openapi: 3.2.0 info: title: Dependency Track Project API version: 1.0.0 contact: name: The Dependency-Track Authors url: https://github.com/DependencyTrack/dependency-track license: name: Apache-2.0 url: https://www.apache.org/licenses/LICENSE-2.0.html description: 'Operations tagged project across 2 of this provider''s published API definitions: dependency-track-openapi-v1.yaml, dependency-track-openapi.yml. Each path carries the servers of the definition it was published in.' servers: - url: /api tags: - name: Project paths: /v1/project: get: description: Requires permission VIEW_PORTFOLIO operationId: getProjects parameters: - description: The page to return. To be used in conjunction with pageSize. in: query name: pageNumber schema: type: string default: '1' - description: Number of elements to return per page. To be used in conjunction with pageNumber. in: query name: pageSize schema: type: string default: '100' - description: Offset to start returning elements from. To be used in conjunction with limit. in: query name: offset schema: type: string - description: Number of elements to return per page. To be used in conjunction with offset. in: query name: limit schema: type: string - description: Name of the resource field to sort on. in: query name: sortName schema: type: string - description: Ordering of items when sorting with sortName. in: query name: sortOrder schema: type: string enum: - asc, desc - description: The optional name of the project to query on in: query name: name schema: type: string - description: Optionally excludes inactive projects from being returned in: query name: excludeInactive schema: type: boolean - description: Optionally excludes children projects from being returned in: query name: onlyRoot schema: type: boolean - description: The UUID of the team which projects shall be excluded in: query name: notAssignedToTeamWithUuid schema: type: string format: uuid responses: '200': content: application/json: schema: type: array items: $ref: '#/components/schemas/ListProjectsResponseItem' description: A list of all projects headers: X-Total-Count: description: The total number of projects schema: format: integer style: simple '401': description: Unauthorized security: - ApiKeyAuth: [] - BearerAuth: [] summary: Returns a list of all projects tags: - Project post: description: 'To re-parent the project, set parent to an object containing the new parent''s uuid. Omit parent (or set it to null) to remove the parent. Providing parent without a non-null uuid is rejected with 400. Requires permission PORTFOLIO_MANAGEMENT or PORTFOLIO_MANAGEMENT_UPDATE' operationId: updateProject requestBody: content: application/json: schema: $ref: '#/components/schemas/Project' responses: '200': content: application/json: schema: $ref: '#/components/schemas/Project' description: The updated project '400': description: Bad Request '401': description: Unauthorized '403': content: application/problem+json: schema: $ref: '#/components/schemas/ProblemDetails' description: Access to the project, the provided parent, or the previous latest project version, is forbidden '404': description: The UUID of the project could not be found '409': description: "" security: - ApiKeyAuth: [] - BearerAuth: [] summary: Updates a project tags: - Project put: description: 'To create the project under a parent, set parent to an object containing the parent''s uuid. To create a top-level project, omit parent or set it to null. Providing parent without a non-null uuid is rejected with 400. When portfolio access control is enabled, one or more teams to grant access to can be provided via accessTeams. Either uuid or name of a team must be specified. Only teams which the authenticated principal is a member of can be assigned. Principals with ACCESS_MANAGEMENT permission can assign any team. Requires permission PORTFOLIO_MANAGEMENT or PORTFOLIO_MANAGEMENT_CREATE' operationId: createProject requestBody: content: application/json: schema: $ref: '#/components/schemas/Project' responses: '201': content: application/json: schema: $ref: '#/components/schemas/Project' description: The created project '400': description: Bad Request '401': description: Unauthorized '403': content: application/problem+json: schema: $ref: '#/components/schemas/ProblemDetails' description: Access to the provided parent project, or previous latest project version, is forbidden '409': description: "" security: - ApiKeyAuth: [] - BearerAuth: [] summary: Creates a new project tags: - Project servers: - url: /api /v1/project/batchDelete: post: description: Requires permission PORTFOLIO_MANAGEMENT or PORTFOLIO_MANAGEMENT_DELETE operationId: deleteProjects requestBody: content: application/json: schema: type: array items: type: string format: uuid maxItems: 1000 minItems: 1 uniqueItems: true responses: '204': description: Projects removed successfully '401': description: Unauthorized security: - ApiKeyAuth: [] - BearerAuth: [] summary: Deletes a list of projects specified by their UUIDs tags: - Project servers: - url: /api /v1/project/classifier/{classifier}: get: description: Requires permission VIEW_PORTFOLIO operationId: getProjectsByClassifier parameters: - description: The page to return. To be used in conjunction with pageSize. in: query name: pageNumber schema: type: string default: '1' - description: Number of elements to return per page. To be used in conjunction with pageNumber. in: query name: pageSize schema: type: string default: '100' - description: Offset to start returning elements from. To be used in conjunction with limit. in: query name: offset schema: type: string - description: Number of elements to return per page. To be used in conjunction with offset. in: query name: limit schema: type: string - description: Name of the resource field to sort on. in: query name: sortName schema: type: string - description: Ordering of items when sorting with sortName. in: query name: sortOrder schema: type: string enum: - asc, desc - description: The classifier to query on in: path name: classifier required: true schema: type: string enum: - APPLICATION - FRAMEWORK - LIBRARY - CONTAINER - OPERATING_SYSTEM - DEVICE - FIRMWARE - FILE - PLATFORM - DEVICE_DRIVER - MACHINE_LEARNING_MODEL - DATA - CRYPTOGRAPHIC_ASSET - description: Optionally excludes inactive projects from being returned in: query name: excludeInactive schema: type: boolean - description: Optionally excludes children projects from being returned in: query name: onlyRoot schema: type: boolean responses: '200': content: application/json: schema: type: array items: $ref: '#/components/schemas/ListProjectsResponseItem' description: A list of all projects by classifier headers: X-Total-Count: description: The total number of projects schema: format: integer style: simple '401': description: Unauthorized security: - ApiKeyAuth: [] - BearerAuth: [] summary: Returns a list of all projects by classifier tags: - Project servers: - url: /api /v1/project/clone: put: deprecated: true description: 'Requires permission PORTFOLIO_MANAGEMENT or PORTFOLIO_MANAGEMENT_CREATE Deprecated! Use /api/v2/projects/{uuid}/clone instead.' operationId: cloneProject requestBody: content: application/json: schema: $ref: '#/components/schemas/CloneProjectRequest' responses: '200': content: application/json: schema: $ref: '#/components/schemas/BomUploadResponse' description: Token to be used for checking cloning progress '401': description: Unauthorized '403': content: application/problem+json: schema: $ref: '#/components/schemas/ProblemDetails' description: Access to the requested project, or the previous latest project version, is forbidden '404': description: The UUID of the project could not be found security: - ApiKeyAuth: [] - BearerAuth: [] summary: Clones a project tags: - Project servers: - url: /api /v1/project/concise: get: description: Requires permission VIEW_PORTFOLIO operationId: getProjectsConcise parameters: - description: The page to return. To be used in conjunction with pageSize. in: query name: pageNumber schema: type: string default: '1' - description: Number of elements to return per page. To be used in conjunction with pageNumber. in: query name: pageSize schema: type: string default: '100' - description: Offset to start returning elements from. To be used in conjunction with limit. in: query name: offset schema: type: string - description: Number of elements to return per page. To be used in conjunction with offset. in: query name: limit schema: type: string - description: Name of the resource field to sort on. in: query name: sortName schema: type: string - description: Ordering of items when sorting with sortName. in: query name: sortOrder schema: type: string enum: - asc, desc - description: Name to filter on. Must be exact match. in: query name: name schema: type: string - description: Version to filter on. Must be exact match. in: query name: version schema: type: string - description: Classifier to filter on. Must be exact match. in: query name: classifier schema: type: string - description: Tag to filter on. Must be exact match. in: query name: tag schema: type: string - description: Team to filter on. Must be exact match. in: query name: team schema: type: string - description: Whether to show only active, or only inactive projects. in: query name: active schema: type: boolean - description: Whether to show only root projects, i.e. those without a parent. in: query name: onlyRoot schema: type: boolean - description: Whether to include metrics in the response. in: query name: includeMetrics schema: type: boolean responses: '200': content: application/json: schema: type: array items: $ref: '#/components/schemas/ConciseProject' description: A list of all projects in concise representation headers: X-Total-Count: description: The total number of projects schema: format: integer style: simple '401': description: Unauthorized security: - ApiKeyAuth: [] - BearerAuth: [] summary: Returns a list of all projects, in a concise representation tags: - Project servers: - url: /api /v1/project/concise/{uuid}/children: get: description: Requires permission VIEW_PORTFOLIO operationId: getProjectChildrenConcise parameters: - description: The page to return. To be used in conjunction with pageSize. in: query name: pageNumber schema: type: string default: '1' - description: Number of elements to return per page. To be used in conjunction with pageNumber. in: query name: pageSize schema: type: string default: '100' - description: Offset to start returning elements from. To be used in conjunction with limit. in: query name: offset schema: type: string - description: Number of elements to return per page. To be used in conjunction with offset. in: query name: limit schema: type: string - description: Name of the resource field to sort on. in: query name: sortName schema: type: string - description: Ordering of items when sorting with sortName. in: query name: sortOrder schema: type: string enum: - asc, desc - description: UUID of the project in: path name: uuid required: true schema: type: string - description: Name to filter on. Must be exact match. in: query name: name schema: type: string - description: Version to filter on. Must be exact match. in: query name: version schema: type: string - description: Classifier to filter on. Must be exact match. in: query name: classifier schema: type: string - description: Tag to filter on. Must be exact match. in: query name: tag schema: type: string - description: Team to filter on. Must be exact match. in: query name: team schema: type: string - description: Whether to show only active, or only inactive projects. Omitting the filter will show both. in: query name: active schema: type: boolean - description: Whether to include metrics in the response. in: query name: includeMetrics schema: type: boolean responses: '200': content: application/json: schema: type: array items: $ref: '#/components/schemas/ConciseProject' description: A list of all child projects in a concise representation headers: X-Total-Count: description: The total number of child projects schema: format: integer style: simple '401': description: Unauthorized security: - ApiKeyAuth: [] - BearerAuth: [] summary: Returns a list of a given project's children, in a concise representation tags: - Project servers: - url: /api /v1/project/latest/{name}: get: description: Requires permission VIEW_PORTFOLIO operationId: getLatestProjectByName parameters: - description: The name of the project to retrieve the latest version of in: path name: name required: true schema: type: string responses: '200': content: application/json: schema: $ref: '#/components/schemas/Project' description: The latest version of the specified project '401': description: Unauthorized '403': content: application/problem+json: schema: $ref: '#/components/schemas/ProblemDetails' description: Access to the requested project is forbidden '404': description: The project could not be found security: - ApiKeyAuth: [] - BearerAuth: [] summary: Returns the latest version of a project by its name tags: - Project servers: - url: /api /v1/project/lookup: get: description: Requires permission VIEW_PORTFOLIO operationId: getProjectByNameAndVersion parameters: - description: The name of the project to query on in: query name: name required: true schema: type: string - description: The version of the project to query on in: query name: version schema: type: string responses: '200': content: application/json: schema: $ref: '#/components/schemas/Project' description: A specific project by its name and version '401': description: Unauthorized '403': content: application/problem+json: schema: $ref: '#/components/schemas/ProblemDetails' description: Access to the requested project is forbidden '404': description: The project could not be found security: - ApiKeyAuth: [] - BearerAuth: [] summary: Returns a specific project by its name and version tags: - Project servers: - url: /api /v1/project/tag/{tag}: get: description: Requires permission VIEW_PORTFOLIO operationId: getProjectsByTag parameters: - description: The page to return. To be used in conjunction with pageSize. in: query name: pageNumber schema: type: string default: '1' - description: Number of elements to return per page. To be used in conjunction with pageNumber. in: query name: pageSize schema: type: string default: '100' - description: Offset to start returning elements from. To be used in conjunction with