openapi: 3.2.0 info: title: Harness Exemption Rules API version: '1.0' description: The Harness Software Delivery Platform uses OpenAPI Specification v3.0. contact: name: API Support email: contact@harness.io url: https://harness.io/ x-logo: url: https://mma.prnewswire.com/media/779232/Harnes_logo_horizontal.jpg?p=facebook altText: Harness termsOfService: https://harness.io/terms-of-use/ servers: - url: https://app.harness.io description: Harness host URL - url: https://{vanity} description: Vanity URL variables: vanity: default: app.harness.io security: - x-api-key: [] tags: - name: ExemptionRules description: Manage admin-defined rules that gate Exemption creation paths: /sto/api/v2/exemption-rules: get: tags: - ExemptionRules description: List a collection of Exemption Rules operationId: ExemptionRules#ListExemptionRules parameters: - name: accountId in: query description: Harness Account ID allowEmptyValue: true required: true schema: type: string description: Harness Account ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ example: abcdef1234567890ghijkl - name: page in: query description: Page number to fetch (starting from 0) allowEmptyValue: true schema: type: integer description: Page number to fetch (starting from 0) default: 0 example: 4 format: int64 minimum: 0 example: 4 - name: pageSize in: query description: Number of results per page allowEmptyValue: true schema: type: integer description: Number of results per page default: 30 example: 50 format: int64 minimum: 1 maximum: 100 example: 50 - name: X-Api-Key in: header description: Harness personal or service access token allowEmptyValue: true schema: type: string description: Harness personal or service access token example: Qui dolore. example: Repellat omnis ex porro repellat. responses: '200': description: OK response. content: application/json: schema: $ref: '#/components/schemas/ExemptionRulesListExemptionRulesResponseBody' example: pagination: link: '' page: 4 pageSize: 20 totalItems: 230 totalPages: 12 results: - actions: duration: maxDurationDays: 3 conditions: epss_score: gte: 90 reachable: true severity_code: - Critical created: 1651578240 createdBy: user111111111111111111 description: Critical findings that are reachable in production must be remediated quickly; cap exemptions at 3 days. enabled: true id: abcdef1234567890ghijkl lastModified: 1651578240 lastModifiedBy: user111111111111111111 name: 'Critical reachable issues: 3 days max' priority: 0 - actions: duration: maxDurationDays: 3 conditions: epss_score: gte: 90 reachable: true severity_code: - Critical created: 1651578240 createdBy: user111111111111111111 description: Critical findings that are reachable in production must be remediated quickly; cap exemptions at 3 days. enabled: true id: abcdef1234567890ghijkl lastModified: 1651578240 lastModifiedBy: user111111111111111111 name: 'Critical reachable issues: 3 days max' priority: 0 - actions: duration: maxDurationDays: 3 conditions: epss_score: gte: 90 reachable: true severity_code: - Critical created: 1651578240 createdBy: user111111111111111111 description: Critical findings that are reachable in production must be remediated quickly; cap exemptions at 3 days. enabled: true id: abcdef1234567890ghijkl lastModified: 1651578240 lastModifiedBy: user111111111111111111 name: 'Critical reachable issues: 3 days max' priority: 0 - actions: duration: maxDurationDays: 3 conditions: epss_score: gte: 90 reachable: true severity_code: - Critical created: 1651578240 createdBy: user111111111111111111 description: Critical findings that are reachable in production must be remediated quickly; cap exemptions at 3 days. enabled: true id: abcdef1234567890ghijkl lastModified: 1651578240 lastModifiedBy: user111111111111111111 name: 'Critical reachable issues: 3 days max' priority: 0 '400': description: 'BadRequest: Bad Request response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: 'Bad Request: accountId parameter is required' status: 400 '401': description: 'Unauthorized: Unauthorized response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Unauthorized status: 401 '403': description: 'Forbidden: Forbidden response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Forbidden status: 403 '404': description: 'NotFound: Not Found response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Not Found status: 404 '429': description: 'TooManyRequests: Too Many Requests response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Too Many Requests status: 429 '500': description: 'InternalServerError: Internal Server Error response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Internal Server Error status: 500 security: - X-Api-Key_header_X-Api-Key: [] jwt_header_Authorization: - sto_exemption_view summary: Exemption Rules#List exemption rules x-summary-source: derived post: tags: - ExemptionRules description: Create a new Exemption Rule operationId: ExemptionRules#CreateExemptionRule parameters: - name: accountId in: query description: Harness Account ID allowEmptyValue: true required: true schema: type: string description: Harness Account ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ example: