openapi: 3.2.0 info: title: Harness Exemptions API version: '1.0' description: The Harness Software Delivery Platform uses OpenAPI Specification v3.0. contact: name: API Support email: contact@harness.io url: https://harness.io/ x-logo: url: https://mma.prnewswire.com/media/779232/Harnes_logo_horizontal.jpg?p=facebook altText: Harness termsOfService: https://harness.io/terms-of-use/ servers: - url: https://app.harness.io description: Harness host URL - url: https://{vanity} description: Vanity URL variables: vanity: default: app.harness.io security: - x-api-key: [] tags: - name: Exemptions description: Access and modify Exemptions to Security Issues paths: /sto/api/v2/exemptions: get: tags: - Exemptions description: List a collection of Exemptions operationId: Exemptions#ListExemptions parameters: - name: accountId in: query description: Harness Account ID allowEmptyValue: true required: true schema: type: string description: Harness Account ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ example: abcdef1234567890ghijkl - name: page in: query description: Page number to fetch (starting from 0) allowEmptyValue: true schema: type: integer description: Page number to fetch (starting from 0) default: 0 example: 4 format: int64 minimum: 0 example: 4 - name: pageSize in: query description: Number of results per page allowEmptyValue: true schema: type: integer description: Number of results per page default: 30 example: 50 format: int64 minimum: 1 maximum: 100 example: 50 - name: orgId in: query description: Harness Organization ID allowEmptyValue: true schema: type: string description: Harness Organization ID example: example_org pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 example: example_org - name: projectId in: query description: Harness Project ID allowEmptyValue: true schema: type: string description: Harness Project ID example: example_project pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 example: example_project - name: X-Api-Key in: header description: Harness personal or service access token allowEmptyValue: true schema: type: string description: Harness personal or service access token example: Rerum optio voluptatem eum quo. example: Quasi culpa. responses: '200': description: OK response. content: application/json: schema: $ref: '#/components/schemas/ExemptionsListExemptionsResponseBody' example: pagination: link: '' page: 4 pageSize: 20 totalItems: 230 totalPages: 12 results: - approverEmail: user@harness.io approverId: user111111111111111111 approverName: firstname lastname canApproveFor: - ACCOUNT - ORG - PROJECT - PIPELINE canCancel: true canCreate: true canReApprove: true canReject: true comment: This exemption was reviewed by the security team. created: 1651578240 exemptionStatusAtScan: Approved expiration: 1651578240 id: abcdef1234567890ghijkl isDeleted: true issueId: abcdef1234567890ghijkl lastModified: 1651578240 link: https://example.com/ABC-1234 numOccurrences: 10 occurrences: - 42 - 666 orgId: your_project orgName: Organization Name pendingChanges: durationDays: 7 pipelineId: your_pipeline projectId: your_project projectName: Project Name reason: Waiting on upstream bug fix requestedOn: 1651578240 requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname reviewedOn: 1651578240 scanId: abcdef1234567890ghijkl scope: PROJECT search: CWE-123,5 status: Expired targetId: abcdef1234567890ghijkl type: Other - approverEmail: user@harness.io approverId: user111111111111111111 approverName: firstname lastname canApproveFor: - ACCOUNT - ORG - PROJECT - PIPELINE canCancel: true canCreate: true canReApprove: true canReject: true comment: This exemption was reviewed by the security team. created: 1651578240 exemptionStatusAtScan: Approved expiration: 1651578240 id: abcdef1234567890ghijkl isDeleted: true issueId: abcdef1234567890ghijkl lastModified: 1651578240 link: https://example.com/ABC-1234 numOccurrences: 10 occurrences: - 42 - 666 orgId: your_project orgName: Organization Name pendingChanges: durationDays: 7 pipelineId: your_pipeline projectId: your_project projectName: Project Name reason: Waiting on upstream bug fix requestedOn: 1651578240 requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname reviewedOn: 1651578240 scanId: abcdef1234567890ghijkl scope: PROJECT search: CWE-123,5 status: Expired targetId: abcdef1234567890ghijkl type: Other '400': description: 'BadRequest: Bad Request response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: 'Bad Request: accountId parameter is required' status: 400 '401': description: 'Unauthorized: Unauthorized response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Unauthorized status: 401 '403': description: 'Forbidden: Forbidden response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Forbidden status: 403 '404': description: 'NotFound: Not Found response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Not Found status: 404 '429': description: 'TooManyRequests: Too Many Requests response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Too Many Requests status: 429 '500': description: 'InternalServerError: Internal Server Error response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Internal Server Error status: 500 security: - X-Api-Key_header_X-Api-Key: [] jwt_header_Authorization: - sto_exemption_view summary: Exemptions#List exemptions x-summary-source: derived post: tags: - Exemptions description: Create a new Exemption operationId: Exemptions#CreateExemption parameters: - name: accountId in: query description: Harness Account ID allowEmptyValue: true required: true schema: type: string description: Harness Account ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ example: abcdef1234567890ghijkl - name: orgId in: query description: ID of the Harness Organization to which the exemption applies. Cannot be specified alongside "targetId". allowEmptyValue: true required: true schema: type: string description: ID of the Harness Organization to which the exemption applies. Cannot be specified alongside "targetId". example: your_project pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 examples: default: summary: default value: your_project - name: projectId in: query description: ID of the Harness Project to which the exemption applies. You must also specify "orgId". Cannot be specified alongside "targetId". allowEmptyValue: true required: true schema: type: string description: ID of the Harness Project to which the exemption applies. You must also specify "orgId". Cannot be specified alongside "targetId". example: your_project pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 examples: default: summary: default value: your_project - name: X-Api-Key in: header description: Harness personal or service access token allowEmptyValue: true schema: type: string description: Harness personal or service access token example: Expedita deleniti veniam tempora in. example: Minima quia voluptas ut cumque quos et. requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/CreateExemptionRequestBody' example: exemptFutureOccurrences: false expiration: 1651578240 issueId: abcdef1234567890ghijkl link: https://example.com/ABC-1234 occurrences: - 42 - 666 pendingChanges: durationDays: 7 pipelineId: your_pipeline reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterName: firstname lastname scanId: abcdef1234567890ghijkl search: CWE-123,5 targetId: abcdef1234567890ghijkl type: Other responses: '200': description: OK response. content: application/json: schema: $ref: '#/components/schemas/IDResult' example: id: abcdef1234567890ghijkl '400': description: 'BadRequest: Bad Request response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: 'Bad Request: accountId parameter is required' status: 400 '401': description: 'Unauthorized: Unauthorized response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Unauthorized status: 401 '403': description: 'Forbidden: Forbidden response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Forbidden status: 403 '429': description: 'TooManyRequests: Too Many Requests response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Too Many Requests status: 429 '500': description: 'InternalServerError: Internal Server Error response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Internal Server Error status: 500 security: - X-Api-Key_header_X-Api-Key: [] jwt_header_Authorization: - sto_exemption_create summary: Exemptions#Create exemption x-summary-source: derived /sto/api/v2/exemptions/{id}: delete: description: Delete an existing Exemption operationId: Exemptions#DeleteExemption parameters: - allowEmptyValue: true description: Harness Account ID example: abcdef1234567890ghijkl in: query name: accountId required: true schema: description: Harness Account ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ type: string - allowEmptyValue: true description: Harness Organization ID examples: default: summary: default value: example_org in: query name: orgId schema: description: Harness Organization ID example: example_org maxLength: 128 pattern: ^[A-Za-z_][A-Za-z0-9_]*$ type: string - allowEmptyValue: true description: Harness Project ID examples: default: summary: default value: example_project in: query name: projectId schema: description: Harness Project ID example: example_project maxLength: 128 pattern: ^[A-Za-z_][A-Za-z0-9_]*$ type: string - description: The ID of the Exemption to delete example: abcdef1234567890ghijkl in: path name: id required: true schema: description: The ID of the Exemption to delete example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ type: string responses: '204': description: No Content response. '400': content: application/json: example: message: 'Bad Request: accountId parameter is required' status: 400 schema: $ref: '#/components/schemas/NotFound' description: 'BadRequest: Bad Request response.' '401': content: application/json: example: message: Unauthorized status: 401 schema: $ref: '#/components/schemas/NotFound' description: 'Unauthorized: Unauthorized response.' '403': content: application/json: example: message: Forbidden status: 403 schema: $ref: '#/components/schemas/NotFound' description: 'Forbidden: Forbidden response.' '404': content: application/json: example: message: Not Found status: 404 schema: $ref: '#/components/schemas/NotFound' description: 'NotFound: Not Found response.' '429': content: application/json: example: message: Too Many Requests status: 429 schema: $ref: '#/components/schemas/NotFound' description: 'TooManyRequests: Too Many Requests response.' '500': content: application/json: example: message: Internal Server Error status: 500 schema: $ref: '#/components/schemas/NotFound' description: 'InternalServerError: Internal Server Error response.' security: - jwt_header_Authorization: - sto_exemption_create tags: - Exemptions x-internal: true summary: Exemptions#Delete exemption x-summary-source: derived get: tags: - Exemptions description: Find Exemption by ID operationId: Exemptions#FindExemptionById parameters: - name: accountId in: query description: Harness Account ID allowEmptyValue: true required: true schema: type: string description: Harness Account ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ example: abcdef1234567890ghijkl - name: orgId in: query description: Harness Organization ID allowEmptyValue: true schema: type: string description: Harness Organization ID example: example_org pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 examples: default: summary: default value: example_org - name: projectId in: query description: Harness Project ID allowEmptyValue: true schema: type: string description: Harness Project ID example: example_project pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 examples: default: summary: default value: example_project - name: executionId in: query description: Harness Execution ID