Go to example tasks
Block an SPDX release on a denied license
Created by
Cedric Günther
Evaluate a synthetic SPDX 2.3 release SBOM and retain deterministic FAIL evidence when GPL-3.0-only violates the release policy.
SBOM Policy Evidence Gateceddl/sbom-policy-evidence-gate
Record type
Sbom id
Format
Spec version
+15 fieldsTextNumberBooleanListObject
Input
Inline SBOMs(required)
SBOM ID(required):synthetic-spdx-denied-license
Inline SBOM JSON object(required)
Versioned technical policy(required)
Policy name(required):synthetic-release-license-gate
Policy version(required):1.0.0
Require document provenance(required):true
Required component fields(required):name+2
Denied licenses(required):GPL-3.0-only
Allowed licenses(required)
Unknown license behavior(required):DENY
Denied package URLs(required)
Require relationship integrity(required):true
Output fields
Record type
Sbom id
Format
Spec version
Status
Component count
Relationship count
Finding count
Finding code
Severity
Component id
Path
Message
Fingerprint
Error code
Policy name
Policy version
Policy hash
Input hash
Sign up on Apify01
Create your Apify account to access the SBOM Policy Evidence Gate.
Start the run02
The Actor will start running based on the input automatically.
Receive the output03
Monitor the progress in real-time. You will be notified as soon as your dataset is complete and ready for review.
Integrate into your workflow04
The final output is delivered in JSON, CSV, or Excel format, ready to be plugged into your workflow.
