Request schema
{
"type": "object",
"description": "Provide either a raw lockfile or a pre-parsed components array; body size and component limits come from GET /v1/capabilities.",
"properties": {
"lockfile": {
"type": "object",
"description": "A raw lockfile.",
"properties": {
"format": {
"type": "string",
"enum": [
"package-lock.json",
"pnpm-lock.yaml",
"yarn.lock",
"requirements.txt",
"poetry.lock",
"uv.lock",
"Pipfile.lock",
"Cargo.lock",
"go.sum"
],
"description": "Lockfile format."
},
"content": {
"type": "string",
"description": "Raw lockfile content."
}
}
},
"components": {
"type": "array",
"description": "Pre-parsed dependencies.",
"items": {
"type": "object",
"properties": {
"ecosystem": {
"type": "string",
"description": "e.g. npm, pypi, go, cargo."
},
"name": {
"type": "string",
"description": "Package name."
},
"version": {
"type": "string",
"description": "Package version."
}
}
}
},
"options": {
"type": "object",
"description": "Scan options.",
"properties": {
"since": {
"type": "string",
"description": "Only advisories newer than this timestamp (monitor mode)."
},
"heuristics": {
"type": "boolean",
"description": "Add typosquat, install-script and dormancy signals."
}
}
}
},
"required": []
}
Response schema
{
"type": "object",
"description": "For POST /v1/scan, a JSON object with a `findings` array — each dependency's verdict (malicious, vulnerable, suspicious, clean), a summary, and a data_as_of timestamp. Findings vary by each supplier's snapshot freshness and converge as mirrors sync. The exact shape is the service's own and is not pinned here; errors return a JSON object with an `error` field, and the GET routes return their own small JSON documents."
}