Integrate with Sonatype Guide
Integrate with Sonatype Guide
Sonatype Guide API
The Sonatype Guide API lets you access Sonatype’s component intelligence and security data through a simple, REST-based interface. Built on the proven OSS Index foundation, it provides a familiar yet more powerful way to access Sonatype’s open-source insights.
You can use the API to integrate Sonatype’s intelligence into your tools and workflows, enabling automated security checks and component insights directly within your development environment.
Use the API to perform actions like the following:
- Search for open-source components and filter results by ecosystem, license, or security attributes.
- Retrieve detailed vulnerability information, including severity, CVSS scores, and affected ecosystems.
- Perform a unified global search across components and vulnerabilities.
- Request version recommendations to identify secure, up-to-date dependency options.
Common Use Cases
You can use the Sonatype Guide API to extend Sonatype’s open-source intelligence beyond the Guide UI and into your development and automation workflows.
- Integrate with CI/CD pipelines – Automate component and vulnerability checks as part of your build process.
- Support custom automation and tooling – Embed component and vulnerability lookups directly into your organization’s developer tools, chatbots, or issue trackers for real-time insights during development.
- Enhancing IDE or AI assistant integrations – Connect IDE extensions or AI assistants to Guide’s APIs for on-demand component intelligence and upgrade recommendations.
For detailed parameter lists and response schemas, see the API Documentation tab within the Sonatype API section of the Guide user interface.
Search results
No results found