Sbom Service API Reference

FieldValue
Source specsbom-service/openapi/v1.json
OpenAPI version3.1.1
API version1.0.0
Operations81
Path filterAll paths

Operations

POST /api/change-traces/build

Builds a deterministic change trace document for the supplied tenant and artifact digest pair. Accepts modern fromDigest/toDigest fields and legacy fromScanId/toScanId compatibility fields.

PropertyValue
Operation IDBuildChangeTrace
TagsStellaOps.SbomService
AuthRequired
Request bodyapplication/json

Responses:

StatusDescriptionContent types
200OK-

GET /api/change-traces/{traceId}

Reconstructs a deterministic change trace document from a shareable traceId without requiring persisted trace blobs.

PropertyValue
Operation IDGetChangeTrace
TagsStellaOps.SbomService
AuthRequired
Request body-

Parameters:

NameInRequiredDescription
traceIdpathyes

Responses:

StatusDescriptionContent types
200OK-

GET /api/compare/baselines/{scanDigest}

Returns baseline scan recommendations for delta comparison. Returns empty recommendations when no previous scans are available.

PropertyValue
Operation IDGetCompareBaselineRecommendation
TagsCompare
AuthRequired
Request body-

Parameters:

NameInRequiredDescription
scanDigestpathyes

Responses:

StatusDescriptionContent types
200OK-

POST /api/v1/artifact-links

Creates or updates a source/build/image/SBOM/scan artifact association. OCI image subjects require immutable sha256 digests, source snapshots require repoUrl plus commitSha, and weak evidence creates candidates only.

PropertyValue
Operation IDCreateArtifactLink
TagsStellaOps.SbomService
AuthRequired
Request bodyapplication/json

Responses:

StatusDescriptionContent types
200OK-

GET /api/v1/artifact-links/candidates

Lists strong candidate artifact links that still need operator confirmation or deterministic evidence verification.

PropertyValue
Operation IDListArtifactLinkCandidates
TagsStellaOps.SbomService
AuthRequired
Request body-

Parameters:

NameInRequiredDescription
limitqueryno
tenantqueryno

Responses:

StatusDescriptionContent types
200OK-

POST /api/v1/artifact-links/import

Imports a related source/build/image/SBOM/scan/detector bundle and creates deterministic first-class artifact links for every supplied relationship.

PropertyValue
Operation IDImportArtifactLinks
TagsStellaOps.SbomService
AuthRequired
Request bodyapplication/json

Responses:

StatusDescriptionContent types
200OK-

GET /api/v1/artifact-links/resolve

Resolves an artifact association graph by subject key, image digest, SBOM digest, scan job ID, or source repo URL plus commit SHA.

PropertyValue
Operation IDResolveArtifactLinks
TagsStellaOps.SbomService
AuthRequired
Request body-

Parameters:

NameInRequiredDescription
commitShaqueryno
imageDigestqueryno
maxDepthqueryno
repoUrlqueryno
sbomDigestqueryno
scanJobIdqueryno
subjectKeyqueryno
tenantqueryno

Responses:

StatusDescriptionContent types
200OK-

GET /api/v1/artifact-links/unlinked

Lists artifact subjects with no non-rejected links so operators can resolve missing source/image/SBOM/scan associations.

PropertyValue
Operation IDListUnlinkedArtifactSubjects
TagsStellaOps.SbomService
AuthRequired
Request body-

Parameters:

NameInRequiredDescription
kindqueryno
limitqueryno
tenantqueryno

Responses:

StatusDescriptionContent types
200OK-

POST /api/v1/artifact-links/{linkId}/confirm

Confirms an artifact link from the UI or CLI and promotes it to verified UI-confirmed evidence.

PropertyValue
Operation IDConfirmArtifactLink
TagsStellaOps.SbomService
AuthRequired
Request bodyapplication/json

Parameters:

NameInRequiredDescription
linkIdpathyes

Responses:

StatusDescriptionContent types
200OK-

POST /api/v1/artifact-links/{linkId}/reject

Rejects an artifact association candidate and removes it from resolved graphs while retaining audit history.

PropertyValue
Operation IDRejectArtifactLink
TagsStellaOps.SbomService
AuthRequired
Request bodyapplication/json

Parameters:

NameInRequiredDescription
linkIdpathyes

Responses:

StatusDescriptionContent types
200OK-

POST /api/v1/artifact-links/{linkId}/verify

Re-evaluates an artifact link confidence from its stored evidence type and promotes strong evidence to verified.

