Create Revision Attribution Public Report Sync V2
https://app.fossa.com/api/v2/revisions/{locator}/attribution/publicCreate a public attribution report link for a revision, synchronously (V2). Renders the report inline, uploads it, and returns the created `Report` record directly. Use this when you need the finished report link in the response. The `POST` on this same path queues a background job instead and returns `202` with the pending record plus its `task`; that is the better choice for large reports, since this operation holds the connection open for the whole render. **Requires a Premium subscription** and report-link permission on the project. `format` defaults to `HTML` when omitted. **Note:** Not all report options are valid for every report format. Use your project's Reports UI to see which options apply to a given format.
Path parameters
locatorstringrequiredThe URL-encoded locator of the revision
Query parameters
formatenumThe format of the report
HTMLMDPDFCSVTXTSPDXSPDX_JSONCYCLONEDX_JSONCYCLONEDX_XMLincludeDeepDependenciesbooleanWhether to include deep dependencies (default is false)
includeDirectDependenciesbooleanWhether to include direct dependencies (default is false)
includeLicenseListbooleanWhether to include the license list (default is false)
includeLicenseScanbooleanWhether to include the first-party license scan (default is false)
includeProjectLicensebooleanWhether to include the project's declared license (default is false)
includeCopyrightListbooleanWhether to include the copyright list (default is false)
includeFileMatchesbooleanWhether to include license file matches (default is false)
includeOpenVulnerabilitiesbooleanWhether to include open vulnerabilities (default is false)
includeClosedVulnerabilitiesbooleanWhether to include closed vulnerabilities (default is false)
includeDependencySummarybooleanWhether to include the dependency summary (default is false)
includeLicenseHeadersbooleanWhether to include license headers (default is false)
includePackageLabelsbooleanWhether to include the package labels assigned to each dependency (default is false)
excludeUnknownDependenciesbooleanWhether to exclude unknown (unresolved) dependencies from the report (default is false, meaning unknown dependencies are included)
excludeFieldsobjectObject controlling which dependencies are excluded from the report. The only supported nested field is `packageLabels`: a non-empty array of package-label values; dependencies carrying any of these labels are excluded from the report. The server parses the query string with the `qs` library, so the array is sent using bracket-and-index notation rather than standard OpenAPI `deepObject` serialization. For example, to exclude two labels send (before URL-encoding): `excludeFields[packageLabels][0]=internal&excludeFields[packageLabels][1]=vendored`.
Responses
201The created public report recordidintegerThe report ID
uuidstringThe public UUID used in the report's URL
urlstringThe S3 URL of the generated report
publicbooleanWhether the report is publicly accessible
organizationIdintegerprojectIdstringrevisionIdstring400BadRequestuuidstringUnique identifier associated with the error
codeintegerfossa specific error code
messagestringmessage associated with this error
namestringname of the error
httpStatusCodeintegerhttp status code number
401UnauthorizeduuidstringUnique identifier associated with the error
codeintegerfossa specific error code
messagestringmessage associated with this error
namestringname of the error
httpStatusCodeintegerhttp status code number
403Forbidden. The organization lacks a premium subscription, or the user lacks report-link permission on the project.uuidstringUnique identifier associated with the error
codeintegerfossa specific error code
messagestringmessage associated with this error
namestringname of the error
httpStatusCodeintegerhttp status code number
404NotFounduuidstringUnique identifier associated with the error
codeintegerfossa specific error code
messagestringmessage associated with this error
namestringname of the error
httpStatusCodeintegerhttp status code number
500Server ErroruuidstringUnique identifier associated with the error
codeintegerfossa specific error code
messagestringmessage associated with this error
namestringname of the error
httpStatusCodeintegerhttp status code number
Try this endpoint
Build a request and run it against app.fossa.com.
Stored in this browser for 24 hours. Try It uses a docs proxy for CORS and does not store tokens server-side.
GET https://app.fossa.com/api/v2/revisions/%7Blocator%7D/attribution/publiccurl --request GET \ --url 'https://app.fossa.com/api/v2/revisions/%7Blocator%7D/attribution/public' \ --header 'accept: application/json' \ --header 'authorization: Bearer YOUR_API_TOKEN'Real request. Mutating methods can change data.
Path params
locatorstringrequiredThe URL-encoded locator of the revision
Query params
formatenumThe format of the report
includeDeepDependenciesbooleanWhether to include deep dependencies (default is false)
includeDirectDependenciesbooleanWhether to include direct dependencies (default is false)
includeLicenseListbooleanWhether to include the license list (default is false)
includeLicenseScanbooleanWhether to include the first-party license scan (default is false)
includeProjectLicensebooleanWhether to include the project's declared license (default is false)
includeCopyrightListbooleanWhether to include the copyright list (default is false)
includeFileMatchesbooleanWhether to include license file matches (default is false)
includeOpenVulnerabilitiesbooleanWhether to include open vulnerabilities (default is false)
includeClosedVulnerabilitiesbooleanWhether to include closed vulnerabilities (default is false)
includeDependencySummarybooleanWhether to include the dependency summary (default is false)
includeLicenseHeadersbooleanWhether to include license headers (default is false)
includePackageLabelsbooleanWhether to include the package labels assigned to each dependency (default is false)
excludeUnknownDependenciesbooleanWhether to exclude unknown (unresolved) dependencies from the report (default is false, meaning unknown dependencies are included)
excludeFieldsobjectObject controlling which dependencies are excluded from the report. The only supported nested field is `packageLabels`: a non-empty array of package-label values; dependencies carrying any of these labels are excluded from the report. The server parses the query string with the `qs` library, so the array is sent using bracket-and-index notation rather than standard OpenAPI `deepObject` serialization. For example, to exclude two labels send (before URL-encoding): `excludeFields[packageLabels][0]=internal&excludeFields[packageLabels][1]=vendored`.