AIBOM JSON response
This page describes the aibom_info section of the scan result, for integrations that parse it. For what AIBOM detects and how to read it, see AI Bill of Materials (AIBOM) (Beta).
JSON structure
Block states
The shape of aibom_info tells you whether AIBOM ran:
Shape | Meaning |
|---|---|
| AIBOM did not run: it is disabled in the workflow. |
| AIBOM ran and could not finish. |
| AIBOM ran. When it found nothing, the verdict is |
Field notes
Absent keys mean "not known". Values are never
null,""or[]in place of an unknown, so"version" in componentis a reliable test. Exceptions: theformatentry ofmetadatais always present, the counts inlicensing_component_countsalways include zeros, andmodel_card.metricsis carried exactly as the publisher wrote it,nullvalues included.Finding the scanned file in a repository. In a component's
hashes[], the entry whosesha256equalscomponent_group.group_id(without thesha256:prefix) is the file you scanned, under the name that repository gives it. That name often differs from the one you submitted.Header facts versus registry facts.
component_group.metadatacomes from the file's bytes; everything on a component comes from the publishing registry. If they disagree, for examplearchitectureinmetadataagainstmodel_card.architecture, that is worth reviewing, not an error in the report.Metadata names are the scanner's own. Entries in
metadatause the scanner's names, not the keys inside the file. A GGUF header'sgeneral.licenseis reported aslicense. Its value is free text the file declares; license buckets come from the repository's declaration, not from it.Component order. Components are sorted by repository id. When exactly one repository keeps the file at its root under the name you submitted, that repository comes first.
Example
A safetensors file submitted as model.safetensors, matched to one repository that keeps it as 1_Dense/model.safetensors: