{
  "openapi": "3.0.1",
  "info": {
    "title": "SBOM Policy Evidence Gate",
    "description": "Evaluate bounded CycloneDX or SPDX JSON SBOMs against a versioned technical policy and emit durable JSON and SARIF evidence.",
    "version": "0.1",
    "x-build-id": "EJaeI7cK7wvNK3zsH"
  },
  "servers": [
    {
      "url": "https://api.apify.com/v2"
    }
  ],
  "paths": {
    "/acts/ceddl~sbom-policy-evidence-gate/run-sync-get-dataset-items": {
      "post": {
        "operationId": "run-sync-get-dataset-items-ceddl-sbom-policy-evidence-gate",
        "x-openai-isConsequential": false,
        "summary": "Executes an Actor, waits for its completion, and returns Actor's dataset items in response.",
        "tags": [
          "Run Actor"
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/inputSchema"
              }
            }
          }
        },
        "parameters": [
          {
            "name": "token",
            "in": "query",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "Enter your Apify token here"
          }
        ],
        "responses": {
          "200": {
            "description": "OK"
          }
        }
      }
    },
    "/acts/ceddl~sbom-policy-evidence-gate/runs": {
      "post": {
        "operationId": "runs-sync-ceddl-sbom-policy-evidence-gate",
        "x-openai-isConsequential": false,
        "summary": "Executes an Actor and returns information about the initiated run in response.",
        "tags": [
          "Run Actor"
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/inputSchema"
              }
            }
          }
        },
        "parameters": [
          {
            "name": "token",
            "in": "query",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "Enter your Apify token here"
          }
        ],
        "responses": {
          "200": {
            "description": "OK",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "#/components/schemas/runsResponseSchema"
                }
              }
            }
          }
        }
      }
    },
    "/acts/ceddl~sbom-policy-evidence-gate/run-sync": {
      "post": {
        "operationId": "run-sync-ceddl-sbom-policy-evidence-gate",
        "x-openai-isConsequential": false,
        "summary": "Executes an Actor, waits for completion, and returns the OUTPUT from Key-value store in response.",
        "tags": [
          "Run Actor"
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "$ref": "#/components/schemas/inputSchema"
              }
            }
          }
        },
        "parameters": [
          {
            "name": "token",
            "in": "query",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "Enter your Apify token here"
          }
        ],
        "responses": {
          "200": {
            "description": "OK"
          }
        }
      }
    }
  },
  "components": {
    "schemas": {
      "inputSchema": {
        "type": "object",
        "required": [
          "items",
          "policy"
        ],
        "properties": {
          "items": {
            "title": "Inline SBOMs",
            "minItems": 1,
            "maxItems": 10,
            "type": "array",
            "description": "CycloneDX JSON 1.5/1.6 or SPDX JSON 2.3 documents evaluated independently.",
            "items": {
              "type": "object",
              "required": [
                "id",
                "sbom"
              ],
              "additionalProperties": false,
              "properties": {
                "id": {
                  "title": "SBOM ID",
                  "description": "Stable caller-provided identifier used to correlate SBOM policy reports and findings.",
                  "type": "string",
                  "minLength": 1,
                  "maxLength": 120
                },
                "sbom": {
                  "title": "Inline SBOM JSON object",
                  "description": "One inline CycloneDX JSON 1.5/1.6 or SPDX JSON 2.3 document to evaluate.",
                  "type": "object",
                  "editor": "json"
                }
              }
            }
          },
          "policy": {
            "title": "Versioned technical policy",
            "required": [
              "name",
              "version",
              "requireDocumentProvenance",
              "requiredComponentFields",
              "deniedLicenses",
              "allowedLicenses",
              "unknownLicenseBehavior",
              "deniedPurls",
              "requireRelationshipIntegrity"
            ],
            "type": "object",
            "description": "Deterministic provenance, component, relationship, and license checks applied to every SBOM.",
            "properties": {
              "name": {
                "title": "Policy name",
                "description": "Caller-defined policy name included in deterministic evidence.",
                "type": "string",
                "minLength": 1,
                "maxLength": 120
              },
              "version": {
                "title": "Policy version",
                "description": "Caller-defined policy version included in deterministic evidence.",
                "type": "string",
                "minLength": 1,