allowEmptyValue: true schema: type: string description: Harness Execution ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ example: abcdef1234567890ghijkl - name: ignoreScope in: query description: Ignore scope allowEmptyValue: true schema: type: boolean description: Ignore scope example: false example: false - name: id in: path description: The ID of the Exemption to retrieve required: true schema: type: string description: The ID of the Exemption to retrieve example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ example: abcdef1234567890ghijkl - name: X-Api-Key in: header description: Harness personal or service access token allowEmptyValue: true schema: type: string description: Harness personal or service access token example: Laboriosam sint dolores. example: Rerum ut aut vel ipsum. responses: '200': description: OK response. content: application/json: schema: $ref: '#/components/schemas/Exemption' example: approverEmail: user@harness.io approverId: user111111111111111111 approverName: firstname lastname canApproveFor: - ACCOUNT - ORG - PROJECT - PIPELINE canCancel: true canCreate: true canReApprove: true canReject: true comment: This exemption was reviewed by the security team. created: 1651578240 exemptionStatusAtScan: Approved expiration: 1651578240 id: abcdef1234567890ghijkl isDeleted: true issueId: abcdef1234567890ghijkl lastModified: 1651578240 link: https://example.com/ABC-1234 numOccurrences: 10 occurrences: - 42 - 666 orgId: your_project orgName: Organization Name pendingChanges: durationDays: 7 pipelineId: your_pipeline projectId: your_project projectName: Project Name reason: Waiting on upstream bug fix requestedOn: 1651578240 requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname reviewedOn: 1651578240 scanId: abcdef1234567890ghijkl scope: PROJECT search: CWE-123,5 status: Expired targetId: abcdef1234567890ghijkl type: Other '400': description: 'BadRequest: Bad Request response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: 'Bad Request: accountId parameter is required' status: 400 '401': description: 'Unauthorized: Unauthorized response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Unauthorized status: 401 '403': description: 'Forbidden: Forbidden response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Forbidden status: 403 '404': description: 'NotFound: Not Found response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Not Found status: 404 '429': description: 'TooManyRequests: Too Many Requests response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Too Many Requests status: 429 '500': description: 'InternalServerError: Internal Server Error response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Internal Server Error status: 500 security: - X-Api-Key_header_X-Api-Key: [] jwt_header_Authorization: - sto_exemption_view summary: Exemptions#Find exemption by id x-summary-source: derived put: tags: - Exemptions description: Update an existing Exemption operationId: Exemptions#UpdateExemption parameters: - name: accountId in: query description: Harness Account ID allowEmptyValue: true required: true schema: type: string description: Harness Account ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ example: abcdef1234567890ghijkl - name: orgId in: query description: ID of the Harness Organization to which the exemption applies. Cannot be specified alongside "targetId". allowEmptyValue: true schema: type: string description: ID of the Harness Organization to which the exemption applies. Cannot be specified alongside "targetId". example: your_project pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 examples: default: summary: default value: your_project - name: projectId in: query description: ID of the Harness Project to which the exemption applies. You must also specify "orgId". Cannot be specified alongside "targetId". allowEmptyValue: true schema: type: string description: ID of the Harness Project to which the exemption applies. You must also specify "orgId". Cannot be specified alongside "targetId". example: your_project pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 examples: default: summary: default value: your_project - name: id in: path description: The ID of the Exemption to update required: true schema: type: string description: The ID of the Exemption to update example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ example: abcdef1234567890ghijkl - name: X-Api-Key in: header description: Harness personal or service access token allowEmptyValue: true schema: type: string description: Harness personal or service access token example: Iure quo vero at exercitationem. example: Quae aut nemo corporis pariatur. requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/UpdateExemptionRequestBody' example: expiration: 1651578240 link: https://example.com/ABC-1234 pendingChanges: durationDays: 7 pipelineId: your_pipeline reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterName: firstname lastname targetId: abcdef1234567890ghijkl type: Other responses: '200': description: OK response. content: application/json: schema: $ref: '#/components/schemas/Exemption' example: approverEmail: user@harness.io approverId: user111111111111111111 approverName: firstname lastname canApproveFor: - ACCOUNT - ORG - PROJECT - PIPELINE canCancel: true canCreate: true canReApprove: true canReject: true comment: This exemption was reviewed by the security team. created: 1651578240 exemptionStatusAtScan: Approved expiration: 1651578240 id: abcdef1234567890ghijkl isDeleted: true issueId: abcdef1234567890ghijkl lastModified: 1651578240 link: https://example.com/ABC-1234 numOccurrences: 10 occurrences: - 42 - 666 orgId: your_project orgName: Organization Name pendingChanges: durationDays: 7 pipelineId: your_pipeline projectId: your_project projectName: Project Name reason: Waiting on upstream bug fix requestedOn: 1651578240 requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname reviewedOn: 1651578240 scanId: abcdef1234567890ghijkl scope: PROJECT search: CWE-123,5 status: Expired targetId: abcdef1234567890ghijkl type: Other '400': description: 'BadRequest: Bad Request response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: 'Bad Request: accountId parameter is required' status: 400 '401': description: 'Unauthorized: Unauthorized response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Unauthorized status: 401 '403': description: 'Forbidden: Forbidden response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Forbidden status: 403 '404': description: 'NotFound: Not Found response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Not Found status: 404 '429': description: 'TooManyRequests: Too Many Requests response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Too Many Requests status: 429 '500': description: 'InternalServerError: Internal Server Error response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Internal Server Error status: 500 security: - X-Api-Key_header_X-Api-Key: [] jwt_header_Authorization: - sto_exemption_create summary: Exemptions#Update exemption x-summary-source: derived /sto/api/v2/exemptions/{id}/{action}: put: tags: - Exemptions description: Approve/reject an existing Exemption operationId: Exemptions#ApproveExemption parameters: - name: accountId in: query description: Harness Account ID allowEmptyValue: true required: true schema: type: string description: Harness Account ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ example: abcdef1234567890ghijkl - name: orgId in: query description: Harness Organization ID allowEmptyValue: true schema: type: string description: Harness Organization ID example: example_org pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 examples: default: summary: default value: example_org - name: projectId in: query description: Harness Project ID allowEmptyValue: true schema: type: string description: Harness Project ID example: example_project pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 examples: default: summary: default value: example_project - name: id in: path description: The ID of the Exemption to update required: true schema: type: string description: The ID of the Exemption to update example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ example: abcdef1234567890ghijkl - name: action in: path description: The approval action to take on the Exemption required: true schema: type: string description: The approval action to take on the Exemption example: approve enum: - approve - reject example: approve - name: X-Api-Key in: header description: Harness personal or service access token allowEmptyValue: true schema: type: string description: Harness personal or service access token example: Pariatur repellendus nisi. example: Maxime ducimus. requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/ApproveExemptionRequestBody' example: comment: This is a comment for the approval or rejection of the exemption pendingChangesOverride: durationDays: 30 responses: '200': description: OK response. content: application/json: schema: $ref: '#/components/schemas/Exemption' example: approverEmail: user@harness.io approverId: user111111111111111111 approverName: firstname lastname canApproveFor: - ACCOUNT - ORG - PROJECT - PIPELINE canCancel: true canCreate: true canReApprove: true canReject: true comment: This exemption was reviewed by the security team. created: 1651578240 exemptionStatusAtScan: Approved expiration: 1651578240 id: abcdef1234567890ghijkl isDeleted: true issueId: abcdef1234567890ghijkl lastModified: 1651578240 link: https://example.com/ABC-1234 numOccurrences: 10 occurrences: - 42 - 666 orgId: your_project orgName: Organization Name pendingChanges: durationDays: 7 pipelineId: your_pipeline projectId: your_project projectName: Project Name reason: Waiting on upstream bug fix requestedOn: 1651578240 requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname reviewedOn: 1651578240 scanId: abcdef1234567890ghijkl scope: PROJECT search: CWE-123,5 status: Expired targetId: abcdef1234567890ghijkl type: Other '400': description: 'BadRequest: Bad Request response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: 'Bad Request: accountId parameter is required' status: 400 '401': description: 'Unauthorized: Unauthorized response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Unauthorized status: 401 '403': description: 'Forbidden: Forbidden response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Forbidden status: 403 '404': description: 'NotFound: Not Found response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Not Found status: 404 '429': description: 'TooManyRequests: Too Many Requests response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Too Many Requests status: 429 '500': description: 'InternalServerError: Internal Server Error response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Internal Server Error status: 500 security: - X-Api-Key_header_X-Api-Key: [] jwt_header_Authorization: - sto_exemption_approve summary: Exemptions#Approve exemption x-summary-source: derived /sto/api/v2/exemptions/{id}/promote: put: tags: - Exemptions description: Promote an existing Exemption to a higher scope operationId: Exemptions#PromoteExemption parameters: - name: accountId in: query description: Harness Account ID allowEmptyValue: true required: true schema: type: string description: Harness Account ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ example: abcdef1234567890ghijkl - name: orgId in: query description: Harness Organization ID allowEmptyValue: true schema: type: string description: Harness Organization ID example: example_org pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 examples: default: summary: default value: example_org - name: projectId in: query description: Harness Project ID allowEmptyValue: true schema: type: string description: Harness Project ID example: example_project pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 examples: default: summary: default value: example_project - name: id in: path description: The ID of the Exemption to promote required: true schema: type: string description: The ID of the Exemption to promote example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ example: abcdef1234567890ghijkl - name: X-Api-Key in: header description: Harness personal or service access token allowEmptyValue: true schema: type: string description: Harness personal or service access token example: Dolor quasi et odit. example: Animi non ipsa nisi sed voluptas. requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/PromoteExemptionRequestBody' example: comment: This is a comment for the approval or rejection of the exemption pendingChangesOverride: durationDays: 30 pipelineId: abcdef1234567890ghijkl targetId: abcdef1234567890ghijkl responses: '200': description: OK response. content: application/json: schema: $ref: '#/components/schemas/Exemption' example: approverEmail: user@harness.io approverId: user111111111111111111 approverName: firstname lastname canApproveFor: - ACCOUNT - ORG - PROJECT - PIPELINE canCancel: true canCreate: true canReApprove: true canReject: true comment: This exemption was reviewed by the security team. created: 1651578240 exemptionStatusAtScan: Approved expiration: 1651578240 id: abcdef1234567890ghijkl isDeleted: true issueId: abcdef1234567890ghijkl lastModified: 1651578240 link: https://example.com/ABC-1234 numOccurrences: 10 occurrences: - 42 - 666 orgId: your_project orgName: Organization Name pendingChanges: durationDays: 7 pipelineId: your_pipeline projectId: your_project projectName: Project Name reason: Waiting on upstream bug fix requestedOn: 1651578240 requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname reviewedOn: 1651578240 scanId: abcdef1234567890ghijkl scope: PROJECT search: CWE-123,5 status: Expired targetId: abcdef1234567890ghijkl type: Other '400': description: 'BadRequest: Bad Request response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: 'Bad Request: accountId parameter is required' status: 400 '401': description: 'Unauthorized: Unauthorized response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Unauthorized status: 401 '403': description: 'Forbidden: Forbidden response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Forbidden status: 403 '404': description: 'NotFound: Not Found response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Not Found status: 404 '429': description: 'TooManyRequests: Too Many Requests response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Too Many Requests status: 429 '500': description: 'InternalServerError: Internal Server Error response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Internal Server Error status: 500 security: - X-Api-Key_header_X-Api-Key: [] jwt_header_Authorization: - sto_exemption_approve summary: Exemptions#Promote exemption x-summary-source: derived /sto/api/v2/exemptions/bulk: post: tags: - Exemptions summary: Bulk create exemptions description: 'Create multiple Exemptions in bulk. The batch is all-or-none for policy violations: if any item would violate an exemption rule, the entire batch is rejected with HTTP 400 and a single error message naming the failing issue and rule (no DB writes happen). Infrastructure failures (DB constraint violations, transaction errors) also fail the entire batch and are surfaced per-item in the response body so ops can diagnose which item triggered the failure.' operationId: Exemptions#BulkCreateExemptions parameters: - name: accountId in: query description: Harness Account ID allowEmptyValue: true required: true schema: type: string description: Harness Account ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ example: abcdef1234567890ghijkl - name: orgId in: query description: Harness Organization ID allowEmptyValue: true required: true schema: type: string description: Harness Organization ID example: example_org pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 example: example_org - name: projectId in: query description: Harness Project ID allowEmptyValue: true required: true schema: type: string description: Harness Project ID example: example_project pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 example: example_project - name: X-Api-Key in: header description: Harness personal or service access token allowEmptyValue: true schema: type: string description: Harness personal or service access token example: Earum ipsa et cumque. example: Modi ad quam et est saepe. requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/BulkCreateExemptionsRequestBody' example: exemptFutureOccurrences: false expiration: 1651578240 items: - issueId: abcdef1234567890ghijkl occurrences: - 42 - 666 pipelineId: your_pipeline scanId: abcdef1234567890ghijkl search: CWE-123,5 targetId: abcdef1234567890ghijkl - issueId: abcdef1234567890ghijkl occurrences: - 42 - 666 pipelineId: your_pipeline scanId: abcdef1234567890ghijkl search: CWE-123,5 targetId: abcdef1234567890ghijkl - issueId: abcdef1234567890ghijkl occurrences: - 42 - 666 pipelineId: your_pipeline scanId: abcdef1234567890ghijkl search: CWE-123,5 targetId: abcdef1234567890ghijkl link: https://example.com/ABC-1234 pendingChanges: durationDays: 7 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterName: firstname lastname type: Other responses: '200': description: OK response. content: application/json: schema: $ref: '#/components/schemas/BulkExemptionResult' example: failed: 1 results: - error: '"targetId" must be specified when "exempt future occurrences" is disabled' id: abcdef1234567890ghijkl issueId: abcdef1234567890ghijkl statusCode: 201 - error: '"targetId" must be specified when "exempt future occurrences" is disabled' id: abcdef1234567890ghijkl issueId: abcdef1234567890ghijkl statusCode: 201 succeeded: 5 '400': description: 'BadRequest: Bad Request response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: 'Bad Request: accountId parameter is required' status: 400 '401': description: 'Unauthorized: Unauthorized response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Unauthorized status: 401 '403': description: 'Forbidden: Forbidden response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Forbidden status: 403 '429': description: 'TooManyRequests: Too Many Requests response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Too Many Requests status: 429 '500': description: 'InternalServerError: Internal Server Error response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Internal Server Error status: 500 security: - X-Api-Key_header_X-Api-Key: [] jwt_header_Authorization: - sto_exemption_create /sto/api/v2/exemptions/issue/{issueId}: get: tags: - Exemptions summary: Get exemption for issue description: Get the highest-priority exemption for an issue across all scopes (account, org, project) operationId: Exemptions#GetExemptionForIssue parameters: - name: accountId in: query description: Harness Account ID allowEmptyValue: true required: true schema: type: string description: Harness Account ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ example: abcdef1234567890ghijkl - name: orgId in: query description: Harness Organization ID allowEmptyValue: true schema: type: string description: Harness Organization ID example: example_org pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 example: example_org - name: projectId in: query description: Harness Project ID allowEmptyValue: true schema: type: string description: Harness Project ID example: example_project pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 example: example_project - name: issueId in: path description: Issue ID to find exemption for required: true schema: type: string description: Issue ID to find exemption for example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ example: abcdef1234567890ghijkl - name: X-Api-Key in: header description: Harness personal or service access token allowEmptyValue: true schema: type: string description: Harness personal or service access token example: Nesciunt repellendus omnis et. example: Est ex sed blanditiis cum. responses: '200': description: OK response. content: application/json: schema: $ref: '#/components/schemas/Exemption' example: approverEmail: user@harness.io approverId: user111111111111111111 approverName: firstname lastname canApproveFor: - ACCOUNT - ORG - PROJECT - PIPELINE canCancel: true canCreate: true canReApprove: true canReject: true comment: This exemption was reviewed by the security team. created: 1651578240 exemptionStatusAtScan: Approved expiration: 1651578240 id: abcdef1234567890ghijkl isDeleted: true issueId: abcdef1234567890ghijkl lastModified: 1651578240 link: https://example.com/ABC-1234 numOccurrences: 10 occurrences: - 42 - 666 orgId: your_project orgName: Organization Name pendingChanges: durationDays: 7 pipelineId: your_pipeline projectId: your_project projectName: Project Name reason: Waiting on upstream bug fix requestedOn: 1651578240 requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname reviewedOn: 1651578240 scanId: abcdef1234567890ghijkl scope: PROJECT search: CWE-123,5 status: Expired targetId: abcdef1234567890ghijkl type: Other '400': description: 'BadRequest: Bad Request response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: 'Bad Request: accountId parameter is required' status: 400 '401': description: 'Unauthorized: Unauthorized response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Unauthorized status: 401 '403': description: 'Forbidden: Forbidden response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Forbidden status: 403 '429': description: 'TooManyRequests: Too Many Requests response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Too Many Requests status: 429 '500': description: 'InternalServerError: Internal Server Error response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Internal Server Error status: 500 security: - X-Api-Key_header_X-Api-Key: [] jwt_header_Authorization: - sto_exemption_view /sto/api/v2/exemptions/issue/{issueId}/history: get: tags: - Exemptions summary: List exemption history for issue description: Paginated flat timeline of exemption history events for an issue operationId: Exemptions#ListIssueExemptionHistory parameters: - name: accountId in: query description: Harness Account ID allowEmptyValue: true required: true schema: type: string description: Harness Account ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ example: abcdef1234567890ghijkl - name: orgId in: query description: Harness Organization ID allowEmptyValue: true schema: type: string description: Harness Organization ID example: example_org pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 example: example_org - name: projectId in: query description: Harness Project ID allowEmptyValue: true schema: type: string description: Harness Project ID example: example_project pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 example: example_project - name: page in: query description: Page number to fetch (starting from 0) allowEmptyValue: true schema: type: integer description: Page number to fetch (starting from 0) default: 0 example: 4 format: int64 minimum: 0 example: 4 - name: pageSize in: query description: Number of results per page allowEmptyValue: true schema: type: integer description: Number of results per page default: 30 example: 50 format: int64 minimum: 1 maximum: 100 example: 50 - name: pipelineId in: query description: Harness pipeline ID. When set with targetId, scopes history to that pipeline/target (Vulnerabilities tab). Requires orgId and projectId. allowEmptyValue: true schema: type: string description: Harness pipeline ID. When set with targetId, scopes history to that pipeline/target (Vulnerabilities