openapi: 3.2.0 info: title: Harness Remediation Agent API version: '1.0' description: The Harness Software Delivery Platform uses OpenAPI Specification v3.0. contact: name: API Support email: contact@harness.io url: https://harness.io/ x-logo: url: https://mma.prnewswire.com/media/779232/Harnes_logo_horizontal.jpg?p=facebook altText: Harness termsOfService: https://harness.io/terms-of-use/ servers: - url: https://app.harness.io description: Harness host URL - url: https://{vanity} description: Vanity URL variables: vanity: default: app.harness.io security: - x-api-key: [] tags: - name: Remediation Agent description: Project-level remediation agent configuration paths: /iacm/api/orgs/{org}/projects/{project}/remediation/config: delete: tags: - Remediation Agent summary: Disable project remediation description: Disable project-level AI remediation operationId: remediation-agent#disable-project-remediation parameters: - name: org in: path description: Org is the organisation identifier. required: true schema: type: string description: Org is the organisation identifier. example: v minLength: 1 maxLength: 128 example: p - name: project in: path description: Project is the project identifier. required: true schema: type: string description: Project is the project identifier. example: d2z minLength: 1 maxLength: 128 example: 6ai - name: Harness-Account in: header description: Account is the internal customer account ID. allowEmptyValue: true required: true schema: type: string description: Account is the internal customer account ID. example: hte minLength: 1 maxLength: 128 example: sx responses: '200': description: OK response. '400': description: 'BadRequestError: Bad Request response.' content: application/vnd.goa.error: schema: $ref: '#/components/schemas/IaCMError' '401': description: 'UnauthorizedError: Unauthorized response.' content: application/vnd.goa.error: schema: $ref: '#/components/schemas/IaCMError' '403': description: 'ForbiddenError: Forbidden response.' content: application/vnd.goa.error: schema: $ref: '#/components/schemas/IaCMError' '404': description: 'NotFoundError: Not Found response.' content: application/vnd.goa.error: schema: $ref: '#/components/schemas/IaCMError' '408': description: 'TimeoutError: Request Timeout response.' content: application/vnd.goa.error: schema: $ref: '#/components/schemas/IaCMError' '409': description: 'ConflictError: Conflict response.' content: application/vnd.goa.error: schema: $ref: '#/components/schemas/IaCMError' '423': description: 'LockedError: Locked response.' content: application/vnd.goa.error: schema: $ref: '#/components/schemas/IaCMError' '499': description: 'ContextCancelledError: response.' content: application/vnd.goa.error: schema: $ref: '#/components/schemas/IaCMError' '500': description: 'InternalServerError: Internal Server Error response.' content: application/vnd.goa.error: schema: $ref: '#/components/schemas/IaCMError' '502': description: 'BadGatewayError: Bad Gateway response.' content: application/vnd.goa.error: schema: $ref: '#/components/schemas/IaCMError' get: tags: - Remediation Agent summary: Get project remediation config description: Check whether project-level AI remediation is enabled operationId: remediation-agent#get-project-remediation-config parameters: - name: org in: path description: Org is the organisation identifier. required: true schema: type: string description: Org is the organisation identifier. example: s minLength: 1 maxLength: 128 example: hn - name: project in: path description: Project is the project identifier. required: true schema: type: string description: Project is the project identifier. example: ld minLength: 1 maxLength: 128 example: a43 - name: Harness-Account in: header description: Account is the internal customer account ID. allowEmptyValue: true required: true schema: type: string description: Account is the internal customer account ID. example: o minLength: 1 maxLength: 128 example: oxj responses: '200': description: OK response. content: application/json: schema: $ref: '#/components/schemas/GetProjectRemediationConfigResponse' example: enabled: true pipeline_id: At tempore. '400': description: 'BadRequestError: Bad Request response.' content: application/vnd.goa.error: schema: $ref: '#/components/schemas/IaCMError' '401': description: 'UnauthorizedError: Unauthorized response.' content: application/vnd.goa.error: schema: $ref: '#/components/schemas/IaCMError' '403': description: 