PropertyValue
Operation IDVerifyArtifactLink
TagsStellaOps.SbomService
AuthRequired
Request bodyapplication/json

Parameters:

NameInRequiredDescription
linkIdpathyes

Responses:

StatusDescriptionContent types
200OK-

GET /api/v1/buildinfo

API alias for /buildinfo.json (same payload).

PropertyValue
Operation IDStellaOpsBuildInfoApi
TagsStellaOps.SbomService
AuthNot declared
Request body-

Responses:

StatusDescriptionContent types
200OK-

GET /api/v1/lineage/compare

Returns a rich comparison between two artifact versions by lineage digest (a and b) for the given tenant. Optionally includes SBOM diff, VEX deltas, reachability deltas, attestations, and replay hashes. Returns 404 if comparison data is not found.

PropertyValue
Operation IDCompareLineage
TagsStellaOps.SbomService
AuthRequired
Request body-

Parameters:

NameInRequiredDescription
aqueryno
bqueryno
includeAttestationsqueryno
includeReachabilityDeltasqueryno
includeReplayHashesqueryno
includeSbomDiffqueryno
includeVexDeltasqueryno
tenantqueryno

Responses:

StatusDescriptionContent types
200OK-

POST /api/v1/lineage/compare-drift

Compares two replay hashes (hashA and hashB) for the given tenant to detect drift between two release decision points. Returns a structured drift report indicating whether the two points are equivalent. Requires hashA, hashB, and tenantId.

PropertyValue
Operation IDCompareLineageDrift
TagsStellaOps.SbomService
AuthRequired
Request bodyapplication/json

Responses:

StatusDescriptionContent types
200OK-

GET /api/v1/lineage/diff

Returns a graph-level diff between two artifact lineage graphs identified by their digests (from and to) for the given tenant. Highlights added and removed nodes and edges between two artifact versions. Returns 404 if either graph is not found.

PropertyValue
Operation IDGetLineageDiff
TagsStellaOps.SbomService
AuthRequired
Request body-

Parameters:

NameInRequiredDescription
fromqueryno
tenantqueryno
toqueryno

Responses:

StatusDescriptionContent types
200OK-

POST /api/v1/lineage/export

Exports the lineage evidence pack between two artifact digests for the given tenant as a structured bundle. Enforces a 50 MB size limit on the export payload. Returns 413 if the export exceeds the size limit. Requires fromDigest, toDigest, and tenantId in the request body.

PropertyValue
Operation IDExportLineage
TagsStellaOps.SbomService
AuthRequired
Request bodyapplication/json

Responses:

StatusDescriptionContent types
200OK-

GET /api/v1/lineage/hover

Returns a lightweight hover card summary of the lineage relationship between two artifact digests for the given tenant. Used for fast UI hover popups. Cached for low-latency responses. Returns 404 if no hover card data is available.

PropertyValue
Operation IDGetLineageHoverCard
TagsStellaOps.SbomService
AuthRequired
Request body-

Parameters:

NameInRequiredDescription
fromqueryno
tenantqueryno
toqueryno

Responses:

StatusDescriptionContent types
200OK-

POST /api/v1/lineage/verify

Verifies a deterministic replay hash against the current policy and SBOM state to confirm the release decision is reproducible. Optionally re-evaluates the policy against current feeds. Requires replayHash and tenantId in the request body.

PropertyValue
Operation IDVerifyLineageReplay
TagsStellaOps.SbomService
AuthRequired
Request bodyapplication/json

Responses:

StatusDescriptionContent types
200OK-

GET /api/v1/lineage/{artifactDigest}

Returns the lineage graph for a specific artifact by digest for the given tenant, including upstream provenance nodes up to maxDepth levels, optional trust badges, and an optional deterministic replay hash. Returns 404 if the graph is not found.

PropertyValue
Operation IDGetLineageGraph
TagsStellaOps.SbomService
AuthRequired
Request body-

Parameters:

NameInRequiredDescription
artifactDigestpathyes
includeBadgesqueryno
includeReplayHashqueryno
maxDepthqueryno
tenantqueryno

Responses:

StatusDescriptionContent types
200OK-

GET /api/v1/lineage/{artifactDigest}/children

Returns the direct child artifacts in the lineage graph for a specific artifact digest and tenant. Lists artifacts that were built from or derived from the specified artifact.