abcdef1234567890ghijkl - name: X-Api-Key in: header description: Harness personal or service access token allowEmptyValue: true schema: type: string description: Harness personal or service access token example: Ut et. example: Exercitationem at et repudiandae esse. requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/CreateExemptionRuleRequestBody' example: actions: duration: maxDurationDays: 3 conditions: epss_score: gte: 90 reachable: true severity_code: - Critical description: Critical findings that are reachable in production must be remediated quickly; cap exemptions at 3 days. enabled: true name: 'Critical reachable issues: 3 days max' priority: 0 userId: abcdef1234567890ghijkl responses: '200': description: OK response. content: application/json: schema: $ref: '#/components/schemas/IDResult' example: id: abcdef1234567890ghijkl '400': description: 'BadRequest: Bad Request response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: 'Bad Request: accountId parameter is required' status: 400 '401': description: 'Unauthorized: Unauthorized response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Unauthorized status: 401 '403': description: 'Forbidden: Forbidden response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Forbidden status: 403 '429': description: 'TooManyRequests: Too Many Requests response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Too Many Requests status: 429 '500': description: 'InternalServerError: Internal Server Error response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Internal Server Error status: 500 security: - X-Api-Key_header_X-Api-Key: [] jwt_header_Authorization: - sto_exemption_approve summary: Exemption Rules#Create exemption rule x-summary-source: derived /sto/api/v2/exemption-rules/{id}: delete: description: Delete an existing Exemption Rule operationId: ExemptionRules#DeleteExemptionRule parameters: - allowEmptyValue: true description: Harness Account ID example: abcdef1234567890ghijkl in: query name: accountId required: true schema: description: Harness Account ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ type: string - description: The ID of the Exemption Rule to delete example: abcdef1234567890ghijkl in: path name: id required: true schema: description: The ID of the Exemption Rule to delete example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ type: string responses: '204': description: No Content response. '400': content: application/json: example: message: 'Bad Request: accountId parameter is required' status: 400 schema: $ref: '#/components/schemas/NotFound' description: 'BadRequest: Bad Request response.' '401': content: application/json: example: message: Unauthorized status: 401 schema: $ref: '#/components/schemas/NotFound' description: 'Unauthorized: Unauthorized response.' '403': content: application/json: example: message: Forbidden status: 403 schema: $ref: '#/components/schemas/NotFound' description: 'Forbidden: Forbidden response.' '404': content: application/json: example: message: Not Found status: 404 schema: $ref: '#/components/schemas/NotFound' description: 'NotFound: Not Found response.' '429': content: application/json: example: message: Too Many Requests status: 429 schema: $ref: '#/components/schemas/NotFound' description: 'TooManyRequests: Too Many Requests response.' '500': content: application/json: example: message: Internal Server Error status: 500 schema: $ref: '#/components/schemas/NotFound' description: 'InternalServerError: Internal Server Error response.' security: - jwt_header_Authorization: - sto_exemption_approve tags: - ExemptionRules x-internal: true summary: Exemption Rules#Delete exemption rule x-summary-source: derived get: tags: - ExemptionRules description: Find Exemption Rule by ID operationId: ExemptionRules#FindExemptionRuleById parameters: - name: accountId in: query description: Harness Account ID allowEmptyValue: true required: true schema: type: string description: Harness Account ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ example: abcdef1234567890ghijkl - name: id in: path description: The ID of the Exemption Rule to retrieve required: true schema: type: string description: The ID of the Exemption Rule to retrieve example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ example: abcdef1234567890ghijkl - name: X-Api-Key in: header description: Harness personal or service access token allowEmptyValue: true schema: type: string description: Harness personal or service access token example: Aut sunt iste repudiandae rerum quia. example: Suscipit adipisci ut beatae. responses: '200': description: OK response. content: application/json: schema: $ref: '#/components/schemas/ExemptionRule' example: actions: duration: maxDurationDays: 3 conditions: epss_score: gte: 90 reachable: true severity_code: - Critical created: 1651578240 createdBy: user111111111111111111 description: Critical findings that are reachable in production must be remediated quickly; cap exemptions at 3 days. enabled: true id: abcdef1234567890ghijkl lastModified: 1651578240 lastModifiedBy: user111111111111111111 name: 'Critical reachable issues: 3 days max' priority: 0 '400': description: 'BadRequest: Bad Request response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: 'Bad Request: accountId parameter is required' status: 400 '401': description: 'Unauthorized: Unauthorized response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Unauthorized status: 401 '403': description: 'Forbidden: Forbidden response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Forbidden status: 403 '404': description: 'NotFound: Not Found response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Not Found status: 404 '429': description: 'TooManyRequests: Too Many Requests response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Too Many Requests status: 429 '500': description: 'InternalServerError: Internal Server Error response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Internal Server Error status: 500 security: - X-Api-Key_header_X-Api-Key: [] jwt_header_Authorization: - sto_exemption_view summary: Exemption Rules#Find exemption rule by id x-summary-source: derived put: tags: - ExemptionRules description: Update an existing Exemption Rule operationId: ExemptionRules#UpdateExemptionRule parameters: - name: accountId in: query description: Harness Account ID allowEmptyValue: true required: true schema: type: string description: Harness Account ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ example: abcdef1234567890ghijkl - name: id in: path description: The ID of the Exemption Rule to update required: true schema: type: string description: The ID of the Exemption Rule to update example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ example: abcdef1234567890ghijkl - name: X-Api-Key in: header description: Harness personal or service access token allowEmptyValue: true schema: type: string description: Harness personal or service access token example: Illum sunt id. example: Consequatur quis beatae voluptatem. requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/UpdateExemptionRuleRequestBody' example: actions: duration: maxDurationDays: 3 conditions: epss_score: gte: 90 reachable: true severity_code: - Critical description: Critical findings that are reachable in production must be remediated quickly; cap exemptions at 3 days. enabled: true name: 'Critical reachable issues: 3 days max' priority: 0 userId: abcdef1234567890ghijkl responses: '200': description: OK response. content: application/json: schema: $ref: '#/components/schemas/ExemptionRule' example: actions: duration: maxDurationDays: 3 conditions: epss_score: gte: 90 reachable: true severity_code: - Critical created: 1651578240 createdBy: user111111111111111111 description: Critical findings that are reachable in production must be remediated quickly; cap exemptions at 3 days. enabled: true id: abcdef1234567890ghijkl lastModified: 1651578240 lastModifiedBy: user111111111111111111 name: 'Critical reachable issues: 3 days max' priority: 0 '400': description: 'BadRequest: Bad Request response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: 'Bad Request: accountId parameter is required' status: 400 '401': description: 'Unauthorized: Unauthorized response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Unauthorized status: 401 '403': description: 'Forbidden: Forbidden response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Forbidden status: 403 '404': description: 'NotFound: Not Found response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Not Found status: 404 '429': description: 'TooManyRequests: Too Many Requests response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Too Many Requests status: 429 '500': description: 'InternalServerError: Internal Server Error response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Internal Server Error status: 500 security: - X-Api-Key_header_X-Api-Key: [] jwt_header_Authorization: - sto_exemption_approve summary: Exemption Rules#Update exemption rule x-summary-source: derived /sto/api/v2/exemption-rules/constraints: post: tags: - ExemptionRules summary: Get exemption constraints for issues or occurrences description: 'Evaluate the exemption rule engine and return the **strictest** constraint that applies to an exemption request. Pass `items[]` (max 100); a single exemption is just a one-element list. Each item self-describes its own scope and kind: • **target-scoped issue**: set `targetId`. • **pipeline-scoped issue**: set `pipelineId` (mutually exclusive with `targetId`). • **project-scoped issue**: set neither (scope comes from the request-level `orgId`/`projectId`). • **occurrence-level**: set `occurrences[]`, or set `scanId` (with `targetId`) to evaluate all non-exempted occurrences from that scan — used when "Exempt all future occurrences" is unchecked. Items in a single batch may mix scopes and kinds freely. The response carries the strictest matched constraint across everything evaluated: `maxDurationDays` is the minimum of every non-null per-item cap (or null if all are unconstrained), and `matchedRuleId` names the rule contributing that minimum. Optional `type` carries the FE "Reason" dropdown value (same enum as POST /exemptions.type) so rules with `reason` conditions evaluate correctly.' operationId: ExemptionRules#GetExemptionConstraints parameters: - name: accountId in: query description: Harness Account ID allowEmptyValue: true required: true schema: type: string description: Harness Account ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ example: abcdef1234567890ghijkl - name: X-Api-Key in: header description: Harness personal or service access token allowEmptyValue: true schema: type: string description: Harness personal or service access token example: Quia vel porro. example: Fuga consectetur occaecati. requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/GetExemptionConstraintsRequestBody' example: items: - issueId: abcdef1234567890ghijkl occurrences: - 101 - 102 pipelineId: my_pipeline scanId: abcdef1234567890ghijkl targetId: abcdef1234567890ghijkl - issueId: abcdef1234567890ghijkl occurrences: - 101 - 102 pipelineId: my_pipeline scanId: abcdef1234567890ghijkl targetId: abcdef1234567890ghijkl - issueId: abcdef1234567890ghijkl occurrences: - 101 - 102 pipelineId: my_pipeline scanId: abcdef1234567890ghijkl targetId: abcdef1234567890ghijkl orgId: default projectId: my_project type: False Positive responses: '200': description: OK response. content: application/json: schema: $ref: '#/components/schemas/ExemptionConstraints' example: matchedRuleId: rule11111111111111111a maxDurationDays: 7 '400': description: 'BadRequest: Bad Request response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: 'Bad Request: accountId parameter is required' status: 400 '401': description: 'Unauthorized: Unauthorized response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Unauthorized status: 401 '403': description: 'Forbidden: Forbidden response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Forbidden status: 403 '404': description: 'NotFound: Not Found response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Not Found status: 404 '429': description: 'TooManyRequests: Too Many Requests response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Too Many Requests status: 429 '500': description: 'InternalServerError: Internal Server Error response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Internal Server Error status: 500 security: - X-Api-Key_header_X-Api-Key: [] jwt_header_Authorization: - sto_exemption_view components: schemas: ExemptionConstraints: type: object properties: matchedRuleId: type: string description: ID of the rule that fired. Empty string if no rule matched (request is unconstrained by policy). example: rule11111111111111111a maxDurationDays: type: integer description: Maximum duration in days that this exemption may run. Null means no cap and indefinite ("All Time") is allowed; a non-null value forbids "All Time". example: 7 format: int64 minimum: 1 description: Constraints that apply to an exemption request for a specific issue, computed by evaluating account-level exemption rules against the issue's attributes. example: matchedRuleId: rule11111111111111111a maxDurationDays: 7 required: - matchedRuleId UpdateExemptionRuleRequestBody: type: object properties: actions: type: object description: 'Actions to apply when the rule matches. Today: duration only. Action handlers are pluggable; see the design doc for the planned set.' example: duration: maxDurationDays: 3 additionalProperties: true conditions: type: object description: Matcher conditions. Keys are attribute names that appear in the issue context (severity_code, type, reachability, exploitability, epss, plus anything in issue.details). Missing keys are wildcards. Each value is either an array (OR-list), an object describing a numeric range, or a scalar (equality). example: epss_score: gte: 90 reachable: true severity_code: - Critical additionalProperties: true description: type: string description: Free-form rule description. example: Critical findings that are reachable in production must be remediated quickly; cap exemptions at 3 days. maxLength: 1024 enabled: type: boolean description: 'Whether the rule is active. Disabled rules are retained and still listed, but are skipped during evaluation. OPTIONAL: defaults to true on create; on update, omit to keep the current state or send false/true to toggle.' example: true name: type: string description: Human-readable rule name. Must be unique within an account. example: 'Critical reachable issues: 3 days max' minLength: 1 maxLength: 256 priority: type: integer description: '0-based rank within an account. Lower fires first (first-match-wins). OPTIONAL on both create and update: if omitted on CREATE the new rule is appended at the bottom (rank = current rule count); if omitted on UPDATE the rule keeps its current rank. When supplied, send 0 to insert at the top, 1..n to insert at that rank, or any value >= rule count to land at the tail.' example: 0 format: int64 minimum: 0 userId: type: string description: Harness User ID example: abcdef1234567890ghijkl example: actions: duration: maxDurationDays: 3 conditions: epss_score: gte: 90 reachable: true severity_code: - Critical description: Critical findings that are reachable in production must be remediated quickly; cap exemptions at 3 days. enabled: true name: 'Critical reachable