CBOM JSON response
JSON structure
Fields that have no value are omitted entirely; they are never returned as null, "" or []. Treat an absent key as "not known", not as "empty".
Type-specific properties
Each component carries one *_properties object inside crypto_properties, selected by asset_type:
| Object | Fields |
|---|---|---|
|
|
|
|
|
|
|
|
|
|
|
|
| (none) | Library details are at the |
For certificates, signature_algorithm_details and public_key_algorithm_details are full algorithm objects, each with its own risk block. A certificate takes the weaker of its two algorithms' risk on each axis, so these objects explain why it was graded as it was. public_key_algorithm_details.detected_key_length is the key length measured from the certificate itself.
For libraries, detection_kind tells how the library was found: declared-dependency (named in a package manifest) or link-flag (only linked in a build script, so no version or package identity is available).
Field notes
Risk
overall_safeis what the UI shows as Overall Risk:trueis Safe,falseis Unsafe. An asset with anunknownlevel on either axis counts as unsafe.quantum.is_pqcnames a mechanism and is distinct from thequantum-safelevel: AES-256 is quantum-safe without being a post-quantum algorithm.quantum.recommended_replacementis an array, because there can be more than one successor. RSA, for example, needs ML-KEM (FIPS 203) for key establishment and ML-DSA (FIPS 204) for signatures;applies_tosays which use each entry covers. If you need a single answer, read the first element.
Evidence
Certificates extracted from binary files are byte-offset findings, not line-based ones. Their entries carry line: 0 by design, and the location is given in the match string:
pe_attribute_certificate_table@0x<offset>: a certificate from the Windows PE attribute certificate table.pe_embedded_pem@0x<offset>: a PEM block embedded in the file.
Verdict
verdict is evaluated in this order, No Cryptography Found, Risk Cryptography Found (risk_summary.overall.unsafe is greater than 0), Cryptography Found.
Note:
No Cryptography Foundis returned both when an analyzed file yields no cryptographic assets and when the file type is not covered by CBOM analysis. The verdict does not distinguish between these two cases.