PropertyValue
Operation IDGetLineageChildren
TagsStellaOps.SbomService
AuthRequired
Request body-

Parameters:

NameInRequiredDescription
artifactDigestpathyes
tenantqueryno

Responses:

StatusDescriptionContent types
200OK-

GET /api/v1/lineage/{artifactDigest}/parents

Returns the direct parent artifacts in the lineage graph for a specific artifact digest and tenant. Lists artifacts from which the specified artifact was built or derived.

PropertyValue
Operation IDGetLineageParents
TagsStellaOps.SbomService
AuthRequired
Request body-

Parameters:

NameInRequiredDescription
artifactDigestpathyes
tenantqueryno

Responses:

StatusDescriptionContent types
200OK-

GET /api/v1/registry-sources

PropertyValue
Operation IDListRegistrySources
TagsRegistrySources
AuthRequired
Request body-

Parameters:

NameInRequiredDescription
integrationIdqueryno
pagequeryno
pageSizequeryno
searchqueryno
sortByqueryno
sortDescendingqueryno
statusqueryno
triggerModequeryno
typequeryno

Responses:

StatusDescriptionContent types
200OK-

POST /api/v1/registry-sources

PropertyValue
Operation IDCreateRegistrySource
TagsRegistrySources
AuthRequired
Request bodyapplication/json

Responses:

StatusDescriptionContent types
200OK-

POST /api/v1/registry-sources/test

PropertyValue
Operation IDTestNewRegistrySource
TagsRegistrySources
AuthRequired
Request bodyapplication/json

Responses:

StatusDescriptionContent types
200OK-

GET /api/v1/registry-sources/{id}

PropertyValue
Operation IDGetRegistrySource
TagsRegistrySources
AuthRequired
Request body-

Parameters:

NameInRequiredDescription
idpathyes

Responses:

StatusDescriptionContent types
200OK-

PUT /api/v1/registry-sources/{id}

PropertyValue
Operation IDUpdateRegistrySource
TagsRegistrySources
AuthRequired
Request bodyapplication/json

Parameters:

NameInRequiredDescription
idpathyes

Responses:

StatusDescriptionContent types
200OK-

DELETE /api/v1/registry-sources/{id}

PropertyValue
Operation IDDeleteRegistrySource
TagsRegistrySources
AuthRequired
Request body-

Parameters:

NameInRequiredDescription
idpathyes

Responses:

StatusDescriptionContent types
200OK-

POST /api/v1/registry-sources/{id}/discover-and-scan

PropertyValue
Operation IDDiscoverAndScanRegistrySource
TagsRegistrySources
AuthRequired
Request body-

Parameters:

NameInRequiredDescription
idpathyes

Responses:

StatusDescriptionContent types
200OK-

GET /api/v1/registry-sources/{id}/discover/images

PropertyValue
Operation IDDiscoverRegistrySourceImages
TagsRegistrySources
AuthRequired
Request body-

Parameters:

NameInRequiredDescription
idpathyes

Responses:

StatusDescriptionContent types
200OK-

GET /api/v1/registry-sources/{id}/discover/repositories

PropertyValue
Operation IDDiscoverRegistrySourceRepositories
TagsRegistrySources
AuthRequired
Request body-

Parameters:

NameInRequiredDescription
idpathyes

Responses:

StatusDescriptionContent types
200OK-

GET /api/v1/registry-sources/{id}/discover/tags/{repository}

PropertyValue
Operation IDDiscoverRegistrySourceTags
TagsRegistrySources
AuthRequired
Request body-

Parameters:

NameInRequiredDescription
idpathyes
repositorypathyes

Responses:

StatusDescriptionContent types
200OK-

GET /api/v1/registry-sources/{id}/images

PropertyValue
Operation IDListRegistrySourceImages
TagsRegistrySources
AuthRequired
Request body-

Parameters:

NameInRequiredDescription
idpathyes
digestqueryno
limitqueryno
repositoryqueryno
tagqueryno

Responses:

StatusDescriptionContent types
200OK-

GET /api/v1/registry-sources/{id}/images/sbom

PropertyValue
Operation IDGetRegistrySourceImageSbom
TagsRegistrySources
AuthRequired
Request body-