issues: 3 days max' priority: 0 userId: abcdef1234567890ghijkl required: - userId IDResult: type: object properties: id: type: string description: Resource identifier example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ example: id: abcdef1234567890ghijkl required: - id StoPagination: type: object properties: link: type: string description: Link-based paging example: '' page: type: integer description: Page number (starting from 0) example: 4 format: int64 pageSize: type: integer description: Requested page size example: 20 format: int64 totalItems: type: integer description: Total results available example: 230 format: int64 totalPages: type: integer description: Total pages available example: 12 format: int64 example: link: '' page: 4 pageSize: 20 totalItems: 230 totalPages: 12 required: - page - pageSize - totalPages - totalItems GetExemptionConstraintsRequestBody: type: object properties: items: type: array items: $ref: '#/components/schemas/IssueItem' description: Evaluation entries (max 100). Each item self-describes its scope (`targetId` / `pipelineId` / neither) and kind (`occurrences[]` present ⇒ occurrence-level). A single exemption is a one-element list. Items may mix scopes and kinds. example: - issueId: abcdef1234567890ghijkl occurrences: - 101 - 102 pipelineId: my_pipeline scanId: abcdef1234567890ghijkl targetId: abcdef1234567890ghijkl - issueId: abcdef1234567890ghijkl occurrences: - 101 - 102 pipelineId: my_pipeline scanId: abcdef1234567890ghijkl targetId: abcdef1234567890ghijkl - issueId: abcdef1234567890ghijkl occurrences: - 101 - 102 pipelineId: my_pipeline scanId: abcdef1234567890ghijkl targetId: abcdef1234567890ghijkl maxItems: 100 orgId: type: string description: 'Harness Organization id this exemption request is scoped to. Required: the backend resolves the project hierarchy (parent_unique_id) from `orgId`/`projectId` to scope attribute resolution for project- and pipeline-level evaluation, and rules conditioned on `org_id` evaluate correctly.' example: default pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 projectId: type: string description: 'Harness Project id this exemption request is scoped to. Required: the backend resolves the project hierarchy (parent_unique_id) from `orgId`/`projectId` to scope attribute resolution for project- and pipeline-level evaluation, and rules conditioned on `project_id` evaluate correctly.' example: my_project pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 type: type: string description: Value of the FE's "Reason" dropdown — i.e. the same enum sent as `type` on POST /exemptions ("False Positive", "Acceptable Risk", "Compensating Controls", "Acceptable Use", "Fix Unavailable", "Other"). When set, it is merged into every issue's context so rules with `reason` conditions evaluate correctly. Omit if the user has not picked from the dropdown yet — rules with reason conditions will be skipped in that case. Named `type` here for parity with POST /exemptions.type; internally the rule engine surfaces it as the `reason` axis (which matches the FE dropdown label customers see). example: False Positive enum: - Compensating Controls - Acceptable Use - Acceptable Risk - False Positive - Fix Unavailable - Other example: items: - issueId: abcdef1234567890ghijkl occurrences: - 101 - 102 pipelineId: my_pipeline scanId: abcdef1234567890ghijkl targetId: abcdef1234567890ghijkl - issueId: abcdef1234567890ghijkl occurrences: - 101 - 102 pipelineId: my_pipeline scanId: abcdef1234567890ghijkl targetId: abcdef1234567890ghijkl - issueId: abcdef1234567890ghijkl occurrences: - 101 - 102 pipelineId: my_pipeline scanId: abcdef1234567890ghijkl targetId: abcdef1234567890ghijkl orgId: default projectId: my_project type: False Positive required: - orgId - projectId NotFound: type: object properties: message: type: string example: Not Found status: type: integer default: 404 example: 404 format: int64 example: message: Not Found status: 404 required: - message ExemptionRule: type: object properties: actions: type: object description: 'Actions to apply when the rule matches. Today: duration only. Action handlers are pluggable; see the design doc for the planned set.' example: duration: maxDurationDays: 3 additionalProperties: true conditions: type: object description: Matcher conditions. Keys are attribute names that appear in the issue context (severity_code, type, reachability, exploitability, epss, plus anything in issue.details). Missing keys are wildcards. Each value is either an array (OR-list), an object describing a numeric range, or a scalar (equality). example: epss_score: gte: 90 reachable: true severity_code: - Critical additionalProperties: true created: type: integer description: Unix timestamp at which the resource was created example: 1651578240 format: int64 createdBy: type: string description: ID of the user who created the rule. example: user111111111111111111 pattern: ^[a-zA-Z0-9_-]{22}$ description: type: string description: Free-form rule description. example: Critical findings that are reachable in production must be remediated quickly; cap exemptions at 3 days. maxLength: 1024 enabled: type: boolean description: 