openapi: 3.2.0 info: title: Dependency Track Metrics API version: 1.0.0 contact: name: The Dependency-Track Authors url: https://github.com/DependencyTrack/dependency-track license: name: Apache-2.0 url: https://www.apache.org/licenses/LICENSE-2.0.html description: 'Operations tagged metrics across 2 of this provider''s published API definitions: dependency-track-openapi-v1.yaml, dependency-track-openapi.yml. Each path carries the servers of the definition it was published in.' servers: - url: /api tags: - name: Metrics paths: /v1/metrics/component/{uuid}/current: get: description: Requires permission VIEW_PORTFOLIO operationId: getComponentCurrentMetrics parameters: - description: The UUID of the component to retrieve metrics for in: path name: uuid required: true schema: type: string format: uuid responses: '200': content: application/json: schema: $ref: '#/components/schemas/DependencyMetrics' description: Current metrics for a specific component '401': description: Unauthorized '403': content: application/problem+json: schema: $ref: '#/components/schemas/ProblemDetails' description: Access to the requested component is forbidden '404': description: The component could not be found security: - ApiKeyAuth: [] - BearerAuth: [] summary: Returns current metrics for a specific component tags: - Metrics servers: - url: /api /v1/metrics/component/{uuid}/days/{days}: get: description: Requires permission VIEW_PORTFOLIO operationId: getComponentMetricsXDays parameters: - description: The UUID of the component to retrieve metrics for in: path name: uuid required: true schema: type: string format: uuid - description: The number of days back to retrieve metrics for in: path name: days required: true schema: type: integer format: int32 responses: '200': content: application/json: schema: type: array items: $ref: '#/components/schemas/DependencyMetrics' description: X days of historical metrics for a specific component '401': description: Unauthorized '403': content: application/problem+json: schema: $ref: '#/components/schemas/ProblemDetails' description: Access to the requested component is forbidden '404': description: The component could not be found security: - ApiKeyAuth: [] - BearerAuth: [] summary: Returns X days of historical metrics for a specific component tags: - Metrics servers: - url: /api /v1/metrics/component/{uuid}/refresh: get: description: Requires permission PORTFOLIO_MANAGEMENT or PORTFOLIO_MANAGEMENT_UPDATE operationId: RefreshComponentMetrics parameters: - description: The UUID of the component to refresh metrics on in: path name: uuid required: true schema: type: string format: uuid responses: '200': description: Refresh requested successfully '401': description: Unauthorized '403': content: application/problem+json: schema: $ref: '#/components/schemas/ProblemDetails' description: Access to the requested component is forbidden '404': description: The component could not be found security: - ApiKeyAuth: [] - BearerAuth: [] summary: Requests a refresh of a specific components metrics tags: - Metrics servers: - url: /api /v1/metrics/component/{uuid}/since/{date}: get: description: 'Date format must be YYYYMMDD. The date is interpreted as UTC midnight. Requires permission VIEW_PORTFOLIO' operationId: getComponentMetricsSince parameters: - description: The UUID of the component to retrieve metrics for in: path name: uuid required: true schema: type: string format: uuid - description: The start date (UTC) to retrieve metrics for in: path name: date required: true schema: type: string responses: '200': content: application/json: schema: type: array items: $ref: '#/components/schemas/DependencyMetrics' description: Historical metrics for a specific component from a specific date '401': description: Unauthorized '403': content: application/problem+json: schema: $ref: '#/components/schemas/ProblemDetails' description: Access to the requested component is forbidden '404': description: The component could not be found security: - ApiKeyAuth: [] - BearerAuth: [] summary: Returns historical metrics for a specific component from a specific date tags: - Metrics servers: - url: /api /v1/metrics/portfolio/current: get: description: Requires permission VIEW_PORTFOLIO operationId: getPortfolioCurrentMetrics