Parameters:

NameInRequiredDescription
idpathyes
digestqueryno
repositoryqueryno
tagqueryno

Responses:

StatusDescriptionContent types
200OK-

POST /api/v1/registry-sources/{id}/pause

PropertyValue
Operation IDPauseRegistrySource
TagsRegistrySources
AuthRequired
Request bodyapplication/json

Parameters:

NameInRequiredDescription
idpathyes

Responses:

StatusDescriptionContent types
200OK-

POST /api/v1/registry-sources/{id}/resume

PropertyValue
Operation IDResumeRegistrySource
TagsRegistrySources
AuthRequired
Request body-

Parameters:

NameInRequiredDescription
idpathyes

Responses:

StatusDescriptionContent types
200OK-

GET /api/v1/registry-sources/{id}/runs

PropertyValue
Operation IDGetRegistrySourceRuns
TagsRegistrySources
AuthRequired
Request body-

Parameters:

NameInRequiredDescription
idpathyes
limitqueryno

Responses:

StatusDescriptionContent types
200OK-

POST /api/v1/registry-sources/{id}/test

PropertyValue
Operation IDTestRegistrySource
TagsRegistrySources
AuthRequired
Request body-

Parameters:

NameInRequiredDescription
idpathyes

Responses:

StatusDescriptionContent types
200OK-

POST /api/v1/registry-sources/{id}/trigger

PropertyValue
Operation IDTriggerRegistrySource
TagsRegistrySources
AuthRequired
Request bodyapplication/json

Parameters:

NameInRequiredDescription
idpathyes

Responses:

StatusDescriptionContent types
200OK-

GET /api/v1/sbom/ledger/diff

Canonical v1 API alias for /sbom/ledger/diff. Required so the Console SBOM A/B diff round-trips via the gateway’s /api/v1/sbom(.*) regex.

PropertyValue
Operation IDGetSbomLedgerDiffV1
TagsStellaOps.SbomService
AuthRequired
Request body-

Parameters:

NameInRequiredDescription
afterqueryno
beforequeryno

Responses:

StatusDescriptionContent types
200OK-

GET /api/v1/sbom/production-answer

Returns the authenticated tenant’s bounded SBOM production answer: accepted CycloneDX/SPDX versions, canonical ingest routes, and the latest persisted SBOM per artifact with stored producer provenance and a format-preserving raw-document export handoff when available. Items cap at 100 while totalProduced remains exact.

PropertyValue
Operation IDGetSbomProductionAnswerV1
TagsStellaOps.SbomService
AuthRequired
Request body-

Parameters:

NameInRequiredDescription
limitqueryno

Responses:

StatusDescriptionContent types
200OK-

GET /api/v1/sbom/subject/{subjectRef}/cyclonedx

Returns the raw CycloneDX SBOM document (byte-for-byte verbatim) for the given subject (artifact ref), tenant-scoped by the authenticated stellaops:tenant claim. Optional ?version=<guid|latest> selects a specific ledger version (default latest). 200 with application/json (or application/vnd.cyclonedx+json when requested via Accept). 404 when no SBOM exists for that subject/tenant - never fabricated. Consumed by the ExportCenter audit bundle.

PropertyValue
Operation IDGetSbomSubjectCycloneDxV1
TagsStellaOps.SbomService
AuthRequired
Request body-

Parameters:

NameInRequiredDescription
subjectRefpathyes
versionqueryno

Responses:

StatusDescriptionContent types
200OK-

GET /api/v1/sbom/subject/{subjectRef}/document

Returns the raw uploaded SBOM document byte-for-byte for the authenticated tenant using its stored media type (CycloneDX JSON or SPDX JSON). Optional version selects a ledger version; missing tenant ownership or missing legacy sidecar returns 404 rather than fabricated content.

PropertyValue
Operation IDGetSbomSubjectDocumentV1
TagsStellaOps.SbomService
AuthRequired
Request body-

Parameters:

NameInRequiredDescription
subjectRefpathyes
versionqueryno

Responses:

StatusDescriptionContent types
200OK-

POST /api/v1/sbom/upload

Canonical v1 API path alias for UploadSbom. Uploads and ingests a new SBOM for the specified artifact, validating the payload and persisting it to the ledger. Returns 202 Accepted with the artifact reference and ledger entry on success.