tab). Requires orgId and projectId. example: sto-core-ci pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 example: sto-core-ci - name: targetId in: query description: Harness target ID. When set with pipelineId, scopes history to that pipeline/target (Vulnerabilities tab). Requires orgId and projectId. allowEmptyValue: true schema: type: string description: Harness target ID. When set with pipelineId, scopes history to that pipeline/target (Vulnerabilities tab). Requires orgId and projectId. example: target1111111111111111 pattern: ^[a-zA-Z0-9_-]{22}$ example: target1111111111111111 - name: issueId in: path description: Issue ID required: true schema: type: string description: Issue ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ example: abcdef1234567890ghijkl - name: X-Api-Key in: header description: Harness personal or service access token allowEmptyValue: true schema: type: string description: Harness personal or service access token example: Est laudantium cupiditate est ad repellendus aliquam. example: Ut non non. responses: '200': description: OK response. content: application/json: schema: $ref: '#/components/schemas/IssueExemptionHistoryResult' example: events: - comment: p8h commenterEmail: priya.nair@harness.io commenterId: user111111111111111111 commenterName: Priya Nair created: 1781391060 durationDays: 3208129927373090300 exemptedOccurrenceCount: 744031225383331100 exemptionId: exmp111111111111111111 expiration: 4477985376795396000 id: hist111111111111111111 isAutoExpiry: false isOccurrenceLevel: false orgId: Nobis quo dolores commodi. orgName: Default pipelineId: Neque libero qui. pipelineName: STO Core CI projectId: Sed qui harum et cupiditate doloremque corporis. projectName: STO Core reasonType: Compensating Controls scope: ORG status: Pending targetId: Qui aperiam dicta. targetName: sto-core - comment: p8h commenterEmail: priya.nair@harness.io commenterId: user111111111111111111 commenterName: Priya Nair created: 1781391060 durationDays: 3208129927373090300 exemptedOccurrenceCount: 744031225383331100 exemptionId: exmp111111111111111111 expiration: 4477985376795396000 id: hist111111111111111111 isAutoExpiry: false isOccurrenceLevel: false orgId: Nobis quo dolores commodi. orgName: Default pipelineId: Neque libero qui. pipelineName: STO Core CI projectId: Sed qui harum et cupiditate doloremque corporis. projectName: STO Core reasonType: Compensating Controls scope: ORG status: Pending targetId: Qui aperiam dicta. targetName: sto-core - comment: p8h commenterEmail: priya.nair@harness.io commenterId: user111111111111111111 commenterName: Priya Nair created: 1781391060 durationDays: 3208129927373090300 exemptedOccurrenceCount: 744031225383331100 exemptionId: exmp111111111111111111 expiration: 4477985376795396000 id: hist111111111111111111 isAutoExpiry: false isOccurrenceLevel: false orgId: Nobis quo dolores commodi. orgName: Default pipelineId: Neque libero qui. pipelineName: STO Core CI projectId: Sed qui harum et cupiditate doloremque corporis. projectName: STO Core reasonType: Compensating Controls scope: ORG status: Pending targetId: Qui aperiam dicta. targetName: sto-core pagination: link: '' page: 4 pageSize: 20 totalItems: 230 totalPages: 12 '400': description: 'BadRequest: Bad Request response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: 'Bad Request: accountId parameter is required' status: 400 '401': description: 'Unauthorized: Unauthorized response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Unauthorized status: 401 '403': description: 'Forbidden: Forbidden response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Forbidden status: 403 '429': description: 'TooManyRequests: Too Many Requests response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Too Many Requests status: 429 '500': description: 'InternalServerError: Internal Server Error response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Internal Server Error status: 500 security: - X-Api-Key_header_X-Api-Key: [] jwt_header_Authorization: - sto_exemption_view /sto/api/v2/exemptions/issue/{issueId}/history/export: get: tags: - Exemptions summary: Export exemption history for issue as CSV description: CSV export of the full exemption history timeline for an issue (fetch-all, no pagination) operationId: Exemptions#ExportIssueExemptionHistory parameters: - name: accountId in: query description: Harness Account ID allowEmptyValue: true required: true schema: type: string description: Harness Account ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ example: abcdef1234567890ghijkl - name: orgId in: query description: Harness Organization ID allowEmptyValue: true schema: type: string description: Harness Organization ID example: example_org pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 example: example_org - name: projectId in: query description: Harness Project ID allowEmptyValue: true schema: type: string description: Harness Project ID example: example_project pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 example: example_project - name: pipelineId in: query description: Harness pipeline ID. When set with targetId, scopes history to that pipeline/target (Vulnerabilities tab). Requires orgId and projectId. allowEmptyValue: true schema: type: string description: Harness pipeline ID. When set with targetId, scopes history to that pipeline/target (Vulnerabilities tab). Requires orgId and projectId. example: sto-core-ci pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 example: sto-core-ci - name: targetId in: query description: Harness target ID. When set with pipelineId, scopes history to that pipeline/target (Vulnerabilities tab). Requires orgId and projectId. allowEmptyValue: true schema: type: string description: Harness target ID. When set with pipelineId, scopes history to that pipeline/target (Vulnerabilities tab). Requires orgId and projectId. example: target1111111111111111 pattern: ^[a-zA-Z0-9_-]{22}$ example: target1111111111111111 - name: issueId in: path description: Issue ID required: true schema: type: string description: Issue ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ example: abcdef1234567890ghijkl - name: X-Api-Key in: header description: Harness personal or service access token allowEmptyValue: true schema: type: string description: Harness personal or service access token example: Molestias earum. example: Dolor velit quidem harum hic harum perspiciatis. responses: '200': description: OK response. content: application/json: schema: $ref: '#/components/schemas/ExportIssueExemptionHistoryResponseBody' example: data: - - Qui sint. - Similique voluptatibus velit. - - Minus voluptatum eos fugiat commodi. - Autem enim qui facilis. - - Ex ad eius. - Necessitatibus id reiciendis error facere. - Non facilis reiciendis sed. - Reiciendis voluptas omnis est omnis dolores. filename: Velit animi incidunt. headers: - Neque fugit suscipit dolorem. - Molestiae ea et quis. - Consectetur cupiditate voluptatem ut eligendi. issueId: Repellendus non. totalRows: 4551642554385867300 '400': description: 'BadRequest: Bad Request response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: 'Bad Request: accountId parameter is required' status: 400 '401': description: 'Unauthorized: Unauthorized response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Unauthorized status: 401 '403': description: 'Forbidden: Forbidden response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Forbidden status: 403 '429': description: 'TooManyRequests: Too Many Requests response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Too Many Requests status: 429 '500': description: 'InternalServerError: Internal Server Error response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Internal Server Error status: 500 security: - X-Api-Key_header_X-Api-Key: [] jwt_header_Authorization: - sto_exemption_view /v1/orgs/{org}/projects/{project}/exemptions: parameters: - $ref: '#/components/parameters/OrgParam1' - $ref: '#/components/parameters/ProjectParam1' get: summary: List exemptions for project tags: - Exemptions security: - x-api-key: [] responses: '200': $ref: '#/components/responses/ExemptionListResponseDTO' '400': description: Bad Request '500': description: Internal Server Error operationId: listExemptionsForProject x-stoplight: id: 9rlhvfejqah63 parameters: - $ref: '#/components/parameters/AccountHeader6' - $ref: '#/components/parameters/Limit6' - $ref: '#/components/parameters/Page2' - schema: type: array items: $ref: '#/components/schemas/ExemptionStatusDTO' in: query name: status description: status of the exemption, all statuses will be returned if this is null - schema: type: string in: query name: artifact_id description: artifactId of the exemption, only applicable for exemptions with ARTIFACT scope - schema: type: string in: query name: search_term description: Search for exemptions by name post: summary: Create exemption for project tags: - Exemptions operationId: createExemptionForProject security: - x-api-key: [] responses: '201': description: '' content: application/json: schema: $ref: '#/components/schemas/ExemptionResponseDTO' '400': description: Bad Request '500': description: Internal Server Error x-stoplight: id: bgtzrf9osfkqt parameters: - $ref: '#/components/parameters/AccountHeader6' requestBody: description: '' content: application/json: schema: $ref: '#/components/schemas/ExemptionRequestDTO' /v1/orgs/{org}/projects/{project}/artifacts/{artifact}/exemptions: parameters: - $ref: '#/components/parameters/ProjectParam1' - $ref: '#/components/parameters/OrgParam1' - $ref: '#/components/parameters/Artifact' post: summary: Create exemption for artifact operationId: createExemptionForArtifact security: - x-api-key: [] responses: '201': description: '' content: application/json: schema: $ref: '#/components/schemas/ExemptionResponseDTO' '400': description: Bad Request '500': description: Internal Server Error parameters: - $ref: '#/components/parameters/AccountHeader6' requestBody: description: '' content: application/json: schema: $ref: '#/components/schemas/ExemptionRequestDTO' x-stoplight: id: gnrf5uwmpc5nq tags: - Exemptions /v1/orgs/{org}/projects/{project}/exemptions/{exemption}: parameters: - $ref: '#/components/parameters/OrgParam1' - $ref: '#/components/parameters/ProjectParam1' - $ref: '#/components/parameters/Exemption' get: summary: Get exemption for project tags: - Exemptions security: - x-api-key: [] responses: '200': description: '' content: application/json: schema: $ref: '#/components/schemas/ExemptionResponseDTO' '400': description: Bad Request '500': description: Internal Server Error operationId: getExemptionForProject parameters: - $ref: '#/components/parameters/AccountHeader6' x-stoplight: id: doij0dtepyqtg put: summary: Update exemption for project operationId: updateExemptionForProject security: - x-api-key: [] responses: '200': description: '' content: application/json: schema: $ref: '#/components/schemas/ExemptionResponseDTO' '400': description: Bad Request '500': description: Internal Server Error x-stoplight: id: 10lshl289t84n requestBody: description: '' content: application/json: schema: $ref: '#/components/schemas/ExemptionRequestDTO' parameters: - $ref: '#/components/parameters/AccountHeader6' tags: - Exemptions delete: summary: Delete exemption for project operationId: deleteExemptionForProject security: - x-api-key: [] responses: '204': description: '' '400': description: Bad Request '500': description: Internal Server Error x-stoplight: id: 5rkc3a8lvyqa5 parameters: - $ref: '#/components/parameters/AccountHeader6' tags: - Exemptions /v1/orgs/{org}/projects/{project}/artifacts/{artifact}/exemptions/{exemption}: parameters: - $ref: '#/components/parameters/OrgParam1' - $ref: '#/components/parameters/ProjectParam1' - $ref: '#/components/parameters/Exemption' - $ref: '#/components/parameters/Artifact' get: summary: Get exemption for artifact tags: - Exemptions security: - x-api-key: [] responses: '200': description: '' content: application/json: schema: $ref: '#/components/schemas/ExemptionResponseDTO' '400': description: Bad Request '500': description: Internal Server Error operationId: getExemptionForArtifact parameters: - $ref: '#/components/parameters/AccountHeader6' x-stoplight: id: 47eka1spqllsf put: summary: Update exemption for artifact operationId: updateExemptionForArtifact tags: - Exemptions security: - x-api-key: [] responses: '200': description: '' content: application/json: schema: $ref: '#/components/schemas/ExemptionResponseDTO' '400': description: Bad Request '500': description: Internal Server Error requestBody: description: '' content: application/json: schema: $ref: '#/components/schemas/ExemptionRequestDTO' parameters: - $ref: '#/components/parameters/AccountHeader6' x-stoplight: id: wo6x8cpwhbq3m delete: summary: Delete exemption for artifact operationId: deleteExemptionForArtifact tags: - Exemptions security: - x-api-key: [] responses: '204': description: '' '400': description: Bad Request '500': description: Internal Server Error parameters: - $ref: '#/components/parameters/AccountHeader6' x-stoplight: id: m4w47h5007z2e /v1/orgs/{org}/projects/{project}/exemptions/{exemption}/review: parameters: - $ref: '#/components/parameters/OrgParam1' - $ref: '#/components/parameters/ProjectParam1' - $ref: '#/components/parameters/Exemption' put: summary: Review exemption for project tags: - Exemptions security: - x-api-key: [] operationId: reviewExemptionForProject responses: '200': description: '' content: application/json: schema: $ref: '#/components/schemas/ExemptionResponseDTO' '400': description: Bad Request '500': description: Internal Server Error x-stoplight: id: l079e2dbui1m8 parameters: - $ref: '#/components/parameters/AccountHeader6' requestBody: description: '' content: application/json: schema: $ref: '#/components/schemas/ExemptionReviewRequestDTO' /v1/orgs/{org}/projects/{project}/artifacts/{artifact}/exemptions/{exemption}/review: parameters: - $ref: '#/components/parameters/OrgParam1' - $ref: '#/components/parameters/ProjectParam1' - $ref: '#/components/parameters/Exemption' - $ref: '#/components/parameters/Artifact' put: summary: Review exemption for artifact operationId: reviewExemptionForArtifact tags: - Exemptions security: - x-api-key: [] responses: '200': description: '' content: application/json: schema: $ref: '#/components/schemas/ExemptionResponseDTO' '400': description: Bad Request '500': description: Internal Server Error parameters: - $ref: '#/components/parameters/AccountHeader6' x-stoplight: id: 2guw8lpxf9fwg requestBody: description: Shared Request content: application/json: schema: $ref: '#/components/schemas/ExemptionReviewRequestDTO' components: schemas: ExemptionHistoryEvent: type: object properties: comment: type: string description: eh.comment when present example: qj7 maxLength: 1024 commenterEmail: type: string description: Email of the commenter example: priya.nair@harness.io commenterId: type: string description: User ID; absent for auto-expiry example: user111111111111111111 pattern: ^[a-zA-Z0-9_-]{22}$ commenterName: type: string description: Display name of the commenter example: Priya Nair created: type: integer description: Unix timestamp (seconds) example: 1781391060 format: int64 durationDays: type: integer description: COALESCE(eh.state.duration_days, pending_changes fallback) example: 9210991542842275000 format: int64 exemptedOccurrenceCount: type: integer description: Count of occurrences covered (issue-level fingerprint or scan-scoped) example: 8118853364885305000 format: int64 exemptionId: type: string description: Parent exemption.id example: exmp111111111111111111 pattern: ^[a-zA-Z0-9_-]{22}$ expiration: type: integer description: Unix timestamp from eh.state.expiration when present example: 5621343883892058000 format: int64 id: type: string description: exemption_history.id example: hist111111111111111111 pattern: ^[a-zA-Z0-9_-]{22}$ isAutoExpiry: type: boolean description: True when status=Expired and commenter_id IS NULL default: false example: true isOccurrenceLevel: type: boolean description: True when exemption has exemption_occurrence rows at event time example: true orgId: type: string example: Quia labore. orgName: type: string description: Display name for orgId, resolved via ng-manager example: Default pipelineId: type: string description: From eh.state.pipeline_id when scope=PIPELINE example: Porro qui ut occaecati aperiam. pipelineName: type: string description: Display name for pipelineId, resolved via pipeline service example: STO Core CI projectId: type: string example: Iure aperiam. projectName: type: string description: Display name for projectId, resolved via ng-manager example: STO Core reasonType: type: string description: From eh.state.type (Compensating Controls, False Positive, etc.) example: Compensating Controls scope: type: string example: TARGET enum: - ACCOUNT - ORG - PROJECT - PIPELINE - TARGET status: type: string example: Approved enum: - Pending - Approved - Rejected - Expired - Canceled targetId: type: string description: From eh.state.target_id when scope=TARGET example: Nemo qui accusamus et cupiditate voluptatem dolorem. targetName: type: string description: Display name for targetId example: sto-core description: Single exemption history row with per-event scope snapshot example: comment: 1j8 commenterEmail: priya.nair@harness.io commenterId: user111111111111111111 commenterName: Priya Nair created: 1781391060 durationDays: 3814440511166016500 exemptedOccurrenceCount: 2123339849563154200 exemptionId: exmp111111111111111111 expiration: 3829887781061036000 id: hist111111111111111111 isAutoExpiry: true isOccurrenceLevel: true orgId: Quam cum tenetur aut doloremque eius est. orgName: Default pipelineId: Omnis et voluptatem reiciendis pariatur. pipelineName: STO Core CI projectId: Dolor ut rerum qui. projectName: STO Core reasonType: Compensating Controls scope: TARGET status: Expired targetId: Beatae adipisci magnam. targetName: sto-core required: - id - exemptionId - status - created - scope - isAutoExpiry ExemptionsListExemptionsResponseBody: type: object properties: pagination: $ref: '#/components/schemas/StoPagination' results: type: array items: $ref: '#/components/schemas/Exemption' example: - approverEmail: user@harness.io approverId: user111111111111111111 approverName: firstname lastname canApproveFor: - ACCOUNT - ORG - PROJECT - PIPELINE canCancel: true canCreate: true canReApprove: true canReject: true comment: This exemption was reviewed by the security team. created: 1651578240 exemptionStatusAtScan: Approved expiration: 1651578240 id: abcdef1234567890ghijkl isDeleted: true issueId: abcdef1234567890ghijkl lastModified: 1651578240 link: https://example.com/ABC-1234 numOccurrences: 10 occurrences: - 42 - 666 orgId: your_project orgName: Organization Name pendingChanges: durationDays: 7 pipelineId: your_pipeline projectId: your_project projectName: Project Name reason: Waiting on upstream bug fix requestedOn: 1651578240 requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname reviewedOn: 1651578240 scanId: abcdef1234567890ghijkl scope: PROJECT search: CWE-123,5 status: Expired targetId: abcdef1234567890ghijkl type: Other - approverEmail: user@harness.io approverId: user111111111111111111 approverName: firstname lastname canApproveFor: - ACCOUNT - ORG - PROJECT - PIPELINE canCancel: true canCreate: true canReApprove: true canReject: true comment: This exemption was reviewed by the security team. created: 1651578240 exemptionStatusAtScan: Approved expiration: 1651578240 id: abcdef1234567890ghijkl isDeleted: true issueId: abcdef1234567890ghijkl lastModified: 1651578240 link: https://example.com/ABC-1234 numOccurrences: 10 occurrences: - 42 - 666 orgId: your_project orgName: Organization Name pendingChanges: durationDays: 7 pipelineId: your_pipeline projectId: your_project projectName: Project Name reason: Waiting on upstream bug fix requestedOn: 1651578240 requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname reviewedOn: 1651578240 scanId: abcdef1234567890ghijkl scope: PROJECT search: CWE-123,5 status: Expired targetId: abcdef1234567890ghijkl type: Other example: pagination: link: '' page: 4 pageSize: 20 totalItems: 230 totalPages: 12 results: - approverEmail: user@harness.io approverId: user111111111111111111 approverName: firstname lastname canApproveFor: - ACCOUNT - ORG - PROJECT - PIPELINE canCancel: true canCreate: true canReApprove: true canReject: true comment: This exemption was reviewed by the security team. created: 1651578240 exemptionStatusAtScan: Approved expiration: 1651578240 id: abcdef1234567890ghijkl isDeleted: true issueId: abcdef1234567890ghijkl lastModified: 1651578240 link: https://example.com/ABC-1234 numOccurrences: 10 occurrences: - 42 - 666 orgId: your_project orgName: Organization Name pendingChanges: durationDays: 7 pipelineId: your_pipeline projectId: your_project projectName: Project Name reason: Waiting on upstream bug fix requestedOn: 1651578240 requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname reviewedOn: 1651578240 scanId: abcdef1234567890ghijkl scope: PROJECT search: CWE-123,5 status: Expired targetId: abcdef1234567890ghijkl type: Other - approverEmail: user@harness.io approverId: user111111111111111111 approverName: firstname lastname canApproveFor: - ACCOUNT - ORG - PROJECT - PIPELINE canCancel: true canCreate: true canReApprove: true canReject: true comment: This exemption was reviewed by the security team. created: 1651578240 exemptionStatusAtScan: Approved expiration: 1651578240 id: abcdef1234567890ghijkl isDeleted: true issueId: abcdef1234567890ghijkl lastModified: 1651578240 link: https://example.com/ABC-1234 numOccurrences: 10 occurrences: - 42 - 666 orgId: your_project orgName: Organization Name pendingChanges: durationDays: 7 pipelineId: your_pipeline projectId: your_project projectName: Project Name reason: Waiting on upstream bug fix requestedOn: 1651578240 requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname reviewedOn: 1651578240 scanId: abcdef1234567890ghijkl scope: PROJECT search: CWE-123,5 status: Expired targetId: abcdef1234567890ghijkl type: Other - approverEmail: user@harness.io approverId: user111111111111111111 approverName: firstname lastname canApproveFor: - ACCOUNT - ORG - PROJECT - PIPELINE canCancel: true canCreate: true canReApprove: true canReject: true comment: This exemption was reviewed by the security team. created: 1651578240 exemptionStatusAtScan: Approved expiration: 1651578240 id: abcdef1234567890ghijkl isDeleted: true issueId: abcdef1234567890ghijkl lastModified: 1651578240 link: https://example.com/ABC-1234 numOccurrences: 10 occurrences: - 42 - 666 orgId: your_project orgName: Organization Name pendingChanges: durationDays: 7 pipelineId: your_pipeline projectId: your_project projectName: Project Name reason: Waiting on upstream bug fix requestedOn: 1651578240 requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname reviewedOn: 1651578240 scanId: abcdef1234567890ghijkl scope: PROJECT search: CWE-123,5 status: Expired targetId: abcdef1234567890ghijkl type: Other required: - results - pagination ApproveExemptionRequestBody: type: object properties: comment: type: string description: Comment to be added to the Exemption approval or rejection example: This is a comment for the approval or rejection of the exemption maxLength: 1024 pendingChangesOverride: $ref: '#/components/schemas/PendingChanges' example: comment: This is a comment for the approval or rejection of the exemption pendingChangesOverride: durationDays: 30 required: - type - reason - pendingChanges - issueId - status - requesterId - created - lastModified