openapi: 3.2.0 info: title: Dependency Track Analysis API version: 1.0.0 contact: name: The Dependency-Track Authors url: https://github.com/DependencyTrack/dependency-track license: name: Apache-2.0 url: https://www.apache.org/licenses/LICENSE-2.0.html description: 'Operations tagged analysis across 2 of this provider''s published API definitions: dependency-track-openapi-v1.yaml, dependency-track-openapi.yml. Each path carries the servers of the definition it was published in.' servers: - url: /api tags: - name: Analysis paths: /v1/analysis: get: description: Requires permission VIEW_VULNERABILITY operationId: retrieveAnalysis parameters: - description: The UUID of the project in: query name: project schema: type: string format: uuid - description: The UUID of the component in: query name: component required: true schema: type: string format: uuid - description: The UUID of the vulnerability in: query name: vulnerability required: true schema: type: string format: uuid responses: '200': content: application/json: schema: $ref: '#/components/schemas/AnalysisTrailResponse' description: An analysis trail '401': description: Unauthorized '403': content: application/problem+json: schema: $ref: '#/components/schemas/ProblemDetails' description: Access to the requested project is forbidden '404': description: The project, component, or vulnerability could not be found security: - ApiKeyAuth: [] - BearerAuth: [] summary: Retrieves an analysis trail tags: - Analysis put: description: Requires permission VULNERABILITY_ANALYSIS or VULNERABILITY_ANALYSIS_UPDATE operationId: updateAnalysis requestBody: content: application/json: schema: $ref: '#/components/schemas/AnalysisRequest' responses: '200': content: application/json: schema: $ref: '#/components/schemas/AnalysisTrailResponse' description: The created analysis '401': description: Unauthorized '403': content: application/problem+json: schema: $ref: '#/components/schemas/ProblemDetails' description: Access to the requested project is forbidden '404': description: The project, component, or vulnerability could not be found security: - ApiKeyAuth: [] - BearerAuth: [] summary: Records an analysis decision tags: - Analysis servers: - url: /api components: schemas: AnalysisRequest: type: object properties: analysisDetails: type: string pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$ analysisJustification: type: string enum: - CODE_NOT_PRESENT - CODE_NOT_REACHABLE - REQUIRES_CONFIGURATION - REQUIRES_DEPENDENCY - REQUIRES_ENVIRONMENT - PROTECTED_BY_COMPILER - PROTECTED_AT_RUNTIME - PROTECTED_AT_PERIMETER - PROTECTED_BY_MITIGATING_CONTROL - NOT_SET analysisResponse: type: string enum: - CAN_NOT_FIX - WILL_NOT_FIX - UPDATE - ROLLBACK - WORKAROUND_AVAILABLE - NOT_SET analysisState: type: string enum: - EXPLOITABLE - IN_TRIAGE - FALSE_POSITIVE - NOT_AFFECTED - RESOLVED - NOT_SET comment: type: string pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$ component: type: string pattern: ^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$ isSuppressed: type: boolean writeOnly: true project: type: string pattern: ^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$ suppressed: type: boolean vulnerability: type: string pattern: ^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$ required: - component - vulnerability ProblemDetails: type: object description: An RFC 9457 problem object properties: detail: type: string description: Human-readable explanation specific to this occurrence of the problem example: Example detail instance: type: string format: uri description: Reference URI that identifies the specific occurrence of the problem example: https://api.example.org/foo/bar/example-instance status: type: integer format: int32 description: HTTP status code generated by the origin server for this occurrence of the problem example: 400 title: type: string description: Short, human-readable summary of the problem type example: Example title type: type: string format: uri description: A URI reference that identifies the problem type example: https://api.example.org/foo/bar/example-problem required: - detail - status - title AnalysisTrailResponse: type: object properties: analysisComments: type: array description: Audit trail of analysis comments items: $ref: '#/components/schemas/Comment' analysisDetails: type: string description: Free-form details of the analysis decision analysisJustification: type: string description: The justification of the analysis decision enum: - CODE_NOT_PRESENT - CODE_NOT_REACHABLE - REQUIRES_CONFIGURATION - REQUIRES_DEPENDENCY - REQUIRES_ENVIRONMENT - PROTECTED_BY_COMPILER - PROTECTED_AT_RUNTIME - PROTECTED_AT_PERIMETER - PROTECTED_BY_MITIGATING_CONTROL - NOT_SET analysisResponse: type: string description: The vendor response to the vulnerability enum: - CAN_NOT_FIX - WILL_NOT_FIX - UPDATE - ROLLBACK - WORKAROUND_AVAILABLE - NOT_SET analysisState: type: string description: The state of the analysis decision enum: - EXPLOITABLE - IN_TRIAGE - FALSE_POSITIVE - NOT_AFFECTED - RESOLVED - NOT_SET cvssV2Score: type: number description: CVSS v2 score assigned by the analysis cvssV2Vector: type: string description: CVSS v2 vector assigned by the analysis cvssV3Score: type: number description: CVSS v3 score assigned by the analysis cvssV3Vector: type: string description: CVSS v3 vector assigned by the analysis cvssV4Score: type: number description: CVSS v4 score assigned by the analysis cvssV4Vector: type: string description: CVSS v4 vector assigned by the analysis isSuppressed: type: boolean description: Whether the finding is suppressed owaspScore: type: number description: OWASP Risk Rating score assigned by the analysis owaspVector: type: string description: OWASP Risk Rating vector assigned by the analysis severity: type: string description: Severity assigned by the analysis enum: - CRITICAL - HIGH - MEDIUM - LOW - INFO - UNASSIGNED required: - analysisComments - analysisState - isSuppressed Comment: type: object description: Audit trail of analysis comments properties: comment: type: string description: The comment text commenter: type: string description: Identifier of the user who wrote the comment timestamp: type: integer format: int64 description: Timestamp the comment was recorded at required: - comment - timestamp securitySchemes: ApiKeyAuth: description: Authentication via API key. in: header name: X-Api-Key type: apiKey BearerAuth: bearerFormat: Opaque description: 'Authentication via opaque server-issued session token. Tokens are obtained from `POST /api/v1/user/login` or `POST /api/v1/user/oidc/login`.' scheme: bearer type: http x-refined-from: - dependency-track-openapi-v1.yaml - dependency-track-openapi.yml