                "maxLength": 80
              },
              "requireDocumentProvenance": {
                "title": "Require document provenance",
                "description": "Require the supported SBOM document-level provenance fields checked by this Actor.",
                "type": "boolean"
              },
              "requiredComponentFields": {
                "title": "Required component fields",
                "description": "Component fields that must be present and non-empty.",
                "type": "array",
                "uniqueItems": true,
                "maxItems": 3,
                "editor": "json"
              },
              "deniedLicenses": {
                "title": "Denied licenses",
                "description": "Exact SPDX-style license identifiers or expressions that produce policy findings.",
                "type": "array",
                "uniqueItems": true,
                "maxItems": 200,
                "editor": "json"
              },
              "allowedLicenses": {
                "title": "Allowed licenses",
                "description": "Optional exact allowlist; leave empty to accept licenses not explicitly denied.",
                "type": "array",
                "uniqueItems": true,
                "maxItems": 200,
                "editor": "json"
              },
              "unknownLicenseBehavior": {
                "title": "Unknown license behavior",
                "description": "Choose whether absent or unrecognized component license evidence is allowed or denied.",
                "type": "string",
                "enum": [
                  "ALLOW",
                  "DENY"
                ]
              },
              "deniedPurls": {
                "title": "Denied package URLs",
                "description": "Exact package URLs that produce policy findings when present.",
                "type": "array",
                "uniqueItems": true,
                "maxItems": 200,
                "editor": "json"
              },
              "requireRelationshipIntegrity": {
                "title": "Require relationship integrity",
                "description": "Require dependency relationships to reference declared components or the document root.",
                "type": "boolean"
              }
            },
            "additionalProperties": false
          },
          "maxSbomBytes": {
            "title": "Maximum canonical SBOM bytes",
            "minimum": 1024,
            "maximum": 2000000,
            "type": "integer",
            "description": "Reject an SBOM when its canonical JSON representation exceeds this byte limit.",
            "default": 2000000
          },
          "maxComponents": {
            "title": "Maximum components per SBOM",
            "minimum": 1,
            "maximum": 5000,
            "type": "integer",
            "description": "Reject an SBOM when its component count exceeds this limit.",
            "default": 5000
          },
          "maxRelationships": {
            "title": "Maximum relationships per SBOM",
            "minimum": 0,
            "maximum": 10000,
            "type": "integer",
            "description": "Reject an SBOM when its relationship count exceeds this limit.",
            "default": 10000
          },
          "maxFindings": {
            "title": "Maximum findings per SBOM",
            "minimum": 1,
            "maximum": 1000,
            "type": "integer",
            "description": "Stop collecting findings for an SBOM after this limit is reached.",
            "default": 1000
          }
        }
      },
      "runsResponseSchema": {
        "type": "object",
        "properties": {
          "data": {
            "type": "object",
            "properties": {
              "id": {
                "type": "string"
              },
              "actId": {
                "type": "string"
              },
              "userId": {
                "type": "string"
              },
              "startedAt": {
                "type": "string",
                "format": "date-time",
                "example": "2025-01-08T00:00:00.000Z"
              },
              "finishedAt": {
                "type": "string",
                "format": "date-time",
                "example": "2025-01-08T00:00:00.000Z"
              },
              "status": {
                "type": "string",
                "example": "READY"
              },
              "meta": {
                "type": "object",
                "properties": {
                  "origin": {
                    "type": "string",
                    "example": "API"
                  },
                  "userAgent": {
                    "type": "string"
                  }
                }
              },
              "stats": {
                "type": "object",
                "properties": {
                  "inputBodyLen": {
                    "type": "integer",
                    "example": 2000
                  },
                  "rebootCount": {
                    "type": "integer",
                    "example": 0
                  },
                  "restartCount": {
                    "type": "integer",
                    "example": 0
