SBOM
Providers using this tag (22)
Ranked by API Evangelist rating — Exemplar and Strong are expanded by default.
Developing 7 Usable, with meaningful gaps to close
Thin 6 Limited public surface area
Emerging 5 Early or largely undocumented
Minimal 2 Almost no public developer surface
APIs with this tag (27)
Ranked by the provider's API Evangelist rating — the Kin Score is scored per provider, not per API, so every API of a provider shares its band. How the rating works →
Exemplar 3 Complete, well-documented, and agent-ready
Developing 17 Usable, with meaningful gaps to close
Dependency TrackSBOM upload to the University's Dependency Track instance from external networks. Public and running in the...CloudGuard Identity APIIAM Safe identity protection - lease-based elevation of IAM entities and the identity surface CloudGuard us...CloudGuard Inventory - AWS Application Integration APIAWS application-integration inventory - SNS topics, SQS queues and related messaging services.CloudGuard Inventory - AWS Global APIGlobal AWS inventory entities - organizational units, regions and account-wide objects CloudGuard fetches f...CloudGuard Inventory - AWS IAM APIAWS IAM inventory - users, roles, policies, virtual MFA devices and credential objects CloudGuard fetches f...CloudGuard Inventory - AWS Machine Learning APIAWS machine-learning inventory - SageMaker resources CloudGuard tracks as protected assets.CloudGuard Inventory - AWS Management Tools APIAWS management-tooling inventory - AWS Config settings, CloudTrail and related governance services.CloudGuard Inventory - AWS Networking and Content Delivery APIAWS networking inventory - VPCs, subnets, route tables, load balancers, Route 53 domains and CloudFront dis...CloudGuard Inventory - AWS Security, Identity and Compliance APIAWS security-service inventory - KMS keys, Secrets Manager and related security services as CloudGuard prot...CloudGuard Inventory - AWS Storage APIAWS storage inventory - S3 buckets, EBS volumes and backup vaults as CloudGuard protected assets.CloudGuard Inventory - GCP APIGoogle Cloud inventory - networks, Pub/Sub topics, compute, storage and IAM objects CloudGuard fetches from...CloudGuard Inventory - OCI APIOracle Cloud Infrastructure inventory - compartments and OCI resources CloudGuard fetches from onboarded OC...CloudGuard Inventory APICross-cloud protected-asset inventory - entity reports and the generic inventory surface CloudGuard exposes...OrteliusOrtelius is an open source supply chain evidence store that aggregates continuous security intelligence acr...Sysdig SBOM APISoftware Bill of Materials managementTrivyTrivy is a comprehensive open source security scanner for containers, Kubernetes, code repositories, clouds...Anchore SBOM APIThe SBOM API from Anchore — 1 operation(s) for sbom.
Thin 4 Limited public surface area
Finite State GraphQL APIGraphQL API historically documented at https://platform.finitestate.io/api/v1/graphql and still the transpo...Finite State Platform APIToken-authenticated REST API for the Finite State platform, served under /api/public/v0 on the platform hos...GUAC (Graph for Understanding Artifact Composition)GUAC aggregates software supply-chain security metadata (SBOMs, attestations, vulnerabilities, signatures) ...Manifest Cyber APIThe official public API for the Manifest Cyber platform v1. Used by Manifest's frontend apps and internal E...
Emerging 3 Early or largely undocumented
Copa VEX OutputCopa can emit a Vulnerability Exchange (VEX) document describing which CVEs were patched. VEX documents hel...GrypeGrype is an open source vulnerability scanner for container images and filesystems developed by Anchore. It...SPDX APIAPI for accessing SPDX open standard resources for software bill of materials, license compliance, and soft...
Companies reaching this through an API (10)
These companies publish an API, specification or operation carrying “SBOM” but do not classify their business under it. Listed unranked and kept out of the count above, because one tagged operation is not a statement about what a company does.
Aqua Security
CloudGuard
Continuous Delivery Foundation
Copa (Project Copacetic)
Harness
OpenSSF
Palo Alto Networks
Snyk
Sysdig
University of Helsinki
Score breakdown
Frequency
47.0
log-scaled weighted occurrences
Breadth
0.6
spread across providers
Quality lift
38.0
mean composite of providers using it
Cohesion
0.0
strength of nearest seed neighbor
Related tags
Software Composition Analysis 10 co-occurrences
Software Supply Chain 7 co-occurrences
Container Security 7 co-occurrences
DevSecOps 14 co-occurrences
Vulnerabilities 8 co-occurrences
Vulnerability Scanning 6 co-occurrences
Vulnerability Management 15 co-occurrences
Supply Chain Security 5 co-occurrences
Where this tag comes from
Provider tag22
Api tag15
Openapi tag16
Openapi op tag22
Work with this as data
Every tag here is available over the APIs.io API and to AI agents over MCP.