openapi: 3.2.0 info: title: Dependency Track Policy API version: 1.0.0 contact: name: The Dependency-Track Authors url: https://github.com/DependencyTrack/dependency-track license: name: Apache-2.0 url: https://www.apache.org/licenses/LICENSE-2.0.html description: 'Operations tagged policy across 2 of this provider''s published API definitions: dependency-track-openapi-v1.yaml, dependency-track-openapi.yml. Each path carries the servers of the definition it was published in.' servers: - url: /api tags: - name: Policy paths: /v1/policy: get: description: Requires permission POLICY_MANAGEMENT or POLICY_MANAGEMENT_READ operationId: getPolicies parameters: - description: The page to return. To be used in conjunction with pageSize. in: query name: pageNumber schema: type: string default: '1' - description: Number of elements to return per page. To be used in conjunction with pageNumber. in: query name: pageSize schema: type: string default: '100' - description: Offset to start returning elements from. To be used in conjunction with limit. in: query name: offset schema: type: string - description: Number of elements to return per page. To be used in conjunction with offset. in: query name: limit schema: type: string - description: Name of the resource field to sort on. in: query name: sortName schema: type: string - description: Ordering of items when sorting with sortName. in: query name: sortOrder schema: type: string enum: - asc, desc responses: '200': content: application/json: schema: type: array items: $ref: '#/components/schemas/Policy' description: A list of all policies headers: X-Total-Count: description: The total number of policies schema: format: integer style: simple '401': description: Unauthorized security: - ApiKeyAuth: [] - BearerAuth: [] summary: Returns a list of all policies tags: - Policy post: description: Requires permission POLICY_MANAGEMENT or POLICY_MANAGEMENT_UPDATE operationId: updatePolicy requestBody: content: application/json: schema: $ref: '#/components/schemas/Policy' responses: '200': content: application/json: schema: $ref: '#/components/schemas/Policy' description: The updated policy '401': description: Unauthorized '404': description: The policy could not be found security: - ApiKeyAuth: [] - BearerAuth: [] summary: Updates a policy tags: - Policy put: description: Requires permission POLICY_MANAGEMENT or POLICY_MANAGEMENT_CREATE operationId: createPolicy requestBody: content: application/json: schema: $ref: '#/components/schemas/Policy' responses: '201': content: application/json: schema: $ref: '#/components/schemas/Policy' description: The created policy '401': description: Unauthorized '409': description: A policy with the specified name already exists security: - ApiKeyAuth: [] - BearerAuth: [] summary: Creates a new policy tags: - Policy servers: - url: /api /v1/policy/{policyUuid}/project/{projectUuid}: delete: description: Requires permission POLICY_MANAGEMENT or POLICY_MANAGEMENT_DELETE operationId: removeProjectFromPolicy parameters: - description: The UUID of the policy to remove the project from in: path name: policyUuid required: true schema: type: string format: uuid - description: The UUID of the project to remove from the policy in: path name: projectUuid required: true schema: type: string format: uuid responses: '200': content: application/json: schema: $ref: '#/components/schemas/Policy' description: The updated policy '304': description: The policy does not have the specified project assigned '401': description: Unauthorized '403': content: application/problem+json: schema: $ref: '#/components/schemas/ProblemDetails' description: Access to the requested project is forbidden '404': description: The policy or project could not be found security: - ApiKeyAuth: [] - BearerAuth: [] summary: Removes a project from a policy tags: - Policy post: description: Requires permission POLICY_MANAGEMENT or POLICY_MANAGEMENT_UPDATE operationId: addProjectToPolicy parameters: - description: The UUID of the policy to add a project to in: path name: policyUuid required: true schema: type: string format: uuid - description: The UUID of the project to add to the rule in: path name: projectUuid required: true schema: type: string format: uuid responses: '200': content: application/json: schema: $ref: '#/components/schemas/Policy' description: The updated policy '304': description: The policy already has the specified project assigned '401': description: Unauthorized '403': content: application/problem+json: schema: $ref: '#/components/schemas/ProblemDetails' description: Access to the requested project is forbidden '404': description: The policy or project could not be found security: - ApiKeyAuth: [] - BearerAuth: [] summary: Adds a project to a policy tags: - Policy servers: - url: /api /v1/policy/{uuid}: delete: description: Requires permission POLICY_MANAGEMENT or POLICY_MANAGEMENT_DELETE operationId: deletePolicy parameters: - description: The UUID of the policy to delete in: path name: uuid required: true schema: type: string format: uuid responses: '204': description: Policy removed successfully '401': description: Unauthorized '404': description: The UUID of the policy could not be found security: - ApiKeyAuth: [] - BearerAuth: [] summary: Deletes a policy tags: - Policy get: description: Requires permission POLICY_MANAGEMENT or POLICY_MANAGEMENT_READ operationId: getPolicy parameters: - description: The UUID of the policy to retrieve in: path name: uuid required: true schema: type: string format: uuid responses: '200': content: application/json: schema: $ref: '#/components/schemas/Policy' description: A specific policy '401': description: Unauthorized '404': description: The policy could not be found security: - ApiKeyAuth: [] - BearerAuth: [] summary: Returns a specific policy tags: - Policy servers: - url: /api components: schemas: AffectedComponent: type: object properties: affectedVersionAttributions: type: array items: $ref: '#/components/schemas/AffectedVersionAttribution' identity: type: string identityType: type: string enum: - CPE - PURL uuid: type: string format: uuid version: type: string versionEndExcluding: type: string versionEndIncluding: type: string versionStartExcluding: type: string versionStartIncluding: type: string versionType: type: string enum: - EXACT - RANGE DataClassification: type: object properties: direction: type: string enum: - INBOUND - OUTBOUND - BI_DIRECTIONAL - UNKNOWN name: type: string Cwe: type: object properties: cweId: type: integer format: int32 name: type: string pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$ Tools: type: object properties: components: type: array items: $ref: '#/components/schemas/Component' services: type: array items: $ref: '#/components/schemas/ServiceComponent' Vulnerability: type: object properties: affectedActiveProjectCount: type: integer format: int32 affectedComponents: type: array items: $ref: '#/components/schemas/AffectedComponent' affectedInactiveProjectCount: type: integer format: int32 affectedProjectCount: type: integer format: int32 aliases: type: array items: $ref: '#/components/schemas/VulnerabilityAlias' components: type: array items: $ref: '#/components/schemas/Component' created: type: string format: date-time credits: type: string pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$ cvssV2BaseScore: type: number cvssV2ExploitabilitySubScore: type: number cvssV2ImpactSubScore: type: number cvssV2Vector: type: string pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$ cvssV3BaseScore: type: number cvssV3ExploitabilitySubScore: type: number cvssV3ImpactSubScore: type: number cvssV3Vector: type: string pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$ cvssV4Score: type: number cvssV4Vector: type: string pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$ cwes: type: array items: $ref: '#/components/schemas/Cwe' description: type: string pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$ detail: type: string pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$ epss: $ref: '#/components/schemas/Epss' epssPercentile: type: number epssScore: type: number friendlyVulnId: type: string maxLength: 255 minLength: 1 pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$ isKev: type: boolean owaspRRBusinessImpactScore: type: number owaspRRLikelihoodScore: type: number owaspRRTechnicalImpactScore: type: number owaspRRVector: type: string pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$ patchedVersions: type: string pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$ published: type: string format: date-time recommendation: type: string pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$ references: type: string pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$ rejected: type: string format: date-time serviceComponents: type: array items: $ref: '#/components/schemas/ServiceComponent' severity: type: string enum: - CRITICAL - HIGH - MEDIUM - LOW - INFO - UNASSIGNED pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$ source: type: string maxLength: 255 minLength: 1 pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$ subTitle: type: string pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$ tags: type: array items: $ref: '#/components/schemas/Tag' uniqueItems: true title: type: string pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$ updated: type: string format: date-time uuid: type: string format: uuid vulnId: type: string maxLength: 255 minLength: 1 pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$ vulnerableVersions: type: string pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$ required: - friendlyVulnId - source - uuid - vulnId ProblemDetails: type: object description: An RFC 9457 problem object properties: detail: type: string description: Human-readable explanation specific to this occurrence of the problem example: Example detail instance: type: string format: uri description: Reference URI that identifies the specific occurrence of the problem example: https://api.example.org/foo/bar/example-instance status: type: integer format: int32 description: HTTP status code generated by the origin server for this occurrence of the problem example: 400 title: type: string description: Short, human-readable summary of the problem type example: Example title type: type: string format: uri description: A URI reference that identifies the problem type example: https://api.example.org/foo/bar/example-problem required: - detail - status - title DependencyMetrics: type: object properties: critical: type: integer format: int32 findingsAudited: type: integer format: int32 findingsTotal: type: integer format: int32 findingsUnaudited: type: integer format: int32 firstOccurrence: type: integer format: int64 description: UNIX epoch timestamp in milliseconds high: type: integer format: int32 inheritedRiskScore: type: number format: double kev: type: integer format: int32 lastOccurrence: type: integer format: int64 description: UNIX epoch timestamp in milliseconds low: type: integer format: int32 medium: type: integer format: int32 policyViolationsAudited: type: integer format: int32 policyViolationsFail: type: integer format: int32 policyViolationsInfo: type: integer format: int32 policyViolationsLicenseAudited: type: integer format: int32 policyViolationsLicenseTotal: type: integer format: int32 policyViolationsLicenseUnaudited: type: integer format: int32 policyViolationsOperationalAudited: type: integer format: int32 policyViolationsOperationalTotal: type: integer format: int32 policyViolationsOperationalUnaudited: type: integer format: int32 policyViolationsSecurityAudited: type: integer format: int32 policyViolationsSecurityTotal: type: integer format: int32 policyViolationsSecurityUnaudited: type: integer format: int32 policyViolationsTotal: type: integer format: int32 policyViolationsUnaudited: type: integer format: int32 policyViolationsWarn: type: integer format: int32 suppressed: type: integer format: int32 unassigned: type: integer format: int32 vulnerabilities: type: integer format: int32 required: - firstOccurrence - lastOccurrence ProjectVersion: type: object properties: active: type: boolean isLatest: type: boolean uuid: type: string format: uuid version: type: string MappedOidcGroup: type: object properties: group: $ref: '#/components/schemas/OidcGroup' uuid: type: string format: uuid required: - uuid ProjectMetrics: type: object properties: components: type: integer format: int32 critical: type: integer format: int32 findingsAudited: type: integer format: int32 findingsTotal: type: integer format: int32 findingsUnaudited: type: integer format: int32 firstOccurrence: type: integer format: int64 description: UNIX epoch timestamp in milliseconds high: type: integer format: int32 inheritedRiskScore: type: number format: double kev: type: integer format: int32 lastOccurrence: type: integer format: int64 description: UNIX epoch timestamp in milliseconds low: type: integer format: int32 medium: type: integer format: int32 policyViolationsAudited: type: integer format: int32 policyViolationsFail: type: integer format: int32 policyViolationsInfo: type: integer format: int32 policyViolationsLicenseAudited: type: integer format: int32 policyViolationsLicenseTotal: type: integer format: int32 policyViolationsLicenseUnaudited: type: integer format: int32 policyViolationsOperationalAudited: type: integer format: int32 policyViolationsOperationalTotal: type: integer format: int32 policyViolationsOperationalUnaudited: type: integer format: int32 policyViolationsSecurityAudited: type: integer format: int32 policyViolationsSecurityTotal: type: integer format: int32 policyViolationsSecurityUnaudited: type: integer format: int32 policyViolationsTotal: type: integer format: int32 policyViolationsUnaudited: type: integer format: int32 policyViolationsWarn: type: integer format: int32 suppressed: type: integer format: int32 unassigned: type: integer format: int32 vulnerabilities: type: integer format: int32 vulnerableComponents: type: integer format: int32 required: - firstOccurrence - lastOccurrence MappedLdapGroup: type: object properties: dn: type: string maxLength: 255 minLength: 1 pattern: '[\P{Cc}]+' uuid: type: string format: uuid required: - dn - uuid LdapUser: type: object properties: dn: type: string maxLength: 255 minLength: 1 pattern: '[\P{Cc}]+' email: type: string maxLength: 255 minLength: 0 pattern: '[\P{Cc}]+' permissions: type: array items: $ref: '#/components/schemas/Permission' teams: type: array items: $ref: '#/components/schemas/Team' username: type: string maxLength: 255 minLength: 1 pattern: '[\P{Cc}]+' required: - username OidcUser: type: object properties: email: type: string maxLength: 255 minLength: 0 pattern: '[\P{Cc}]+' permissions: type: array items: $ref: '#/components/schemas/Permission' subjectIdentifier: type: string maxLength: 255 minLength: 1 pattern: '[\P{Cc}]+' teams: type: array items: $ref: '#/components/schemas/Team' username: type: string maxLength: 255 minLength: 1 pattern: '[\P{Cc}]+' required: - username ApiKey: type: object properties: comment: type: string maxLength: 255 minLength: 0 created: type: integer format: int64 description: UNIX epoch timestamp in milliseconds expiresAt: type: integer format: int64 description: UNIX epoch timestamp in milliseconds key: type: string lastUsed: type: integer format: int64 description: UNIX epoch timestamp in milliseconds legacy: type: boolean maskedKey: type: string publicId: type: string maxLength: 8 minLength: 5 Component: type: object properties: author: type: string authors: type: array items: $ref: '#/components/schemas/OrganizationalContact' blake2b_256: type: string pattern: ^[0-9a-f]{64}$ blake2b_384: type: string pattern: ^[0-9a-f]{96}$ blake2b_512: type: string pattern: ^[0-9a-f]{128}$ blake3: type: string pattern: ^[A-Fa-f0-9]*$ children: type: array items: $ref: '#/components/schemas/Component' classifier: type: string enum: - APPLICATION - FRAMEWORK - LIBRARY - CONTAINER - OPERATING_SYSTEM - DEVICE - FIRMWARE - FILE - PLATFORM - DEVICE_DRIVER - MACHINE_LEARNING_MODEL - DATA - CRYPTOGRAPHIC_ASSET copyright: type: string maxLength: 1024 minLength: 0 pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$ cpe: type: string maxLength: 255 minLength: 0 pattern: (cpe:2\.3:[aho\*\-](:(((\?*|\*?)([a-zA-Z0-9\-\._]|(\\[\\\*\?!"#$$%&'\(\)\+,/:;<=>@\[\]\^`\{\|}~]))+(\?*|\*?))|[\*\-])){5}(:(([a-zA-Z]{2,3}(-([a-zA-Z]{2}|[0-9]{3}))?)