SBOM Diff
Compare two supported SBOMs by unique exact group/name (default) or versionless generic-PURL identity. Report added/removed components and version/license/hash/PURL/type changes. Duplicate identities are rejected rather than cross-paired. Reference IDs and source positions are ignored; license comparison is textual, not semantic.
supply-chain · Operation ID: sbom-diff
Choose this operation when
- Review deterministic component changes between two caller-supplied SBOMs
- Reject ambiguous duplicates instead of inventing version matches
Outside this profile
- License equivalence, transitive graph impact or vulnerability analysis
- Inventing matches across renamed packages, ecosystems or duplicate identities
Exact release references
Static JSON contract · Markdown reference · Fixed example response
Complete input schema
{
"$schema": "https://json-schema.org/draft/2020-12/schema",
"type": "object",
"properties": {
"before": {
"type": "object",
"propertyNames": {
"type": "string"
},
"additionalProperties": {},
"description": "JSON document: at most 100,000 UTF-8 serialized bytes per request, 12,000 nodes and 24 levels; consumed fields are type-checked; unconsumed fields are ignored, not standards-validated."
},
"after": {
"type": "object",
"propertyNames": {
"type": "string"
},
"additionalProperties": {},
"description": "JSON document: at most 100,000 UTF-8 serialized bytes per request, 12,000 nodes and 24 levels; consumed fields are type-checked; unconsumed fields are ignored, not standards-validated."
},
"matchBy": {
"default": "name",
"type": "string",
"enum": [
"name",
"purl"
]
}
},
"required": [
"before",
"after"
],
"additionalProperties": false
}
Complete output-envelope schema
{
"type": "object",
"required": [
"operation",
"version",
"result",
"provenance"
],
"properties": {
"operation": {
"const": "sbom-diff",
"type": "string"
},
"version": {
"const": "0.29.0",
"type": "string"
},
"result": {
"$schema": "https://json-schema.org/draft/2020-12/schema",
"type": "object",
"properties": {
"matchBy": {
"type": "string",
"enum": [
"name",
"purl"
]
},
"added": {
"maxItems": 500,
"type": "array",
"items": {
"type": "object",
"properties": {
"identity": {
"type": "string",
"maxLength": 12288
},
"component": {
"type": "object",
"properties": {
"sourcePointer": {
"type": "string",
"maxLength": 4096
},
"reference": {
"anyOf": [
{
"type": "string",
"maxLength": 2048
},
{
"type": "null"
}
]
},
"name": {
"type": "string",
"maxLength": 2048
},
"group": {
"anyOf": [
{
"type": "string",
"maxLength": 2048
},
{
"type": "null"
}
]
},
"version": {
"anyOf": [
{
"type": "string",
"maxLength": 2048
},
{
"type": "null"
}
]
},
"purl": {
"anyOf": [
{
"type": "string",
"maxLength": 4096
},
{
"type": "null"
}
]
},
"type": {
"anyOf": [
{
"type": "string",
"maxLength": 2048
},
{
"type": "null"
}
]
},
"licenses": {
"maxItems": 16,
"type": "array",
"items": {
"type": "object",
"properties": {
"kind": {
"type": "string",
"enum": [
"id",
"name",
"expression",
"declared",
"concluded"
]
},
"value": {
"type": "string",
"maxLength": 2048
}
},
"required": [
"kind",
"value"
],
"additionalProperties": false
}
},
"hashes": {
"maxItems": 16,
"type": "array",
"items": {
"type": "object",
"properties": {
"algorithm": {
"type": "string",
"maxLength": 100
},
"value": {
"type": "string",
"maxLength": 2048
}
},
"required": [
"algorithm",
"value"
],
"additionalProperties": false
}
}
},
"required": [
"sourcePointer",
"reference",
"name",
"group",
"version",
"purl",
