Skip to content

Export the dependency graph as an SPDX 2.3 JSON document, in sbom.

GET/repos/{owner}/{name}/dependency-graph/sbom

Every package is named by its package URL.

sbom is an SPDX 2.3 JSON document, sent as SPDX spells it. Save it with jq .sbom.

  • Authentication: Required. Send an access token as Authorization: Bearer.
  • MCP tool: security with action sbom, and the same inputs
  • Scope: An access token needs security:read.
Name Type Required Description
owner string Yes The workspace that owns the repository.
name string Yes The repository’s name.
curl https://api.g1t.sh/repos/flagon-io/hello/dependency-graph/sbom \
-H "Authorization: Bearer $G1T_TOKEN"

A successful request answers 200 with:

{
"sbom": {
"spdxVersion": "SPDX-2.3",
"dataLicense": "CC0-1.0",
"SPDXID": "SPDXRef-DOCUMENT",
"name": "flagon-io/hello dependency graph",
"documentNamespace": "https://g1t.sh/flagon-io/hello/sbom/sbom_01kq2tdk0m1n2p3q4r5s6t7v8w",
"creationInfo": {
"created": "2026-10-06T09:14:02Z",
"creators": [
"Tool: g1t",
"Organization: g1t"
],
"comment": "Read from the repository's lockfiles on its default branch."
},
"documentDescribes": [
"SPDXRef-Repository-flagon-io-hello"
],
"packages": [
{
"SPDXID": "SPDXRef-Repository-flagon-io-hello",
"name": "flagon-io/hello",
"versionInfo": "4807077b296e6edbf410d55e72749d3e1170c291",
"downloadLocation": "git+https://g1t.sh/flagon-io/hello.git",
"filesAnalyzed": false,
"licenseConcluded": "NOASSERTION",
"licenseDeclared": "NOASSERTION",
"copyrightText": "NOASSERTION",
"primaryPackagePurpose": "SOURCE",
"externalRefs": []
},
{
"SPDXID": "SPDXRef-Package-npm-lodash-4.17.20",
"name": "lodash",
"versionInfo": "4.17.20",
"downloadLocation": "NOASSERTION",
"filesAnalyzed": false,
"licenseConcluded": "NOASSERTION",
"licenseDeclared": "MIT",
"copyrightText": "NOASSERTION",
"primaryPackagePurpose": "LIBRARY",
"comment": "Resolved by package-lock.json (direct dependency).",
"externalRefs": [
{
"referenceCategory": "PACKAGE-MANAGER",
"referenceType": "purl",
"referenceLocator": "pkg:npm/lodash@4.17.20"
}
]
}
],
"relationships": [
{
"spdxElementId": "SPDXRef-DOCUMENT",
"relationshipType": "DESCRIBES",
"relatedSpdxElement": "SPDXRef-Repository-flagon-io-hello"
},
{
"spdxElementId": "SPDXRef-Repository-flagon-io-hello",
"relationshipType": "DEPENDS_ON",
"relatedSpdxElement": "SPDXRef-Package-npm-lodash-4.17.20"
}
]
}
}

A failed request answers with one of these statuses and a body like {"error": {"code": "not_found", "message": "Repository not found."}}. See errors.

Status Code When
401 unauthenticated A token is required, or the one sent is not valid.
403 forbidden The token is valid but not allowed to do this, such as a member-only change or an agent token outside its repository.
404 not_found It does not exist, or you cannot see it.
422 invalid The input is not valid. message says which field and why.