Create a snapshot of dependencies for a repository
Create a new snapshot of a repository’s dependencies.
The authenticated user must have access to the repository.
OAuth app tokens and personal access tokens (classic) need the repo scope to use this endpoint.
Parameters
Section titled “ Parameters ”Path Parameters
Section titled “ Path Parameters ”The account owner of the repository. The name is not case sensitive.
The name of the repository without the .git extension. The name is not case sensitive.
Request Body required
Section titled “ Request Body required ”Create a new snapshot of a repository’s dependencies.
object
The version of the repository snapshot submission.
object
The external ID of the job.
Correlator provides a key that is used to group snapshots submitted over time. Only the “latest” submitted snapshot for a given combination of job.correlator and detector.name will be considered when calculating a repository’s current dependencies. Correlator should be as unique as it takes to distinguish all detection runs for a given “wave” of CI workflow you run. If you’re using GitHub Actions, a good default value for this could be the environment variables GITHUB_WORKFLOW and GITHUB_JOB concatenated together. If you’re using a build matrix, then you’ll also need to add additional key(s) to distinguish between each submission inside a matrix variation.
The url for the job.
The commit SHA associated with this dependency snapshot. Maximum length: 40 characters.
The repository branch that triggered this snapshot.
A description of the detector used.
object
The name of the detector used.
The version of the detector used.
The url of the detector used.
A collection of package manifests, which are a collection of related dependencies declared in a file or representing a logical group of dependencies.
object
object
The name of the manifest.
object
The path of the manifest file relative to the root of the Git repository.
A collection of resolved package dependencies.
object
object
Package-url (PURL) of dependency. See https://github.com/package-url/purl-spec for more details.
A notation of whether a dependency is requested directly by this manifest or is a dependency of another dependency.
A notation of whether the dependency is required for the primary build artifact (runtime) or is only used for development. Future versions of this specification may allow for more granular scopes.
Array of package-url (PURLs) of direct child dependencies.
The time at which the snapshot was scanned.
Examples
{ "version": 0, "sha": "ce587453ced02b1526dfb4cb910479d431683101", "ref": "refs/heads/main", "job": { "correlator": "yourworkflowname_youractionname", "id": "yourrunid" }, "detector": { "name": "octo-detector", "version": "0.0.1", "url": "https://github.com/octo-org/octo-repo" }, "scanned": "2022-06-14T20:25:00Z", "manifests": { "package-lock.json": { "name": "package-lock.json", "file": { "source_location": "src/package-lock.json" }, "resolved": { "@actions/core": { "package_url": "pkg:/npm/%40actions/core@1.1.9", "dependencies": [ "@actions/http-client" ] }, "@actions/http-client": { "package_url": "pkg:/npm/%40actions/http-client@1.0.7", "dependencies": [ "tunnel" ] }, "tunnel": { "package_url": "pkg:/npm/tunnel@0.0.6" } } } }}Responses
Section titled “ Responses ”Response
object
ID of the created snapshot.
The time at which the snapshot was created.
Either “SUCCESS”, “ACCEPTED”, or “INVALID”. “SUCCESS” indicates that the snapshot was successfully created and the repository’s dependencies were updated. “ACCEPTED” indicates that the snapshot was successfully created, but the repository’s dependencies were not updated. “INVALID” indicates that the snapshot was malformed.
A message providing further details about the result, such as why the dependencies were not updated.
Examples
{ "id": 12345, "created_at": "2018-05-04T01:14:52Z", "message": "Dependency results for the repo have been successfully updated.", "result": "SUCCESS"}