"type",
"licenses",
"hashes"
],
"additionalProperties": false
}
},
"required": [
"identity",
"component"
],
"additionalProperties": false
}
},
"removed": {
"maxItems": 500,
"type": "array",
"items": {
"type": "object",
"properties": {
"identity": {
"type": "string",
"maxLength": 12288
},
"component": {
"type": "object",
"properties": {
"sourcePointer": {
"type": "string",
"maxLength": 4096
},
"reference": {
"anyOf": [
{
"type": "string",
"maxLength": 2048
},
{
"type": "null"
}
]
},
"name": {
"type": "string",
"maxLength": 2048
},
"group": {
"anyOf": [
{
"type": "string",
"maxLength": 2048
},
{
"type": "null"
}
]
},
"version": {
"anyOf": [
{
"type": "string",
"maxLength": 2048
},
{
"type": "null"
}
]
},
"purl": {
"anyOf": [
{
"type": "string",
"maxLength": 4096
},
{
"type": "null"
}
]
},
"type": {
"anyOf": [
{
"type": "string",
"maxLength": 2048
},
{
"type": "null"
}
]
},
"licenses": {
"maxItems": 16,
"type": "array",
"items": {
"type": "object",
"properties": {
"kind": {
"type": "string",
"enum": [
"id",
"name",
"expression",
"declared",
"concluded"
]
},
"value": {
"type": "string",
"maxLength": 2048
}
},
"required": [
"kind",
"value"
],
"additionalProperties": false
}
},
"hashes": {
"maxItems": 16,
"type": "array",
"items": {
"type": "object",
"properties": {
"algorithm": {
"type": "string",
"maxLength": 100
},
"value": {
"type": "string",
"maxLength": 2048
}
},
"required": [
"algorithm",
"value"
],
"additionalProperties": false
}
}
},
"required": [
"sourcePointer",
"reference",
"name",
"group",
"version",
"purl",
"type",
"licenses",
"hashes"
],
"additionalProperties": false
}
},
"required": [
"identity",
"component"
],
"additionalProperties": false
}
},
"changed": {
"maxItems": 500,
"type": "array",
"items": {
"type": "object",
"properties": {
"identity": {
"type": "string",
"maxLength": 12288
},
"fields": {
"maxItems": 5,
"type": "array",
"items": {
"type": "string",
"enum": [
"version",
"licenses",
"hashes",
"purl",
"type"
]
}
},
"before": {
"type": "object",
"properties": {
"sourcePointer": {
"type": "string",
"maxLength": 4096
},
"reference": {
"anyOf": [
{
"type": "string",
"maxLength": 2048
},
{
"type": "null"
}
]
},
"name": {
"type": "string",
"maxLength": 2048
},
"group": {
"anyOf": [
{
"type": "string",
"maxLength": 2048
},
{
"type": "null"
}
]
},
"version": {
"anyOf": [
{
"type": "string",
"maxLength": 2048
},
{
"type": "null"
}
]
},
"purl": {
"anyOf": [
{
"type": "string",
"maxLength": 4096
},
{
"type": "null"
}
]
},
"type": {
"anyOf": [
{
"type": "string",
"maxLength": 2048
},
{
"type": "null"
}
]
},
"licenses": {
"maxItems": 16,
"type": "array",
"items": {
"type": "object",
"properties": {
"kind": {
"type": "string",
"enum": [
"id",
"name",
"expression",
"declared",
"concluded"
]
},
"value": {
"type": "string",
"maxLength": 2048
}
},
"required": [
"kind",
"value"
],
"additionalProperties": false
}
},
"hashes": {
"maxItems": 16,
"type": "array",
"items": {
"type": "object",
"properties": {
"algorithm": {
"type": "string",
"maxLength": 100
},
"value": {
"type": "string",
"maxLength": 2048
}
},
"required": [
"algorithm",
"value"
],
"additionalProperties": false
}
}
},
"required": [
"sourcePointer",
"reference",
"name",
"group",
"version",
"purl",
"type",
"licenses",
"hashes"
],
"additionalProperties": false
},
"after": {
"type": "object",
"properties": {
"sourcePointer": {
"type": "string",
"maxLength": 4096
},
"reference": {
"anyOf": [
{
"type": "string",
"maxLength": 2048
},
{
"type": "null"
}
]
},
"name": {