                  },
                  "resurrectCount": {
                    "type": "integer",
                    "example": 0
                  },
                  "computeUnits": {
                    "type": "integer",
                    "example": 0
                  }
                }
              },
              "options": {
                "type": "object",
                "properties": {
                  "build": {
                    "type": "string",
                    "example": "latest"
                  },
                  "timeoutSecs": {
                    "type": "integer",
                    "example": 300
                  },
                  "memoryMbytes": {
                    "type": "integer",
                    "example": 1024
                  },
                  "diskMbytes": {
                    "type": "integer",
                    "example": 2048
                  }
                }
              },
              "buildId": {
                "type": "string"
              },
              "defaultKeyValueStoreId": {
                "type": "string"
              },
              "defaultDatasetId": {
                "type": "string"
              },
              "defaultRequestQueueId": {
                "type": "string"
              },
              "buildNumber": {
                "type": "string",
                "example": "1.0.0"
              },
              "containerUrl": {
                "type": "string"
              },
              "usage": {
                "type": "object",
                "properties": {
                  "ACTOR_COMPUTE_UNITS": {
                    "type": "integer",
                    "example": 0
                  },
                  "DATASET_READS": {
                    "type": "integer",
                    "example": 0
                  },
                  "DATASET_WRITES": {
                    "type": "integer",
                    "example": 0
                  },
                  "KEY_VALUE_STORE_READS": {
                    "type": "integer",
                    "example": 0
                  },
                  "KEY_VALUE_STORE_WRITES": {
                    "type": "integer",
                    "example": 1
                  },
                  "KEY_VALUE_STORE_LISTS": {
                    "type": "integer",
                    "example": 0
                  },
                  "REQUEST_QUEUE_READS": {
                    "type": "integer",
                    "example": 0
                  },
                  "REQUEST_QUEUE_WRITES": {
                    "type": "integer",
                    "example": 0
                  },
                  "DATA_TRANSFER_INTERNAL_GBYTES": {
                    "type": "integer",
                    "example": 0
                  },
                  "DATA_TRANSFER_EXTERNAL_GBYTES": {
                    "type": "integer",
                    "example": 0
                  },
                  "PROXY_RESIDENTIAL_TRANSFER_GBYTES": {
                    "type": "integer",
                    "example": 0
                  },
                  "PROXY_SERPS": {
                    "type": "integer",
                    "example": 0
                  }
                }
              },
              "usageTotalUsd": {
                "type": "number",
                "example": 0.00005
              },
              "usageUsd": {
                "type": "object",
                "properties": {
                  "ACTOR_COMPUTE_UNITS": {
                    "type": "integer",
                    "example": 0
                  },
                  "DATASET_READS": {
                    "type": "integer",
                    "example": 0
                  },
                  "DATASET_WRITES": {
                    "type": "integer",
                    "example": 0
                  },
                  "KEY_VALUE_STORE_READS": {
                    "type": "integer",
                    "example": 0
                  },
                  "KEY_VALUE_STORE_WRITES": {
                    "type": "number",
                    "example": 0.00005
                  },
                  "KEY_VALUE_STORE_LISTS": {
                    "type": "integer",
                    "example": 0
                  },
                  "REQUEST_QUEUE_READS": {
                    "type": "integer",
                    "example": 0
                  },
                  "REQUEST_QUEUE_WRITES": {
                    "type": "integer",
                    "example": 0
                  },
                  "DATA_TRANSFER_INTERNAL_GBYTES": {
                    "type": "integer",
                    "example": 0
                  },
                  "DATA_TRANSFER_EXTERNAL_GBYTES": {
                    "type": "integer",
                    "example": 0
                  },
                  "PROXY_RESIDENTIAL_TRANSFER_GBYTES": {
                    "type": "integer",
                    "example": 0
                  },
                  "PROXY_SERPS": {
                    "type": "integer",
                    "example": 0
                  }
                }
              }
            }
          }
        }
      }
    }
  }
}