|[\*\-]))(:(((\?*|\*?)([a-zA-Z0-9\-\._]|(\\[\\\*\?!"#$$%&'\(\)\+,/:;<=>@\[\]\^`\{\|}~]))+(\?*|\*?))|[\*\-])){4})|([c][pP][eE]:/[AHOaho]?(:[A-Za-z0-9\._\-~%]*){0,6}) dependencyGraph: type: array items: type: string format: uuid uniqueItems: true description: type: string maxLength: 1024 minLength: 0 pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$ directDependencies: type: string expandDependencyGraph: type: boolean extension: type: string maxLength: 255 minLength: 0 pattern: ^[\p{Alnum}!@#$%^&{}\[\]()_+\-=,.~'` ]{1,255}$ externalReferences: type: array items: $ref: '#/components/schemas/ExternalReference' filename: type: string maxLength: 255 minLength: 0 pattern: ^[\p{Alnum}:/\\!@#$%^&{}\[\]()_+\-=,.~'` ]{1,255}$ group: type: string maxLength: 255 minLength: 0 pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$ isInternal: type: boolean lastInheritedRiskScore: type: number format: double license: type: string maxLength: 255 minLength: 0 pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$ licenseExpression: type: string pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$ licenseUrl: type: string maxLength: 255 minLength: 0 pattern: ^((((https?|ftps?|sftp|imap|rtsp|rtmp|sip|sips|git|ssh|telnet|nntp|file)://)|(mailto:|news:))(%[0-9A-Fa-f]{2}|[-()_.!~*';/?:@&=+$,A-Za-z0-9])+)([).!';/?:,][[:blank:]])?$ md5: type: string pattern: ^[0-9a-fA-F]{32}$ metrics: $ref: '#/components/schemas/DependencyMetrics' name: type: string maxLength: 255 minLength: 1 pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$ notes: type: string occurrenceCount: type: integer format: int64 parent: $ref: '#/components/schemas/Component' project: $ref: '#/components/schemas/Project' properties: type: array items: $ref: '#/components/schemas/ComponentProperty' publisher: type: string maxLength: 255 minLength: 0 pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$ purl: type: string maxLength: 1024 minLength: 0 purlCoordinates: type: string maxLength: 1024 minLength: 0 readOnly: true repositoryMeta: $ref: '#/components/schemas/RepositoryMetaComponent' resolvedLicense: $ref: '#/components/schemas/License' scope: type: string enum: - REQUIRED - OPTIONAL - EXCLUDED maxLength: 255 minLength: 0 sha1: type: string pattern: ^[0-9a-fA-F]{40}$ sha256: type: string pattern: ^[0-9a-fA-F]{64}$ sha384: type: string pattern: ^[0-9a-fA-F]{96}$ sha3_256: type: string pattern: ^[0-9a-fA-F]{64}$ sha3_384: type: string pattern: ^[0-9a-fA-F]{96}$ sha3_512: type: string pattern: ^[0-9a-fA-F]{128}$ sha512: type: string pattern: ^[0-9a-fA-F]{128}$ streebog_256: type: string pattern: ^[0-9a-fA-F]{64}$ streebog_512: type: string pattern: ^[0-9a-fA-F]{128}$ supplier: $ref: '#/components/schemas/OrganizationalEntity' swidTagId: type: string maxLength: 255 minLength: 0 pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$ uuid: type: string format: uuid version: type: string maxLength: 255 minLength: 0 pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$ vulnerabilities: type: array items: $ref: '#/components/schemas/Vulnerability' required: - classifier - name - project - uuid ServiceComponent: type: object properties: authenticated: type: boolean bomRef: type: string children: type: array items: $ref: '#/components/schemas/ServiceComponent' crossesTrustBoundary: type: boolean data: type: array items: $ref: '#/components/schemas/DataClassification' description: type: string maxLength: 1024 minLength: 0 pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$ endpoints: type: array items: type: string externalReferences: type: array items: $ref: '#/components/schemas/ExternalReference' group: type: string maxLength: 255 minLength: 0 pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$ lastInheritedRiskScore: type: number format: double name: type: string maxLength: 255 minLength: 1 pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$ notes: type: string parent: $ref: '#/components/schemas/ServiceComponent' project: $ref: '#/components/schemas/Project' provider: $ref: '#/components/schemas/OrganizationalEntity' uuid: type: string format: uuid version: type: string maxLength: 