Browse operation contracts · Static machine index · OpenAPI release reference · Build manifest

SBOM Diff

Compare two supported SBOMs by unique exact group/name (default) or versionless generic-PURL identity. Report added/removed components and version/license/hash/PURL/type changes. Duplicate identities are rejected rather than cross-paired. Reference IDs and source positions are ignored; license comparison is textual, not semantic.

supply-chain · Operation ID: sbom-diff

Choose this operation when

Outside this profile

Exact release references

Static JSON contract · Markdown reference · Fixed example response

Complete input schema

{
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "type": "object",
  "properties": {
    "before": {
      "type": "object",
      "propertyNames": {
        "type": "string"
      },
      "additionalProperties": {},
      "description": "JSON document: at most 100,000 UTF-8 serialized bytes per request, 12,000 nodes and 24 levels; consumed fields are type-checked; unconsumed fields are ignored, not standards-validated."
    },
    "after": {
      "type": "object",
      "propertyNames": {
        "type": "string"
      },
      "additionalProperties": {},
      "description": "JSON document: at most 100,000 UTF-8 serialized bytes per request, 12,000 nodes and 24 levels; consumed fields are type-checked; unconsumed fields are ignored, not standards-validated."
    },
    "matchBy": {
      "default": "name",
      "type": "string",
      "enum": [
        "name",
        "purl"
      ]
    }
  },
  "required": [
    "before",
    "after"
  ],
  "additionalProperties": false
}

