# Office Hours Q&A

**URL:** <https://community.sonatype.com/t/office-hours-q-a/5169>\
**Category:** Office Hours\
**Created:** [October 20, 2020, 7:04pm UTC](https://community.sonatype.com/t/office-hours-q-a/5169 "2020-10-20T19:04:46Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![edeboer](https://yyz1.discourse-cdn.com/flex047/user_avatar/community.sonatype.com/edeboer/32/349_2.png) [@edeboer](https://community.sonatype.com/u/edeboer)\
**Post date:** [October 20, 2020, 7:04pm UTC](https://community.sonatype.com/t/office-hours-q-a/5169/1 "2020-10-20T19:04:46Z")

</div>

Customers who have follow-up questions from Office Hours can add them here by replying to this thread.

---

<div class="post-metadata">

**Author:** ![prashant.shah](https://avatars.discourse-cdn.com/v4/letter/p/cdc98d/32.png) [@prashant.shah](https://community.sonatype.com/u/prashant.shah)\
**Post date:** [June 23, 2023, 6:54pm UTC](https://community.sonatype.com/t/office-hours-q-a/5169/2 "2023-06-23T18:54:51Z")

</div>

I attended today’s office hours however I could not stay past 10:30 as I had a hard stop. I have the following question. We have been using the Nexus Lifecycle CycloneDx SBOM API to retrieve the Component and the Vulnerability information from Nexus Lifecycle. The Component data that is returned also has the License information. However, we do not see the License Threat Group in the data that is returned from that API. Is there a way to get the License Threat Group information as well using the SBOM or any other API?

---

<div class="post-metadata">

**Author:** ![dgriffin](https://avatars.discourse-cdn.com/v4/letter/d/e47774/32.png) [@dgriffin](https://community.sonatype.com/u/dgriffin)\
**Post date:** [June 23, 2023, 7:34pm UTC](https://community.sonatype.com/t/office-hours-q-a/5169/3 "2023-06-23T19:34:48Z")

</div>

Hi Prashant,

You can use the [REST Report API](https://help.sonatype.com/iqserver/automating/rest-apis/report-related-rest-apis---v2#ReportrelatedRESTAPIsv2-RawComponent'sDatabyReportRESTAPI(v2)) to get the License Threat Groups for the effective license set. If you have the [Advanced Legal Pack](https://help.sonatype.com/iqserver/product-information/add-on-packs#AddonPacks-AdvancedLegalPack), and you need more detailed information, you can use the [License Legal API](https://help.sonatype.com/iqserver/automating/rest-apis/license-legal-rest-api---v2) to get the LTG on a per license basis in addition to a complete breakdown of multilicenses along with other legal information.

Example of the license data from the rest report API:

```auto
"licenseData": {
"declaredLicenses": [
{
"licenseId": "EPL-1.0",
"licenseName": "EPL-1.0"
},
{
"licenseId": "EDL-1.0",
"licenseName": "EDL-1.0"
}
],
"observedLicenses": [
{
"licenseId": "EPL-1.0",
"licenseName": "EPL-1.0"
},
{
"licenseId": "BSD-3-Clause",
"licenseName": "BSD-3-Clause"
}
],
"effectiveLicenses": [
{
"licenseId": "EPL-1.0",
"licenseName": "EPL-1.0"
},
{
"licenseId": "EDL-1.0",
"licenseName": "EDL-1.0"
},
{
"licenseId": "BSD-3-Clause",
"licenseName": "BSD-3-Clause"
}
],
"overriddenLicenses": [],
"status": "Open",
"effectiveLicenseThreats": [
{
"licenseThreatGroupName": "Weak Copyleft",
"licenseThreatGroupLevel": 2,
"licenseThreatGroupCategory": "moderate"
},
{
"licenseThreatGroupName": "Liberal",
"licenseThreatGroupLevel": 0,
"licenseThreatGroupCategory": "no-threat"
}
]
},

```

---

<div class="post-metadata">

**Author:** ![prashant.shah](https://avatars.discourse-cdn.com/v4/letter/p/cdc98d/32.png) [@prashant.shah](https://community.sonatype.com/u/prashant.shah)\
**Post date:** [July 9, 2023, 7:55pm UTC](https://community.sonatype.com/t/office-hours-q-a/5169/4 "2023-07-09T19:55:16Z")

</div>

Hi Dgriffin! Thanks! I think this will work for us!
