Skip to main content

JSON

Purpose: Structured scan results for custom consumers that do not ingest CBOM or SARIF directly. When to use: Internal dashboards, scripts, or early integration work before adopting CycloneDX.

Example

Caveats

Prefer CBOM for portable inventory interchange and SARIF for code-scanning UIs when those consumers exist. JSON is the escape hatch, not the primary compliance artifact.