Skip to content

Roles and Scopes

This table gives an overview of which role is allowed to execute which actions.

Function Developer Manager Compliance Manager Portfolio Manager Account Manager Enterprise Admin Company Component Manager Company Security Manager
CORE
/users
> GET nologin checked checked
> GET Keyusage checked checked
/accounts
> GET authorization checked checked checked checked checked checked checked checked
/imports
> POST checked checked checked checked checked
/projects
> GET checked checked checked checked
> POST checked checked checked
> DEL checked checked checked checked
> GET /partsList checked checked checked checked
> GET /sbom checked checked checked checked
/modules
> GET /modules checked checked checked checked checked
> DEL checked checked checked checked
> POST checked checked
> GET /partsList checked checked checked checked checked
/reports
> GET cveImpcat checked checked checked checked checked
> GET dashboard checked checked checked checked checked
> GET licenses checked checked checked
> GET versioning checked checked checked checked checked checked
> GET viability checked checked checked checked checked checked
> GET vulnerabilities checked checked checked checked checked checked
/scans
> GET
> POST checked
> GET /binaryLinks checked checked checked checked checked
> POST /binaryLinks checked checked checked
> POST reProcess checked checked checked checked checked
COMPLIANCE
/approvals
> POST checked
> GET checked checked checked checked
> POST approve checked
> POST reject checked
/check
> POST component checked checked checked checked checked checked
> POST license checked checked checked checked checked checked
REPOSITORY
> POST scan checked checked checked checked checked
> GET scan checked checked checked checked checked checked
> GET status checked checked checked checked checked
> GET results checked checked checked checked checked checked
VULNERABILITIES
> POST cveDetails checked checked checked checked checked checked checked checked
> POST cveFind checked checked checked checked checked checked checked checked
> GET cwes checked checked checked checked checked checked checked checked

Besides these we have a handful of public functions, which can be triggered by using the Release keys. Actually they are not really public, you will require the Release key to access the associated information, but everybody using the key will be able to access all information. Currently we have three documents, that can be retrieved:

  • SBOM
  • Notice File
  • CSAF VEX