limit. in: query name: offset schema: type: string - description: Number of elements to return per page. To be used in conjunction with offset. in: query name: limit schema: type: string - description: Name of the resource field to sort on. in: query name: sortName schema: type: string - description: Ordering of items when sorting with sortName. in: query name: sortOrder schema: type: string enum: - asc, desc - description: The tag to query on in: path name: tag required: true schema: type: string - description: Optionally excludes inactive projects from being returned in: query name: excludeInactive schema: type: boolean - description: Optionally excludes children projects from being returned in: query name: onlyRoot schema: type: boolean responses: '200': content: application/json: schema: type: array items: $ref: '#/components/schemas/ListProjectsResponseItem' description: A list of all projects by tag headers: X-Total-Count: description: The total number of projects schema: format: integer style: simple '401': description: Unauthorized security: - ApiKeyAuth: [] - BearerAuth: [] summary: Returns a list of all projects by tag tags: - Project servers: - url: /api /v1/project/withoutDescendantsOf/{uuid}: get: description: Requires permission VIEW_PORTFOLIO operationId: getProjectsWithoutDescendantsOf parameters: - description: The page to return. To be used in conjunction with pageSize. in: query name: pageNumber schema: type: string default: '1' - description: Number of elements to return per page. To be used in conjunction with pageNumber. in: query name: pageSize schema: type: string default: '100' - description: Offset to start returning elements from. To be used in conjunction with limit. in: query name: offset schema: type: string - description: Number of elements to return per page. To be used in conjunction with offset. in: query name: limit schema: type: string - description: Name of the resource field to sort on. in: query name: sortName schema: type: string - description: Ordering of items when sorting with sortName. in: query name: sortOrder schema: type: string enum: - asc, desc - description: The UUID of the project which descendants will be excluded in: path name: uuid required: true schema: type: string format: uuid - description: The optional name of the project to query on in: query name: name schema: type: string - description: Optionally excludes inactive projects from being returned in: query name: excludeInactive schema: type: boolean responses: '200': content: application/json: schema: type: array items: $ref: '#/components/schemas/ListProjectsResponseItem' description: A list of all projects without the descendants of the selected project headers: X-Total-Count: description: The total number of projects schema: format: integer style: simple '401': description: Unauthorized '403': content: application/problem+json: schema: $ref: '#/components/schemas/ProblemDetails' description: Access to the requested project is forbidden '404': description: The UUID of the project could not be found security: - ApiKeyAuth: [] - BearerAuth: [] summary: Returns a list of all projects without the descendants of the selected project tags: - Project servers: - url: /api /v1/project/{uuid}: delete: description: Requires permission PORTFOLIO_MANAGEMENT or PORTFOLIO_MANAGEMENT_DELETE operationId: deleteProject parameters: - description: The UUID of the project to delete in: path name: uuid required: true schema: type: string format: uuid responses: '204': description: Project removed successfully '401': description: Unauthorized '403': content: application/problem+json: schema: $ref: '#/components/schemas/ProblemDetails' description: Access to the requested project is forbidden '404': content: application/problem+json: schema: $ref: '#/components/schemas/ProblemDetails' description: The UUID of the project could not be found '500': description: Unable to delete components of the project security: - ApiKeyAuth: [] - BearerAuth: [] summary: Deletes a project tags: - Project get: description: Requires permission VIEW_PORTFOLIO operationId: getProject parameters: - description: The UUID of the project to retrieve in: path name: uuid required: true schema: type: string format: uuid responses: '200': content: application/json: schema: $ref: '#/components/schemas/Project' description: A specific project '401': description: Unauthorized '403': content: application/problem+json: schema: $ref: '#/components/schemas/ProblemDetails' description: Access to the requested project is forbidden '404': description: The project could not be found security: - ApiKeyAuth: [] - BearerAuth: [] summary: Returns a specific project tags: - Project patch: description: 'To re-parent the project, set parent to an object containing the new parent''s uuid. Omit parent (or set it to null) to leave the parent unchanged. Providing parent without a non-null uuid is rejected with 400. Requires permission PORTFOLIO_MANAGEMENT or PORTFOLIO_MANAGEMENT_UPDATE' operationId: patchProject parameters: - description: The UUID of the project to modify in: path name: uuid required: true schema: type: string format: uuid requestBody: content: application/json: schema: $ref: '#/components/schemas/Project' responses: '200': content: application/json: schema: $ref: '#/components/schemas/Project' description: The updated project '400': description: Bad Request '401': description: Unauthorized '403': content: application/problem+json: schema: $ref: '#/components/schemas/ProblemDetails' description: Access to the requested project, the provided parent, or the previous latest project version, is forbidden '404': description: The UUID of the project could not be found '409': description: "" security: - ApiKeyAuth: [] - BearerAuth: [] summary: Partially updates a project tags: - Project servers: - url: /api /v1/project/{uuid}/children: get: description: Requires permission VIEW_PORTFOLIO operationId: getChildrenProjects parameters: - description: The page to return. To be used in conjunction with pageSize. in: query name: pageNumber schema: type: string default: '1' - description: Number of elements to return per page. To be used in conjunction with pageNumber. in: query name: pageSize schema: type: string default: '100' - description: Offset to start returning elements from. To be used in conjunction with limit. in: query name: offset schema: type: string - description: Number of elements to return per page. To be used in conjunction with offset. in: query name: limit schema: type: string - description: Name of the resource field to sort on. in: query name: sortName schema: type: string - description: Ordering of items when sorting with sortName. in: query name: sortOrder schema: type: string enum: - asc, desc - description: The UUID of the project to get the children from in: path name: uuid required: true schema: type: string format: uuid - description: Optionally excludes inactive projects from being returned in: query name: excludeInactive schema: type: boolean responses: '200': content: application/json: schema: type: array items: $ref: '#/components/schemas/ListProjectsResponseItem' description: A list of all children for a project headers: X-Total-Count: description: The total number of projects schema: format: integer style: simple '401': description: Unauthorized '403': content: application/problem+json: schema: $ref: '#/components/schemas/ProblemDetails' description: Access to the requested project is forbidden '404': description: The UUID of the project could not be found security: - ApiKeyAuth: [] - BearerAuth: [] summary: Returns a list of all children for a project tags: - Project servers: - url: /api /v1/project/{uuid}/children/classifier/{classifier}: get: description: Requires permission VIEW_PORTFOLIO operationId: getChildrenProjectsByClassifier parameters: - description: The page to return. To be used in conjunction with pageSize. in: query name: pageNumber schema: type: string default: '1' - description: Number of elements to return per page. To be used in conjunction with pageNumber. in: query name: pageSize schema: type: string default: '100' - description: Offset to start returning elements from. To be used in conjunction with limit. in: query name: offset schema: type: string - description: Number of elements to return per page. To be used in conjunction with offset. in: query name: limit schema: type: string - description: Name of the resource field to sort on. in: query name: sortName schema: type: string - description: Ordering of items when sorting with sortName. in: query name: sortOrder schema: type: string enum: - asc, desc - description: The classifier to query on in: path name: classifier required: true schema: type: string enum: - APPLICATION - FRAMEWORK - LIBRARY - CONTAINER - OPERATING_SYSTEM - DEVICE - FIRMWARE - FILE - PLATFORM - DEVICE_DRIVER - MACHINE_LEARNING_MODEL - DATA - CRYPTOGRAPHIC_ASSET - description: The UUID of the project to get the children from in: path name: uuid required: true schema: type: string format: uuid - description: Optionally excludes inactive projects from being returned in: query name: excludeInactive schema: type: boolean responses: '200': content: application/json: schema: type: array items: $ref: '#/components/schemas/ListProjectsResponseItem' description: A list of all children for a project by classifier headers: X-Total-Count: description: The total number of projects schema: format: integer style: simple '401': description: Unauthorized '403': content: application/problem+json: schema: $ref: '#/components/schemas/ProblemDetails' description: Access to the requested project is forbidden '404': description: The UUID of the project could not be found security: - ApiKeyAuth: [] - BearerAuth: [] summary: Returns a list of all children for a project by classifier tags: - Project servers: - url: /api /v1/project/{uuid}/children/tag/{tag}: get: description: Requires permission VIEW_PORTFOLIO operationId: getChildrenProjectsByTag parameters: - description: The page to return. To be used in conjunction with pageSize. in: query name: pageNumber schema: type: string default: '1' - description: Number of elements to return per page. To be used in conjunction with pageNumber. in: query name: pageSize schema: type: string default: '100' - description: Offset to start returning elements from. To be used in conjunction with limit. in: query name: offset schema: type: string - description: Number of elements to return per page. To be used in conjunction with offset. in: query name: limit schema: type: string - description: Name of the resource field to sort on. in: query name: sortName schema: type: string - description: Ordering of items when sorting with sortName. in: query name: sortOrder schema: type: string enum: - asc, desc - description: The tag to query on in: path name: tag required: true schema: type: string - description: The UUID of the project to get the children from in: path name: uuid required: true schema: type: string format: uuid - description: Optionally excludes inactive projects from being returned in: query name: excludeInactive schema: type: boolean responses: '200': content: application/json: schema: type: array items: $ref: '#/components/schemas/ListProjectsResponseItem' description: A list of all children for a project by tag headers: X-Total-Count: description: The total number of projects schema: format: integer style: simple '401': description: Unauthorized '403': content: application/problem+json: schema: $ref: '#/components/schemas/ProblemDetails' description: Access to the requested project is forbidden '404': description: The UUID of the project could not be found security: - ApiKeyAuth: [] - BearerAuth: [] summary: Returns a list of all children for a project by tag tags: - Project servers: - url: /api components: schemas: AffectedComponent: type: object properties: affectedVersionAttributions: type: array items: $ref: '#/components/schemas/AffectedVersionAttribution' identity: type: string identityType: type: string enum: - CPE - PURL uuid: type: string format: uuid version: type: string versionEndExcluding: type: string versionEndIncluding: type: string versionStartExcluding: type: string versionStartIncluding: type: string versionType: type: string enum: - EXACT - RANGE DataClassification: type: object properties: direction: type: string enum: - INBOUND - OUTBOUND - BI_DIRECTIONAL - UNKNOWN name: type: string Cwe: type: object properties: cweId: type: integer format: int32 name: type: string pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$ ConciseProject: type: object description: A concise representation of a project properties: active: type: boolean description: Whether the project is active classifier: type: string description: Classifier of the project enum: - APPLICATION - FRAMEWORK - LIBRARY - CONTAINER - OPERATING_SYSTEM - DEVICE - FIRMWARE - FILE - PLATFORM - DEVICE_DRIVER - MACHINE_LEARNING_MODEL - DATA - CRYPTOGRAPHIC_ASSET collectionLogic: type: string description: Collection logic for aggregating child metrics enum: - AGGREGATE_DIRECT_CHILDREN - AGGREGATE_DIRECT_CHILDREN_WITH_TAG - AGGREGATE_LATEST_VERSION_CHILDREN group: type: string description: Group or namespace of the project hasChildren: type: boolean description: Whether the project has children isLatest: type: boolean description: Whether the project version is latest lastBomImport: type: integer format: int64 description: Timestamp of the last BOM import lastBomImportFormat: type: string description: Format of the last imported BOM lastRiskScore: type: number format: double description: Last observed risk score metrics: $ref: '#/components/schemas/ConciseProjectMetrics' name: type: string description: Name of the project tags: type: array description: Tags associated with the project items: $ref: '#/components/schemas/Tag' teams: type: array description: Teams associated with the project items: $ref: '#/components/schemas/Team' uuid: type: string format: uuid description: UUID of the project version: type: string description: Version of the project required: - active - hasChildren - name - uuid Tools: type: object properties: components: type: array items: $ref: '#/components/schemas/Component' services: type: array items: $ref: '#/components/schemas/ServiceComponent' Vulnerability: type: object properties: affectedActiveProjectCount: type: integer format: int32 affectedComponents: type: array items: $ref: '#/components/schemas/AffectedComponent' affectedInactiveProjectCount: type: integer format: int32 affectedProjectCount: type: integer format: int32 aliases: type: array items: $ref: '#/components/schemas/VulnerabilityAlias' components: type: array items: $ref: '#/components/schemas/Component' created: type: string format: date-time credits: type: string pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$ cvssV2BaseScore: type: number cvssV2ExploitabilitySubScore: type: number cvssV2ImpactSubScore: type: number cvssV2Vector: type: string pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$ cvssV3BaseScore: type: number cvssV3ExploitabilitySubScore: type: number cvssV3ImpactSubScore: type: number cvssV3Vector: type: string pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$ cvssV4Score: type: number cvssV4Vector: type: string pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$ cwes: type: array items: $ref: '#/components/schemas/Cwe' description: type: string pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$ detail: type: string pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$ epss: $ref: '#/components/schemas/Epss' epssPercentile: type: number epssScore: type: number friendlyVulnId: type: string maxLength: 255 minLength: 1 pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$ isKev: type: boolean owaspRRBusinessImpactScore: type: number owaspRRLikelihoodScore: type: number owaspRRTechnicalImpactScore: type: number owaspRRVector: type: string pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$ patchedVersions: type: string pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$ published: type: string format: date-time recommendation: type: string pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$ references: type: string pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$ rejected: type: string format: date-time serviceComponents: type: array items: $ref: '#/components/schemas/ServiceComponent' severity: type: string enum: - CRITICAL - HIGH - MEDIUM - LOW - INFO - UNASSIGNED pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$ source: type: string maxLength: 255 minLength: 1 pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$ subTitle: type: string pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$ tags: type: array items: $ref: '#/components/schemas/Tag' uniqueItems: true title: type: string pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$ updated: type: string format: date-time uuid: type: string format: uuid vulnId: type: string maxLength: 255 minLength: 1 pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$ vulnerableVersions: type: string pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$ required: - friendlyVulnId - source - uuid - vulnId ProblemDetails: type: object description: An RFC 9457 problem object properties: detail: type: string description: Human-readable explanation specific to this occurrence of the problem example: Example detail instance: type: string format: uri description: Reference URI that identifies the specific occurrence of the problem example: https://api.example.org/foo/bar/example-instance status: type: integer format: int32 description: HTTP status code generated by the origin server for this occurrence of the problem example: 400 title: type: string description: Short, human-readable summary of the problem type example: Example title type: type: string format: uri description: A URI reference that identifies the problem type example: https://api.example.org/foo/bar/example-problem required: - detail - status - title DependencyMetrics: type: object properties: critical: type: integer format: int32 findingsAudited: type: integer format: int32 findingsTotal: type: integer format: int32 findingsUnaudited: type: integer format: int32 firstOccurrence: type: integer format: int64 description: UNIX epoch timestamp in milliseconds high: type: integer format: int32 inheritedRiskScore: type: number format: double kev: type: integer format: int32 lastOccurrence: type: integer format: int64 description: UNIX epoch timestamp in milliseconds low: type: integer format: int32 medium: type: integer format: int32 policyViolationsAudited: type: integer format: int32 policyViolationsFail: type: integer format: int32 policyViolationsInfo: type: integer format: int32 policyViolationsLicenseAudited: type: integer format: int32 policyViolationsLicenseTotal: type: integer format: int32 policyViolationsLicenseUnaudited: type: integer format: int32 policyViolationsOperationalAudited: type: integer format: int32 policyViolationsOperationalTotal: type: integer format: int32 policyViolationsOperationalUnaudited: type: integer format: int32 policyViolationsSecurityAudited: type: integer format: int32 policyViolationsSecurityTotal: type: integer format: int32 policyViolationsSecurityUnaudited: type: integer format: int32 policyViolationsTotal: type: integer format: int32 policyViolationsUnaudited: type: integer format: int32 policyViolationsWarn: type: integer format: int32 suppressed: type: integer format: int32 unassigned: type: integer format: int32 vulnerabilities: type: integer format: int32 required: - firstOccurrence - lastOccurrence ProjectVersion: type: object properties: active: type: boolean isLatest: type: boolean uuid: type: string format: uuid version: type: string MappedOidcGroup: type: object properties: group: $ref: '#/components/schemas/OidcGroup' uuid: type: string format: uuid required: - uuid ProjectMetrics: type: object properties: components: type: integer format: int32 critical: type: integer format: int32 findingsAudited: type: integer format: int32 findingsTotal: type: integer format: int32 findingsUnaudited: type: integer format: int32 firstOccurrence: type: integer format: int64 description: UNIX epoch timestamp in milliseconds high: type: integer format: int32 inheritedRiskScore: type: number format: double kev: type: integer format: int32 lastOccurrence: type: integer format: int64 description: UNIX epoch timestamp in milliseconds low: type: integer format: int32 medium: type: integer format: int32 policyViolationsAudited: type: integer format: int32 policyViolationsFail: type: integer format: int32 policyViolationsInfo: type: integer format: int32 policyViolationsLicenseAudited: type: integer format: int32 policyViolationsLicenseTotal: type: integer format: int32 policyViolationsLicenseUnaudited: type: integer format: int32 policyViolationsOperationalAudited: type: integer format: int32 policyViolationsOperationalTotal: type: integer format: int32 policyViolationsOperationalUnaudited: type: integer format: int32 policyViolationsSecurityAudited: type: integer format: int32 policyViolationsSecurityTotal: type: integer format: int32 policyViolationsSecurityUnaudited: type: integer format: int32 policyViolationsTotal: type: integer format: int32 policyViolationsUnaudited: type: integer format: int32 policyViolationsWarn: type: integer format: int32 suppressed: type: integer format: int32 unassigned: type: integer format: int32 vulnerabilities: type: integer format: int32 vulnerableComponents: type: integer format: int32 required: - firstOccurrence - lastOccurrence CloneProjectRequest: type: object properties: includeACL: type: boolean writeOnly: true includeAuditHistory: type: boolean writeOnly: true includeComponents: type: boolean writeOnly: true includeDependencies: type: boolean writeOnly: true includePolicyViolations: type: boolean writeOnly: true includeProperties: type: boolean writeOnly: true includeServices: type: boolean writeOnly: true includeTags: type: boolean writeOnly: true makeCloneLatest: type: boolean writeOnly: true project: type: string pattern: ^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$ version: type: string minLength: 1 pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$ required: - project - version MappedLdapGroup: type: object properties: dn: type: string maxLength: 255 minLength: 1 pattern: '[\P{Cc}]+' uuid: type: string format: uuid required: - dn - uuid LdapUser: type: object properties: dn: type: string maxLength: 255 minLength: 1 pattern: '[\P{Cc}]+' email: type: string maxLength: 255 minLength: 0 pattern: '[\P{Cc}]+' permissions: type: array items: $ref: '#/components/schemas/Permission' teams: type: array items: $ref: '#/components/schemas/Team' username: type: string maxLength: 255 minLength: 1 pattern: '[\P{Cc}]+' required: - username OidcUser: type: object properties: email: type: string maxLength: 255 minLength: 0 pattern: '[\P{Cc}]+' permissions: type: array items: $ref: '#/components/schemas/Permission' subjectIdentifier: type: string maxLength: 255 minLength: 1 pattern: '[\P{Cc}]+' teams: type: array items: $ref: '#/components/schemas/Team' username: type: string maxLength: 255 minLength: 1 pattern: '[\P{Cc}]+' required: - username ApiKey: type: object properties: comment: type: string maxLength: 255 minLength: 0 created: type: integer format: int64 description: UNIX epoch timestamp in milliseconds expiresAt: type: integer format: int64 description: UNIX epoch timestamp in milliseconds key: type: string lastUsed: type: integer format: int64 description: UNIX epoch timestamp in milliseconds legacy: type: boolean maskedKey: type: string publicId: type: string maxLength: 8 minLength: 5 Component: type: object properties: author: type: string authors: type: array items: $ref: '#/components/schemas/OrganizationalContact' blake2b_256: type: string pattern: ^[0-9a-f]{64}$ blake2b_384: type: string pattern: ^[0-9a-f]{96}$ blake2b_512: type: string pattern: ^[0-9a-f]{128}$ blake3: type: string pattern: ^[A-Fa-f0-9]*$ children: type: array items: $ref: '#/components/schemas/Component' classifier: type: string enum: - APPLICATION - FRAMEWORK - LIBRARY - CONTAINER - OPERATING_SYSTEM - DEVICE - FIRMWARE - FILE - PLATFORM - DEVICE_DRIVER - MACHINE_LEARNING_MODEL - DATA - CRYPTOGRAPHIC_ASSET copyright: type: string maxLength: 1024 minLength: 0 pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$ cpe: type: string maxLength: 255 minLength: 0 pattern: (cpe:2\.3:[aho\*\-](:(((\?*|\*?)([a-zA-Z0-9\-\._]|(\\[\\\*\?!"#$$%&'\(\)\+,/:;<=>@\[\]\^`\{\|}~]))+(\?*|\*?))|[\*\-])){5}(:(([a-zA-Z]{2,3}(-([a-zA-Z]{2}|[0-9]{3}))?)|[\*\-]))(:(((\?*|\*?)([a-zA-Z0-9\-\._]|(\\[\\\*\?!"#$$%&'\(\)\+,/:;<=>@\[\]\^`\{\|}~]))+(\?*|\*?))|[\*\-])){4})|([c][pP][eE]:/[AHOaho]?(:[A-Za-z0-9\._\-~%]*){0,6}) dependencyGraph: type: array items: type: string format: uuid uniqueItems: true description: type: string maxLength: 1024 minLength: 0 pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$ directDependencies: type: string expandDependencyGraph: type: boolean extension: type: string maxLength: 255 minLength: 0 pattern: ^[\p{Alnum}!@#$%^&{}\[\]()_+\-=,.~'` ]{1,255}$ externalReferences: type: array items: $ref: '#/components/schemas/ExternalReference' filename: type: string maxLength: 255 minLength: 0 pattern: ^[\p{Alnum}:/\\!@#$%^&{}\[\]()_+\-=,.~'` ]{1,255}$ group: type: string maxLength: 255 minLength: 0 pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$ isInternal: type: boolean lastInheritedRiskScore: type: number format: double license: type: string maxLength: 255 minLength: 0 pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$ licenseExpression: type: string pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$ licenseUrl: type: string maxLength: 255 minLength: 0 pattern: ^((((https?|ftps?|sftp|imap|rtsp|rtmp|sip|sips|git|ssh|telnet|nntp|file)://)|(mailto:|news:))(%[0-9A-Fa-f]{2}|[-()_.!~*';/?:@&=+$,A-Za-z0-9])+)([).!';/?:,][[:blank:]])?$ md5: type: string pattern: ^[0-9a-fA-F]{32}$ metrics: $ref: '#/components/schemas/DependencyMetrics' name: type: string maxLength: 255 minLength: 1 pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$ notes: type: string occurrenceCount: type: integer format: int64 parent: $ref: '#/components/schemas/Component' project: $ref: '#/components/schemas/Project' properties: type: array items: $ref: '#/components/schemas/ComponentProperty' publisher: type: string maxLength: 255 minLength: 0 pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$ purl: type: string maxLength: 1024 minLength: 0 purlCoordinates: type: string maxLength: 1024 minLength: 0 readOnly: true repositoryMeta: $ref: '#/components/schemas/RepositoryMetaComponent' resolvedLicense: $ref: '#/components/schemas/License' scope: type: string enum: - REQUIRED - OPTIONAL - EXCLUDED maxLength: 255 minLength: 0 sha1: type: string pattern: ^[0-9a-fA-F]{40}$ sha256: type: string pattern: ^[0-9a-fA-F]{64}$ sha384: type: string pattern: ^[0-9a-fA-F]{96}$ sha3_256: type: string pattern: ^[0-9a-fA-F]{64}$ sha3_384: type: string pattern: ^[0-9a-fA-F]{96}$ sha3_512: type: string pattern: ^[0-9a-fA-F]{128}$ sha512: type: string pattern: ^[0-9a-fA-F]{128}$ streebog_256: type: string pattern: ^[0-9a-fA-F]{64}$ streebog_512: type: string pattern: ^[0-9a-fA-F]{128}$ supplier: $ref: '#/components/schemas/OrganizationalEntity' swidTagId: type: string maxLength: 255 minLength: 0 pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$ uuid: type: string format: uuid version: type: string maxLength: 255 minLength: 0 pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$ vulnerabilities: type: array items: $ref: '#/components/schemas/Vulnerability' required: - classifier - name - project - uuid ServiceComponent: type: object properties: authenticated: type: boolean bomRef: type: string children: type: array items: $ref: '#/components/schemas/ServiceComponent' crossesTrustBoundary: type: boolean data: type: array items: $ref: '#/components/schemas/DataClassification' description: type: string maxLength: 1024 minLength: 0 pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$ endpoints: type: array items: type: string externalReferences: type: array items: $ref: '#/components/schemas/ExternalReference' group: type: string maxLength: 255 minLength: 0 pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$ lastInheritedRiskScore: type: number format: double name: type: string maxLength: 255 minLength: 1 pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$ notes: type: string parent: $ref: '#/components/schemas/ServiceComponent' project: $ref: '#/components/schemas/Project' provider: $ref: '#/components/schemas/OrganizationalEntity' uuid: type: string format: uuid version: type: string maxLength: 255 minLength: 0 pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$ vulnerabilities: type: array items: $ref: '#/components/schemas/Vulnerability' required: - name - project - uuid OrganizationalContact: type: object properties: email: type: string name: type: string phone: type: string LicenseGroup: type: object properties: licenses: type: array items: $ref: '#/components/schemas/License' name: type: string maxLength: 255 minLength: 1 pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$ riskWeight: type: integer format: int32 uuid: type: string format: uuid required: - name - uuid ComponentProperty: type: object properties: description: type: string maxLength: 255 minLength: 0 pattern: \P{Cc}+ groupName: type: string maxLength: 255 minLength: 1 pattern: \P{Cc}+ propertyName: type: string maxLength: 255 minLength: 1 pattern: \P{Cc}+ propertyType: type: string enum: - BOOLEAN - INTEGER - NUMBER - STRING - TIMESTAMP - URL - UUID propertyValue: type: string maxLength: 1024 minLength: 0 pattern: \P{Cc}+ uuid: type: string format: uuid required: - propertyName - propertyType - uuid Parent: type: object properties: name: type: string uuid: type: string format: uuid version: type: string required: - name - uuid Permission: type: object properties: description: type: string ldapUsers: type: array items: $ref: '#/components/schemas/LdapUser' managedUsers: type: array items: $ref: '#/components/schemas/ManagedUser' name: type: string maxLength: 255 minLength: 1 pattern: ^[a-zA-Z_0-9]*$ oidcUsers: type: array items: $ref: '#/components/schemas/OidcUser' required: - name Team: type: object properties: apiKeys: type: array items: $ref: '#/components/schemas/ApiKey' ldapUsers: type: array items: $ref: '#/components/schemas/LdapUser' managedUsers: type: array items: $ref: '#/components/schemas/ManagedUser' mappedLdapGroups: type: array items: $ref: '#/components/schemas/MappedLdapGroup' mappedOidcGroups: type: array items: $ref: '#/components/schemas/MappedOidcGroup' name: type: string maxLength: 255 minLength: 1 pattern: '[\P{Cc}]+' oidcUsers: type: array items: $ref: '#/components/schemas/OidcUser' permissions: type: array items: $ref: '#/components/schemas/Permission' serviceAccounts: type: array items: $ref: '#/components/schemas/ServiceAccount' uuid: type: string format: uuid required: - name - uuid OrganizationalEntity: type: object properties: contacts: type: array items: $ref: '#/components/schemas/OrganizationalContact' name: type: string urls: type: array items: type: string ExternalReference: type: object properties: comment: type: string pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$ type: type: string enum: - vcs - issue-tracker - website - advisories - bom - mailing-list - social - chat - documentation - support - source-distribution - distribution - distribution-intake - license - build-meta - build-system - release-notes - security-contact - model-card - attestation - threat-model - adversary-model - risk-assessment - vulnerability-assertion - exploitability-statement - pentest-report - static-analysis-report - dynamic-analysis-report - runtime-analysis-report - component-analysis-report - maturity-report - certification-report - codified-infrastructure - quality-metrics - log - configuration - evidence - formulation - rfc-9116 - electronic-signature - digital-signature - patent - patent-family - patent-assertion - citation - poam - other url: type: string minLength: 1 required: - url License: type: object properties: isCustomLicense: type: boolean isDeprecatedLicenseId: type: boolean isFsfLibre: type: boolean isOsiApproved: type: boolean licenseComments: type: string licenseGroups: type: array items: $ref: '#/components/schemas/LicenseGroup' licenseId: type: string maxLength: 255 minLength: 1 pattern: ^[a-zA-Z0-9_.\-+]*$ licenseText: type: string name: type: string maxLength: 255 minLength: 1 pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$ seeAlso: type: array items: type: string standardLicenseHeader: type: string standardLicenseTemplate: type: string uuid: type: string format: uuid required: - licenseId - name - uuid ManagedUser: type: object properties: confirmPassword: type: string email: type: string maxLength: 255 minLength: 0 pattern: '[\P{Cc}]+' forcePasswordChange: type: boolean fullname: type: string maxLength: 255 minLength: 0 pattern: '[\P{Cc}]+' lastPasswordChange: type: integer format: int64 description: UNIX epoch timestamp in milliseconds newPassword: type: string nonExpiryPassword: type: boolean permissions: type: array items: $ref: '#/components/schemas/Permission' suspended: type: boolean teams: type: array items: $ref: '#/components/schemas/Team' username: type: string maxLength: 255 minLength: 1 pattern: '[\P{Cc}]+' required: - lastPasswordChange - username AffectedVersionAttribution: type: object properties: firstSeen: type: integer format: int64 description: UNIX epoch timestamp in milliseconds lastSeen: type: integer format: int64 deprecated: true description: Deprecated; always equal to firstSeen source: type: string enum: - NVD - GITHUB - VULNDB - OSSINDEX - INTERNAL - OSV - SNYK - CX - JVN - UNKNOWN required: - firstSeen - lastSeen VulnerabilityAlias: type: object properties: cveId: type: string pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$ cxId: type: string pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$ ghsaId: type: string pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$ gsdId: type: string pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$ internalId: type: string pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$ osvId: type: string pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$ snykId: type: string pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$ sonatypeId: type: string pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$ vulnDbId: type: string pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$ ProjectMetadata: type: object properties: authors: type: array items: $ref: '#/components/schemas/OrganizationalContact' supplier: $ref: '#/components/schemas/OrganizationalEntity' tools: $ref: '#/components/schemas/Tools' readOnly: true BomUploadResponse: type: object properties: projectUuid: type: string format: uuid description: UUID of the project the BOM was uploaded for token: type: string format: uuid description: Token used to check task progress required: - projectUuid - token Project: type: object properties: accessTeams: type: array items: $ref: '#/components/schemas/Team' uniqueItems: true writeOnly: true active: type: boolean author: type: string authors: type: array items: $ref: '#/components/schemas/OrganizationalContact' bomRef: type: string children: type: array items: $ref: '#/components/schemas/Project' classifier: type: string enum: - APPLICATION - FRAMEWORK - LIBRARY - CONTAINER - OPERATING_SYSTEM - DEVICE - FIRMWARE - FILE - PLATFORM - DEVICE_DRIVER - MACHINE_LEARNING_MODEL - DATA - CRYPTOGRAPHIC_ASSET collectionLogic: type: string enum: - AGGREGATE_DIRECT_CHILDREN - AGGREGATE_DIRECT_CHILDREN_WITH_TAG - AGGREGATE_LATEST_VERSION_CHILDREN collectionTag: $ref: '#/components/schemas/Tag' cpe: type: string maxLength: 255 minLength: 0 pattern: (cpe:2\.3:[aho\*\-](:(((\?*|\*?)([a-zA-Z0-9\-\._]|(\\[\\\*\?!"#$$%&'\(\)\+,/:;<=>@\[\]\^`\{\|}~]))+(\?*|\*?))|[\*\-])){5}(:(([a-zA-Z]{2,3}(-([a-zA-Z]{2}|[0-9]{3}))?)