PropertyValue
Operation IDUploadSbomV1
TagsStellaOps.SbomService
AuthRequired
Request bodyapplication/json

Responses:

StatusDescriptionContent types
200OK-

GET /api/v1/sbom/uploads

Canonical v1 API GET path for uploaded SBOMs (alias for /sbom/ledger/history). Returns the paginated ledger history for the artifact query parameter. Required so SBOM uploads round-trip via the gateway’s /api/v1/sbom(.*) regex without being silently shadowed by the SPA fallback. Returns 404 when no uploads exist for the artifact.

PropertyValue
Operation IDListSbomUploadsV1
TagsStellaOps.SbomService
AuthRequired
Request body-

Parameters:

NameInRequiredDescription
artifactqueryno
cursorqueryno
limitqueryno

Responses:

StatusDescriptionContent types
200OK-

GET /api/v1/sbom/uploads/{artifactRef}

Canonical v1 API GET-by-artifact path for uploaded SBOMs (alias for /sbom/ledger/history). The artifactRef route parameter is URL-decoded before lookup so the gateway can pass artifact references that contain ‘:’ and ‘/’ verbatim. Returns the paginated ledger history. Returns 404 when no uploads exist.

PropertyValue
Operation IDGetSbomUploadByArtifactV1
TagsStellaOps.SbomService
AuthRequired
Request body-

Parameters:

NameInRequiredDescription
artifactRefpathyes
cursorqueryno
limitqueryno

Responses:

StatusDescriptionContent types
200OK-

GET /api/v1/sbom/versions

Canonical v1 API alias for /sbom/versions. Required so the Console SBOM A/B diff version picker round-trips via the gateway’s /api/v1/sbom(.*) regex.

PropertyValue
Operation IDGetSbomVersionsV1
TagsStellaOps.SbomService
AuthRequired
Request body-

Parameters:

NameInRequiredDescription
artifactqueryno
cursorqueryno
limitqueryno

Responses:

StatusDescriptionContent types
200OK-

GET /api/v1/scan/results

Vuln/scan report by subject (artifact ref or digest), tenant-scoped by the authenticated stellaops:tenant claim. Proxies Scanner’s canonical artifact vulnerability report endpoint and returns Scanner 200 JSON verbatim; Scanner 404/empty remains 404 so audit bundles omit the section; Scanner transport failures return a non-placeholder 503.

PropertyValue
Operation IDGetScanResultsBySubjectV1
TagsStellaOps.SbomService
AuthRequired
Request body-

Parameters:

NameInRequiredDescription
digestqueryno
subjectqueryno

Responses:

StatusDescriptionContent types
200OK-

GET /buildinfo.json

Image build provenance (module, gitSha, gitCommitTime, imageBuiltAt, branch) for drift detection.

PropertyValue
Operation IDStellaOpsBuildInfoFile
TagsStellaOps.SbomService
AuthNot declared
Request body-

Responses:

StatusDescriptionContent types
200OK-

GET /components/lookup

Looks up the authenticated tenant’s component read model by PURL, optionally filtered by artifact. Neighbors are keyed by tenant (migration 006); another tenant’s rows - and legacy rows with no tenant - are never returned.

PropertyValue
Operation IDLookupSbomComponent
TagsStellaOps.SbomService
AuthRequired
Request body-

Parameters:

NameInRequiredDescription
artifactqueryno
cursorqueryno
limitqueryno
purlqueryno

Responses:

StatusDescriptionContent types
200OK-

GET /console/sboms

Returns the authenticated tenant’s paginated SBOM catalog, optionally filtered by artifact name, license, scope, and asset tag. Rows are keyed by tenant (migration 006); another tenant’s rows - and legacy rows with no tenant - are never returned.

PropertyValue
Operation IDListConsoleSboms
TagsStellaOps.SbomService
AuthRequired
Request body-

Parameters:

NameInRequiredDescription
artifactqueryno
assetTagqueryno
cursorqueryno
licensequeryno
limitqueryno
scopequeryno

Responses:

StatusDescriptionContent types
200OK-

GET /entrypoints

Returns all registered service entrypoints for the authenticated tenant, listing artifact, service, path, scope, and runtime flag for each. An optional tenant query value is accepted only as a matching assertion.