IDResult: type: object properties: id: type: string description: Resource identifier example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ example: id: abcdef1234567890ghijkl required: - id PromoteExemptionRequestBody: type: object properties: comment: type: string description: Comment to be added to the Exemption approval or rejection example: This is a comment for the approval or rejection of the exemption maxLength: 1024 pendingChangesOverride: $ref: '#/components/schemas/PendingChanges' pipelineId: type: string description: Harness STO pipeline ID example: abcdef1234567890ghijkl pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 targetId: type: string description: Harness STO Target ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ example: comment: This is a comment for the approval or rejection of the exemption pendingChangesOverride: durationDays: 30 pipelineId: abcdef1234567890ghijkl targetId: abcdef1234567890ghijkl required: - type - reason - pendingChanges - issueId - status - requesterId - created - lastModified StoPagination: type: object properties: link: type: string description: Link-based paging example: '' page: type: integer description: Page number (starting from 0) example: 4 format: int64 pageSize: type: integer description: Requested page size example: 20 format: int64 totalItems: type: integer description: Total results available example: 230 format: int64 totalPages: type: integer description: Total pages available example: 12 format: int64 example: link: '' page: 4 pageSize: 20 totalItems: 230 totalPages: 12 required: - page - pageSize - totalPages - totalItems CreateExemptionRequestBody: type: object properties: exemptFutureOccurrences: type: boolean description: States if the user wants to exempt future occurrences of the issue default: true example: false expiration: type: integer description: Unix timestamp at which this Exemption will expire example: 1651578240 format: int64 issueId: type: string description: Issue ID associated with the Exemption example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ link: type: string description: Link to a related ticket example: https://example.com/ABC-1234 maxLength: 1024 occurrences: type: array items: type: integer example: 3733837613986067500 format: int64 description: Array of occurrence Ids example: - 42 - 666 pendingChanges: $ref: '#/components/schemas/PendingChanges' pipelineId: type: string description: ID of the Harness Pipeline to which the exemption applies. You must also specify "projectId" and "orgId". Cannot be specified alongside "targetId". example: your_pipeline pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 reason: type: string description: Text describing why this Exemption is necessary example: Waiting on upstream bug fix maxLength: 1024 requesterEmail: type: string description: Email of the user who requested this Exemption example: user@harness.io requesterName: type: string description: Name of the user who requested this Exemption example: firstname lastname scanId: type: string description: ID of the Harness Scan to determine all the occurrences for the scan-issue. You must also specify "projectId", "orgId" and "targetId". Cannot be specified alongside "pipelineId". example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ search: type: string description: Search parameter to find filtered occurrences of the issue example: CWE-123,5 maxLength: 256 targetId: type: string description: ID of the Target to which the exemption applies. Cannot be specified alongside "projectId" or "pipelineId". example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ type: type: string description: Type of Exemption (Compensating Controls / Acceptable Use / Acceptable Risk / False Positive / Fix Unavailable / Other) example: Other enum: - Compensating Controls - Acceptable Use - Acceptable Risk - False Positive - Fix Unavailable - Other example: exemptFutureOccurrences: false expiration: 1651578240 issueId: abcdef1234567890ghijkl link: https://example.com/ABC-1234 occurrences: - 42 - 666 pendingChanges: durationDays: 7 pipelineId: your_pipeline reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterName: firstname lastname scanId: abcdef1234567890ghijkl search: CWE-123,5 targetId: abcdef1234567890ghijkl type: Other required: - type - reason - pendingChanges - issueId - status - requesterId - id - created - lastModified BulkExemptionItem: type: object properties: issueId: type: string description: Issue ID associated with the Exemption example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ occurrences: type: array items: type: integer example: 1662420723120880000 format: int64 description: Array of occurrence IDs example: - 42 - 666 pipelineId: type: string description: ID of the Harness Pipeline to which the exemption applies. Cannot be specified alongside "targetId". example: your_pipeline pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 scanId: type: string description: ID of the Harness Scan to determine all occurrences for the scan-issue. example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ search: type: string description: Search parameter to find filtered occurrences of the issue example: CWE-123,5 maxLength: 256 targetId: type: string description: ID of the Target to which the exemption applies. Cannot be specified alongside "pipelineId". example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ example: issueId: abcdef1234567890ghijkl occurrences: - 42 - 666 pipelineId: your_pipeline scanId: abcdef1234567890ghijkl search: CWE-123,5 targetId: abcdef1234567890ghijkl required: - issueId PendingChanges: type: object properties: durationDays: type: integer description: The number of days an issue should be exempted for example: 7 format: int64 example: durationDays: 7 NotFound: type: object properties: message: type: string example: Not Found status: type: integer default: 404 example: 404 format: int64 example: message: Not Found status: 404 required: - message UpdateExemptionRequestBody: type: object properties: expiration: type: integer description: Unix timestamp at which this Exemption will expire example: 1651578240 format: int64 link: type: string description: Link to a related ticket example: https://example.com/ABC-1234 maxLength: 1024 pendingChanges: $ref: '#/components/schemas/PendingChanges' pipelineId: type: string description: ID of the Harness Pipeline to which the exemption applies. You must also specify "projectId" and "orgId". Cannot be specified alongside "targetId". example: your_pipeline pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 reason: type: string description: Text describing why this Exemption is necessary example: Waiting on upstream bug fix maxLength: 1024 requesterEmail: type: string description: Email of the user who requested this Exemption example: user@harness.io requesterName: type: string description: Name of the user who requested this Exemption example: firstname lastname targetId: type: string description: ID of the Target to which the exemption applies. Cannot be specified alongside "projectId" or "pipelineId". example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ type: type: string description: Type of Exemption (Compensating Controls / Acceptable Use / Acceptable Risk / False Positive / Fix Unavailable / Other) example: Other enum: - Compensating Controls - Acceptable Use - Acceptable Risk - False Positive - Fix Unavailable - Other example: expiration: 1651578240 link: https://example.com/ABC-1234 pendingChanges: durationDays: 7 pipelineId: your_pipeline reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterName: firstname lastname targetId: abcdef1234567890ghijkl type: Other required: - type - reason - pendingChanges - issueId - status - requesterId - created - lastModified BulkExemptionItemResult: type: object properties: error: type: string description: Error message (populated on failure) example: '"targetId" must be specified when "exempt future occurrences" is disabled' id: type: string description: ID of the created exemption (populated on success) example: abcdef1234567890ghijkl issueId: type: string description: Issue ID of the exemption item example: abcdef1234567890ghijkl statusCode: type: integer description: HTTP status code for this item (201 on success, 4xx/5xx on failure) example: 201 format: int64 example: error: '"targetId" must be specified when "exempt future occurrences" is disabled' id: abcdef1234567890ghijkl issueId: abcdef1234567890ghijkl statusCode: 201 required: - issueId - statusCode ExportIssueExemptionHistoryResponseBody: type: object properties: data: type: array items: type: array items: type: string example: Molestiae placeat impedit quibusdam quae nihil qui. example: - In maiores labore aspernatur aut. - Facilis quia earum nostrum vitae. - Reiciendis sapiente excepturi rerum. description: CSV data rows example: - - Quo dolor explicabo non cumque est et. - Sit magnam libero. - Nulla voluptatem ut rerum commodi esse. - Architecto voluptas qui quia eaque praesentium. - - Cumque atque esse quo. - Optio temporibus assumenda consequatur doloribus. - Corporis perferendis nemo deserunt et molestiae. - Numquam molestias velit ut ab sunt. - - Repellat facere facilis. - Voluptas voluptas maiores minima sunt quo repellendus. - Dolores voluptatibus. filename: type: string description: Suggested filename for download example: Necessitatibus ipsum. headers: type: array items: type: string example: Et sunt quas distinctio dolores. description: CSV column headers example: - Veritatis consequatur ut. - Eum amet rerum nulla omnis pariatur. issueId: type: string description: Issue ID for this export example: Quos est esse iure. totalRows: type: integer description: Total number of data rows example: 1630037832351495200 format: int64 example: data: - - Similique repellendus repellat quas. - In quas quia dolorum quaerat quam ab. - Maiores eius animi dolorum blanditiis ut. - Consequatur ratione repellendus et occaecati. - - Exercitationem perspiciatis qui nam. - Impedit doloremque dolor. filename: Et consequatur ipsum sed. headers: - Similique aut magni dolorem. - Non velit porro sit. - Qui culpa debitis. - Quidem eveniet doloribus. issueId: Omnis unde quo pariatur maxime cupiditate quisquam. totalRows: 2327911194105004000 required: - headers - data - filename - totalRows - issueId Exemption: type: object properties: approverEmail: type: string description: Email of the user who approved this Exemption example: user@harness.io approverId: type: string description: User ID the user who approved or rejected this exemptions example: user111111111111111111 pattern: ^[a-zA-Z0-9_-]{22}$ approverName: type: string description: Name of the user who approved this Exemption example: firstname lastname canApproveFor: type: array items: type: string example: ACCOUNT enum: - ACCOUNT - ORG - PROJECT - PIPELINE - TARGET description: Consists of RBAC scopes for an user associated with this Exemption example: - ACCOUNT - ORG - PROJECT - PIPELINE canCancel: type: boolean description: States if the user can cancel the exemption default: false example: true canCreate: type: boolean description: States whether the user can create or reopen the exemption default: false example: true canReApprove: type: boolean description: States if the user can re-approve the exemption for the exemption's scope default: false example: true canReject: type: boolean description: States whether the user can reject the exemption default: false example: true comment: type: string description: The additional comment to include with the exemption example: This exemption was reviewed by the security team. created: type: integer description: Unix timestamp at which the resource was created example: 1651578240 format: int64 exemptionStatusAtScan: type: string description: Exemption's status