|[\*\-]))(:(((\?*|\*?)([a-zA-Z0-9\-\._]|(\\[\\\*\?!"#$$%&'\(\)\+,/:;<=>@\[\]\^`\{\|}~]))+(\?*|\*?))|[\*\-])){4})|([c][pP][eE]:/[AHOaho]?(:[A-Za-z0-9\._\-~%]*){0,6}) description: type: string maxLength: 255 minLength: 0 pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$ directDependencies: type: string externalReferences: type: array items: $ref: '#/components/schemas/ExternalReference' group: type: string maxLength: 255 minLength: 0 pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$ inactiveSince: type: integer format: int64 description: UNIX epoch timestamp in milliseconds readOnly: true isLatest: type: boolean lastBomImport: type: integer format: int64 description: UNIX epoch timestamp in milliseconds lastBomImportFormat: type: string lastInheritedRiskScore: type: number format: double lastVulnerabilityAnalysis: type: integer format: int64 description: UNIX epoch timestamp in milliseconds manufacturer: $ref: '#/components/schemas/OrganizationalEntity' metadata: $ref: '#/components/schemas/ProjectMetadata' metrics: $ref: '#/components/schemas/ProjectMetrics' name: type: string maxLength: 255 minLength: 1 pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$ parent: $ref: '#/components/schemas/Project' publisher: type: string maxLength: 255 minLength: 0 pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$ purl: type: string maxLength: 1024 minLength: 0 supplier: $ref: '#/components/schemas/OrganizationalEntity' swidTagId: type: string maxLength: 255 minLength: 0 pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$ tags: type: array items: $ref: '#/components/schemas/Tag' uniqueItems: true uuid: type: string format: uuid version: type: string pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$ versions: type: array items: $ref: '#/components/schemas/ProjectVersion' required: - lastBomImport - name - uuid ServiceAccount: type: object properties: email: type: string maxLength: 255 minLength: 0 pattern: '[\P{Cc}]+' permissions: type: array items: $ref: '#/components/schemas/Permission' suspended: type: boolean teams: type: array items: $ref: '#/components/schemas/Team' username: type: string maxLength: 255 minLength: 1 pattern: '[\P{Cc}]+' required: - username ConciseProjectMetrics: type: object description: A concise representation of a project's metrics properties: components: type: integer format: int32 description: Total number of components critical: type: integer format: int32 description: Number of vulnerabilities with critical severity high: type: integer format: int32 description: Number of vulnerabilities with high severity inheritedRiskScore: type: number format: double description: The inherited risk score kev: type: integer format: int32 description: Number of vulnerabilities known to be exploited low: type: integer format: int32 description: Number of vulnerabilities with low severity medium: type: integer format: int32 description: Number of vulnerabilities with medium severity policyViolationsFail: type: integer format: int32 description: Number of policy violations with status FAIL policyViolationsInfo: type: integer format: int32 description: Number of policy violations with status WARN policyViolationsLicenseTotal: type: integer format: int32 description: Number of license policy violations policyViolationsOperationalTotal: type: integer format: int32 description: Number of operational policy violations policyViolationsSecurityTotal: type: integer format: int32 description: Number of security policy violations policyViolationsTotal: type: integer format: int32 description: Total number of policy violations policyViolationsWarn: type: integer format: int32 description: Number of policy violations with status WARN unassigned: type: integer format: int32 description: Number of vulnerabilities with unassigned severity vulnerabilities: type: integer format: int32 description: Total number of vulnerabilities required: - components - critical - high - inheritedRiskScore - kev - low - medium - policyViolationsFail - policyViolationsInfo - policyViolationsLicenseTotal - policyViolationsOperationalTotal - policyViolationsSecurityTotal - policyViolationsTotal - policyViolationsWarn - unassigned - vulnerabilities ListProjectsResponseItem: type: object properties: active: type: boolean authors: type: array items: $ref: '#/components/schemas/OrganizationalContact' classifier: type: string enum: - APPLICATION - FRAMEWORK - LIBRARY - CONTAINER - OPERATING_SYSTEM - DEVICE - FIRMWARE - FILE - PLATFORM - DEVICE_DRIVER - MACHINE_LEARNING_MODEL - DATA - CRYPTOGRAPHIC_ASSET collectionLogic: type: string enum: - AGGREGATE_DIRECT_CHILDREN - AGGREGATE_DIRECT_CHILDREN_WITH_TAG - AGGREGATE_LATEST_VERSION_CHILDREN collectionTag: $ref: '#/components/schemas/Tag' cpe: type: string description: type: string directDependencies: type: string externalReferences: type: array items: $ref: '#/components/schemas/ExternalReference' group: type: string hasChildren: type: boolean description: Whether the project has child projects inactiveSince: type: integer format: int64 description: UNIX epoch timestamp in milliseconds readOnly: true isLatest: type: boolean lastBomImport: type: integer format: int64 description: UNIX epoch timestamp in milliseconds lastBomImportFormat: type: string lastInheritedRiskScore: type: number format: double lastVulnerabilityAnalysis: type: integer format: int64 description: UNIX epoch timestamp in milliseconds manufacturer: $ref: '#/components/schemas/OrganizationalEntity' metadata: $ref: '#/components/schemas/ProjectMetadata' metrics: $ref: '#/components/schemas/ProjectMetrics' name: type: string parent: $ref: '#/components/schemas/Parent' publisher: type: string purl: type: string supplier: $ref: '#/components/schemas/OrganizationalEntity' swidTagId: type: string tags: type: array items: $ref: '#/components/schemas/Tag' uuid: type: string format: uuid version: type: string required: - hasChildren - lastBomImport - name - uuid RepositoryMetaComponent: type: object properties: lastCheck: type: integer format: int64 description: UNIX epoch timestamp in milliseconds latestVersion: type: string latestVersionPublishedAt: type: integer format: int64 description: UNIX epoch timestamp in milliseconds name: type: string namespace: type: string repositoryType: type: string enum: - MAVEN - NPM - GEM - PYPI - NUGET - HEX - COMPOSER - CARGO - GO_MODULES - CPAN - GITHUB - HACKAGE - NIXPKGS - UNSUPPORTED OidcGroup: type: object properties: name: type: string maxLength: 255 minLength: 1 pattern: '[\P{Cc}]+' uuid: type: string format: uuid required: - name - uuid Tag: type: object properties: name: type: string maxLength: 255 minLength: 1 pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$ required: - name Epss: type: object properties: cve: type: string percentile: type: number score: type: number securitySchemes: ApiKeyAuth: description: Authentication via API key. in: header name: X-Api-Key type: apiKey BearerAuth: bearerFormat: Opaque description: 'Authentication via opaque server-issued session token. Tokens are obtained from `POST /api/v1/user/login` or `POST /api/v1/user/oidc/login`.' scheme: bearer type: http x-refined-from: - dependency-track-openapi-v1.yaml - dependency-track-openapi.yml