PropertyValue
Operation IDListSbomEntrypoints
TagsStellaOps.SbomService
AuthRequired
Request body-

Parameters:

NameInRequiredDescription
tenantqueryno

Responses:

StatusDescriptionContent types
200OK-

POST /entrypoints

Creates or updates a service entrypoint for the authenticated tenant linking an artifact to a service path. Returns the full updated entrypoint list. The optional tenant body value is a matching assertion; artifact, service, and path are required.

PropertyValue
Operation IDUpsertSbomEntrypoint
TagsStellaOps.SbomService
AuthRequired
Request bodyapplication/json

Responses:

StatusDescriptionContent types
200OK-

GET /healthz

Returns liveness status of the SBOM service. Always returns 200 OK with status ‘ok’ when the process is running. Used by infrastructure liveness probes.

PropertyValue
Operation IDSbomHealthz
TagsStellaOps.SbomService
AuthNot declared
Request body-

Responses:

StatusDescriptionContent types
200OK-

GET /internal/orchestrator/control

Internal endpoint. Returns the current orchestrator control state for the given tenant including pause/resume flags and scheduling overrides. Requires tenant query parameter.

PropertyValue
Operation IDGetOrchestratorControl
TagsStellaOps.SbomService
AuthRequired
Request body-

Parameters:

NameInRequiredDescription
tenantqueryno

Responses:

StatusDescriptionContent types
200OK-

POST /internal/orchestrator/control

Internal endpoint. Updates the orchestrator control state for the given tenant, allowing operators to pause, resume, or adjust scheduling parameters. Requires tenantId in the request body.

PropertyValue
Operation IDUpdateOrchestratorControl
TagsStellaOps.SbomService
AuthRequired
Request bodyapplication/json

Responses:

StatusDescriptionContent types
200OK-

GET /internal/orchestrator/sources

Internal endpoint. Returns all registered orchestrator artifact sources for the given tenant. Requires tenant query parameter.

PropertyValue
Operation IDListOrchestratorSources
TagsStellaOps.SbomService
AuthRequired
Request body-

Parameters:

NameInRequiredDescription
tenantqueryno

Responses:

StatusDescriptionContent types
200OK-

POST /internal/orchestrator/sources

Internal endpoint. Registers a new orchestrator artifact source for the given tenant linking an artifact digest to a source type. Requires tenantId, artifactDigest, and sourceType in the request body.

PropertyValue
Operation IDRegisterOrchestratorSource
TagsStellaOps.SbomService
AuthRequired
Request bodyapplication/json

Responses:

StatusDescriptionContent types
200OK-

GET /internal/orchestrator/watermarks

Internal endpoint. Returns the current ingestion watermark state for the given tenant, indicating the last successfully processed position in the artifact stream. Requires tenant query parameter.

PropertyValue
Operation IDGetOrchestratorWatermarks
TagsStellaOps.SbomService
AuthRequired
Request body-

Parameters:

NameInRequiredDescription
tenantqueryno

Responses:

StatusDescriptionContent types
200OK-

POST /internal/orchestrator/watermarks

Internal endpoint. Sets the ingestion watermark for the given tenant to the specified value, marking the last processed position in the artifact stream. Requires tenant query parameter.

PropertyValue
Operation IDSetOrchestratorWatermark
TagsStellaOps.SbomService
AuthRequired
Request body-

Parameters:

NameInRequiredDescription
tenantqueryno
watermarkqueryno

Responses:

StatusDescriptionContent types
200OK-

GET /internal/sbom/analysis/jobs

Internal endpoint. Returns the chronologically ordered list of SBOM analysis jobs for a specific artifact. Requires artifact query parameter.

PropertyValue
Operation IDListSbomAnalysisJobs
TagsStellaOps.SbomService
AuthRequired
Request body-

Parameters:

NameInRequiredDescription
artifactqueryno

Responses:

StatusDescriptionContent types
200OK-

GET /internal/sbom/asset-events

Internal endpoint. Returns all SBOM asset-level events from the configured event store. Used by orchestrators to process asset lifecycle changes associated with SBOM versions.

PropertyValue
Operation IDListSbomAssetEvents
TagsStellaOps.SbomService
AuthRequired
Request body-

Responses:

StatusDescriptionContent types
200OK-

GET /internal/sbom/events

Internal endpoint. Returns all SBOM version-created events in the configured event store backlog. Logs a warning if the backlog exceeds 100 entries. Used by orchestrators to process pending SBOM ingestion events.

