Creates or Updates Services

Note on the uniqueness of a service

The unique identifier within VSM for a service is the combination of id+sourceInstance+sourceType. Hence, if any of the components change it will result in a different service in VSM.

Supported SBOM versions

We currently support CycloneDX versions <=1.5 and SPDX in both xml as well as json file format

Minimum requirements for an SBOM to be processed

  1. We only process components of type library when CycloneDX SBOM file is provided
  2. The library must have a valid purl as our correlation depends on that and it's the most popular & recommended way to identify libraries. We don't support other IDs like SWID.
