Complete reference for the bomly explain JSON output.
| Field | Type | Description |
|---|---|---|
schema_version |
string |
|
command |
string |
|
project |
ProjectDescriptor |
|
query |
ExplainQuery |
|
dependency |
ExplainDependency |
|
paths |
Array<DependencyPath> |
|
findings |
Array<AuditFinding> |
|
audit_summary |
AuditSummary |
|
targets |
Array<ExplainTargetResponse> |
|
warnings |
Array<DetectorWarning> |
|
metadata |
Metadata |
| Field | Type | Description |
|---|---|---|
symbol |
string |
|
kind |
string |
|
package |
string |
|
module |
string |
|
definition |
SourcePosition |
| Field | Type | Description |
|---|---|---|
id |
string |
|
kind |
string |
|
severity |
string |
|
package |
FindingPackageRef |
|
title |
string |
|
reasons |
Array<string> |
|
source |
string |
|
auditor |
string |
|
rule_id |
string |
|
policy_status |
string |
|
vulnerability_id |
string |
|
dependency_refs |
Array<string> |
| Field | Type | Description |
|---|---|---|
critical |
integer |
|
high |
integer |
|
medium |
integer |
|
low |
integer |
|
unknown |
integer |
|
total |
integer |
| Field | Type | Description |
|---|---|---|
vector |
string |
|
score |
number |
|
version |
string |
|
source |
string |
| Field | Type | Description |
|---|---|---|
cve |
string |
|
id |
string |
|
source |
string |
|
type |
string |
| Field | Type | Description |
|---|---|---|
function |
string |
|
package |
string |
|
receiver |
string |
|
position |
SourcePosition |
| Field | Type | Description |
|---|---|---|
sink |
AffectedSymbol |
|
frames |
Array<CallFrame> |
| Field | Type | Description |
|---|---|---|
relationship |
string |
|
packages |
Array<PackageRef> |
|
introduced_via |
string |
|
cyclic |
boolean |
|
cycle_to |
string |
| Field | Type | Description |
|---|---|---|
type |
string |
|
code |
string |
|
source |
string |
|
subproject |
string |
|
manifest |
string |
|
message |
string |
| Field | Type | Description |
|---|---|---|
cve |
string |
|
epss |
number |
|
percentile |
number |
|
date |
string |
| Field | Type | Description |
|---|---|---|
name |
string |
|
version |
string |
|
scope |
string |
|
purl |
string |
|
id |
string |
|
metadata |
object |
|
locations |
Array<LocationRef> |
|
licenses |
Array<LicenseRef> |
|
vulnerabilities |
Array<VulnerabilityRef> |
|
scorecard |
PackageScorecard |
|
relationship |
string |
|
direct |
boolean |
|
remediation |
PackageRemediation |
| Field | Type | Description |
|---|---|---|
name |
string |
| Field | Type | Description |
|---|---|---|
project |
ProjectDescriptor |
|
detector |
string |
|
package_manager |
string |
|
dependency |
ExplainDependency |
|
paths |
Array<DependencyPath> |
|
findings |
Array<AuditFinding> |
|
audit_summary |
AuditSummary |
| Field | Type | Description |
|---|---|---|
name |
string |
|
org |
string |
|
version |
string |
|
purl |
string |
|
ecosystem |
string |
| Field | Type | Description |
|---|---|---|
version |
string |
|
date |
string |
|
kind |
string |
| Field | Type | Description |
|---|---|---|
cve |
string |
|
vendor_project |
string |
|
product |
string |
|
date_added |
string |
|
required_action |
string |
|
due_date |
string |
|
known_ransomware_campaign_use |
string |
|
notes |
string |
|
urls |
Array<string> |
|
cwes |
Array<string> |
| Field | Type | Description |
|---|---|---|
value |
string |
|
spdxExpression |
string |
|
type |
string |
| Field | Type | Description |
|---|---|---|
real_path |
string |
|
access_path |
string |
|
position |
PositionRef |
| Field | Type | Description |
|---|---|---|
duration_ms |
integer |
|
reachability_enabled |
boolean |
|
scorecard_enabled |
boolean |
|
analyzer_runs |
Array<string> |
|
analyzer_stats |
object |
| Field | Type | Description |
|---|---|---|
name |
string |
|
version |
string |
|
scope |
string |
|
purl |
string |
|
id |
string |
|
metadata |
object |
|
locations |
Array<LocationRef> |
|
licenses |
Array<LicenseRef> |
|
vulnerabilities |
Array<VulnerabilityRef> |
|
scorecard |
PackageScorecard |
|
relationship |
string |
|
direct |
boolean |
| Field | Type | Description |
|---|---|---|
status |
string |
|
recommended_version |
string |
|
suggestions |
Array<PackageRemediationSuggestion> |
| Field | Type | Description |
|---|---|---|
affected_dependency_refs |
Array<string> |
|
suggested_action_dependency_ref |
string |
|
manifest_path |
string |
|
action |
string |
|
override_advice |
string |
| Field | Type | Description |
|---|---|---|
source |
string |
|
repository |
string |
|
commitSha |
string |
|
scorecardVersion |
string |
|
runDate |
Time |
|
aggregateScore |
number |
|
checks |
Array<PackageScorecardCheck> |
| Field | Type | Description |
|---|---|---|
name |
string |
|
score |
integer |
|
reason |
string |
|
documentation |
string |
| Field | Type | Description |
|---|---|---|
file |
string |
|
line |
integer |
|
column |
integer |
|
end_line |
integer |
| Field | Type | Description |
|---|---|---|
name |
string |
|
path |
string |
|
target_type |
string |
|
target_ref |
string |
|
ecosystem |
string |
|
package_manager |
string |
| Field | Type | Description |
|---|---|---|
status |
string |
|
tier |
string |
|
analyzer |
string |
|
reason |
string |
|
symbols |
Array<AffectedSymbol> |
|
call_paths |
Array<CallPath> |
|
hops |
integer |
|
confidence |
string |
|
dynamic_imports_detected |
boolean |
|
analyzed_at |
string |
| Field | Type | Description |
|---|---|---|
url |
string |
|
type |
string |
| Field | Type | Description |
|---|---|---|
file |
string |
|
line |
integer |
|
column |
integer |
|
end_line |
integer |
| Field | Type | Description |
|---|---|---|
id |
string |
|
source |
string |
|
title |
string |
|
severity |
string |
|
severity_source |
string |
|
aliases |
Array<string> |
|
description |
string |
|
reasons |
Array<string> |
|
cvss |
Array<CVSSScore> |
|
fixed_in |
string |
|
fixed_versions |
Array<string> |
|
fix_state |
string |
|
fix_available |
Array<FixAvailable> |
|
affected_version_range |
string |
|
references |
Array<Reference> |
|
kev_exploited |
boolean |
|
known_exploited |
Array<KnownExploited> |
|
epss |
Array<EPSSScore> |
|
cwes |
Array<CWE> |
|
risk_score |
number |
|
data_source |
string |
|
namespace |
string |
|
cpes |
Array<string> |
|
affected_symbols |
Array<AffectedSymbol> |
|
reachability |
Reachability |