Complete output-envelope schema

{
  "type": "object",
  "required": [
    "operation",
    "version",
    "result",
    "provenance"
  ],
  "properties": {
    "operation": {
      "const": "sbom-diff",
      "type": "string"
    },
    "version": {
      "const": "0.29.0",
      "type": "string"
    },
    "result": {
      "$schema": "https://json-schema.org/draft/2020-12/schema",
      "type": "object",
      "properties": {
        "matchBy": {
          "type": "string",
          "enum": [
            "name",
            "purl"
          ]
        },
        "added": {
          "maxItems": 500,
          "type": "array",
          "items": {
            "type": "object",
            "properties": {
              "identity": {
                "type": "string",
                "maxLength": 12288
              },
              "component": {
                "type": "object",
                "properties": {
                  "sourcePointer": {
                    "type": "string",
                    "maxLength": 4096
                  },
                  "reference": {
                    "anyOf": [
                      {
                        "type": "string",
                        "maxLength": 2048
                      },
                      {
                        "type": "null"
                      }
                    ]
                  },
                  "name": {
                    "type": "string",
                    "maxLength": 2048
                  },
                  "group": {
                    "anyOf": [
                      {
                        "type": "string",
                        "maxLength": 2048
                      },
                      {
                        "type": "null"
                      }
                    ]
                  },
                  "version": {
                    "anyOf": [
                      {
                        "type": "string",
                        "maxLength": 2048
                      },
                      {
                        "type": "null"
                      }
                    ]
                  },
                  "purl": {
                    "anyOf": [
                      {
                        "type": "string",
                        "maxLength": 4096
                      },
                      {
                        "type": "null"
                      }
                    ]
                  },
                  "type": {
                    "anyOf": [
                      {
                        "type": "string",
                        "maxLength": 2048
                      },
                      {
                        "type": "null"
                      }
                    ]
                  },
                  "licenses": {
                    "maxItems": 16,
                    "type": "array",
                    "items": {
                      "type": "object",
                      "properties": {
                        "kind": {
                          "type": "string",
                          "enum": [
                            "id",
                            "name",
                            "expression",
                            "declared",
                            "concluded"
                          ]
                        },
                        "value": {
                          "type": "string",
                          "maxLength": 2048
                        }
                      },
                      "required": [
                        "kind",
                        "value"
                      ],
                      "additionalProperties": false
                    }
                  },
                  "hashes": {
                    "maxItems": 16,
                    "type": "array",
                    "items": {
                      "type": "object",
                      "properties": {
                        "algorithm": {
                          "type": "string",
                          "maxLength": 100
                        },
                        "value": {
                          "type": "string",
                          "maxLength": 2048
                        }
                      },
                      "required": [
                        "algorithm",
                        "value"
                      ],
                      "additionalProperties": false
                    }
                  }
                },
                "required": [
                  "sourcePointer",
                  "reference",
                  "name",
                  "group",
                  "version",
                  "purl",
                  "type",
                  "licenses",
                  "hashes"
                ],
                "additionalProperties": false
              }
            },
            "required": [
              "identity",
              "component"
            ],
            "additionalProperties": false
          }
        },
        "removed": {
          "maxItems": 500,
          "type": "array",
          "items": {
            "type": "object",
            "properties": {
              "identity": {
                "type": "string",
                "maxLength": 12288
              },
              "component": {
                "type": "object",
                "properties": {
                  "sourcePointer": {
                    "type": "string",
                    "maxLength": 4096
                  },
                  "reference": {
                    "anyOf": [
                      {
                        "type": "string",
                        "maxLength": 2048
                      },
                      {
                        "type": "null"
                      }
                    ]
                  },
                  "name": {
                    "type": "string",
                    "maxLength": 2048
                  },
                  "group": {
                    "anyOf": [
                      {
                        "type": "string",
                        "maxLength": 2048
                      },
                      {
                        "type": "null"
                      }
                    ]
                  },
                  "version": {
                    "anyOf": [
                      {
                        "type": "string",
                        "maxLength": 2048
                      },
                      {
                        "type": "null"
                      }
                    ]
                  },
                  "purl": {
                    "anyOf": [
                      {
                        "type": "string",
                        "maxLength": 4096
                      },
                      {
                        "type": "null"
                      }
                    ]
                  },
                  "type": {
                    "anyOf": [
                      {
                        "type": "string",
                        "maxLength": 2048
                      },
                      {
                        "type": "null"
                      }
                    ]
                  },
                  "licenses": {
                    "maxItems": 16,
                    "type": "array",
                    "items": {
                      "type": "object",
                      "properties": {
                        "kind": {
                          "type": "string",
                          "enum": [
                            "id",
                            "name",
                            "expression",
                            "declared",
                            "concluded"
                          ]
                        },
                        "value": {
                          "type": "string",
                          "maxLength": 2048
                        }
                      },
                      "required": [
                        "kind",
                        "value"
                      ],
                      "additionalProperties": false
                    }
                  },
                  "hashes": {
                    "maxItems": 16,
                    "type": "array",
                    "items": {
                      "type": "object",
                      "properties": {
                        "algorithm": {
                          "type": "string",
                          "maxLength": 100
                        },
                        "value": {
                          "type": "string",
                          "maxLength": 2048
                        }
                      },
                      "required": [
                        "algorithm",
                        "value"
                      ],
                      "additionalProperties": false
                    }
                  }
                },
                "required": [
                  "sourcePointer",
                  "reference",
                  "name",
                  "group",
                  "version",
                  "purl",
                  "type",
                  "licenses",
                  "hashes"
                ],
                "additionalProperties": false
              }
            },
            "required": [
              "identity",
              "component"
            ],
            "additionalProperties": false
          }
        },
        "changed": {
          "maxItems": 500,
          "type": "array",
          "items": {
            "type": "object",
            "properties": {
              "identity": {
                "type": "string",
                "maxLength": 12288
              },