PropertyValue
Operation IDListSbomEvents
TagsStellaOps.SbomService
AuthRequired
Request body-

Responses:

StatusDescriptionContent types
200OK-

POST /internal/sbom/events/backfill

Internal endpoint. Replays all known SBOM projections as version-created events into the event store backlog. Used for backfill and recovery scenarios after store resets. Returns the count of successfully published events.

PropertyValue
Operation IDBackfillSbomEvents
TagsStellaOps.SbomService
AuthRequired
Request body-

Responses:

StatusDescriptionContent types
200OK-

GET /internal/sbom/inventory

Internal endpoint. Returns all SBOM inventory entries from the event store, representing the known set of artifacts and their SBOM state across tenants.

PropertyValue
Operation IDListSbomInventory
TagsStellaOps.SbomService
AuthRequired
Request body-

Responses:

StatusDescriptionContent types
200OK-

POST /internal/sbom/inventory/backfill

Internal endpoint. Clears and replays the SBOM inventory by re-fetching projections for known snapshot/tenant pairs. Used for recovery after inventory store resets. Returns the count of replayed entries.

PropertyValue
Operation IDBackfillSbomInventory
TagsStellaOps.SbomService
AuthRequired
Request body-

Responses:

StatusDescriptionContent types
200OK-

GET /internal/sbom/ledger/audit

Internal endpoint. Returns the chronologically ordered audit trail for a specific artifact from the SBOM ledger, listing all state transitions and operations. Requires artifact query parameter.

PropertyValue
Operation IDGetSbomLedgerAudit
TagsStellaOps.SbomService
AuthRequired
Request body-

Parameters:

NameInRequiredDescription
artifactqueryno

Responses:

StatusDescriptionContent types
200OK-

GET /internal/sbom/resolver-feed

Internal endpoint. Returns all resolver feed candidates from the event store. The resolver feed is used by the policy engine and scanner to resolve component identities across SBOM versions.

PropertyValue
Operation IDGetSbomResolverFeed
TagsStellaOps.SbomService
AuthRequired
Request body-

Responses:

StatusDescriptionContent types
200OK-

POST /internal/sbom/resolver-feed/backfill

Internal endpoint. Clears and replays the resolver feed by re-fetching projections for known snapshot/tenant pairs. Used for recovery after resolver store resets. Returns the count of re-published resolver feed entries.

PropertyValue
Operation IDBackfillSbomResolverFeed
TagsStellaOps.SbomService
AuthRequired
Request body-

Responses:

StatusDescriptionContent types
200OK-

GET /internal/sbom/resolver-feed/export

Internal endpoint. Exports all resolver feed candidates as a newline-delimited JSON (NDJSON) stream. Used for bulk export and offline processing of the resolver feed by external consumers.

PropertyValue
Operation IDExportSbomResolverFeed
TagsStellaOps.SbomService
AuthRequired
Request body-

Responses:

StatusDescriptionContent types
200OK-

POST /internal/sbom/retention/prune

Internal endpoint. Applies the configured retention policy to the SBOM ledger, pruning old versions beyond the configured min/max version counts. Records pruned version counts in metrics. Returns a retention result summary.

PropertyValue
Operation IDPruneSbomRetention
TagsStellaOps.SbomService
AuthRequired
Request body-

Responses:

StatusDescriptionContent types
200OK-

GET /readyz

Returns readiness status of the SBOM service. Returns 200 with status ‘warming’ while the service is starting up. Used by infrastructure readiness probes.

PropertyValue
Operation IDSbomReadyz
TagsStellaOps.SbomService
AuthNot declared
Request body-

Responses:

StatusDescriptionContent types
200OK-

GET /sbom/context

Returns an assembled SBOM context for an artifact. Timeline and persisted dependency-path data are both read under the authenticated tenant; another tenant’s graph rows and legacy tenantless rows are never returned.

PropertyValue
Operation IDGetSbomContext
TagsStellaOps.SbomService
AuthRequired
Request body-

Parameters:

NameInRequiredDescription
artifactIdqueryno
includeBlastRadiusqueryno
includeEnvironmentFlagsqueryno
maxDependencyPathsqueryno
maxTimelineEntriesqueryno
purlqueryno

Responses:

StatusDescriptionContent types
200OKapplication/json

GET /sbom/ledger/diff

Returns a component-level diff between two SBOM ledger entries identified by their GUIDs (before and after). Highlights added, removed, and changed components between two SBOM versions. Returns 404 if either entry is not found.

