Compare two software inventories and report what entered, left and moved
Compare two software inventories and report what entered, left and moved. Reads CycloneDX components and SPDX packages, matching by package URL where both sides carry one because a bare name matches the wrong component across ecosystems. Reports version moves with breaking risk, a declared licence that changed, and a new component declaring no licence. A licence change is reported as a change in a declared field, not as a licensing conclusion.
Answeringour last check, 2026-10-04
1 of 1checks answered this week
2481 msmedian answer time
$0.16listed price per call
$0.16price it asked us
Paid test badge: not yet. The checks above are free: we call the tool without paying and read the payment request it sends back. The Verified badge needs paid calls whose answers match the promised output, and nobody can buy a badge.
Endpoint
POST https://api.zfinia.com/x402/v1/sbom-component-diff
| Category | Everything else |
|---|---|
| Provider host | api.zfinia.com |
| Networks | eip155:8453 |
| Payment schemes | exact |
| Self-reported calls, 30 days | 1 from 1 payers (the provider's figure, not ours) |
Our checks, last 30 days
| Day | Result | HTTP | Asked | Time |
|---|---|---|---|---|
| 2026-10-04 | valid payment request | 402 | $0.16 | 2481 ms |
Example input (from the provider)
{
"body": {
"after": {
"bomFormat": "CycloneDX",
"components": [
{
"licenses": [
{
"license": {
"id": "MIT"
}
}
],
"name": "express",
"purl": "pkg:npm/express",
"type": "library",
"version": "5.0.0"
},
{
"licenses": [
{
"license": {
"id": "GPL-3.0-only"
}
}
],
"name": "tiny-lib",
"purl": "pkg:npm/tiny-lib",
"type": "library",
"version": "0.5.0"
},
{
"name": "fresh-dep",
"purl": "pkg:npm/fresh-dep",
"type": "library",
"version": "1.0.0"
}
],
"specVersion": "1.5"
},
"before": {
"bomFormat": "CycloneDX",
"components": [
{
"licenses": [
{
"license": {
"id": "MIT"
}
}
],
"name": "express",
"purl": "pkg:npm/express",
"type": "library",
"version": "4.18.2"
},
{
"licenses": [
{
"license": {
"id": "MIT"
}
}
],
"name": "tiny-lib",
"purl": "pkg:npm/tiny-lib",
"type": "library",
"version": "0.4.1"
},
{
"licenses": [
{
"license": {
"id": "Apache-2.0"
}
}
],
"name": "retired",
"purl": "pkg:npm/retired",
"type": "library",
"version": "1.0.0"
}
],
"specVersion": "1.5"
}
},
"bodyType": "json",
"method": "POST",
"type": "http"
}
Promised output schema (from the provider)
{
"$schema": "https://json-schema.org/draft/2020-12/schema",
"properties": {
"input": {
"additionalProperties": false,
"properties": {
"body": {
"additionalProperties": false,
"properties": {
"after": {
"type": "object"
},
"before": {
"type": "object"
}
},
"required": [
"before",
"after"
],
"type": "object"
},
"bodyType": {
"enum": [
"json",
"form-data",
"text"
],
"type": "string"
},
"method": {
"enum": [
"POST"
],
"type": "string"
},
"type": {
"const": "http",
"type": "string"
}
},
"required": [
"type",
"method",
"bodyType",
"body"
],
"type": "object"
},
"output": {
"properties": {
"example": {
"type": "object"
},
"type": {
"type": "string"
}
},
"required": [
"type"
],
"type": "object"
}
},
"required": [
"input"
],
"type": "object"
}