              "fields": {
                "maxItems": 5,
                "type": "array",
                "items": {
                  "type": "string",
                  "enum": [
                    "version",
                    "licenses",
                    "hashes",
                    "purl",
                    "type"
                  ]
                }
              },
              "before": {
                "type": "object",
                "properties": {
                  "sourcePointer": {
                    "type": "string",
                    "maxLength": 4096
                  },
                  "reference": {
                    "anyOf": [
                      {
                        "type": "string",
                        "maxLength": 2048
                      },
                      {
                        "type": "null"
                      }
                    ]
                  },
                  "name": {
                    "type": "string",
                    "maxLength": 2048
                  },
                  "group": {
                    "anyOf": [
                      {
                        "type": "string",
                        "maxLength": 2048
                      },
                      {
                        "type": "null"
                      }
                    ]
                  },
                  "version": {
                    "anyOf": [
                      {
                        "type": "string",
                        "maxLength": 2048
                      },
                      {
                        "type": "null"
                      }
                    ]
                  },
                  "purl": {
                    "anyOf": [
                      {
                        "type": "string",
                        "maxLength": 4096
                      },
                      {
                        "type": "null"
                      }
                    ]
                  },
                  "type": {
                    "anyOf": [
                      {
                        "type": "string",
                        "maxLength": 2048
                      },
                      {
                        "type": "null"
                      }
                    ]
                  },
                  "licenses": {
                    "maxItems": 16,
                    "type": "array",
                    "items": {
                      "type": "object",
                      "properties": {
                        "kind": {
                          "type": "string",
                          "enum": [
                            "id",
                            "name",
                            "expression",
                            "declared",
                            "concluded"
                          ]
                        },
                        "value": {
                          "type": "string",
                          "maxLength": 2048
                        }
                      },
                      "required": [
                        "kind",
                        "value"
                      ],
                      "additionalProperties": false
                    }
                  },
                  "hashes": {
                    "maxItems": 16,
                    "type": "array",
                    "items": {
                      "type": "object",
                      "properties": {
                        "algorithm": {
                          "type": "string",
                          "maxLength": 100
                        },
                        "value": {
                          "type": "string",
                          "maxLength": 2048
                        }
                      },
                      "required": [
                        "algorithm",
                        "value"
                      ],
                      "additionalProperties": false
                    }
                  }
                },
                "required": [
                  "sourcePointer",
                  "reference",
                  "name",
                  "group",
                  "version",
                  "purl",
                  "type",
                  "licenses",
                  "hashes"
                ],
                "additionalProperties": false
              },
              "after": {
                "type": "object",
                "properties": {
                  "sourcePointer": {
                    "type": "string",
                    "maxLength": 4096
                  },
                  "reference": {
                    "anyOf": [
                      {
                        "type": "string",
                        "maxLength": 2048
                      },
                      {
                        "type": "null"
                      }
                    ]
                  },
                  "name": {
                    "type": "string",
                    "maxLength": 2048
                  },
                  "group": {
                    "anyOf": [
                      {
                        "type": "string",
                        "maxLength": 2048
                      },
                      {
                        "type": "null"
                      }
                    ]
                  },
                  "version": {
                    "anyOf": [
                      {
                        "type": "string",
                        "maxLength": 2048
                      },
                      {
                        "type": "null"
                      }
                    ]
                  },
                  "purl": {
                    "anyOf": [
                      {
                        "type": "string",
                        "maxLength": 4096
                      },
                      {
                        "type": "null"
                      }
                    ]
                  },
                  "type": {
                    "anyOf": [
                      {
                        "type": "string",
                        "maxLength": 2048
                      },
                      {
                        "type": "null"
                      }
                    ]
                  },
                  "licenses": {
                    "maxItems": 16,
                    "type": "array",
                    "items": {
                      "type": "object",
                      "properties": {
                        "kind": {
                          "type": "string",
                          "enum": [
                            "id",
                            "name",
                            "expression",
                            "declared",
                            "concluded"
                          ]
                        },
                        "value": {
                          "type": "string",
                          "maxLength": 2048
                        }
                      },
                      "required": [
                        "kind",
                        "value"
                      ],
                      "additionalProperties": false
                    }
                  },
                  "hashes": {
                    "maxItems": 16,
                    "type": "array",
                    "items": {
                      "type": "object",
                      "properties": {
                        "algorithm": {
                          "type": "string",
                          "maxLength": 100
                        },
                        "value": {
                          "type": "string",
                          "maxLength": 2048
                        }
                      },
                      "required": [
                        "algorithm",
                        "value"
                      ],
                      "additionalProperties": false
                    }
                  }
                },
                "required": [
                  "sourcePointer",
                  "reference",
                  "name",
                  "group",
                  "version",
                  "purl",
                  "type",
                  "licenses",
                  "hashes"
                ],
                "additionalProperties": false
              }
            },
            "required": [
              "identity",
              "fields",
              "before",
              "after"
            ],
            "additionalProperties": false
          }
        },
        "unchangedCount": {
          "type": "integer",
          "minimum": 0,
          "maximum": 500
        },
        "scope": {
          "type": "string",
          "const": "Unique group/name or versionless generic-PURL identities only; reference IDs, ordering, and source positions are ignored. Duplicate identities are rejected, not guessed."
        }
      },
      "required": [
        "matchBy",
        "added",
        "removed",
        "changed",
        "unchangedCount",
        "scope"
      ],
      "additionalProperties": false
    },
    "provenance": {
      "type": "object",
      "required": [
        "inputSha256",
        "outputSha256",
        "deterministic",
        "externalRequests"
      ],
      "properties": {
        "inputSha256": {
          "type": "string",
          "pattern": "^[a-f0-9]{64}$"
        },
        "outputSha256": {
          "type": "string",
          "pattern": "^[a-f0-9]{64}$"
        },
        "deterministic": {
          "const": true
        },
        "externalRequests": {
          "const": 0
        }
      }
    }
  },
  "additionalProperties": false
}