'ForbiddenError: Forbidden response.' content: application/vnd.goa.error: schema: $ref: '#/components/schemas/IaCMError' '404': description: 'NotFoundError: Not Found response.' content: application/vnd.goa.error: schema: $ref: '#/components/schemas/IaCMError' '408': description: 'TimeoutError: Request Timeout response.' content: application/vnd.goa.error: schema: $ref: '#/components/schemas/IaCMError' '409': description: 'ConflictError: Conflict response.' content: application/vnd.goa.error: schema: $ref: '#/components/schemas/IaCMError' '423': description: 'LockedError: Locked response.' content: application/vnd.goa.error: schema: $ref: '#/components/schemas/IaCMError' '499': description: 'ContextCancelledError: response.' content: application/vnd.goa.error: schema: $ref: '#/components/schemas/IaCMError' '500': description: 'InternalServerError: Internal Server Error response.' content: application/vnd.goa.error: schema: $ref: '#/components/schemas/IaCMError' '502': description: 'BadGatewayError: Bad Gateway response.' content: application/vnd.goa.error: schema: $ref: '#/components/schemas/IaCMError' put: tags: - Remediation Agent summary: Enable project remediation description: Enable AI remediation for all workspaces in the project, optionally attaching or replacing a remediation pipeline operationId: remediation-agent#enable-project-remediation parameters: - name: org in: path description: Org is the organisation identifier. required: true schema: type: string description: Org is the organisation identifier. example: 4ip minLength: 1 maxLength: 128 example: lf - name: project in: path description: Project is the project identifier. required: true schema: type: string description: Project is the project identifier. example: lbq minLength: 1 maxLength: 128 example: 2h - name: Harness-Account in: header description: Account is the internal customer account ID. allowEmptyValue: true required: true schema: type: string description: Account is the internal customer account ID. example: '5' minLength: 1 maxLength: 128 example: gc requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/EnableProjectRemediationRequest' example: pipeline_id: Vel est commodi ut qui inventore. responses: '200': description: OK response. '400': description: 'BadRequestError: Bad Request response.' content: application/vnd.goa.error: schema: $ref: '#/components/schemas/IaCMError' '401': description: 'UnauthorizedError: Unauthorized response.' content: application/vnd.goa.error: schema: $ref: '#/components/schemas/IaCMError' '403': description: 'ForbiddenError: Forbidden response.' content: application/vnd.goa.error: schema: $ref: '#/components/schemas/IaCMError' '404': description: 'NotFoundError: Not Found response.' content: application/vnd.goa.error: schema: $ref: '#/components/schemas/IaCMError' '408': description: 'TimeoutError: Request Timeout response.' content: application/vnd.goa.error: schema: $ref: '#/components/schemas/IaCMError' '409': description: 'ConflictError: Conflict response.' content: application/vnd.goa.error: schema: $ref: '#/components/schemas/IaCMError' '423': description: 'LockedError: Locked response.' content: application/vnd.goa.error: schema: $ref: '#/components/schemas/IaCMError' '499': description: 'ContextCancelledError: response.' content: application/vnd.goa.error: schema: $ref: '#/components/schemas/IaCMError' '500': description: 'InternalServerError: Internal Server Error response.' content: application/vnd.goa.error: schema: $ref: '#/components/schemas/IaCMError' '502': description: 'BadGatewayError: Bad Gateway response.' content: application/vnd.goa.error: schema: $ref: '#/components/schemas/IaCMError' /sto/api/v2/remediation-agent/diff-occurrences: get: tags: - Remediation Agent summary: DiffOccurrences RemediationAgent description: Diff the validation execution's scan against the original scan's ignore set. Resolves validationScanId from validationExecutionId (account-scoped — validation pipeline may live in a different org/project than the original scan), derives the original scan's ignored occurrences (every occurrence on the original scan minus the in-scope ones for the scoped issue type, same computation as ListOccurrencesInScope), and removes those (matched by fingerprint) from the validation scan. Remaining occurrences are split into existingOccurrences (fingerprint also present in original in-scope) and newOccurrences (introduced on the