'Whether the rule is active. Disabled rules are retained and still listed, but are skipped during evaluation. OPTIONAL: defaults to true on create; on update, omit to keep the current state or send false/true to toggle.' example: true id: type: string description: Resource identifier example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ lastModified: type: integer description: Unix timestamp at which the resource was most recently modified example: 1651578240 format: int64 lastModifiedBy: type: string description: ID of the user who last modified the rule. example: user111111111111111111 pattern: ^[a-zA-Z0-9_-]{22}$ name: type: string description: Human-readable rule name. Must be unique within an account. example: 'Critical reachable issues: 3 days max' minLength: 1 maxLength: 256 priority: type: integer description: '0-based rank within an account. Lower fires first (first-match-wins). OPTIONAL on both create and update: if omitted on CREATE the new rule is appended at the bottom (rank = current rule count); if omitted on UPDATE the rule keeps its current rank. When supplied, send 0 to insert at the top, 1..n to insert at that rank, or any value >= rule count to land at the tail.' example: 0 format: int64 minimum: 0 description: An admin-defined rule that gates Exemption creation and approval. Rules are evaluated against an exemption request; if a rule matches, its actions fire — typically capping the requested duration. example: actions: duration: maxDurationDays: 3 conditions: epss_score: gte: 90 reachable: true severity_code: - Critical created: 1651578240 createdBy: user111111111111111111 description: Critical findings that are reachable in production must be remediated quickly; cap exemptions at 3 days. enabled: true id: abcdef1234567890ghijkl lastModified: 1651578240 lastModifiedBy: user111111111111111111 name: 'Critical reachable issues: 3 days max' priority: 0 required: - id - name - conditions - actions - priority - enabled - createdBy - lastModifiedBy - created - lastModified CreateExemptionRuleRequestBody: type: object properties: actions: type: object description: 'Actions to apply when the rule matches. Today: duration only. Action handlers are pluggable; see the design doc for the planned set.' example: duration: maxDurationDays: 3 additionalProperties: true conditions: type: object description: Matcher conditions. Keys are attribute names that appear in the issue context (severity_code, type, reachability, exploitability, epss, plus anything in issue.details). Missing keys are wildcards. Each value is either an array (OR-list), an object describing a numeric range, or a scalar (equality). example: epss_score: gte: 90 reachable: true severity_code: - Critical additionalProperties: true description: type: string description: Free-form rule description. example: Critical findings that are reachable in production must be remediated quickly; cap exemptions at 3 days. maxLength: 1024 enabled: type: boolean description: 'Whether the rule is active. Disabled rules are retained and still listed, but are skipped during evaluation. OPTIONAL: defaults to true on create; on update, omit to keep the current state or send false/true to toggle.' example: true name: type: string description: Human-readable rule name. Must be unique within an account. example: 'Critical reachable issues: 3 days max' minLength: 1 maxLength: 256 priority: type: integer description: '0-based rank within an account. Lower fires first (first-match-wins). OPTIONAL on both create and update: if omitted on CREATE the new rule is appended at the bottom (rank = current rule count); if omitted on UPDATE the rule keeps its current rank. When supplied, send 0 to insert at the top, 1..n to insert at that rank, or any value >= rule count to land at the tail.' example: 0 format: int64 minimum: 0 userId: type: string description: Harness User ID example: abcdef1234567890ghijkl example: actions: duration: maxDurationDays: 3 conditions: epss_score: gte: 90 reachable: true severity_code: - Critical description: Critical findings that are reachable in production must be remediated quickly; cap exemptions at 3 days. enabled: true name: 'Critical reachable issues: 3 days max' priority: 0 userId: abcdef1234567890ghijkl required: - userId - name - conditions - actions ExemptionRulesListExemptionRulesResponseBody: type: object properties: pagination: $ref: '#/components/schemas/StoPagination' results: type: array items: $ref: '#/components/schemas/ExemptionRule' example: - actions: duration: maxDurationDays: 3 conditions: epss_score: gte: 90 reachable: true severity_code: - Critical created: 1651578240 createdBy: user111111111111111111 description: Critical findings that are reachable in production must be remediated quickly; cap exemptions at 3 days. enabled: true id: abcdef1234567890ghijkl lastModified: 1651578240 lastModifiedBy: user111111111111111111 name: 'Critical reachable issues: 3 days max' priority: 0 - actions: duration: maxDurationDays: 3 conditions: epss_score: gte: 90 reachable: true severity_code: - Critical created: 1651578240 createdBy: user111111111111111111 description: Critical findings that are