at the Security Scan created time example: Expired enum: - Pending - Approved - Rejected - Expired expiration: type: integer description: Unix timestamp at which this Exemption will expire example: 1651578240 format: int64 id: type: string description: Resource identifier example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ isDeleted: type: boolean description: States if the exemption is deleted default: false example: true issueId: type: string description: Issue ID associated with the Exemption example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ lastModified: type: integer description: Unix timestamp at which the resource was most recently modified example: 1651578240 format: int64 link: type: string description: Link to a related ticket example: https://example.com/ABC-1234 maxLength: 1024 numOccurrences: type: integer description: States how may occurrences are associated with the exemption, if not an issue level exemption default: 0 example: 10 format: int64 occurrences: type: array items: type: integer example: 8626056711372740000 format: int64 description: Array of occurrence Ids example: - 42 - 666 orgId: type: string description: ID of the Harness Organization to which the exemption applies. Cannot be specified alongside "targetId". example: your_project pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 orgName: type: string description: Name of the organization associated with the exemption example: Organization Name pendingChanges: $ref: '#/components/schemas/PendingChanges' pipelineId: type: string description: ID of the Harness Pipeline to which the exemption applies. You must also specify "projectId" and "orgId". Cannot be specified alongside "targetId". example: your_pipeline pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 projectId: type: string description: ID of the Harness Project to which the exemption applies. You must also specify "orgId". Cannot be specified alongside "targetId". example: your_project pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 projectName: type: string description: Name of the project associated with the exemption example: Project Name reason: type: string description: Text describing why this Exemption is necessary example: Waiting on upstream bug fix maxLength: 1024 requestedOn: type: integer description: Unix timestamp of the exemption's current request. Updates each time the exemption is reopened; falls back to the original creation time when never reopened. example: 1651578240 format: int64 requesterEmail: type: string description: Email of the user who requested this Exemption example: user@harness.io requesterId: type: string description: User ID of the user who requested this Exemption example: user111111111111111111 requesterName: type: string description: Name of the user who requested this Exemption example: firstname lastname reviewedOn: type: integer description: Unix timestamp when this exemption was reviewed (approved or rejected). Populated only for approved and rejected exemptions. example: 1651578240 format: int64 scanId: type: string description: ID of the Harness Scan to determine all the occurrences for the scan-issue. You must also specify "projectId", "orgId" and "targetId". Cannot be specified alongside "pipelineId". example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ scope: type: string description: States the scope for the exemption example: PROJECT enum: - ACCOUNT - ORG - PROJECT - PIPELINE - TARGET search: type: string description: Search parameter to find filtered occurrences of the issue example: CWE-123,5 maxLength: 256 status: type: string description: Approval status of Exemption default: Pending example: Canceled enum: - Pending - Approved - Rejected - Expired - Canceled targetId: type: string description: ID of the Target to which the exemption applies. Cannot be specified alongside "projectId" or "pipelineId". example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ type: type: string description: Type of Exemption (Compensating Controls / Acceptable Use / Acceptable Risk / False Positive / Fix Unavailable / Other) example: Other enum: - Compensating Controls - Acceptable Use - Acceptable Risk - False Positive - Fix Unavailable - Other description: Information about an Exemption example: approverEmail: user@harness.io approverId: user111111111111111111 approverName: firstname lastname canApproveFor: - ACCOUNT - ORG - PROJECT - PIPELINE canCancel: true canCreate: true canReApprove: true canReject: true comment: This exemption was reviewed by the security team. created: 1651578240 exemptionStatusAtScan: Approved expiration: 1651578240 id: abcdef1234567890ghijkl isDeleted: true issueId: abcdef1234567890ghijkl lastModified: 1651578240 link: https://example.com/ABC-1234 numOccurrences: 10 occurrences: - 42 - 666 orgId: your_project orgName: Organization Name pendingChanges: durationDays: 7 pipelineId: your_pipeline projectId: your_project projectName: Project Name reason: Waiting on upstream bug fix requestedOn: 1651578240 requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname reviewedOn: 1651578240 scanId: abcdef1234567890ghijkl scope: PROJECT search: CWE-123,5 status: Approved targetId: abcdef1234567890ghijkl type: Other required: - type - reason - pendingChanges - issueId - status - requesterId - id - created - lastModified IssueExemptionHistoryResult: type: object properties: events: type: array items: $ref: '#/components/schemas/ExemptionHistoryEvent' description: Flat timeline, newest first. Not grouped by exemptionId. example: - comment: p8h commenterEmail: priya.nair@harness.io commenterId: user111111111111111111 commenterName: Priya Nair created: 1781391060 durationDays: 3208129927373090300 exemptedOccurrenceCount: 744031225383331100 exemptionId: exmp111111111111111111 expiration: 4477985376795396000 id: hist111111111111111111 isAutoExpiry: false isOccurrenceLevel: false orgId: Nobis quo dolores commodi. orgName: Default pipelineId: Neque libero qui. pipelineName: STO Core CI projectId: Sed qui harum et cupiditate doloremque corporis. projectName: STO Core reasonType: Compensating Controls scope: ORG status: Pending targetId: Qui aperiam dicta. targetName: sto-core - comment: p8h commenterEmail: priya.nair@harness.io commenterId: user111111111111111111 commenterName: Priya Nair created: 1781391060 durationDays: 3208129927373090300 exemptedOccurrenceCount: 744031225383331100 exemptionId: exmp111111111111111111 expiration: 4477985376795396000 id: hist111111111111111111 isAutoExpiry: false isOccurrenceLevel: false orgId: Nobis quo dolores commodi. orgName: Default pipelineId: Neque libero qui. pipelineName: STO Core CI projectId: Sed qui harum et cupiditate doloremque corporis. projectName: STO Core reasonType: Compensating Controls scope: ORG status: Pending targetId: Qui aperiam dicta. targetName: sto-core pagination: $ref: '#/components/schemas/StoPagination' example: events: - comment: p8h commenterEmail: priya.nair@harness.io commenterId: user111111111111111111 commenterName: Priya Nair created: 1781391060 durationDays: 3208129927373090300 exemptedOccurrenceCount: 744031225383331100 exemptionId: exmp111111111111111111 expiration: 4477985376795396000 id: hist111111111111111111 isAutoExpiry: false isOccurrenceLevel: false orgId: Nobis quo dolores commodi. orgName: Default pipelineId: Neque libero qui. pipelineName: STO Core CI projectId: Sed qui harum et cupiditate doloremque corporis. projectName: STO Core reasonType: Compensating Controls scope: ORG status: Pending targetId: Qui aperiam dicta. targetName: sto-core - comment: p8h commenterEmail: priya.nair@harness.io commenterId: user111111111111111111 commenterName: Priya Nair created: 1781391060 durationDays: 3208129927373090300 exemptedOccurrenceCount: 744031225383331100 exemptionId: exmp111111111111111111 expiration: 4477985376795396000 id: hist111111111111111111 isAutoExpiry: false isOccurrenceLevel: false orgId: Nobis quo dolores commodi. orgName: Default pipelineId: Neque libero qui. pipelineName: STO Core CI projectId: Sed qui harum et cupiditate doloremque corporis. projectName: STO Core reasonType: Compensating Controls scope: ORG status: Pending targetId: Qui aperiam dicta. targetName: sto-core pagination: link: '' page: 4 pageSize: 20 totalItems: 230 totalPages: 12 required: - events - pagination BulkExemptionResult: type: object properties: failed: type: integer description: Number of failed exemption creations example: 1 format: int64 results: type: array items: $ref: '#/components/schemas/BulkExemptionItemResult' description: Per-item results in the same order as the request items example: - error: '"targetId" must be specified when "exempt future occurrences" is disabled' id: abcdef1234567890ghijkl issueId: abcdef1234567890ghijkl statusCode: 201 - error: '"targetId" must be specified when "exempt future occurrences" is disabled' id: abcdef1234567890ghijkl issueId: abcdef1234567890ghijkl statusCode: 201 - error: '"targetId" must be specified when "exempt future occurrences" is disabled' id: abcdef1234567890ghijkl issueId: abcdef1234567890ghijkl statusCode: 201 - error: '"targetId" must be specified when "exempt future occurrences" is disabled' id: abcdef1234567890ghijkl issueId: abcdef1234567890ghijkl statusCode: 201 succeeded: type: integer description: Number of successfully created exemptions example: 5 format: int64 example: failed: 1 results: - error: '"targetId" must be specified when "exempt future occurrences" is disabled' id: abcdef1234567890ghijkl issueId: abcdef1234567890ghijkl statusCode: 201 - error: '"targetId" must be specified when "exempt future occurrences" is disabled' id: abcdef1234567890ghijkl issueId: abcdef1234567890ghijkl statusCode: 201 - error: '"targetId" must be specified when "exempt future occurrences" is disabled' id: abcdef1234567890ghijkl issueId: abcdef1234567890ghijkl statusCode: 201 - error: '"targetId" must be specified when "exempt future occurrences" is disabled' id: abcdef1234567890ghijkl issueId: abcdef1234567890ghijkl statusCode: 201 succeeded: 5 required: - results - succeeded - failed BulkCreateExemptionsRequestBody: type: object properties: exemptFutureOccurrences: type: boolean description: Whether to exempt future occurrences of each issue default: true example: false expiration: type: integer description: Unix timestamp at which these Exemptions will expire example: 1651578240 format: int64 items: type: array items: $ref: '#/components/schemas/BulkExemptionItem' description: List of exemption items to create (max 100) example: - issueId: abcdef1234567890ghijkl occurrences: - 42 - 666 pipelineId: your_pipeline scanId: abcdef1234567890ghijkl search: CWE-123,5 targetId: abcdef1234567890ghijkl minItems: 1 maxItems: 100 link: type: string description: Link to a related ticket example: https://example.com/ABC-1234 maxLength: 1024 pendingChanges: $ref: '#/components/schemas/PendingChanges' reason: type: string description: Text describing why these Exemptions are necessary example: Waiting on upstream bug fix maxLength: 1024 requesterEmail: type: string description: Email of the user who requested these Exemptions example: user@harness.io requesterName: type: string description: Name of the user who requested these Exemptions example: firstname lastname type: type: string description: Type of Exemption (Compensating Controls / Acceptable Use / Acceptable Risk / False Positive / Fix Unavailable / Other) example: Other enum: - Compensating Controls - Acceptable Use - Acceptable Risk - False Positive - Fix Unavailable - Other example: exemptFutureOccurrences: false expiration: 1651578240 items: - issueId: abcdef1234567890ghijkl occurrences: - 42 - 666 pipelineId: your_pipeline scanId: abcdef1234567890ghijkl search: CWE-123,5 targetId: abcdef1234567890ghijkl - issueId: abcdef1234567890ghijkl occurrences: - 42 - 666 