responses: '200': content: application/json: schema: $ref: '#/components/schemas/PortfolioMetrics' description: Current metrics for the entire portfolio '401': description: Unauthorized security: - ApiKeyAuth: [] - BearerAuth: [] summary: Returns current metrics for the entire portfolio tags: - Metrics servers: - url: /api /v1/metrics/portfolio/refresh: get: description: Requires permission PORTFOLIO_MANAGEMENT or PORTFOLIO_MANAGEMENT_UPDATE operationId: RefreshPortfolioMetrics responses: '200': description: Refresh requested successfully '401': description: Unauthorized security: - ApiKeyAuth: [] - BearerAuth: [] summary: Requests a refresh of the portfolio metrics tags: - Metrics servers: - url: /api /v1/metrics/portfolio/since/{date}: get: description: 'Date format must be YYYYMMDD. The number of days returned is computed against the current UTC date. Requires permission VIEW_PORTFOLIO' operationId: getPortfolioMetricsSince parameters: - description: The start date to retrieve metrics for in: path name: date required: true schema: type: string responses: '200': content: application/json: schema: type: array items: $ref: '#/components/schemas/PortfolioMetrics' description: Historical metrics for the entire portfolio from a specific date '401': description: Unauthorized security: - ApiKeyAuth: [] - BearerAuth: [] summary: Returns historical metrics for the entire portfolio from a specific date tags: - Metrics servers: - url: /api /v1/metrics/portfolio/{days}/days: get: description: Requires permission VIEW_PORTFOLIO operationId: getPortfolioMetricsXDays parameters: - description: The number of days back to retrieve metrics for in: path name: days required: true schema: type: integer format: int32 exclusiveMinimum: 0 responses: '200': content: application/json: schema: type: array items: $ref: '#/components/schemas/PortfolioMetrics' description: X days of historical metrics for the entire portfolio '401': description: Unauthorized security: - ApiKeyAuth: [] - BearerAuth: [] summary: Returns X days of historical metrics for the entire portfolio tags: - Metrics servers: - url: /api /v1/metrics/project/{uuid}/current: get: description: Requires permission VIEW_PORTFOLIO operationId: getProjectCurrentMetrics parameters: - description: The UUID of the project to retrieve metrics for in: path name: uuid required: true schema: type: string format: uuid responses: '200': content: application/json: schema: $ref: '#/components/schemas/ProjectMetrics' description: Current metrics for a specific project '401': description: Unauthorized '403': content: application/problem+json: schema: $ref: '#/components/schemas/ProblemDetails' description: Access to the requested project is forbidden '404': description: The project could not be found security: - ApiKeyAuth: [] - BearerAuth: [] summary: Returns current metrics for a specific project tags: - Metrics servers: - url: /api /v1/metrics/project/{uuid}/days/{days}: get: description: Requires permission VIEW_PORTFOLIO operationId: getProjectMetricsXDays parameters: - description: The UUID of the project to retrieve metrics for in: path name: uuid required: true schema: type: string format: uuid - description: The number of days back to retrieve metrics for in: path name: days required: true schema: type: integer format: int32 responses: '200': content: application/json: schema: type: array items: $ref: '#/components/schemas/ProjectMetrics' description: X days of historical metrics for a specific project '401': description: Unauthorized '403': content: application/problem+json: schema: $ref: '#/components/schemas/ProblemDetails' description: Access to the requested project is forbidden '404': description: The project could not be found security: - ApiKeyAuth: [] - BearerAuth: [] summary: Returns X days of historical metrics for a specific project tags: - Metrics servers: - url: /api /v1/metrics/project/{uuid}/refresh: get: description: Requires permission PORTFOLIO_MANAGEMENT or PORTFOLIO_MANAGEMENT_UPDATE operationId: RefreshProjectMetrics parameters: - description: The UUID of the project to refresh metrics on in: path name: uuid required: true schema: type: string format: uuid responses: '200': description: Refresh requested successfully '401': description: Unauthorized '403': content: application/problem+json: schema: $ref: '#/components/schemas/ProblemDetails' description: Access to the requested project is forbidden '404': description: The project could not be found security: - ApiKeyAuth: [] - BearerAuth: [] summary: Requests a refresh of a specific projects metrics tags: - Metrics servers: - url: /api /v1/metrics/project/{uuid}/since/{date}: get: description: 'Date format must be YYYYMMDD. The date is interpreted as UTC midnight. Requires permission VIEW_PORTFOLIO' operationId: getProjectMetricsSince parameters: - description: The UUID of the project to retrieve metrics for in: path name: uuid required: true schema: type: string format: uuid - description: The start date (UTC) to retrieve metrics for in: path name: date required: true schema: type: string responses: '200': content: application/json: schema: type: array items: $ref: '#/components/schemas/ProjectMetrics' description: Historical metrics for a specific project from a specific date '401': description: Unauthorized '403': content: application/problem+json: schema: $ref: '#/components/schemas/ProblemDetails' description: Access to the requested project is forbidden '404': description: The project could not be found security: - ApiKeyAuth: [] - BearerAuth: [] summary: Returns historical metrics for a specific project from a specific date tags: - Metrics servers: - url: /api /v1/metrics/vulnerability: get: description: Requires permission VIEW_PORTFOLIO operationId: getVulnerabilityMetrics responses: '200': content: application/json: schema: type: array items: $ref: '#/components/schemas/VulnerabilityMetrics' description: The sum of all vulnerabilities in the database by year and month '401': description: Unauthorized security: - ApiKeyAuth: [] - BearerAuth: [] summary: Returns the sum of all vulnerabilities in the database by year and month tags: - Metrics servers: - url: /api components: schemas: VulnerabilityMetrics: type: object properties: count: type: integer format: int32 measuredAt: type: integer format: int64 description: UNIX epoch timestamp in milliseconds month: type: integer format: int32 year: type: integer format: int32 required: - measuredAt ProjectMetrics: type: object properties: components: type: integer format: int32 critical: type: integer format: int32 findingsAudited: type: integer format: int32 findingsTotal: type: integer format: int32 findingsUnaudited: type: integer format: int32 firstOccurrence: type: integer format: int64 description: UNIX epoch timestamp in milliseconds high: type: integer format: int32 inheritedRiskScore: type: number format: double kev: type: integer format: int32 lastOccurrence: type: integer format: int64 description: UNIX epoch timestamp in milliseconds low: type: integer format: int32 medium: type: integer format: int32 policyViolationsAudited: type: integer format: int32 policyViolationsFail: type: integer format: int32 policyViolationsInfo: type: integer format: int32 policyViolationsLicenseAudited: type: integer format: int32 policyViolationsLicenseTotal: type: integer format: int32 policyViolationsLicenseUnaudited: type: integer format: int32 policyViolationsOperationalAudited: type: integer format: int32 policyViolationsOperationalTotal: type: integer format: int32 policyViolationsOperationalUnaudited: type: integer format: int32 policyViolationsSecurityAudited: type: integer format: int32 policyViolationsSecurityTotal: type: integer format: int32 policyViolationsSecurityUnaudited: type: integer format: int32 policyViolationsTotal: type: integer format: int32 policyViolationsUnaudited: type: integer format: int32 policyViolationsWarn: type: integer format: int32 suppressed: type: integer format: int32 unassigned: type: integer format: int32 vulnerabilities: type: integer format: int32 vulnerableComponents: type: integer format: int32 required: - firstOccurrence - lastOccurrence PortfolioMetrics: type: object properties: components: type: integer format: int32 critical: type: integer format: int32 findingsAudited: type: integer format: int32 findingsTotal: type: integer format: int32 findingsUnaudited: type: integer format: int32 firstOccurrence: type: integer format: int64 description: UNIX epoch timestamp in milliseconds high: type: integer