IQ API Reference

IQ API Reference

Use the Swagger API reference for Sonatype IQ Server-powered solutions, including Sonatype Lifecycle, Sonatype Developer, Sonatype SBOM Manager, and Sonatype Firewall.

Sonatype Lifecycle Public REST API 1.205.0-03 OAS 3.0

https://sonatype.github.io/sonatype-documentation/api/iq/latest/iq-api.json

Advanced Search

Use the Advanced Search REST API to perform searches on Lifecycle application scan reports.

Application Categories

Use the Application Categories REST API to manage the application categories or tags assigned to the applications in an organization.

Application Report Data

Use this REST API to retrieve the data from an application composition report, that is generated after an evaluation.

Applications

Use this REST API to manage applications. In addition to the primary functions of create, update and delete, you can also move applications from one organization to other.

Audit Logs

Use this REST API to access the IQ Server audit logs.

Auto Policy Waiver Exclusions

Use this REST API to create and delete auto policy waiver exclusions.

Auto Policy Waivers

Use this REST API to create, modify and retrieve auto policy waivers.

CI Configuration

Use this REST API to manage CI integration configuration. Configurations can be set at organization or application level and are merged from the organization hierarchy with lower levels taking precedence.

Claim Components

Use this REST API to manage components that are developed in-house and are not open-source. Claiming the component stores the identity information for the component hash and avoids triggering the Component-Unknown policy. Components will have a match state as Exact and Identification Source as Manual, for subsequent scans or evaluations.

Component Labels

Use this REST API to manage component labels for applications, organizations and repositories. Component Labels can be used as attributes of a component at the time of creating policies. A policy violation can be triggered based on the component label.

Component Search

Use this REST API to search for components in application evaluation reports.

Components

Use this REST API to retrieve a component's security vulnerability data, license data, age and popularity.

Composite Source Control

Use this REST API to access the composite source control management configuration (SCM) for an application or organization. Composite source control configuration is defined as the configuration that is inherited from the parent organization or is directly assigned.

Composite Source Control Validator

Use this REST API to validate the composite source control management (SCM) configuration. Composite source control configuration is defined as the configuration that is inherited from the parent or is directly assigned.

Config Crowd

Use this REST API to manage the configuration of an existing Atlassian Crowd Server that is being used to authenticate users for IQ Server.

Config Jira

Use this REST API to manage Jira configurations to receive notifications from Lifecycle. It is supported for Jira Cloud, Jira Server, and Jira Data Center.

Config Mail

Use this REST API to manage the configuration of an SMTP server, to receive email notifications.

Config OIDC

Use this REST API to manage the OIDC configuration for IQ Server.

Config Proxy Server

Use this REST API to manage the configuration of IQ Server with an existing HTTP proxy server.

Config Reverse Proxy Authentication

Use this REST API to manage the configuration of a reverse proxy server.

Config SAML

Use this REST API to manage the SAML configuration for IQ Server.

Config Source Control

Use this REST API to manage the configuration of IQ Server with your Source Control Management (SCM) system (e.g. GitHub).

Configuration

Use this REST API to configure the IQ Server system properties. We strongly recommend using this REST API instead of config.yml for versions 142 and higher.

Configure Artifactory Connection

Use this REST API to manage the configuration of Firewall for JFrog Artifactory.

Consumption

CPE Matching Configuration

Use the CPE Matching Configuration REST API to add/set/remove cpe matching configuration to organizations and applications

CycloneDX

Use the CycloneDX REST API to generate CycloneDX SBOMs in XML or JSON formats, containing coordinates and licenses for components found in a scan report.

Data Retention Policies

Set policies for automatic purging of obsolete application and Success Metrics reports. Note that IQ Server has a preset limit of purging 5000 reports in one execution of its report purging job.

Developer Priorities

Use this REST API to export Sonatype Developer component priorities data, including security reachability data.

Endpoints

This REST API returns the OpenAPI documentation for the specified IQ Server REST API.

Feature Configuration

Use this REST API to enable/disable the IQ Server features.

Firewall

Use this REST API for managing and monitoring firewall features, including metrics, repository management, quarantine operations, and namespace confusion prevention.

GitHub App

GitHub App Configuration

GitHub App configuration operations

Legacy Violations

Use this REST API to list, grant, and revoke legacy status for policy violations of an application.

Legacy Violations Configuration

Use this REST API to view and update legacy-violation configuration for an application or organization.

License Legal Metadata Report

Use this REST API to retrieve license legal metadata in raw or HTML format.

License Legal Metadata Template

Use this REST API to manage and customize templates for the license legal metadata generated in HTML format.

License Overrides

Use this REST API to manage license overrides for components in your applications organizations and repositories.

Organizations

Use this REST API to create new organizations, retrieve, edit or delete existing organizations.

Policies

Use this REST API to retrieve details on all existing policies in your instance of Lifecycle.

Policy Evaluation

Use this REST API to perform an application policy evaluation. Policy evaluations are executed asynchronously. This is a 2-step process that involves:

  1. Requesting a policy evaluation (POST)
  2. Checking the status and response of the evaluation request (GET)

Policy Export

Export policy configurations for organizations, applications, and repositories

Policy Violation Details

Use this REST API to obtain the violation details, violation details across stages (cross stage), violations occurring due to transitive dependencies and all waivers applicable to a violation. Cross-stage policy violations are helpful in performance analysis like MTTR metrics.

Policy Waiver Reasons

Use this rest API to fetch available policy waiver reasons

Policy Waiver Requests

Use this REST API to manage policy waiver requests.

Policy Waivers

Use this REST API to create and retrieve policy waivers.

Product License

Use this REST API to manage a product license.

Reachability Evidence

Use this REST API to retrieve reachability evidence showing call paths to vulnerable methods.

Reports

Use this REST API to view application scan reports, generate a list of stale waivers, view existing policy waivers on components, view quarantined components and retrieve additional metrics data.

Repositories

Use this REST API to manage quarantined components.

Role Memberships

Use this REST API to manage authorizations for users or user groups. You can view existing role assignments and grant or revoke user authorization on organizations, applications and repositories.

Roles

Roles provide sets of permissions that grant access to the functionality in the user interface, through integrations, and when using REST APIs. Permissions are granted by assigning users or groups to the system roles or at the various levels in the organizational hierarchy: root organization, repository managers, and applications and organizations. Use this REST API to manage roles.

Scan Health Configuration

Use this REST API to manage Scan Health configuration. This includes settings for failing scans with zero components detected. Configurations can be set at organization or application level and are inherited from the organization hierarchy.

Security Vulnerability Overrides

Use this REST API to retrieve security vulnerabilities that have been overridden.

Solutions

Source Control

Use this REST API to:

Source Control Metrics

Use this REST API to view the response times of a source control evaluation.

SPDX

Use this REST API to generate SPDX SBOMs in XML or JSON formats.

Third-Party Analysis

Use this REST API to scan SBOMs for your applications.

User Token Configuration

Use this REST API to manage user token expiration configuration.

User Tokens

Use this REST API to manage user tokens.

Users

Use this REST API to manage users.

Vulnerability Details

Use this REST API to retrieve vulnerability details.

Waiver Expiration Notification Config

Configure when and to whom notifications are sent before waivers expire.

Schemas