Fixed example

One accepted fixed example, not a custom-input trial. No operation runs when this static page is requested.

Example input

{
  "before": {
    "bomFormat": "CycloneDX",
    "specVersion": "1.6",
    "components": [
      {
        "type": "library",
        "name": "worker-kit",
        "version": "1.2.0",
        "purl": "pkg:npm/worker-kit@1.2.0",
        "licenses": [
          {
            "license": {
              "id": "MIT"
            }
          }
        ]
      }
    ]
  },
  "after": {
    "bomFormat": "CycloneDX",
    "specVersion": "1.6",
    "components": [
      {
        "type": "library",
        "name": "worker-kit",
        "version": "1.3.0",
        "purl": "pkg:npm/worker-kit@1.3.0",
        "licenses": [
          {
            "license": {
              "id": "MIT"
            }
          }
        ]
      }
    ]
  },
  "matchBy": "name"
}

Example response

{
  "operation": "sbom-diff",
  "version": "0.29.0",
  "result": {
    "matchBy": "name",
    "added": [],
    "removed": [],
    "changed": [
      {
        "identity": "[null,\"worker-kit\"]",
        "fields": [
          "version",
          "purl"
        ],
        "before": {
          "sourcePointer": "/components/0",
          "reference": null,
          "name": "worker-kit",
          "group": null,
          "version": "1.2.0",
          "purl": "pkg:npm/worker-kit@1.2.0",
          "type": "library",
          "licenses": [
            {
              "kind": "id",
              "value": "MIT"
            }
          ],
          "hashes": []
        },
        "after": {
          "sourcePointer": "/components/0",
          "reference": null,
          "name": "worker-kit",
          "group": null,
          "version": "1.3.0",
          "purl": "pkg:npm/worker-kit@1.3.0",
          "type": "library",
          "licenses": [
            {
              "kind": "id",
              "value": "MIT"
            }
          ],
          "hashes": []
        }
      }
    ],
    "unchangedCount": 0,
    "scope": "Unique group/name or versionless generic-PURL identities only; reference IDs, ordering, and source positions are ignored. Duplicate identities are rejected, not guessed."
  },
  "provenance": {
    "inputSha256": "b19944d599f94ec8f81c15402bd893787a4e4bbb2eb0f5ae646264db8b31b8b2",
    "outputSha256": "d267cc8407c56c634f70b48cbbdd55534cbeb8ea0c293a8e92a61b1b9e3e31d6",
    "deterministic": true,
    "externalRequests": 0
  }
}

Bounds and precision

JavaScript IEEE-754 numbers; use strings for large integer IDs/exact decimals where the schema accepts strings. No lossless numeric parsing.

{
  "global": {
    "requestBytes": 131072,
    "responseBytes": 524288,
    "jsonDepth": 32,
    "jsonNodes": 20000,
    "requestsPerMinute": 60,
    "paidAttemptsPerMinute": 20,
    "idempotencyHours": 24
  },
  "operation": {
    "inputBytes": 100000,
    "jsonNodes": 12000,
    "jsonDepth": 24,
    "outputBytes": 300000,
    "componentsPerDocument": 500,
    "inputBytesSharedAcrossBothDocuments": 100000
  }
}

Complete schemas, descriptions and cross-field validation may impose additional limits.

Proposed price and protocol definitions

{
  "unit": "one successful operation call",
  "proposedNominalUsd": "0.01",
  "sixDecimalTokenBaseUnits": "10000",
  "subscription": false,
  "includesPayerWalletOrNetworkFees": false,
  "liveQuoteVerified": false,
  "condition": "Actual SDK challenge is authoritative only within the caller's explicit authorization; configured six-decimal token peg is an operator assertion, not a conversion guarantee."
}

Protocol definitions: x402, mpp. MPP uses Tempo charge. Paid MCP execution is unsupported. All runtime readiness is not evaluated in this build.

API path templates, not endpoints on this documentation host

{
  "x402": "/v1/x402/sbom-diff",
  "mpp": "/v1/mpp/sbom-diff"
}

Required headers

{
  "Content-Type": "application/json",
  "Idempotency-Key": "random 16–128 character operation identifier"
}

Actual SDK challenge amount, asset, network, recipient and wallet costs must pass independent authorization. Preserve identical key, body, protocol and credential on retries; on PAYMENT_UNCERTAIN stop and reconcile.

Execution profile and provider conditions

{
  "deterministic": true,
  "externalRequests": 0,
  "maxExternalRequests": 0,
  "resultSnapshotPersisted": false,
  "fixedExampleIsIllustrativeSnapshot": false,
  "requiresPayment": true,
  "supportsMcpExecution": false
}

Deterministic supplied-input operation with no external requests or stored request/result bodies. Payment infrastructure retains payment metadata and hashes.

Failure handling

Declared requirements

Before any paid call, refresh the live operation contract and POST the complete bounded budgeted plan to the separate API's /preflight. Unknown requirements block selection; compatible preflight is not permission to spend.

Related contracts