pipelineId: your_pipeline scanId: abcdef1234567890ghijkl search: CWE-123,5 targetId: abcdef1234567890ghijkl - issueId: abcdef1234567890ghijkl occurrences: - 42 - 666 pipelineId: your_pipeline scanId: abcdef1234567890ghijkl search: CWE-123,5 targetId: abcdef1234567890ghijkl link: https://example.com/ABC-1234 pendingChanges: durationDays: 7 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterName: firstname lastname type: Other required: - type - reason - pendingChanges - items Operator: title: Operator x-stoplight: id: nxhoa45ajna2q enum: - Equals - StartsWith - Contains - NotEquals - GreaterThan - GreaterThanEquals - LessThan - LessThanEquals ExemptionDurationDTO: type: object x-stoplight: id: gwea7nn03kd7b x-examples: {} title: ExemptionDurationDTO properties: always_exempt: type: boolean x-stoplight: id: 0gnxtzccq3n5d days: type: integer ExemptionInitiatorDTO: type: object x-stoplight: id: ps02pr2nesa5m x-examples: {} title: ExemptionInitiatorDTO properties: project_identifier: type: string x-stoplight: id: s4jyr2h417qgt enforcement_id: type: string x-stoplight: id: nwpqxpx81btr0 artifact_id: type: string x-stoplight: id: gnzd8c6qusr3p ExemptionResponseDTO: type: object x-stoplight: id: qhlradvqdsoka x-examples: {} title: ExemptionResponseDTO properties: component_name: type: string x-stoplight: id: yoobm06ffppgf component_version: type: string x-stoplight: id: 92jdhofe26h2u version_operator: $ref: '#/components/schemas/Operator' reason: type: string exemption_duration: $ref: '#/components/schemas/ExemptionDurationDTO' exemption_status: $ref: '#/components/schemas/ExemptionStatusDTO' uuid: type: string artifact_id: type: string x-stoplight: id: x22p27k9urw84 account_id: type: string x-stoplight: id: i54s7qtrmnt2j org_identifier: type: string x-stoplight: id: s1g762zgwnq1a project_identifier: type: string x-stoplight: id: 4haq8eju77mtp created_by_user_id: type: string x-stoplight: id: a19ykfdcx14am created_by_name: type: string x-stoplight: id: 24ht62fxl5olb reviewed_by_user_id: type: string x-stoplight: id: jsavsciecjikp reviewed_by_name: type: string x-stoplight: id: 4pr8z1usbabey updated_by: type: string x-stoplight: id: 9lxgpvwcsrmun review_comment: type: string x-stoplight: id: mwqkzg4jbz7md created_at: type: integer format: int64 x-stoplight: id: m05xxmxxzgzkz updated_at: type: integer format: int64 x-stoplight: id: 5zci7bmqul8xl valid_until: type: integer format: int64 x-stoplight: id: fby36b6and04x reviewed_at: type: integer format: int64 x-stoplight: id: 2sl9aqhubqket exemption_initiator: $ref: '#/components/schemas/ExemptionInitiatorDTO' ExemptionReviewRequestDTO: type: object x-examples: {} properties: exemption_status: $ref: '#/components/schemas/ExemptionStatusDTO' review_comment: type: string x-stoplight: id: 0i96zm7yk9awf x-stoplight: id: f28re4dygdmwl ExemptionRequestDTO: type: object x-examples: {} properties: component_name: type: string x-stoplight: id: yc0pzdwxtjgad component_version: type: string x-stoplight: id: lly9gx9ion1xh version_operator: $ref: '#/components/schemas/Operator' reason: type: string exemption_duration: $ref: '#/components/schemas/ExemptionDurationDTO' exemption_initiator: $ref: '#/components/schemas/ExemptionInitiatorDTO' x-stoplight: id: 9jp76e9ramh63 ExemptionStatusDTO: x-stoplight: id: 5jdd05223xfdn type: string enum: - PENDING - APPROVED - REJECTED - EXPIRED title: ExemptionStatusDTO parameters: Page2: name: page in: query required: false schema: type: integer default: 0 minimum: 0 description: "Pagination page number strategy: Specify the page number within the paginated collection related to the number of items in each page\t" ProjectParam1: in: path required: true schema: type: string description: Harness project ID name: project Limit6: name: limit in: query schema: type: integer default: 30 maximum: 1000 minimum: 1 description: Number of items to return per page. Exemption: name: exemption in: path required: true schema: type: string description: SSCA Enforcement Exemption Id AccountHeader6: name: Harness-Account in: header required: true schema: type: string description: Identifier field of the account the resource is scoped to. This is required for Authorization methods other than the x-api-key header. If you are using the x-api-key header, this can be skipped. Artifact: name: artifact in: path required: true schema: type: string description: Harness artifact identifier OrgParam1: name: org in: path required: true schema: type: string description: Harness organization ID headers: X-Page-Size: schema: type: integer description: Maximum page size in Paginated response. X-Page-Number: schema: type: integer description: Page number in Paginated response. X-Total-Elements: schema: type: integer description: Total number of elements returned in Paginated response. responses: ExemptionListResponseDTO: description: '' content: application/json: schema: type: array items: $ref: '#/components/schemas/ExemptionResponseDTO' headers: X-Total-Elements: $ref: '#/components/headers/X-Total-Elements' X-Page-Number: $ref: '#/components/headers/X-Page-Number' X-Page-Size: $ref: '#/components/headers/X-Page-Size' securitySchemes: x-api-key: name: x-api-key type: apiKey in: header description: API key is a token provided while making the API calls. This is used to authenticate the client at the exposed endpoint. externalDocs: description: Find out more about Swagger url: http://swagger.io x-stoplight: id: oc91t4vrfnjyi x-tagGroups: - name: Organizations tags: - Organization - name: Projects tags: - Org Project - Project - name: Secrets tags: - Account Secret - Org Secret - Project Secret - Secrets - name: Connectors tags: - Account Connector - Org Connector - Project Connector - Connectors - GoogleSecretManagerConnector - name: Roles tags: - Account Roles - Organization Roles - Project Roles - Roles - name: Resource Groups tags: - Account Resource Groups - Organization Resource Groups - Project Resource Groups - Filter Resource Groups - Harness Resource Group - Zendesk - name: Role Assignments tags: - Account Role Assignments - Org Role Assignments - Project Role Assignments - Role Assignments - name: Platform tags: - Access Control List - Account Banner - Account Banner - Account Licensed Modules - Account License Type - Account Webhooks - AccountSetting - Accounts - Analyze Account Access Policy - Analyze Organization Access Policy - Analyze Project Access Policy - ApiKey - Audit - AuditFilters - Authentication Settings - Canny - Devops Essentials License Data By Account - EULA - Filter - Harness Resource Type - Invite - IP Allowlist - Nextgen Ldap - Notification Channels - Notification Rules - OIDC - Oidc-Access-Token - Oidc-ID-Token - Org Webhooks - Permissions - Project Webhooks - Secret Managers - Service Account - Setting - SMTP - Source Code Manager - Token - User - User Group - Variables - name: Delegate tags: - Agent mTLS Endpoint Management - Delegate Download Resource - Delegate Group Tags Resource - Delegate Setup Resource - Delegate Token Resource - name: Pipelines tags: - Pipelines - Input Sets - Approvals - Pipeline Execution - Pipeline Dashboard - Pipeline Input Set - Pipeline - Pipeline Execution Details - Pipeline Execute - Pipeline Refresh - Pipeline data retention - Triggers - TriggersEvents - Webhook Triggers - Webhook Event Handler - DryRunPipeline - name: Artifact Registry tags: - Registries - Artifacts - Docker Artifacts - Helm Artifacts - quarantine - Webhooks - Spaces - Replication - Registry V3 - Registries - Registry V3 - Packages - Registry V3 - Versions - Registry V3 - Files - Registry V3 - Metadata - Registry V3 - Firewall - Registry V3 - Transfer - name: Database DevOps tags: - Database Schema - Database Instance - Deployed State - Execution Config - Migration State - name: CD tags: - K8s Release Service Mapping - CustomDeployment - Environments - EnvironmentGroup - Infrastructures - Usage - File Store - Service Dashboard - ServiceOverrides - Rollback - tas - name: Deployment Freeze tags: - Freeze CRUD - Freeze Evaluation - Freeze Schema - name: Services tags: - Account Services - Org Services - Project Services - Services - name: Rancher Infrastructures tags: - Account Rancher Infrastructure - Org Rancher Infrastructure - Project Rancher Infrastructure - name: Templates tags: - Account Template - Org Template - Project Template - Templates - Global Templates - name: GitOps tags: - Agents - Application - Applications - Certificates - Clusters - Dashboard Aggregates - Dashboards - GnuPGP Keys - GPG Keys - Hosts - Project mappings - Projects - Reconciler - Repositories - Repository Certificates - Repository credentials - ValidateHost - name: GitX tags: - GitX Webhooks - Org Gitx Webhooks - Project Gitx Webhooks - name: CACM tags: - Anomalies Ignorelist Rule - Anomalies - BI Dashboards - Budgets - Budget Groups - Cost Categories - Cloud Accounts - K8S Connectors Metadata - Notification Settings v2 - Overview - Data Job Status - Recommendation cost settings - Unit Metric - Anomaly Comments - Cloud and AI cost anomaly details - Cloud and AI cost anomalies v2 - Cost Details - Currency Preferences - External Data Provider - AiEngine - CACM governance cost settings - Governance Enforcement Recommendation APIs - Governance Alert - Governance Overview - Governance Recommendation APIs - RuleEnforcement - Rule Executions - Rule - Rule Sets - Perspectives Folders - Perspective Reports - Perspectives - Cost Category Jira Project Mapping - Recommendations Details - Recommendations - Recommendation Jira - Recommendation Preferences - Recommendation Presets - Recommendation Servicenow - Recommendation Tags - Recommendation Ignore List - AutoStopping Rules - AutoStopping Rules V2 - AutoStopping Load Balancers - AutoStopping Fixed Schedules - AutoStopping Alerts - Commitment Orchestrator Events APIs - name: Feature Flags tags: - API Keys - Feature Flags - Targets - Target Groups - Environment Perspectives - Anomalies - Proxy - Tags - name: SRM tags: - Monitored Services - SLOs dashboard - NG SLOs - SLOs - Downtime - Srm Notification - name: Internal Developer Portal - IDP tags: - Entities - Teams - CatalogCustomProperties - Scores - DataSource - KubernetesDataPoints - AggregationRules - AppConfig - PluginInfo - LayoutProxy - Kinds - LayoutsV3 - LayoutsV4 - name: Environment Management - IDP tags: - Environment - Infrastructure - Instance - name: Custom Dashboards tags: - aida - dashboards - downloads - embed - folders - name: Policy Management tags: - dashboard - examples - policies - evaluate - evaluations - policysets - system - name: Code tags: - repository - status_checks - pullreq - upload - webhook - resource - rules - labels - name: IaCM tags: - usage - approvals - costs - executions - module-registry - workspaces - settings - tf-standard-backend - variables - name: STO tags: - Exemptions - Issues - Scans - Products - Test Targets - Target Variants - name: SEI tags: - Collection categories - Collections - Contributors - DORA - name: Git Sync (deprecated) tags: - Git Branches - Git Full Sync - Git Sync Settings - Git Sync - Git Sync Errors - name: Error Models tags: - Error Response - Governance Metadata - name: Supply Chain Security tags: - integration - PipelineInfraConfig - SBOM - Integration Step Config - Delete Step Config - Delete Repositories - Pipeline Store Config - Evidence Vault [Beta] - name: Release Management tags: - Release Groups - Releases - Orchestration Processes - Orchestration Activities - Orchestration Executions - Conflicts - Freeze - Reports - Uploads - name: Resilience Testing tags: - Actions - Action Templates - Chaos Components - Chaos Hubs - ChaosGuard Conditions - ChaosGuard Rules - DR Tests - Experiments - Experiment Templates - Faults - Fault Templates - Chaos Infrastructure - Health - Network Maps - Onboarding - Probes - Probe Templates - Chaos Recommendations - Risks