SBOM
Providers using this tag (21)
Ranked by API Evangelist rating — Exemplar and Strong are expanded by default.
Developing 4 Usable, with meaningful gaps to close
Thin 6 Limited public surface area
Minimal 4 Almost no public developer surface
APIs with this tag (16)
Ranked by the provider's API Evangelist rating — the Kin Score is scored per provider, not per API, so every API of a provider shares its band. How the rating works →
Exemplar 4 Complete, well-documented, and agent-ready
Harness SBOM APIThe SBOM API from Harness — 2 operation(s) for sbom.Harness Supply Chain Security APIAPIs for SBOM generation, artifact integrity verification, and policy enforcement for software supply chain...Snyk SBOM APIThe SBOM API from Snyk — 4 operation(s) for sbom.Palo Alto Networks SBOM APIThe SBOM API from Palo Alto Networks — 16 operation(s) for sbom.
Developing 4 Usable, with meaningful gaps to close
OrteliusOrtelius is an open source supply chain evidence store that aggregates continuous security intelligence acr...Dependency TrackSBOM upload to the University's Dependency Track instance from external networks. Public and running in the...Sysdig SBOM APISoftware Bill of Materials managementTrivyTrivy is a comprehensive open source security scanner for containers, Kubernetes, code repositories, clouds...
Thin 5 Limited public surface area
Anchore SBOM APIThe SBOM API from Anchore — 1 operation(s) for sbom.Finite State GraphQL APIGraphQL API historically documented at https://platform.finitestate.io/api/v1/graphql and still the transpo...Finite State Platform APIToken-authenticated REST API for the Finite State platform, served under /api/public/v0 on the platform hos...GUAC (Graph for Understanding Artifact Composition)GUAC aggregates software supply-chain security metadata (SBOMs, attestations, vulnerabilities, signatures) ...Manifest Cyber APIThe official public API for the Manifest Cyber platform v1. Used by Manifest's frontend apps and internal E...
Emerging 2 Early or largely undocumented
Minimal 1 Almost no public developer surface
Companies reaching this through an API (9)
These companies publish an API, specification or operation carrying “SBOM” but do not classify their business under it. Listed unranked and kept out of the count above, because one tagged operation is not a statement about what a company does.
Aqua Security
Continuous Delivery Foundation
Copa (Project Copacetic)
Harness
OpenSSF
Palo Alto Networks
Snyk
Sysdig
University of Helsinki
Score breakdown
Frequency
43.9
log-scaled weighted occurrences
Breadth
0.5
spread across providers
Quality lift
42.2
mean composite of providers using it
Cohesion
0.0
strength of nearest seed neighbor
Related tags
Software Composition Analysis 9 co-occurrences
Software Supply Chain 7 co-occurrences
DevSecOps 14 co-occurrences
Container Security 6 co-occurrences
Vulnerability Scanning 6 co-occurrences
Vulnerabilities 8 co-occurrences
Vulnerability Management 15 co-occurrences
Where this tag comes from
Provider tag21
Api tag16
Openapi tag4
Openapi op tag8
Work with this as data
Every tag here is available over the APIs.io API and to AI agents over MCP.