Create Revision Attribution Public Report Sync V2

gethttps://app.fossa.com/api/v2/revisions/{locator}/attribution/public

Create a public attribution report link for a revision, synchronously (V2). Renders the report inline, uploads it, and returns the created `Report` record directly. Use this when you need the finished report link in the response. The `POST` on this same path queues a background job instead and returns `202` with the pending record plus its `task`; that is the better choice for large reports, since this operation holds the connection open for the whole render. **Requires a Premium subscription** and report-link permission on the project. `format` defaults to `HTML` when omitted. **Note:** Not all report options are valid for every report format. Use your project's Reports UI to see which options apply to a given format.

Path parameters

locatorstringrequired

The URL-encoded locator of the revision

Query parameters

formatenum

The format of the report

HTMLMDPDFCSVTXTSPDXSPDX_JSONCYCLONEDX_JSONCYCLONEDX_XML
includeDeepDependenciesboolean

Whether to include deep dependencies (default is false)

includeDirectDependenciesboolean

Whether to include direct dependencies (default is false)

includeLicenseListboolean

Whether to include the license list (default is false)

includeLicenseScanboolean

Whether to include the first-party license scan (default is false)

includeProjectLicenseboolean

Whether to include the project's declared license (default is false)

includeCopyrightListboolean

Whether to include the copyright list (default is false)

includeFileMatchesboolean

Whether to include license file matches (default is false)

includeOpenVulnerabilitiesboolean

Whether to include open vulnerabilities (default is false)

includeClosedVulnerabilitiesboolean

Whether to include closed vulnerabilities (default is false)

includeDependencySummaryboolean

Whether to include the dependency summary (default is false)

includeLicenseHeadersboolean

Whether to include license headers (default is false)

includePackageLabelsboolean

Whether to include the package labels assigned to each dependency (default is false)

excludeUnknownDependenciesboolean

Whether to exclude unknown (unresolved) dependencies from the report (default is false, meaning unknown dependencies are included)

excludeFieldsobject

Object controlling which dependencies are excluded from the report. The only supported nested field is `packageLabels`: a non-empty array of package-label values; dependencies carrying any of these labels are excluded from the report. The server parses the query string with the `qs` library, so the array is sent using bracket-and-index notation rather than standard OpenAPI `deepObject` serialization. For example, to exclude two labels send (before URL-encoding): `excludeFields[packageLabels][0]=internal&excludeFields[packageLabels][1]=vendored`.

Responses

201The created public report record
idinteger

The report ID

uuidstring

The public UUID used in the report's URL

urlstring

The S3 URL of the generated report

publicboolean

Whether the report is publicly accessible

organizationIdinteger
projectIdstring
revisionIdstring
400BadRequest
uuidstring

Unique identifier associated with the error

codeinteger

fossa specific error code

messagestring

message associated with this error

namestring

name of the error

httpStatusCodeinteger

http status code number

401Unauthorized
uuidstring

Unique identifier associated with the error

codeinteger

fossa specific error code

messagestring

message associated with this error

namestring

name of the error

httpStatusCodeinteger

http status code number

403Forbidden. The organization lacks a premium subscription, or the user lacks report-link permission on the project.
uuidstring

Unique identifier associated with the error

codeinteger

fossa specific error code

messagestring

message associated with this error

namestring

name of the error

httpStatusCodeinteger

http status code number

404NotFound
uuidstring

Unique identifier associated with the error

codeinteger

fossa specific error code

messagestring

message associated with this error

namestring

name of the error

httpStatusCodeinteger

http status code number

500Server Error
uuidstring

Unique identifier associated with the error

codeinteger

fossa specific error code

messagestring

message associated with this error

namestring

name of the error

httpStatusCodeinteger

http status code number

Try this endpoint

Build a request and run it against app.fossa.com.

Bearer

Stored in this browser for 24 hours. Try It uses a docs proxy for CORS and does not store tokens server-side.

GET https://app.fossa.com/api/v2/revisions/%7Blocator%7D/attribution/public
curl --request GET \  --url 'https://app.fossa.com/api/v2/revisions/%7Blocator%7D/attribution/public' \  --header 'accept: application/json' \  --header 'authorization: Bearer YOUR_API_TOKEN'

Real request. Mutating methods can change data.

Click Try It to run a request and see the response here.
Enter a Bearer token before running this request.

Path params

locatorstringrequired

The URL-encoded locator of the revision

Query params

formatenum

The format of the report

includeDeepDependenciesboolean

Whether to include deep dependencies (default is false)

includeDirectDependenciesboolean

Whether to include direct dependencies (default is false)

includeLicenseListboolean

Whether to include the license list (default is false)

includeLicenseScanboolean

Whether to include the first-party license scan (default is false)

includeProjectLicenseboolean

Whether to include the project's declared license (default is false)

includeCopyrightListboolean

Whether to include the copyright list (default is false)

includeFileMatchesboolean

Whether to include license file matches (default is false)

includeOpenVulnerabilitiesboolean

Whether to include open vulnerabilities (default is false)

includeClosedVulnerabilitiesboolean

Whether to include closed vulnerabilities (default is false)

includeDependencySummaryboolean

Whether to include the dependency summary (default is false)

includeLicenseHeadersboolean

Whether to include license headers (default is false)

includePackageLabelsboolean

Whether to include the package labels assigned to each dependency (default is false)

excludeUnknownDependenciesboolean

Whether to exclude unknown (unresolved) dependencies from the report (default is false, meaning unknown dependencies are included)

excludeFieldsobject

Object controlling which dependencies are excluded from the report. The only supported nested field is `packageLabels`: a non-empty array of package-label values; dependencies carrying any of these labels are excluded from the report. The server parses the query string with the `qs` library, so the array is sent using bracket-and-index notation rather than standard OpenAPI `deepObject` serialization. For example, to exclude two labels send (before URL-encoding): `excludeFields[packageLabels][0]=internal&excludeFields[packageLabels][1]=vendored`.