PropertyValue
Operation IDGetSbomLedgerDiff
TagsStellaOps.SbomService
AuthRequired
Request body-

Parameters:

NameInRequiredDescription
afterqueryno
beforequeryno

Responses:

StatusDescriptionContent types
200OK-

GET /sbom/ledger/history

Returns the paginated ledger history for a specific artifact, listing SBOM versions in chronological order with ledger metadata. Requires artifact query parameter. Returns 404 if no history is found.

PropertyValue
Operation IDGetSbomLedgerHistory
TagsStellaOps.SbomService
AuthRequired
Request body-

Parameters:

NameInRequiredDescription
artifactqueryno
cursorqueryno
limitqueryno

Responses:

StatusDescriptionContent types
200OK-

GET /sbom/ledger/lineage

Returns the full artifact lineage chain from the SBOM ledger for a specific artifact, showing the provenance ancestry of SBOM versions. Requires artifact query parameter. Returns 404 if lineage is not found.

PropertyValue
Operation IDGetSbomLedgerLineage
TagsStellaOps.SbomService
AuthRequired
Request body-

Parameters:

NameInRequiredDescription
artifactqueryno

Responses:

StatusDescriptionContent types
200OK-

GET /sbom/ledger/point

Returns the SBOM ledger entry for a specific artifact at a given point in time. Requires artifact and at (ISO-8601 timestamp) query parameters. Returns 404 if no ledger entry exists for the specified time.

PropertyValue
Operation IDGetSbomLedgerPoint
TagsStellaOps.SbomService
AuthRequired
Request body-

Parameters:

NameInRequiredDescription
artifactqueryno
atqueryno

Responses:

StatusDescriptionContent types
200OK-

GET /sbom/ledger/range

Returns paginated SBOM ledger entries for a specific artifact within a time range defined by start and end ISO-8601 timestamps. Requires artifact, start, and end query parameters. Returns 404 if no data is found for the range.

PropertyValue
Operation IDGetSbomLedgerRange
TagsStellaOps.SbomService
AuthRequired
Request body-

Parameters:

NameInRequiredDescription
artifactqueryno
cursorqueryno
endqueryno
limitqueryno
startqueryno

Responses:

StatusDescriptionContent types
200OK-

GET /sbom/paths

Returns deterministic dependency paths from uploaded CycloneDX or SPDX edges for the authenticated tenant. Coverage and truncation fields distinguish complete, partial, zero-edge, and unavailable graphs; paths are never synthesized for orphan components.

PropertyValue
Operation IDGetSbomPaths
TagsStellaOps.SbomService
AuthRequired
Request body-

Parameters:

NameInRequiredDescription
artifactqueryno
cursorqueryno
envqueryno
limitqueryno
purlqueryno
scopequeryno

Responses:

StatusDescriptionContent types
200OKapplication/json

POST /sbom/upload

Uploads and ingests a new SBOM for the specified artifact, validating the payload and persisting it to the ledger. Returns 202 Accepted with the artifact reference and ledger entry on success. Returns 400 if validation fails.

PropertyValue
Operation IDUploadSbom
TagsStellaOps.SbomService
AuthRequired
Request bodyapplication/json

Responses:

StatusDescriptionContent types
200OK-

GET /sbom/versions

Returns the paginated version timeline for a specific artifact, listing SBOM snapshots in chronological order. Requires artifact query parameter. Limit must be between 1 and 200.

PropertyValue
Operation IDGetSbomVersions
TagsStellaOps.SbomService
AuthRequired
Request body-

Parameters:

NameInRequiredDescription
artifactqueryno
cursorqueryno
limitqueryno

Responses:

StatusDescriptionContent types
200OK-

GET /sboms/{snapshotId}/projection

Returns the structured SBOM projection for a specific snapshot ID and tenant. The projection contains the full normalized component graph with schema version and a deterministic hash. Used by the policy engine and reachability graph for decision-making.

PropertyValue
Operation IDGetSbomProjection
TagsStellaOps.SbomService
AuthRequired
Request body-

Parameters:

NameInRequiredDescription
snapshotIdpathyes
tenantqueryno

Responses:

StatusDescriptionContent types
200OK-