openapi: 3.2.0 info: title: Dependency Track Violationanalysis API version: 1.0.0 contact: name: The Dependency-Track Authors url: https://github.com/DependencyTrack/dependency-track license: name: Apache-2.0 url: https://www.apache.org/licenses/LICENSE-2.0.html description: 'Operations tagged violationanalysis across 2 of this provider''s published API definitions: dependency-track-openapi-v1.yaml, dependency-track-openapi.yml. Each path carries the servers of the definition it was published in.' servers: - url: /api tags: - name: violationanalysis paths: /v1/violation/analysis: get: description: Requires permission VIEW_POLICY_VIOLATION operationId: retrieveAnalysis_1 parameters: - description: The UUID of the component in: query name: component required: true schema: type: string format: uuid - description: The UUID of the policy violation in: query name: policyViolation required: true schema: type: string format: uuid responses: '200': content: application/json: schema: $ref: '#/components/schemas/ViolationAnalysisResponse' description: A violation analysis trail '401': description: Unauthorized '403': content: application/problem+json: schema: $ref: '#/components/schemas/ProblemDetails' description: Access to the requested project is forbidden '404': description: The component or policy violation could not be found security: - ApiKeyAuth: [] - BearerAuth: [] summary: Retrieves a violation analysis trail tags: - violationanalysis put: description: Requires permission POLICY_VIOLATION_ANALYSIS operationId: updateAnalysis_1 requestBody: content: application/json: schema: $ref: '#/components/schemas/ViolationAnalysisRequest' responses: '200': content: application/json: schema: $ref: '#/components/schemas/ViolationAnalysisResponse' description: The created violation analysis '401': description: Unauthorized '403': content: application/problem+json: schema: $ref: '#/components/schemas/ProblemDetails' description: Access to the requested project is forbidden '404': description: The component or policy violation could not be found security: - ApiKeyAuth: [] - BearerAuth: [] summary: Records a violation analysis decision tags: - violationanalysis servers: - url: /api components: schemas: ProblemDetails: type: object description: An RFC 9457 problem object properties: detail: type: string description: Human-readable explanation specific to this occurrence of the problem example: Example detail instance: type: string format: uri description: Reference URI that identifies the specific occurrence of the problem example: https://api.example.org/foo/bar/example-instance status: type: integer format: int32 description: HTTP status code generated by the origin server for this occurrence of the problem example: 400 title: type: string description: Short, human-readable summary of the problem type example: Example title type: type: string format: uri description: A URI reference that identifies the problem type example: https://api.example.org/foo/bar/example-problem required: - detail - status - title ViolationAnalysisResponse: type: object properties: analysisComments: type: array description: Audit trail of analysis comments items: $ref: '#/components/schemas/Comment' analysisState: type: string description: The state of the analysis decision enum: - APPROVED - REJECTED - NOT_SET isSuppressed: type: boolean description: Whether the policy violation is suppressed required: - analysisComments - analysisState - isSuppressed Comment: type: object description: Audit trail of analysis comments properties: comment: type: string description: The comment text commenter: type: string description: Identifier of the user who wrote the comment timestamp: type: integer format: int64 description: Timestamp the comment was recorded at required: - comment - timestamp ViolationAnalysisRequest: type: object properties: analysisState: type: string enum: - APPROVED - REJECTED - NOT_SET comment: type: string pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$ component: type: string pattern: ^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$ isSuppressed: type: boolean writeOnly: true policyViolation: type: string pattern: ^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$ suppressed: type: boolean required: - component - policyViolation securitySchemes: ApiKeyAuth: description: Authentication via API key. in: header name: X-Api-Key type: apiKey BearerAuth: bearerFormat: Opaque description: 'Authentication via opaque server-issued session token. Tokens are obtained from `POST /api/v1/user/login` or `POST /api/v1/user/oidc/login`.' scheme: bearer type: http x-refined-from: - dependency-track-openapi-v1.yaml - dependency-track-openapi.yml