IoT / Client / associate_sbom_with_package_version



Associates a software bill of materials (SBOM) with a specific software package version.

Requires permission to access the AssociateSbomWithPackageVersion action.

See also: AWS API Documentation

Request Syntax

response = client.associate_sbom_with_package_version(
        's3Location': {
            'bucket': 'string',
            'key': 'string',
            'version': 'string'
  • packageName (string) –


    The name of the new software package.

  • versionName (string) –


    The name of the new package version.

  • sbom (dict) –


    The Amazon S3 location for the software bill of materials associated with a software package version.

    • s3Location (dict) –

      The S3 location.

      • bucket (string) –

        The S3 bucket.

      • key (string) –

        The S3 key.

      • version (string) –

        The S3 bucket version.

  • clientToken (string) –

    A unique case-sensitive identifier that you can provide to ensure the idempotency of the request. Don’t reuse this client token if a new idempotent request is required.

    This field is autopopulated if not provided.

Return type:



Response Syntax

    'packageName': 'string',
    'versionName': 'string',
    'sbom': {
        's3Location': {
            'bucket': 'string',
            'key': 'string',
            'version': 'string'
    'sbomValidationStatus': 'IN_PROGRESS'|'FAILED'|'SUCCEEDED'

Response Structure

  • (dict) –

    • packageName (string) –

      The name of the new software package.

    • versionName (string) –

      The name of the new package version.

    • sbom (dict) –

      The Amazon S3 location for the software bill of materials associated with a software package version.

      • s3Location (dict) –

        The S3 location.

        • bucket (string) –

          The S3 bucket.

        • key (string) –

          The S3 key.

        • version (string) –

          The S3 bucket version.

    • sbomValidationStatus (string) –

      The status of the initial validation for the SBOM against the Software Package Data Exchange (SPDX) and CycloneDX industry standard format.


  • IoT.Client.exceptions.ThrottlingException

  • IoT.Client.exceptions.ConflictException

  • IoT.Client.exceptions.InternalServerException

  • IoT.Client.exceptions.ValidationException

  • IoT.Client.exceptions.ServiceQuotaExceededException

  • IoT.Client.exceptions.ResourceNotFoundException