"type": "string",
"maxLength": 2048
},
"group": {
"anyOf": [
{
"type": "string",
"maxLength": 2048
},
{
"type": "null"
}
]
},
"version": {
"anyOf": [
{
"type": "string",
"maxLength": 2048
},
{
"type": "null"
}
]
},
"purl": {
"anyOf": [
{
"type": "string",
"maxLength": 4096
},
{
"type": "null"
}
]
},
"type": {
"anyOf": [
{
"type": "string",
"maxLength": 2048
},
{
"type": "null"
}
]
},
"licenses": {
"maxItems": 16,
"type": "array",
"items": {
"type": "object",
"properties": {
"kind": {
"type": "string",
"enum": [
"id",
"name",
"expression",
"declared",
"concluded"
]
},
"value": {
"type": "string",
"maxLength": 2048
}
},
"required": [
"kind",
"value"
],
"additionalProperties": false
}
},
"hashes": {
"maxItems": 16,
"type": "array",
"items": {
"type": "object",
"properties": {
"algorithm": {
"type": "string",
"maxLength": 100
},
"value": {
"type": "string",
"maxLength": 2048
}
},
"required": [
"algorithm",
"value"
],
"additionalProperties": false
}
}
},
"required": [
"sourcePointer",
"reference",
"name",
"group",
"version",
"purl",
"type",
"licenses",
"hashes"
],
"additionalProperties": false
}
},
"required": [
"identity",
"fields",
"before",
"after"
],
"additionalProperties": false
}
},
"unchangedCount": {
"type": "integer",
"minimum": 0,
"maximum": 500
},
"scope": {
"type": "string",
"const": "Unique group/name or versionless generic-PURL identities only; reference IDs, ordering, and source positions are ignored. Duplicate identities are rejected, not guessed."
}
},
"required": [
"matchBy",
"added",
"removed",
"changed",
"unchangedCount",
"scope"
],
"additionalProperties": false
},
"provenance": {
"type": "object",
"required": [
"inputSha256",
"outputSha256",
"deterministic",
"externalRequests"
],
"properties": {
"inputSha256": {
"type": "string",
"pattern": "^[a-f0-9]{64}$"
},
"outputSha256": {
"type": "string",
"pattern": "^[a-f0-9]{64}$"
},
"deterministic": {
"const": true
},
"externalRequests": {
"const": 0
}
}
}
},
"additionalProperties": false
}
Fixed example
One accepted fixed example, not a custom-input trial. No operation runs when this static page is requested.
Example input
{
"before": {
"bomFormat": "CycloneDX",
"specVersion": "1.6",
"components": [
{
"type": "library",
"name": "worker-kit",
"version": "1.2.0",
"purl": "pkg:npm/worker-kit@1.2.0",
"licenses": [
{
"license": {
"id": "MIT"
}
}
]
}
]
},
"after": {
"bomFormat": "CycloneDX",
"specVersion": "1.6",
"components": [
{
"type": "library",
"name": "worker-kit",
"version": "1.3.0",
"purl": "pkg:npm/worker-kit@1.3.0",
"licenses": [
{
"license": {
"id": "MIT"
}
}
]
}
]
},
"matchBy": "name"
}
Example response
{
"operation": "sbom-diff",
"version": "0.29.0",
"result": {
"matchBy": "name",
"added": [],
"removed": [],
"changed": [
{
"identity": "[null,\"worker-kit\"]",
"fields": [
"version",
"purl"
],
"before": {
"sourcePointer": "/components/0",
"reference": null,
"name": "worker-kit",
"group": null,
"version": "1.2.0",
"purl": "pkg:npm/worker-kit@1.2.0",
"type": "library",
"licenses": [
{
"kind": "id",
"value": "MIT"
}
],
"hashes": []
},
"after": {
"sourcePointer": "/components/0",
"reference": null,
"name": "worker-kit",
"group": null,
"version": "1.3.0",
"purl": "pkg:npm/worker-kit@1.3.0",
"type": "library",
"licenses": [
{
"kind": "id",
"value": "MIT"
}
],
"hashes": []
}
}
],
"unchangedCount": 0,
"scope": "Unique group/name or versionless generic-PURL identities only; reference IDs, ordering, and source positions are ignored. Duplicate identities are rejected, not guessed."
