Download the content of one TEA Artifact revision
Download the content of a specific revision of a specific TEA Artifact.
This endpoint returns the bytes of one format of the artifact revision. It is how a TEA server hosts artifact content itself: a format that has no external url is retrieved from here, selected by its mediaType. A format that has a url is retrieved from that external location instead, and this endpoint is not required to serve it.
A TEA access token is sent only to the TEA server's own API base URL. External url targets are retrieved without it. They are openly accessible or require credentials the client arranges separately. Expiring storage links should not be published in url; the server answers from this endpoint, including with 302.
When serving the content itself (200), servers shall return a strong ETag for the HTTP representation selected after negotiation, including content coding, and shall honor If-None-Match with 304. ETag is the only conditional validator for these downloads. Servers that support HEAD for this operation shall return the same headers as GET without a response body. 302 redirects are outside conditional semantics: If-None-Match applies only to the TEA-hosted download response, not to following an external Location.
How long a cache may retain the response depends on whether the content is publicly accessible: see artifact-cache-control-immutable. Immutability does not imply that shared caches may store access-controlled responses. Successful responses include Content-Location as an absolute URL of this versioned download including the mediaType query parameter. That URL identifies the revision and format; HTTP content coding can still be negotiated.
Path parameters
A UUID in lower case (RFC 9562)
UUID of TEA Artifact in the TEA server
Version of TEA Artifact
Query parameters
Selects which of the artifact revision's formats to return, by its mediaType. The parameter value is the media type itself (for example application/vnd.cyclonedx+json), not a pre-encoded wire form. Clients shall apply query-parameter serialization once. Servers shall interpret the value after one query-decoding step.
Matching against a format's mediaType is case-insensitive for the type and subtype. Parameter names are compared case-insensitively; parameter values require exact equality. When omitted, the server selects a format using the request's Accept header per RFC 9110 section 12, and falls back to a format of its choice when Accept does not constrain the result. In either case the Content-Type of the response states which format was returned. An explicit mediaType can remove variation by Accept when it completely determines the format. When it does not, the server shall include Accept in Vary if changing or removing Accept could change the selected format, including when Accept is absent or contains */*. A mediaType query parameter does not eliminate variation by Accept-Encoding; see artifact-vary.
Example after serialization: .../download?mediaType=application%2Fvnd.cyclonedx%2Bjson
Headers
Conditional request validator (RFC 9110). For artifact and signature downloads, ETag is the only defined validator. Servers evaluate If-None-Match with the weak comparison function (RFC 9110 section 13.1.2) against the ETag of the representation selected after negotiation, including content-coding negotiation, and answer 304 when it matches. The corresponding 304 shall carry that representation's validator and shall carry Vary when the 200 would. When present, that ETag is a strong validator. Other validators are not defined for these operations.
Response
The content of the requested TEA Artifact format.
The wire Content-Type is the mediaType of the format returned. The response content key is */* because that type varies by format. Content-Encoding, when present, names the HTTP content coding of the selected representation. Content-Location identifies the revision and format; HTTP content coding can still be negotiated. Vary follows artifact-vary.
Changes
Changed in 18 of the 136 revisions of this API.61730
- ●
the optional response header
Content-Encodingremoved for the status200optional-response-header-removed
- ●
- ●
the optional response header
Content-Encodingremoved for the status200optional-response-header-removed
- ●
- ○
added the optional property
to the response with the statusresponse-optional-property-added
- ○
added the optional property
to the response with the statusresponse-optional-property-added
- ○
added the optional property
to the response with the statusresponse-optional-property-added
- ○
added the optional property
to the response with the statusresponse-optional-property-added
- ○
added the optional property
to the response with the statusresponse-optional-property-added
- ○
removed the
OBJECT_NOT_SHAREABLEenum value from theresponse property for the response statusresponse-property-enum-value-removed
- ○
removed the
OBJECT_NOT_SHAREABLEenum value from theresponse property for the response statusresponse-property-enum-value-removed
- ○
removed the
OBJECT_NOT_SHAREABLEenum value from theresponse property for the response statusresponse-property-enum-value-removed
- ○
removed the
OBJECT_NOT_SHAREABLEenum value from theresponse property for the response statusresponse-property-enum-value-removed
- ○
removed the
OBJECT_NOT_SHAREABLEenum value from theresponse property for the response statusresponse-property-enum-value-removed
- ○
- ▲
removed the media type
application/octet-streamfor the response with the statusresponse-media-type-removed
- ○
added the new optional
headerrequest parameterIf-None-Matchnew-optional-request-parameter
- ○
added the media type
*/*for the response with the statusresponse-media-type-added
- ○
added the non-success response with the status
response-non-success-status-added
- ▲
- ▲
removed the media type
*/*for the response with the statusresponse-media-type-removed
- ●
the optional response header
Content-Locationremoved for the status200optional-response-header-removed
- ●
the optional response header
Varyremoved for the status200optional-response-header-removed
- ●
deleted the
headerrequest parameterIf-None-Matchrequest-parameter-removed
- ○
added the media type
application/octet-streamfor the response with the statusresponse-media-type-added
- ○
removed the non-success response with the status
response-non-success-status-removed
- ▲
- ▲
removed the media type
application/octet-streamfor the response with the statusresponse-media-type-removed
- ○
added the media type
*/*for the response with the statusresponse-media-type-added
- ▲
- ▲
removed the media type
*/*for the response with the statusresponse-media-type-removed
- ○
added the media type
application/octet-streamfor the response with the statusresponse-media-type-added
- ▲
- ▲
removed the media type
application/octet-streamfor the response with the statusresponse-media-type-removed
- ○
added the new optional
headerrequest parameterIf-None-Matchnew-optional-request-parameter
- ○
added the media type
*/*for the response with the statusresponse-media-type-added
- ○
added the non-success response with the status
response-non-success-status-added
- ▲
- ●
added the new
INVALID_PAGE_TOKENenum value to theresponse property for the response statusresponse-property-enum-value-added
- ●
added the new
INVALID_PAGE_TOKENenum value to theresponse property for the response statusresponse-property-enum-value-added
- ●
added the new
INVALID_REQUESTenum value to theresponse property for the response statusresponse-property-enum-value-added
- ●
added the new
INVALID_REQUESTenum value to theresponse property for the response statusresponse-property-enum-value-added
- ●
added the new
NO_ACCEPTABLE_FORMATenum value to theresponse property for the response statusresponse-property-enum-value-added
- ●
added the new
NO_ACCEPTABLE_FORMATenum value to theresponse property for the response statusresponse-property-enum-value-added
- ●
added the new
SIGNATURE_NOT_FOUNDenum value to theresponse property for the response statusresponse-property-enum-value-added
- ●
added the new
SIGNATURE_NOT_FOUNDenum value to theresponse property for the response statusresponse-property-enum-value-added
- ●
- ●
added the new
NOT_IMPLEMENTEDenum value to theresponse property for the response statusresponse-property-enum-value-added
- ●
added the new
NOT_IMPLEMENTEDenum value to theresponse property for the response statusresponse-property-enum-value-added
- ●