255 minLength: 0 pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$ vulnerabilities: type: array items: $ref: '#/components/schemas/Vulnerability' required: - name - project - uuid OrganizationalContact: type: object properties: email: type: string name: type: string phone: type: string LicenseGroup: type: object properties: licenses: type: array items: $ref: '#/components/schemas/License' name: type: string maxLength: 255 minLength: 1 pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$ riskWeight: type: integer format: int32 uuid: type: string format: uuid required: - name - uuid ComponentProperty: type: object properties: description: type: string maxLength: 255 minLength: 0 pattern: \P{Cc}+ groupName: type: string maxLength: 255 minLength: 1 pattern: \P{Cc}+ propertyName: type: string maxLength: 255 minLength: 1 pattern: \P{Cc}+ propertyType: type: string enum: - BOOLEAN - INTEGER - NUMBER - STRING - TIMESTAMP - URL - UUID propertyValue: type: string maxLength: 1024 minLength: 0 pattern: \P{Cc}+ uuid: type: string format: uuid required: - propertyName - propertyType - uuid Policy: type: object properties: global: type: boolean includeChildren: type: boolean invertTagMatch: type: boolean name: type: string maxLength: 255 minLength: 1 pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$ onlyLatestProjectVersion: type: boolean operator: type: string enum: - ALL - ANY maxLength: 255 minLength: 1 pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$ policyConditions: type: array items: $ref: '#/components/schemas/PolicyCondition' projects: type: array items: $ref: '#/components/schemas/Project' tags: type: array items: $ref: '#/components/schemas/Tag' uniqueItems: true uuid: type: string format: uuid violationState: type: string enum: - INFO - WARN - FAIL maxLength: 255 minLength: 1 pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$ required: - name - operator - uuid - violationState Permission: type: object properties: description: type: string ldapUsers: type: array items: $ref: '#/components/schemas/LdapUser' managedUsers: type: array items: $ref: '#/components/schemas/ManagedUser' name: type: string maxLength: 255 minLength: 1 pattern: ^[a-zA-Z_0-9]*$ oidcUsers: type: array items: $ref: '#/components/schemas/OidcUser' required: - name OrganizationalEntity: type: object properties: contacts: type: array items: $ref: '#/components/schemas/OrganizationalContact' name: type: string urls: type: array items: type: string Team: type: object properties: apiKeys: type: array items: $ref: '#/components/schemas/ApiKey' ldapUsers: type: array items: $ref: '#/components/schemas/LdapUser' managedUsers: type: array items: $ref: '#/components/schemas/ManagedUser' mappedLdapGroups: type: array items: $ref: '#/components/schemas/MappedLdapGroup' mappedOidcGroups: type: array items: $ref: '#/components/schemas/MappedOidcGroup' name: type: string maxLength: 255 minLength: 1 pattern: '[\P{Cc}]+' oidcUsers: type: array items: $ref: '#/components/schemas/OidcUser' permissions: type: array items: $ref: '#/components/schemas/Permission' serviceAccounts: type: array items: $ref: '#/components/schemas/ServiceAccount' uuid: type: string format: uuid required: - name - uuid PolicyCondition: type: object properties: operator: type: string enum: - IS - IS_NOT - MATCHES - NO_MATCH - NUMERIC_GREATER_THAN - NUMERIC_LESS_THAN - NUMERIC_EQUAL - NUMERIC_NOT_EQUAL - NUMERIC_GREATER_THAN_OR_EQUAL - NUMERIC_LESSER_THAN_OR_EQUAL - CONTAINS_ALL - CONTAINS_ANY maxLength: 255 minLength: 1 pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$ policy: $ref: '#/components/schemas/Policy' subject: type: string enum: - AGE - COORDINATES - CPE - EXPRESSION - LICENSE - LICENSE_GROUP - PACKAGE_URL - SEVERITY - SWID_TAGID - VERSION - COMPONENT_HASH - IS_INTERNAL - CWE - VULNERABILITY_ID - VERSION_DISTANCE - EPSS maxLength: 255 minLength: 1 pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$ uuid: type: string format: uuid value: type: string maxLength: 2147483647 minLength: 1 pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$ violationType: type: string enum: - LICENSE - SECURITY - OPERATIONAL maxLength: 255 minLength: 1 pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$ required: - operator - subject - uuid - value ExternalReference: type: object properties: comment: type: string pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$ type: type: string enum: - vcs - issue-tracker - website - advisories - bom - mailing-list - social - chat - documentation - support - source-distribution - distribution - distribution-intake - license - build-meta - build-system - release-notes - security-contact - model-card - attestation - threat-model - adversary-model - risk-assessment - vulnerability-assertion - exploitability-statement - pentest-report - static-analysis-report - dynamic-analysis-report - runtime-analysis-report - component-analysis-report - maturity-report - certification-report - codified-infrastructure - quality-metrics - log - configuration - evidence - formulation - rfc-9116 - electronic-signature - digital-signature - patent - patent-family - patent-assertion - citation - poam - other url: type: string minLength: 1 required: - url License: type: object properties: isCustomLicense: type: boolean isDeprecatedLicenseId: type: boolean isFsfLibre: type: boolean isOsiApproved: type: boolean licenseComments: type: string licenseGroups: type: array items: $ref: '#/components/schemas/LicenseGroup' licenseId: type: string maxLength: 255 minLength: 1 pattern: ^[a-zA-Z0-9_.\-+]*$ licenseText: type: string name: type: string maxLength: 255 minLength: 1 pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$ seeAlso: type: array items: type: string standardLicenseHeader: type: string standardLicenseTemplate: type: string uuid: type: string format: uuid required: - licenseId - name - uuid ManagedUser: type: object properties: confirmPassword: type: string email: type: string maxLength: 255 minLength: 0 pattern: '[\P{Cc}]+' forcePasswordChange: type: boolean fullname: type: string maxLength: 255 minLength: 0 pattern: '[\P{Cc}]+' lastPasswordChange: type: integer format: int64 description: UNIX epoch timestamp in milliseconds newPassword: type: string nonExpiryPassword: type: boolean permissions: type: array items: $ref: '#/components/schemas/Permission' suspended: type: boolean teams: type: array items: $ref: '#/components/schemas/Team' username: type: string maxLength: 255 minLength: 1 pattern: '[\P{Cc}]+' required: - lastPasswordChange - username AffectedVersionAttribution: type: object properties: firstSeen: type: integer format: int64 description: UNIX epoch timestamp in milliseconds lastSeen: type: integer format: int64 deprecated: true description: Deprecated; always equal to firstSeen source: type: string enum: - NVD - GITHUB - VULNDB - OSSINDEX - INTERNAL - OSV - SNYK - CX - JVN - UNKNOWN required: - firstSeen - lastSeen VulnerabilityAlias: type: object properties: cveId: type: string pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$ cxId: type: string pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$ ghsaId: type: string pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$ gsdId: type: string pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$ internalId: type: string pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$ osvId: type: string pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$ snykId: type: string pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$ sonatypeId: type: string pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$ vulnDbId: type: string pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$ ProjectMetadata: type: object properties: authors: type: array items: $ref: '#/components/schemas/OrganizationalContact' supplier: $ref: '#/components/schemas/OrganizationalEntity' tools: $ref: '#/components/schemas/Tools' readOnly: true Project: type: object properties: accessTeams: type: array items: $ref: '#/components/schemas/Team' uniqueItems: true writeOnly: true active: type: boolean author: type: string authors: type: array items: $ref: '#/components/schemas/OrganizationalContact' bomRef: type: string children: type: array items: $ref: '#/components/schemas/Project' classifier: type: string enum: - APPLICATION - FRAMEWORK - LIBRARY - CONTAINER - OPERATING_SYSTEM - DEVICE - FIRMWARE - FILE - PLATFORM - DEVICE_DRIVER - MACHINE_LEARNING_MODEL - DATA - CRYPTOGRAPHIC_ASSET collectionLogic: type: string enum: - AGGREGATE_DIRECT_CHILDREN - AGGREGATE_DIRECT_CHILDREN_WITH_TAG - AGGREGATE_LATEST_VERSION_CHILDREN collectionTag: $ref: '#/components/schemas/Tag' cpe: type: string maxLength: 255 minLength: 0 pattern: (cpe:2\.3:[aho\*\-](:(((\?