},
"provenance": {
"inputSha256": "b19944d599f94ec8f81c15402bd893787a4e4bbb2eb0f5ae646264db8b31b8b2",
"outputSha256": "d267cc8407c56c634f70b48cbbdd55534cbeb8ea0c293a8e92a61b1b9e3e31d6",
"deterministic": true,
"externalRequests": 0
}
}
Bounds and precision
JavaScript IEEE-754 numbers; use strings for large integer IDs/exact decimals where the schema accepts strings. No lossless numeric parsing.
{
"global": {
"requestBytes": 131072,
"responseBytes": 524288,
"jsonDepth": 32,
"jsonNodes": 20000,
"requestsPerMinute": 60,
"paidAttemptsPerMinute": 20,
"idempotencyHours": 24
},
"operation": {
"inputBytes": 100000,
"jsonNodes": 12000,
"jsonDepth": 24,
"outputBytes": 300000,
"componentsPerDocument": 500,
"inputBytesSharedAcrossBothDocuments": 100000
}
}
Complete schemas, descriptions and cross-field validation may impose additional limits.
Proposed price and protocol definitions
{
"unit": "one successful operation call",
"proposedNominalUsd": "0.01",
"sixDecimalTokenBaseUnits": "10000",
"subscription": false,
"includesPayerWalletOrNetworkFees": false,
"liveQuoteVerified": false,
"condition": "Actual SDK challenge is authoritative only within the caller's explicit authorization; configured six-decimal token peg is an operator assertion, not a conversion guarantee."
}
Protocol definitions: x402, mpp. MPP uses Tempo charge. Paid MCP execution is unsupported. All runtime readiness is not evaluated in this build.
API path templates, not endpoints on this documentation host
{
"x402": "/v1/x402/sbom-diff",
"mpp": "/v1/mpp/sbom-diff"
}
Required headers
{
"Content-Type": "application/json",
"Idempotency-Key": "random 16–128 character operation identifier"
}
Actual SDK challenge amount, asset, network, recipient and wallet costs must pass independent authorization. Preserve identical key, body, protocol and credential on retries; on PAYMENT_UNCERTAIN stop and reconcile.
Execution profile and provider conditions
{
"deterministic": true,
"externalRequests": 0,
"maxExternalRequests": 0,
"resultSnapshotPersisted": false,
"fixedExampleIsIllustrativeSnapshot": false,
"requiresPayment": true,
"supportsMcpExecution": false
}
Deterministic supplied-input operation with no external requests or stored request/result bodies. Payment infrastructure retains payment metadata and hashes.
Failure handling
- HTTP 400: Malformed JSON, missing/invalid idempotency key, or payment identifier mismatch Correct the request before payment
- HTTP 402: Payment challenge or rejected payment Use official protocol SDK; inspect payment outcome before another payment
- HTTP 409: Idempotency conflict, duplicate proof, or PAYMENT_UNCERTAIN Keep original key, body, and proof; reconcile uncertainty with operator; never blindly repay
- HTTP 413: Input or generated output too large Reduce input; no payment attempted for validation failure
- HTTP 415: Unsupported media type or compression Send uncompressed application/json
- HTTP 422: Schema or service-specific semantic validation failure Correct input using returned error code; no payment attempted
- HTTP 429: Request/payment-attempt rate exceeded Wait for rate limit window; preserve existing payment identity
- HTTP 503: Payment configuration/provider/state unavailable, or live DNS preparation failed before settlement Check readiness; DNS preparation failures may retry the identical key/body/credential only; uncertainty requires reconciliation
Declared requirements
Before any paid call, refresh the live operation contract and POST the complete bounded budgeted plan to the separate API's /preflight. Unknown requirements block selection; compatible preflight is not permission to spend.