openapi: 3.2.0 info: title: Harness Compliance Results API version: '1.0' description: The Harness Software Delivery Platform uses OpenAPI Specification v3.0. contact: name: API Support email: contact@harness.io url: https://harness.io/ x-logo: url: https://mma.prnewswire.com/media/779232/Harnes_logo_horizontal.jpg?p=facebook altText: Harness termsOfService: https://harness.io/terms-of-use/ servers: - url: https://app.harness.io description: Harness host URL - url: https://{vanity} description: Vanity URL variables: vanity: default: app.harness.io security: - x-api-key: [] tags: - name: ComplianceResults paths: /v1/orgs/{org}/projects/{project}/compliance-results/list: parameters: - $ref: '#/components/parameters/OrgParam1' - $ref: '#/components/parameters/ProjectParam1' post: summary: Fetch Compliance Results responses: '200': $ref: '#/components/responses/FetchComplianceResultResponseBody' '400': description: Bad Request '500': description: Internal Server Error operationId: fetchComplianceResults security: - x-api-key: [] parameters: - $ref: '#/components/parameters/AccountHeader6' - $ref: '#/components/parameters/Page2' - $ref: '#/components/parameters/Limit6' requestBody: $ref: '#/components/requestBodies/FetchComplianceResultRequestBody' x-stoplight: id: i0heiwkbw253d tags: - ComplianceResults /v1/orgs/{org}/projects/{project}/compliance-results/compliances: parameters: - $ref: '#/components/parameters/OrgParam1' - $ref: '#/components/parameters/ProjectParam1' post: summary: Fetch Compliance Results Checks responses: '200': $ref: '#/components/responses/ComplianceResultsGroupByComplianceIdResponseBody' '400': description: Bad Request '500': description: Internal Server Error operationId: fetchComplianceResultsGroupById security: - x-api-key: [] parameters: - $ref: '#/components/parameters/AccountHeader6' - $ref: '#/components/parameters/Page2' - $ref: '#/components/parameters/Limit6' - $ref: '#/components/parameters/Order2' - schema: type: string enum: - severity in: query name: sort description: sort entity - schema: type: string in: query name: start_time description: Start time for the query, accepts timestamp epoch UTC - schema: type: string in: query name: end_time description: End time for the query, accepts timestamp epoch UTC requestBody: $ref: '#/components/requestBodies/FetchComplianceResultRequestBody' description: fetch Compliance Results GroupById tags: - ComplianceResults x-stoplight: id: jswpohsezov5y /v1/orgs/{org}/projects/{project}/compliance-results/compliances/{compliance}/artifacts: parameters: - $ref: '#/components/parameters/OrgParam1' - $ref: '#/components/parameters/ProjectParam1' - schema: type: string name: compliance in: path required: true description: compliance ID get: summary: Fetch Compliance Result By Compliance Id tags: - ComplianceResults responses: '200': $ref: '#/components/responses/FetchArtifactsByComplianceIdResponseBody' '500': description: Internal Server Error operationId: fetchComplianceResultsByComplianceId security: - x-api-key: [] x-stoplight: id: i0e7u125rfvdr parameters: - $ref: '#/components/parameters/AccountHeader6' - $ref: '#/components/parameters/Page2' - $ref: '#/components/parameters/Limit6' - $ref: '#/components/parameters/Order2' - schema: type: string enum: - repo_name - updated - status in: query name: sort description: sort order - schema: type: string in: query name: search_term description: artifact name search /v1/orgs/{org}/projects/{project}/compliance-results: parameters: - $ref: '#/components/parameters/OrgParam1' - $ref: '#/components/parameters/ProjectParam1' post: summary: Save Compliance Results responses: '200': description: Shared Response '400': description: Bad Request '500': description: Internal Server Error operationId: saveComplianceResult security: - x-api-key: [] parameters: - $ref: '#/components/parameters/AccountHeader6' requestBody: $ref: '#/components/requestBodies/CreateComplianceResultRequestBody' tags: - ComplianceResults x-stoplight: id: 49usqlvlug1m6 /v1/orgs/{org}/projects/{project}/artifact/{artifact}/compliance-results/list: parameters: - $ref: '#/components/parameters/OrgParam1' - $ref: '#/components/parameters/ProjectParam1' - $ref: '#/components/parameters/Artifact' post: summary: Fetch compliance result by artifact tags: - ComplianceResults responses: '200': $ref: '#/components/responses/FetchComplianceResultByArtifactResponse' operationId: fetchComplianceResultsByArtifact x-stoplight: id: obqv1cnxcb7ur parameters: - $ref: '#/components/parameters/AccountHeader6' - $ref: '#/components/parameters/Page2' - $ref: '#/components/parameters/Limit6' - $ref: '#/components/parameters/Order2' - in: query name: sort description: Parameter on the basis of which sorting is done. schema: enum: - title - severity type: string requestBody: $ref: '#/components/requestBodies/FetchComplianceResultByArtifactRequestBody' security: - x-api-key: [] components: schemas: ComplianceResultDTO: type: object x-examples: {} required: - compliance_id - scm_platform - title - category - category_id - standards - description - severity - reason - status - remediation - entity - type - sub_category - sub_category_id properties: repo_url: type: string compliance_id: type: string scm_platform: type: string title: type: string category: type: string category_id: type: string standards: type: array items: $ref: '#/components/schemas/ComplianceStandardType' description: type: string tags: type: array items: type: string severity: $ref: '#/components/schemas/ComplianceCheckSeverity' reason: type: string status: $ref: '#/components/schemas/ComplianceResultStatus' remediation: type: string url: type: string entity: $ref: '#/components/schemas/ComplianceCheckEntityType' type: $ref: '#/components/schemas/ComplianceCheckType' sub_category: type: string x-stoplight: id: n601b1is8kj1o sub_category_id: type: string x-stoplight: id: 9a1i8xv2h02g2 x-stoplight: id: d289c0pet70he ComplianceCheckSeverity: title: ComplianceCheckSeverity type: string x-stoplight: id: kpbii4pjiw1ff enum: - CRITICAL - HIGH - MEDIUM - LOW ComplianceScanType: title: ComplianceScanType x-stoplight: id: xofqrlg94b1o5 type: string enum: - REPOSITORY - CICD description: Type of scan on the source like Repository scan or Worklfow scan ComplianceExecutionByType: type: object x-examples: Example 1: type: REPOSITORY count: 30 passed: 30 failed: 40 properties: type: $ref: '#/components/schemas/ComplianceScanType' count: type: integer passed: type: integer failed: type: integer x-stoplight: id: vj4sakhy4qexz ComplianceEvaluationHistory: type: object x-examples: Example 1: pipelineId: string pipelineExecutionId: string status: FAILED properties: pipeline_id: type: string x-stoplight: id: oj1ww5qb81ale pipeline_execution_id: type: string x-stoplight: id: ij8zjdiofyxkn status: $ref: '#/components/schemas/ComplianceResultStatus' stage_execution_id: type: string x-stoplight: id: j9vrceq5ahuaa step_execution_id: type: string x-stoplight: id: nmej7ya11phwe reason: type: string x-stoplight: id: vv78jrxqedsek description: type: string x-stoplight: id: 5eh2g6hen0gd6 remediation: type: string x-stoplight: id: 22nyp1fet611d created_at: type: integer x-stoplight: id: i93b23g4ejxnb format: int64 occurrences: type: array items: $ref: '#/components/schemas/ComplianceOccurrenceDTO' x-stoplight: id: s8krm8zvlz556 FetchComplianceResultByArtifactResponseBody: type: object x-examples: Example 1: complianceId: 4.3.5 title: Ensure webhooks of the package registry are secured standards: - CIS severity: LOW status: PASSED evaluationTime: 1718040836473 evaluationHistory: - pipelineId: string pipelineExecutionId: string status: PASSED - pipelineId: string pipelineExecutionId: string status: FAILED properties: compliance_id: type: string x-stoplight: id: 3a0fxwhfip1jx title: type: string standards: type: array items: $ref: '#/components/schemas/ComplianceStandardType' tags: type: array x-stoplight: id: lw9r9bfmoedxe items: x-stoplight: id: tj8w83zbr2ov9 type: string severity: $ref: '#/components/schemas/ComplianceCheckSeverity' status: $ref: '#/components/schemas/ComplianceResultStatus' evaluation_time: type: integer x-stoplight: id: 5jumm3w1luvnd format: int64 evaluation_history: type: array items: $ref: '#/components/schemas/ComplianceEvaluationHistory' reason: type: string x-stoplight: id: b8exmlc6fek9m description: type: string x-stoplight: id: qkjezwyyt94eo remediation: type: string x-stoplight: id: 2k070gxzjlse5 pipelineExecutionId: type: string x-stoplight: id: lnlvofaibaqsv occurrences: type: array x-stoplight: id: 95mz9coytjsgg items: $ref: '#/components/schemas/ComplianceOccurrenceDTO' x-stoplight: id: oa9y4fc633tsf CreateComplianceResult: type: object x-examples: Example 1: repo_url: string repo_org: string repo_name: string default_branch: string pipeline_execution_identifier: string step_execution_identifier: string scm_platform: string results: - compliance_id: string title: string category: string category_id: string type: SCM standards: - CIS description: string tags: - string severity: string reason: string status: string remediation: string url: string entity: REPOSITORY stage_execution_identifier: string pipeline: string x-stoplight: id: crbwzlzs27g42 properties: repo_url: type: string repo_org: type: string repo_name: type: string default_branch: type: string pipeline_execution_identifier: type: string step_execution_identifier: type: string scm_platform: type: string results: type: array items: $ref: '#/components/schemas/ComplianceResult' stage_execution_identifier: type: string pipeline: type: string stage_type: type: string x-stoplight: id: us5qtvrch01yx ComplianceOccurrenceDTO: title: ComplianceOccurrenceDTO x-stoplight: id: 5kz1r0wmqqtb9 type: object properties: snippet: type: string x-stoplight: id: tou5xin4shjem description: Depicts occurrence snippet. snippet_url: type: string x-stoplight: id: elke0tcie443g description: URL to go to snippet line_number: type: integer x-stoplight: id: r956qlsf9zrc0 description: Line number of snippet. ComplianceCheckEntityType: title: ComplianceCheckEntityType type: string x-stoplight: id: c9u1ph0w9r2pc enum: - REPOSITORY - ORGANIZATION - BRANCH - PACKAGEREGISTRY - PIPELINE - DEPENDENCIES - All description: Represents entity type on which compliance check is applicable ComplianceArtifactWithExecution: type: object x-examples: Example 2: name: string type: id: GITHUB compliance_id: string title: string severity: CRITICAL description: string remediation: string standards: - CIS tags: - string updatedAt: string status: compliance_id: string title: string category: string category_id: string standards: - CIS description: string tags: - string severity: CRITICAL reason: string status: PASSED remediation: string url: string entity: REPOSITORY sub_category: string sub_category_id: string executions: pipeline_id: string pipeline_excution_id: string step_execution_id: string stage_execution_id: string status: PASSED reason: string scan_type: CICD x-stoplight: id: grcx43cx5x44a required: - name - type - compliance_id - severity - standards - tags properties: url: type: string x-stoplight: id: mq8x0fp10968z name: type: string x-stoplight: id: d5g0voke9neqg type: type: string compliance_id: type: string x-stoplight: id: sq0u450bxch3w title: type: string severity: $ref: '#/components/schemas/ComplianceCheckSeverity' description: type: string remediation: type: string standards: type: array items: $ref: '#/components/schemas/ComplianceStandardType' tags: type: array items: type: string updatedAt: type: string status: $ref: '#/components/schemas/ComplianceResultStatus' executions: type: array items: $ref: '#/components/schemas/ComplianceEvaluationHistory' reason: type: string x-stoplight: id: 6wg3st0686v9y occurrences: type: array x-stoplight: id: 9gi2t6cvl4axw items: $ref: '#/components/schemas/ComplianceOccurrenceDTO' scan_type: $ref: '#/components/schemas/ComplianceScanType' ComplianceResult: type: object x-examples: {} required: - compliance_id - compliance_val - category - category_id - standards - severity - reason - status - remediation - entity - sub_category - sub_category_id properties: compliance_id: type: string x-stoplight: id: l9pks9athcp51 compliance_val: type: integer x-stoplight: id: u21ksorb3iewy example: 110 title: type: string category: type: string category_id: type: string x-stoplight: id: kg7ooi3esk292 standards: type: array items: $ref: '#/components/schemas/ComplianceStandardType' description: type: string tags: type: array items: type: string severity: $ref: '#/components/schemas/ComplianceCheckSeverity' reason: type: string status: $ref: '#/components/schemas/ComplianceResultStatus' remediation: type: string url: type: string entity: $ref: '#/components/schemas/ComplianceCheckEntityType' sub_category: type: string x-stoplight: id: t6uyz63sy5k68 sub_category_id: type: string x-stoplight: id: gz47g56itzdmu occurrences: type: array x-stoplight: id: zgqjsm3l2x3xr items: $ref: '#/components/schemas/ComplianceOccurrenceDTO' x-stoplight: id: sxoz6cpmag92w ComplianceResultFilter: type: object x-examples: Example 1: standards: - OSWAP severity: High result: Pass/Fail/Unknown compliance_id: 1.1.1 x-stoplight: id: vi62tlx38whfy properties: standards: type: array items: $ref: '#/components/schemas/ComplianceStandardType' severity: $ref: '#/components/schemas/ComplianceCheckSeverity' status: $ref: '#/components/schemas/ComplianceResultStatus' compliance_id: type: string search_term: type: string x-stoplight: id: 42wz9mcka07j4 scan_types: x-stoplight: id: kp8bgb4ba4i1q type: array items: $ref: '#/components/schemas/ComplianceScanType' ComplianceResultByArtifactFilter: title: ComplianceResultByArtifactFilter x-stoplight: id: p67prnxfefvdl type: object properties: standards: type: array items: $ref: '#/components/schemas/ComplianceStandardType' severity: $ref: '#/components/schemas/ComplianceCheckSeverity' status: type: array x-stoplight: id: mt4kx8wt1ufyv items: $ref: '#/components/schemas/ComplianceResultStatus' compliance_id: type: string x-stoplight: id: lm68szljbrvg9 search_term: type: string x-stoplight: id: 0ykysaw7g4s2h ComplianceCheckType: title: ComplianceCheckType type: string x-stoplight: id: 172pz2p0c2bc1 enum: - SCM - ARTIFACT - BUILD - DEPENDENCIES description: Represents Type of Compliance Check ComplianceResultStatus: title: ComplianceResultStatus type: string x-stoplight: id: g7eq9rgfjalfb enum: - PASSED - FAILED - UNKNOWN ComplianceStandardType: title: ComplianceStandardType type: string x-stoplight: id: hqwyia5x65e2x enum: - CIS - OWASP ComplianceResultAggregationByType: type: object x-examples: {} required: - compliance_id - scm_platform - title - standards - tags - severity - entity properties: compliance_id: type: string scm_platform: type: string title: type: string standards: type: array items: $ref: '#/components/schemas/ComplianceStandardType' description: type: string tags: type: array items: type: string severity: $ref: '#/components/schemas/ComplianceCheckSeverity' entity: $ref: '#/components/schemas/ComplianceCheckEntityType' executions: $ref: '#/components/schemas/ComplianceExecutionByType' x-stoplight: id: aih2jjkriqgq8 parameters: Page2: name: page in: query required: false schema: type: integer default: 0 minimum: 0 description: "Pagination page number strategy: Specify the page number within the paginated collection related to the number of items in each page\t" Limit6: name: limit in: query schema: type: integer default: 30 maximum: 1000 minimum: 1 description: Number of items to return per page. OrgParam1: name: org in: path required: true schema: type: string description: Harness organization ID Order2: name: order in: query required: false schema: type: string enum: - ASC - DESC default: ASC description: Order on the basis of which sorting is done. AccountHeader6: name: Harness-Account in: header required: true schema: type: string description: Identifier field of the account the resource is scoped to. This is required for Authorization methods other than the x-api-key header. If you are using the x-api-key header, this can be skipped. ProjectParam1: in: path required: true schema: type: string description: Harness project ID name: project Artifact: name: artifact in: path required: true schema: type: string description: Harness artifact identifier requestBodies: FetchComplianceResultRequestBody: content: application/json: schema: $ref: '#/components/schemas/ComplianceResultFilter' CreateComplianceResultRequestBody: content: application/json: schema: $ref: '#/components/schemas/CreateComplianceResult' examples: Example 1: value: repo_url: string default_branch: string pipeline_execution_identifier: string step_execution_identifier: string scm_platform: string results: - compliance_id: string title: string category: string category_id: string type: SCM standards: - CIS description: string tags: - string severity: CRITICAL reason: string status: PASS remediation: string url: string entity: REPOSITORY stage_execution_identifier: string pipeline: string FetchComplianceResultByArtifactRequestBody: content: application/json: schema: $ref: '#/components/schemas/ComplianceResultByArtifactFilter' responses: FetchComplianceResultResponseBody: description: Example response content: application/json: schema: type: array items: $ref: '#/components/schemas/ComplianceResultDTO' FetchComplianceResultByArtifactResponse: description: Example response content: application/json: schema: type: array items: $ref: '#/components/schemas/FetchComplianceResultByArtifactResponseBody' FetchArtifactsByComplianceIdResponseBody: description: Example response content: application/json: schema: type: array items: $ref: '#/components/schemas/ComplianceArtifactWithExecution' ComplianceResultsGroupByComplianceIdResponseBody: description: Example response content: application/json: schema: type: array items: $ref: '#/components/schemas/ComplianceResultAggregationByType' securitySchemes: x-api-key: name: x-api-key type: apiKey in: header description: API key is a token provided while making the API calls. This is used to authenticate the client at the exposed endpoint. externalDocs: description: Find out more about Swagger url: http://swagger.io x-stoplight: id: oc91t4vrfnjyi x-tagGroups: - name: Organizations tags: - Organization - name: Projects tags: - Org Project - Project - name: Secrets tags: - Account Secret - Org Secret - Project Secret - Secrets - name: Connectors tags: - Account Connector - Org Connector - Project Connector - Connectors - GoogleSecretManagerConnector - name: Roles tags: - Account Roles - Organization Roles - Project Roles - Roles - name: Resource Groups tags: - Account Resource Groups - Organization Resource Groups - Project Resource Groups - Filter Resource Groups - Harness Resource Group - Zendesk - name: Role Assignments tags: - Account Role Assignments - Org Role Assignments - Project Role Assignments - Role Assignments - name: Platform tags: - Access Control List - Account Banner - Account Banner - Account Licensed Modules - Account License Type - Account Webhooks - AccountSetting - Accounts - Analyze Account Access Policy - Analyze Organization Access Policy - Analyze Project Access Policy - ApiKey - Audit - AuditFilters - Authentication Settings - Canny - Devops Essentials License Data By Account - EULA - Filter - Harness Resource Type - Invite - IP Allowlist - Nextgen Ldap - Notification Channels - Notification Rules - OIDC - Oidc-Access-Token - Oidc-ID-Token - Org Webhooks - Permissions - Project Webhooks - Secret Managers - Service Account - Setting - SMTP - Source Code Manager - Token - User - User Group - Variables - name: Delegate tags: - Agent mTLS Endpoint Management - Delegate Download Resource - Delegate Group Tags Resource - Delegate Setup Resource - Delegate Token Resource - name: Pipelines tags: - Pipelines - Input Sets - Approvals - Pipeline Execution - Pipeline Dashboard - Pipeline Input Set - Pipeline - Pipeline Execution Details - Pipeline Execute - Pipeline Refresh - Pipeline data retention - Triggers - TriggersEvents - Webhook Triggers - Webhook Event Handler - DryRunPipeline - name: Artifact Registry tags: - Registries - Artifacts - Docker Artifacts - Helm Artifacts - quarantine - Webhooks - Spaces - Replication - Registry V3 - Registries - Registry V3 - Packages - Registry V3 - Versions - Registry V3 - Files - Registry V3 - Metadata - Registry V3 - Firewall - Registry V3 - Transfer - name: Database DevOps tags: - Database Schema - Database Instance - Deployed State - Execution Config - Migration State - name: CD tags: - K8s Release Service Mapping - CustomDeployment - Environments - EnvironmentGroup - Infrastructures - Usage - File Store - Service Dashboard - ServiceOverrides - Rollback - tas - name: Deployment Freeze tags: - Freeze CRUD - Freeze Evaluation - Freeze Schema - name: Services tags: - Account Services - Org Services - Project Services - Services - name: Rancher Infrastructures tags: - Account Rancher Infrastructure - Org Rancher Infrastructure - Project Rancher Infrastructure - name: Templates tags: - Account Template - Org Template - Project Template - Templates - Global Templates - name: GitOps tags: - Agents - Application - Applications - Certificates - Clusters - Dashboard Aggregates - Dashboards - GnuPGP Keys - GPG Keys - Hosts - Project mappings - Projects - Reconciler - Repositories - Repository Certificates - Repository credentials - ValidateHost - name: GitX tags: - GitX Webhooks - Org Gitx Webhooks - Project Gitx Webhooks - name: CACM tags: - Anomalies Ignorelist Rule - Anomalies - BI Dashboards - Budgets - Budget Groups - Cost Categories - Cloud Accounts - K8S Connectors Metadata - Notification Settings v2 - Overview - Data Job Status - Recommendation cost settings - Unit Metric - Anomaly Comments - Cloud and AI cost anomaly details - Cloud and AI cost anomalies v2 - Cost Details - Currency Preferences - External Data Provider - AiEngine - CACM governance cost settings - Governance Enforcement Recommendation APIs - Governance Alert - Governance Overview - Governance Recommendation APIs - RuleEnforcement - Rule Executions - Rule - Rule Sets - Perspectives Folders - Perspective Reports - Perspectives - Cost Category Jira Project Mapping - Recommendations Details - Recommendations - Recommendation Jira - Recommendation Preferences - Recommendation Presets - Recommendation Servicenow - Recommendation Tags - Recommendation Ignore List - AutoStopping Rules - AutoStopping Rules V2 - AutoStopping Load Balancers - AutoStopping Fixed Schedules - AutoStopping Alerts - Commitment Orchestrator Events APIs - name: Feature Flags tags: - API Keys - Feature Flags - Targets - Target Groups - Environment Perspectives - Anomalies - Proxy - Tags - name: SRM tags: - Monitored Services - SLOs dashboard - NG SLOs - SLOs - Downtime - Srm Notification - name: Internal Developer Portal - IDP tags: - Entities - Teams - CatalogCustomProperties - Scores - DataSource - KubernetesDataPoints - AggregationRules - AppConfig - PluginInfo - LayoutProxy - Kinds - LayoutsV3 - LayoutsV4 - name: Environment Management - IDP tags: - Environment - Infrastructure - Instance - name: Custom Dashboards tags: - aida - dashboards - downloads - embed - folders - name: Policy Management tags: - dashboard - examples - policies - evaluate - evaluations - policysets - system - name: Code tags: - repository - status_checks - pullreq - upload - webhook - resource - rules - labels - name: IaCM tags: - usage - approvals - costs - executions - module-registry - workspaces - settings - tf-standard-backend - variables - name: STO tags: - Exemptions - Issues - Scans - Products - Test Targets - Target Variants - name: SEI tags: - Collection categories - Collections - Contributors - DORA - name: Git Sync (deprecated) tags: - Git Branches - Git Full Sync - Git Sync Settings - Git Sync - Git Sync Errors - name: Error Models tags: - Error Response - Governance Metadata - name: Supply Chain Security tags: - integration - PipelineInfraConfig - SBOM - Integration Step Config - Delete Step Config - Delete Repositories - Pipeline Store Config - Evidence Vault [Beta] - name: Release Management tags: - Release Groups - Releases - Orchestration Processes - Orchestration Activities - Orchestration Executions - Conflicts - Freeze - Reports - Uploads - name: Resilience Testing tags: - Actions - Action Templates - Chaos Components - Chaos Hubs - ChaosGuard Conditions - ChaosGuard Rules - DR Tests - Experiments - Experiment Templates - Faults - Fault Templates - Chaos Infrastructure - Health - Network Maps - Onboarding - Probes - Probe Templates - Chaos Recommendations - Risks