validation scan). operationId: RemediationAgent#DiffOccurrences parameters: - name: accountId in: query description: Harness Account ID allowEmptyValue: true required: true schema: type: string description: Harness Account ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ example: abcdef1234567890ghijkl - name: orgId in: query description: Harness Organization ID allowEmptyValue: true required: true schema: type: string description: Harness Organization ID example: example_org pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 example: example_org - name: projectId in: query description: Harness Project ID allowEmptyValue: true required: true schema: type: string description: Harness Project ID example: example_project pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 example: example_project - name: scanId in: query description: Original STO scan id allowEmptyValue: true required: true schema: type: string description: Original STO scan id example: scan111111111111111111 pattern: ^[a-zA-Z0-9_-]{22}$ example: scan111111111111111111 - name: validationExecutionId in: query description: Validation pipeline execution id allowEmptyValue: true required: true schema: type: string description: Validation pipeline execution id example: exec111111111111111111 maxLength: 128 example: exec111111111111111111 - name: issueTypes in: query description: 'Issue types to scope (v1: SAST, SECRET). Filters i.type. Empty defaults to SAST+SECRET in service.' allowEmptyValue: true schema: type: array items: type: string example: SECRET enum: - SAST - SECRET description: 'Issue types to scope (v1: SAST, SECRET). Filters i.type. Empty defaults to SAST+SECRET in service.' example: - SAST - SECRET example: - SECRET - SAST - SAST - name: onlyTruePositiveIssueTypes in: query description: Issue types that must have a TRUE_POSITIVE triage verdict to stay in scope. Other scoped types are not TP-filtered. Empty + onlyTruePositive=false → no TP filter. Empty + onlyTruePositive=true (legacy) → all resolved issueTypes. allowEmptyValue: true schema: type: array items: type: string example: SAST enum: - SAST - SECRET description: Issue types that must have a TRUE_POSITIVE triage verdict to stay in scope. Other scoped types are not TP-filtered. Empty + onlyTruePositive=false → no TP filter. Empty + onlyTruePositive=true (legacy) → all resolved issueTypes. example: - SECRET - SECRET example: - SECRET - SECRET - SECRET - name: onlyTruePositive in: query description: 'Legacy: when true and onlyTruePositiveIssueTypes is empty, apply TP filter to all resolved issueTypes. Prefer onlyTruePositiveIssueTypes for per-type Exclude False Positives.' allowEmptyValue: true schema: type: boolean description: 'Legacy: when true and onlyTruePositiveIssueTypes is empty, apply TP filter to all resolved issueTypes. Prefer onlyTruePositiveIssueTypes for per-type Exclude False Positives.' default: false example: false example: false - name: excludeUnreachable in: query description: When true, exclude occurrences whose reachability is 'unreachable' (SAST). Missing/unknown reachability stays in scope. allowEmptyValue: true schema: type: boolean description: When true, exclude occurrences whose reachability is 'unreachable' (SAST). Missing/unknown reachability stays in scope. default: false example: true example: true - name: limit in: query description: Maximum number of occurrences allowEmptyValue: true schema: type: integer description: Maximum number of occurrences default: 1000 example: 2214 format: int64 minimum: 1 maximum: 10000 example: 6913 - name: severityCodes in: query description: 'Subset of severities: CRITICAL, HIGH, MEDIUM, LOW, INFO. Empty means all.' allowEmptyValue: true schema: type: array items: type: string example: MEDIUM enum: - CRITICAL - HIGH - MEDIUM - LOW - INFO description: 'Subset of severities: CRITICAL, HIGH, MEDIUM, LOW, INFO. Empty means all.' example: - INFO - LOW example: - MEDIUM - HIGH - name: excludeRepoPatterns in: query description: Glob patterns matching target.name on repository targets allowEmptyValue: true schema: type: array items: type: string example: krt maxLength: 256 description: Glob patterns matching target.name on repository targets example: - zkw - prr - 35w example: - 0u9 - 0uq - pu9 - name: X-Api-Key in: header description: Harness personal or service access token allowEmptyValue: true schema: type: string description: Harness personal or service access token example: Voluptatem