*|\*?)([a-zA-Z0-9\-\._]|(\\[\\\*\?!"#$$%&'\(\)\+,/:;<=>@\[\]\^`\{\|}~]))+(\?*|\*?))|[\*\-])){5}(:(([a-zA-Z]{2,3}(-([a-zA-Z]{2}|[0-9]{3}))?)|[\*\-]))(:(((\?*|\*?)([a-zA-Z0-9\-\._]|(\\[\\\*\?!"#$$%&'\(\)\+,/:;<=>@\[\]\^`\{\|}~]))+(\?*|\*?))|[\*\-])){4})|([c][pP][eE]:/[AHOaho]?(:[A-Za-z0-9\._\-~%]*){0,6}) description: type: string maxLength: 255 minLength: 0 pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$ directDependencies: type: string externalReferences: type: array items: $ref: '#/components/schemas/ExternalReference' group: type: string maxLength: 255 minLength: 0 pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$ inactiveSince: type: integer format: int64 description: UNIX epoch timestamp in milliseconds readOnly: true isLatest: type: boolean lastBomImport: type: integer format: int64 description: UNIX epoch timestamp in milliseconds lastBomImportFormat: type: string lastInheritedRiskScore: type: number format: double lastVulnerabilityAnalysis: type: integer format: int64 description: UNIX epoch timestamp in milliseconds manufacturer: $ref: '#/components/schemas/OrganizationalEntity' metadata: $ref: '#/components/schemas/ProjectMetadata' metrics: $ref: '#/components/schemas/ProjectMetrics' name: type: string maxLength: 255 minLength: 1 pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$ parent: $ref: '#/components/schemas/Project' publisher: type: string maxLength: 255 minLength: 0 pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$ purl: type: string maxLength: 1024 minLength: 0 supplier: $ref: '#/components/schemas/OrganizationalEntity' swidTagId: type: string maxLength: 255 minLength: 0 pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$ tags: type: array items: $ref: '#/components/schemas/Tag' uniqueItems: true uuid: type: string format: uuid version: type: string pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$ versions: type: array items: $ref: '#/components/schemas/ProjectVersion' required: - lastBomImport - name - uuid ServiceAccount: type: object properties: email: type: string maxLength: 255 minLength: 0 pattern: '[\P{Cc}]+' permissions: type: array items: $ref: '#/components/schemas/Permission' suspended: type: boolean teams: type: array items: $ref: '#/components/schemas/Team' username: type: string maxLength: 255 minLength: 1 pattern: '[\P{Cc}]+' required: - username RepositoryMetaComponent: type: object properties: lastCheck: type: integer format: int64 description: UNIX epoch timestamp in milliseconds latestVersion: type: string latestVersionPublishedAt: type: integer format: int64 description: UNIX epoch timestamp in milliseconds name: type: string namespace: type: string repositoryType: type: string enum: - MAVEN - NPM - GEM - PYPI - NUGET - HEX - COMPOSER - CARGO - GO_MODULES - CPAN - GITHUB - HACKAGE - NIXPKGS - UNSUPPORTED OidcGroup: type: object properties: name: type: string maxLength: 255 minLength: 1 pattern: '[\P{Cc}]+' uuid: type: string format: uuid required: - name - uuid Tag: type: object properties: name: type: string maxLength: 255 minLength: 1 pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$ required: - name Epss: type: object properties: cve: type: string percentile: type: number score: type: number securitySchemes: ApiKeyAuth: description: Authentication via API key. in: header name: X-Api-Key type: apiKey BearerAuth: bearerFormat: Opaque description: 'Authentication via opaque server-issued session token. Tokens are obtained from `POST /api/v1/user/login` or `POST /api/v1/user/oidc/login`.' scheme: bearer type: http x-refined-from: - dependency-track-openapi-v1.yaml - dependency-track-openapi.yml