reachable in production must be remediated quickly; cap exemptions at 3 days. enabled: true id: abcdef1234567890ghijkl lastModified: 1651578240 lastModifiedBy: user111111111111111111 name: 'Critical reachable issues: 3 days max' priority: 0 - actions: duration: maxDurationDays: 3 conditions: epss_score: gte: 90 reachable: true severity_code: - Critical created: 1651578240 createdBy: user111111111111111111 description: Critical findings that are reachable in production must be remediated quickly; cap exemptions at 3 days. enabled: true id: abcdef1234567890ghijkl lastModified: 1651578240 lastModifiedBy: user111111111111111111 name: 'Critical reachable issues: 3 days max' priority: 0 example: pagination: link: '' page: 4 pageSize: 20 totalItems: 230 totalPages: 12 results: - actions: duration: maxDurationDays: 3 conditions: epss_score: gte: 90 reachable: true severity_code: - Critical created: 1651578240 createdBy: user111111111111111111 description: Critical findings that are reachable in production must be remediated quickly; cap exemptions at 3 days. enabled: true id: abcdef1234567890ghijkl lastModified: 1651578240 lastModifiedBy: user111111111111111111 name: 'Critical reachable issues: 3 days max' priority: 0 - actions: duration: maxDurationDays: 3 conditions: epss_score: gte: 90 reachable: true severity_code: - Critical created: 1651578240 createdBy: user111111111111111111 description: Critical findings that are reachable in production must be remediated quickly; cap exemptions at 3 days. enabled: true id: abcdef1234567890ghijkl lastModified: 1651578240 lastModifiedBy: user111111111111111111 name: 'Critical reachable issues: 3 days max' priority: 0 - actions: duration: maxDurationDays: 3 conditions: epss_score: gte: 90 reachable: true severity_code: - Critical created: 1651578240 createdBy: user111111111111111111 description: Critical findings that are reachable in production must be remediated quickly; cap exemptions at 3 days. enabled: true id: abcdef1234567890ghijkl lastModified: 1651578240 lastModifiedBy: user111111111111111111 name: 'Critical reachable issues: 3 days max' priority: 0 required: - results - pagination IssueItem: type: object properties: issueId: type: string description: Issue ID to evaluate. example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ occurrences: type: array items: type: integer example: 6624826437369263000 format: int64 description: Occurrence internal IDs being exempted. When present, this item is an occurrence-level exemption (always target-scoped, `targetId` required). When omitted but `scanId` is set, all non-exempted occurrences for the issue in that scan are evaluated. example: - 101 - 102 pipelineId: type: string description: Pipeline id for this item (pipeline scope). Mutually exclusive with `targetId`. Different items may target different pipelines. example: my_pipeline pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 scanId: type: string description: Harness Scan ID. When set with `targetId` and without `occurrences[]`, expands to all non-exempted occurrences for the issue in that scan (current-occurrences-only exemption). Mutually exclusive with `pipelineId`. example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ targetId: type: string description: Target id for this item (target scope). Required when `occurrences[]` is set. Mutually exclusive with `pipelineId`. example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ example: issueId: abcdef1234567890ghijkl occurrences: - 101 - 102 pipelineId: my_pipeline scanId: abcdef1234567890ghijkl targetId: abcdef1234567890ghijkl required: - issueId securitySchemes: x-api-key: name: x-api-key type: apiKey in: header description: API key is a token provided while making the API calls. This is used to authenticate the client at the exposed endpoint. externalDocs: description: Find out more about Swagger url: http://swagger.io x-stoplight: id: oc91t4vrfnjyi x-tagGroups: - name: Organizations tags: - Organization - name: Projects tags: - Org Project - Project - name: Secrets tags: - Account Secret - Org Secret - Project Secret - Secrets - name: Connectors tags: - Account Connector - Org Connector - Project Connector - Connectors - GoogleSecretManagerConnector - name: Roles tags: - Account Roles - Organization Roles - Project Roles - Roles - name: Resource Groups tags: - Account Resource Groups - Organization Resource Groups - Project Resource Groups - Filter Resource Groups - Harness Resource Group - Zendesk - name: Role Assignments tags: - Account Role Assignments - Org Role Assignments - Project Role Assignments - Role Assignments - name: Platform tags: - Access Control List - Account Banner - Account Banner - Account Licensed Modules - Account License Type - Account Webhooks - AccountSetting - Accounts - Analyze Account Access Policy - Analyze Organization Access Policy - Analyze Project Access Policy - ApiKey - Audit - AuditFilters - Authentication Settings - Canny - Devops Essentials License Data By Account - EULA - Filter - Harness Resource Type - Invite - IP Allowlist - Nextgen Ldap - Notification Channels - Notification Rules - OIDC - Oidc-Access-Token - Oidc-ID-Token - Org