et nostrum delectus est dolorem et. example: Beatae tenetur iusto molestias culpa. responses: '200': description: OK response. content: application/json: schema: $ref: '#/components/schemas/DiffOccurrencesResponseBody' example: existingCount: 2200266757158604800 existingOccurrences: - issueId: issue11111111111111111 issueTitle: SQL Injection issueType: SAST occurrenceDetails: Id consequatur ut. occurrenceInternalId: 2002 severityCode: HIGH - issueId: issue11111111111111111 issueTitle: SQL Injection issueType: SAST occurrenceDetails: Id consequatur ut. occurrenceInternalId: 2002 severityCode: HIGH matchedCount: 7786156039682956000 newCount: 1521003095169379000 newOccurrences: - issueId: issue11111111111111111 issueTitle: SQL Injection issueType: SAST occurrenceDetails: Id consequatur ut. occurrenceInternalId: 2002 severityCode: HIGH - issueId: issue11111111111111111 issueTitle: SQL Injection issueType: SAST occurrenceDetails: Id consequatur ut. occurrenceInternalId: 2002 severityCode: HIGH validationScanId: scan222222222222222222 '400': description: 'BadRequest: Bad Request response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: 'Bad Request: accountId parameter is required' status: 400 '401': description: 'Unauthorized: Unauthorized response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Unauthorized status: 401 '403': description: 'Forbidden: Forbidden response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Forbidden status: 403 '429': description: 'TooManyRequests: Too Many Requests response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Too Many Requests status: 429 '500': description: 'InternalServerError: Internal Server Error response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Internal Server Error status: 500 security: - X-Api-Key_header_X-Api-Key: [] jwt_header_Authorization: - sto_issue_view /sto/api/v2/remediation-agent/occurrences-in-scope: get: tags: - Remediation Agent summary: ListOccurrencesInScope RemediationAgent description: List (issue, occurrence) tuples for the remediation pre-plugin. Scoped to one scan and issue type; optionally filters to TRUE_POSITIVE triage verdicts. operationId: RemediationAgent#ListOccurrencesInScope parameters: - name: accountId in: query description: Harness Account ID allowEmptyValue: true required: true schema: type: string description: Harness Account ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ example: abcdef1234567890ghijkl - name: orgId in: query description: Harness Organization ID allowEmptyValue: true required: true schema: type: string description: Harness Organization ID example: example_org pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 example: example_org - name: projectId in: query description: Harness Project ID allowEmptyValue: true required: true schema: type: string description: Harness Project ID example: example_project pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 example: example_project - name: scanId in: query description: STO scan id allowEmptyValue: true required: true schema: type: string description: STO scan id example: scan111111111111111111 pattern: ^[a-zA-Z0-9_-]{22}$ example: scan111111111111111111 - name: targetId in: query description: Optional STO target id allowEmptyValue: true schema: type: string description: Optional STO target id example: target1111111111111111 pattern: ^[a-zA-Z0-9_-]{22}$ example: target1111111111111111 - name: issueTypes in: query description: 'Issue types to scope (v1: SAST, SECRET). Filters i.type. Empty defaults to SAST+SECRET in service.' allowEmptyValue: true schema: type: array items: type: string example: SAST enum: - SAST - SECRET description: 'Issue types to scope (v1: SAST, SECRET). Filters i.type. Empty defaults to SAST+SECRET in service.' example: - SECRET - SAST - SAST - SAST example: - SECRET - SAST - SECRET - name: onlyTruePositiveIssueTypes in: query description: Issue types that must have a TRUE_POSITIVE triage verdict to stay in scope. Other scoped types are not TP-filtered. Empty + onlyTruePositive=false → no TP filter. Empty + onlyTruePositive=true (legacy) → all resolved issueTypes. allowEmptyValue: true schema: type: array items: type: string example: SECRET enum: - SAST - SECRET description: Issue types that must have a TRUE_POSITIVE triage verdict to stay in scope. Other scoped types are not TP-filtered. Empty + onlyTruePositive=false → no TP filter. Empty + onlyTruePositive=true (legacy) → all