Snyk/sbom
Snyk SBOM — software bill of materials testing and analysis
2026.09.08.1
Added: Initial code-generated release of @webframp/snyk/sbom with 3 methods covering the Snyk sbom API surface.
Global Arguments
| Argument | Type | Description |
|---|---|---|
| apiToken | string | Snyk API token |
| orgId | string | Snyk organization ID |
| version | string | Snyk API version date |
| Argument | Type | Description |
|---|---|---|
| data | object |
| Argument | Type | Description |
|---|---|---|
| job_id | string | Job ID |
| Argument | Type | Description |
|---|---|---|
| job_id | string | Job ID |
Resources
2026.08.28.2
Hardened codegen: instance names sanitized against path traversal; 429 rate-limit retry with Retry-After; string schema patterns emit regex validation; output schemas passthrough unknown fields.
2026.08.28.1
Changed: Normalized the extension license to Apache-2.0 and corrected the copyright holder to "Sean Escriva". Extensions that previously shipped an MIT LICENSE.md are now Apache-2.0, consistent with the repository root and every other extension. No code or behavioral changes.
Upgrade note: License text only. No API, schema, or runtime behavior changed.
2026.08.26.2
Fixed: Restored inline npm:zod@4.4.3 import specifiers so the registry
quality scorer can resolve dependencies and score the extension. An earlier
release used a bare "zod" import-map specifier, which published but scored as
unscored.
Changed: Retained explicit compilerOptions.strict in deno.json. No
behavioral or schema changes.
2026.08.26.2
Fixed: Restored inline npm:zod@4.4.3 import specifiers so the registry
quality scorer can resolve dependencies and score the extension. An earlier
release used a bare "zod" import-map specifier, which published but scored as
unscored.
Changed: Retained explicit compilerOptions.strict in deno.json. No
behavioral or schema changes.
2026.08.24.1
Added: Output metadata attributes for observability.
durationMs: Method execution duration in milliseconds.collectedBy: Extension name that produced the data.fetchedAt: ISO 8601 timestamp when data was fetched (added to resources that previously lacked it).
2026.08.21.1
Changed: job_id now must be a non-empty string — previously an empty
value passed schema validation and only failed deep inside the Snyk API call
with a generic 404. Errors from the Snyk API now name the HTTP method and path
that was attempted instead of just the bare status and body. Network-level
failures (DNS, connection refused, TLS errors) reaching the Snyk API are now
also caught and reported with the operation and path that was being attempted,
rather than surfacing as an unhandled fetch exception.
2026.07.19.1
Added: Initial code-generated release of @webframp/snyk/sbom with 3 methods covering the Snyk sbom API surface.
- Has README or module doc2/2earned
- README has a code example1/1earned
- README is substantive1/1earned
- Most symbols documented1/1earned
- No slow types (deprecated)1/1earned
- Dependencies pass trust audit2/2earned
- Has description1/1earned
- Platform support declared (or universal)2/2earned
- License declared1/1earned
- Verified public repository2/2earned