format: int32 inheritedRiskScore: type: number format: double kev: type: integer format: int32 lastOccurrence: type: integer format: int64 description: UNIX epoch timestamp in milliseconds low: type: integer format: int32 medium: type: integer format: int32 policyViolationsAudited: type: integer format: int32 policyViolationsFail: type: integer format: int32 policyViolationsInfo: type: integer format: int32 policyViolationsLicenseAudited: type: integer format: int32 policyViolationsLicenseTotal: type: integer format: int32 policyViolationsLicenseUnaudited: type: integer format: int32 policyViolationsOperationalAudited: type: integer format: int32 policyViolationsOperationalTotal: type: integer format: int32 policyViolationsOperationalUnaudited: type: integer format: int32 policyViolationsSecurityAudited: type: integer format: int32 policyViolationsSecurityTotal: type: integer format: int32 policyViolationsSecurityUnaudited: type: integer format: int32 policyViolationsTotal: type: integer format: int32 policyViolationsUnaudited: type: integer format: int32 policyViolationsWarn: type: integer format: int32 projects: type: integer format: int32 suppressed: type: integer format: int32 unassigned: type: integer format: int32 vulnerabilities: type: integer format: int32 vulnerableComponents: type: integer format: int32 vulnerableProjects: type: integer format: int32 required: - firstOccurrence - lastOccurrence ProblemDetails: type: object description: An RFC 9457 problem object properties: detail: type: string description: Human-readable explanation specific to this occurrence of the problem example: Example detail instance: type: string format: uri description: Reference URI that identifies the specific occurrence of the problem example: https://api.example.org/foo/bar/example-instance status: type: integer format: int32 description: HTTP status code generated by the origin server for this occurrence of the problem example: 400 title: type: string description: Short, human-readable summary of the problem type example: Example title type: type: string format: uri description: A URI reference that identifies the problem type example: https://api.example.org/foo/bar/example-problem required: - detail - status - title DependencyMetrics: type: object properties: critical: type: integer format: int32 findingsAudited: type: integer format: int32 findingsTotal: type: integer format: int32 findingsUnaudited: type: integer format: int32 firstOccurrence: type: integer format: int64 description: UNIX epoch timestamp in milliseconds high: type: integer format: int32 inheritedRiskScore: type: number format: double kev: type: integer format: int32 lastOccurrence: type: integer format: int64 description: UNIX epoch timestamp in milliseconds low: type: integer format: int32 medium: type: integer format: int32 policyViolationsAudited: type: integer format: int32 policyViolationsFail: type: integer format: int32 policyViolationsInfo: type: integer format: int32 policyViolationsLicenseAudited: type: integer format: int32 policyViolationsLicenseTotal: type: integer format: int32 policyViolationsLicenseUnaudited: type: integer format: int32 policyViolationsOperationalAudited: type: integer format: int32 policyViolationsOperationalTotal: type: integer format: int32 policyViolationsOperationalUnaudited: type: integer format: int32 policyViolationsSecurityAudited: type: integer format: int32 policyViolationsSecurityTotal: type: integer format: int32 policyViolationsSecurityUnaudited: type: integer format: int32 policyViolationsTotal: type: integer format: int32 policyViolationsUnaudited: type: integer format: int32 policyViolationsWarn: type: integer format: int32 suppressed: type: integer format: int32 unassigned: type: integer format: int32 vulnerabilities: type: integer format: int32 required: - firstOccurrence - lastOccurrence securitySchemes: ApiKeyAuth: description: Authentication via API key. in: header name: X-Api-Key type: apiKey BearerAuth: bearerFormat: Opaque description: 'Authentication via opaque server-issued session token. Tokens are obtained from `POST /api/v1/user/login` or `POST /api/v1/user/oidc/login`.' scheme: bearer type: http x-refined-from: - dependency-track-openapi-v1.yaml - dependency-track-openapi.yml