: The direction to order the results by. ASC and DESC are valid values. required: false schema: type: string - name: fields in: query description: Comma separated list of fields to return. required: false schema: type: string - name: offset in: query description: Offset of the starting record. 0 indicates the first record. required: false schema: type: integer format: int32 - name: limit in: query description: Maximum records to return. The maximum value allowed is 50. required: false schema: type: integer format: int32 - name: returnTotalComponentCount in: query description: If true return the total number of components. Default is true. required: false schema: type: boolean responses: '200': description: Ok content: application/json: schema: $ref: '#/components/schemas/OpenSourceComponentListResponse' text/json: schema: $ref: '#/components/schemas/OpenSourceComponentListResponse' application/xml: schema: $ref: '#/components/schemas/OpenSourceComponentListResponse' text/xml: schema: $ref: '#/components/schemas/OpenSourceComponentListResponse' '401': description: Unauthorized '403': description: Forbidden '429': description: TooManyRequests '500': description: InternalServerError /api/v3/open-source-scans/{scanId}/sbom: get: tags: - Open Source Components summary: Download the Open Source SBOM file description: 'Allowed Scopes: api-tenant, view-issues' operationId: OpenSourceComponentsV3_DownloadOpenSourceSbomFile parameters: - name: scanId in: path description: The scan id required: true schema: type: integer format: int32 - name: format in: query description: The format of the SBOM file (e.g., "CycloneDx" or "SPDx") required: false schema: type: string responses: '200': description: Ok content: application/json: schema: type: string text/json: schema: type: string application/xml: schema: type: string text/xml: schema: type: string '400': description: BadRequest content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' text/json: schema: $ref: '#/components/schemas/ErrorResponse' application/xml: schema: $ref: '#/components/schemas/ErrorResponse' text/xml: schema: $ref: '#/components/schemas/ErrorResponse' '401': description: Unauthorized content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' text/json: schema: $ref: '#/components/schemas/ErrorResponse' application/xml: schema: $ref: '#/components/schemas/ErrorResponse' text/xml: schema: $ref: '#/components/schemas/ErrorResponse' '403': description: Forbidden '404': description: NotFound content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' text/json: schema: $ref: '#/components/schemas/ErrorResponse' application/xml: schema: $ref: '#/components/schemas/ErrorResponse' text/xml: schema: $ref: '#/components/schemas/ErrorResponse' '429': description: TooManyRequests '500': description: InternalServerError components: schemas: OpenSourceComponentListResponse: description: Generic List Response type: object properties: items: description: The list of items type: array items: $ref: '#/components/schemas/OpenSourceComponent' totalCount: format: int32 description: Total count of items type: integer offset: format: int32 description: Offset of the starting record. 0 indicates the first record. type: integer limit: format: int32 description: Maximum records to return. type: integer VulnerabilityCount: type: object properties: severityId: format: int32 type: integer readOnly: true severity: type: string readOnly: true count: format: int32 type: integer Error: description: Error type: object properties: errorCode: format: int32 description: The error code type: integer message: description: The error message type: string OpenSourceComponentRelease: type: object properties: applicationId: format: int32 type: integer applicationName: type: string releaseId: format: int32 type: integer releaseName: type: string OpenSourceComponentLicense: type: object properties: name: type: string ErrorResponse: description: Error Response type: object properties: errors: description: List of errors type: array items: $ref: '#/components/schemas/Error' OpenSourceComponent: type: object properties: componentHash: type: string componentName: type: string componentVersionName: type: string licenses: type: array items: $ref: '#/components/schemas/OpenSourceComponentLicense' vulnerabilityCounts: type: array items: $ref: '#/components/schemas/VulnerabilityCount' releases: type: array items: $ref: '#/components/schemas/OpenSourceComponentRelease' packageUrl: type: string scanTool: type: string