Webhooks - Permissions - Project Webhooks - Secret Managers - Service Account - Setting - SMTP - Source Code Manager - Token - User - User Group - Variables - name: Delegate tags: - Agent mTLS Endpoint Management - Delegate Download Resource - Delegate Group Tags Resource - Delegate Setup Resource - Delegate Token Resource - name: Pipelines tags: - Pipelines - Input Sets - Approvals - Pipeline Execution - Pipeline Dashboard - Pipeline Input Set - Pipeline - Pipeline Execution Details - Pipeline Execute - Pipeline Refresh - Pipeline data retention - Triggers - TriggersEvents - Webhook Triggers - Webhook Event Handler - DryRunPipeline - name: Artifact Registry tags: - Registries - Artifacts - Docker Artifacts - Helm Artifacts - quarantine - Webhooks - Spaces - Replication - Registry V3 - Registries - Registry V3 - Packages - Registry V3 - Versions - Registry V3 - Files - Registry V3 - Metadata - Registry V3 - Firewall - Registry V3 - Transfer - name: Database DevOps tags: - Database Schema - Database Instance - Deployed State - Execution Config - Migration State - name: CD tags: - K8s Release Service Mapping - CustomDeployment - Environments - EnvironmentGroup - Infrastructures - Usage - File Store - Service Dashboard - ServiceOverrides - Rollback - tas - name: Deployment Freeze tags: - Freeze CRUD - Freeze Evaluation - Freeze Schema - name: Services tags: - Account Services - Org Services - Project Services - Services - name: Rancher Infrastructures tags: - Account Rancher Infrastructure - Org Rancher Infrastructure - Project Rancher Infrastructure - name: Templates tags: - Account Template - Org Template - Project Template - Templates - Global Templates - name: GitOps tags: - Agents - Application - Applications - Certificates - Clusters - Dashboard Aggregates - Dashboards - GnuPGP Keys - GPG Keys - Hosts - Project mappings - Projects - Reconciler - Repositories - Repository Certificates - Repository credentials - ValidateHost - name: GitX tags: - GitX Webhooks - Org Gitx Webhooks - Project Gitx Webhooks - name: CACM tags: - Anomalies Ignorelist Rule - Anomalies - BI Dashboards - Budgets - Budget Groups - Cost Categories - Cloud Accounts - K8S Connectors Metadata - Notification Settings v2 - Overview - Data Job Status - Recommendation cost settings - Unit Metric - Anomaly Comments - Cloud and AI cost anomaly details - Cloud and AI cost anomalies v2 - Cost Details - Currency Preferences - External Data Provider - AiEngine - CACM governance cost settings - Governance Enforcement Recommendation APIs - Governance Alert - Governance Overview - Governance Recommendation APIs - RuleEnforcement - Rule Executions - Rule - Rule Sets - Perspectives Folders - Perspective Reports - Perspectives - Cost Category Jira Project Mapping - Recommendations Details - Recommendations - Recommendation Jira - Recommendation Preferences - Recommendation Presets - Recommendation Servicenow - Recommendation Tags - Recommendation Ignore List - AutoStopping Rules - AutoStopping Rules V2 - AutoStopping Load Balancers - AutoStopping Fixed Schedules - AutoStopping Alerts - Commitment Orchestrator Events APIs - name: Feature Flags tags: - API Keys - Feature Flags - Targets - Target Groups - Environment Perspectives - Anomalies - Proxy - Tags - name: SRM tags: - Monitored Services - SLOs dashboard - NG SLOs - SLOs - Downtime - Srm Notification - name: Internal Developer Portal - IDP tags: - Entities - Teams - CatalogCustomProperties - Scores - DataSource - KubernetesDataPoints - AggregationRules - AppConfig - PluginInfo - LayoutProxy - Kinds - LayoutsV3 - LayoutsV4 - name: Environment Management - IDP tags: - Environment - Infrastructure - Instance - name: Custom Dashboards tags: - aida - dashboards - downloads - embed - folders - name: Policy Management tags: - dashboard - examples - policies - evaluate - evaluations - policysets - system - name: Code tags: - repository - status_checks - pullreq - upload - webhook - resource - rules - labels - name: IaCM tags: - usage - approvals - costs - executions - module-registry - workspaces - settings - tf-standard-backend - variables - name: STO tags: - Exemptions - Issues - Scans - Products - Test Targets - Target Variants - name: SEI tags: - Collection categories - Collections - Contributors - DORA - name: Git Sync (deprecated) tags: - Git Branches - Git Full Sync - Git Sync Settings - Git Sync - Git Sync Errors - name: Error Models tags: - Error Response - Governance Metadata - name: Supply Chain Security tags: - integration - PipelineInfraConfig - SBOM - Integration Step Config - Delete Step Config - Delete Repositories - Pipeline Store Config - Evidence Vault [Beta] - name: Release Management tags: - Release Groups - Releases - Orchestration Processes - Orchestration Activities - Orchestration Executions - Conflicts - Freeze - Reports - Uploads - name: Resilience Testing tags: - Actions - Action Templates - Chaos Components - Chaos Hubs - ChaosGuard Conditions - ChaosGuard Rules - DR Tests - Experiments - Experiment Templates - Faults - Fault Templates - Chaos Infrastructure - Health - Network Maps - Onboarding - Probes - Probe Templates - Chaos Recommendations - Risks