resolved issueTypes. example: - SECRET - SECRET - SECRET example: - SECRET - SECRET - SAST - SAST - name: onlyTruePositive in: query description: 'Legacy: when true and onlyTruePositiveIssueTypes is empty, apply TP filter to all resolved issueTypes. Prefer onlyTruePositiveIssueTypes for per-type Exclude False Positives.' allowEmptyValue: true schema: type: boolean description: 'Legacy: when true and onlyTruePositiveIssueTypes is empty, apply TP filter to all resolved issueTypes. Prefer onlyTruePositiveIssueTypes for per-type Exclude False Positives.' default: false example: false example: false - name: excludeUnreachable in: query description: When true, exclude occurrences whose reachability is 'unreachable' (SAST). Missing/unknown reachability stays in scope. allowEmptyValue: true schema: type: boolean description: When true, exclude occurrences whose reachability is 'unreachable' (SAST). Missing/unknown reachability stays in scope. default: false example: false example: true - name: limit in: query description: Maximum number of occurrences allowEmptyValue: true schema: type: integer description: Maximum number of occurrences default: 1000 example: 9104 format: int64 minimum: 1 maximum: 10000 example: 9064 - name: severityCodes in: query description: 'Subset of severities: CRITICAL, HIGH, MEDIUM, LOW, INFO. Empty means all.' allowEmptyValue: true schema: type: array items: type: string example: MEDIUM enum: - CRITICAL - HIGH - MEDIUM - LOW - INFO description: 'Subset of severities: CRITICAL, HIGH, MEDIUM, LOW, INFO. Empty means all.' example: - LOW - CRITICAL - INFO - HIGH example: - INFO - MEDIUM - CRITICAL - CRITICAL - name: excludeRepoPatterns in: query description: Glob patterns matching target.name on repository targets allowEmptyValue: true schema: type: array items: type: string example: 39k maxLength: 256 description: Glob patterns matching target.name on repository targets example: - ycn - boa - n6q example: - j7h - 8b4 - c8z responses: '200': description: OK response. content: application/json: schema: $ref: '#/components/schemas/ListOccurrencesInScopeResponseBody2' example: ignoredOccurrenceIds: - 100075217567337500 - 3480029860213520000 originalOccurrenceCount: 3149822788500633000 results: - issueId: issue11111111111111111 issueTitle: SQL Injection issueType: SAST occurrenceDetails: Id consequatur ut. occurrenceInternalId: 2002 severityCode: HIGH - issueId: issue11111111111111111 issueTitle: SQL Injection issueType: SAST occurrenceDetails: Id consequatur ut. occurrenceInternalId: 2002 severityCode: HIGH - issueId: issue11111111111111111 issueTitle: SQL Injection issueType: SAST occurrenceDetails: Id consequatur ut. occurrenceInternalId: 2002 severityCode: HIGH - issueId: issue11111111111111111 issueTitle: SQL Injection issueType: SAST occurrenceDetails: Id consequatur ut. occurrenceInternalId: 2002 severityCode: HIGH '400': description: 'BadRequest: Bad Request response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: 'Bad Request: accountId parameter is required' status: 400 '401': description: 'Unauthorized: Unauthorized response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Unauthorized status: 401 '403': description: 'Forbidden: Forbidden response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Forbidden status: 403 '429': description: 'TooManyRequests: Too Many Requests response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Too Many Requests status: 429 '500': description: 'InternalServerError: Internal Server Error response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Internal Server Error status: 500 security: - jwt_header_Authorization: - sto_internal_use_only /sto/api/v2/remediation-agent/results/batch: post: tags: - Remediation Agent summary: BatchPersistResults RemediationAgent description: Atomically upsert per-occurrence remediation rows for one agent run. STO Core resolves in-scope occurrences for originalScanId (same query as ListOccurrencesInScope, using the same RemAgentScopeFilters from sto-plugins) and stamps pullRequestMetadata onto each issue_augmentation row. Run-level rollup counts on this payload are stored for audit/UI; the post-plugin ALSO posts the same counts to ssca-manager agentResults for the Agents Executions tab (same split as FP triage). operationId: RemediationAgent#BatchPersistResults parameters: - name: accountId in: query description: Harness Account ID allowEmptyValue: true required: true schema: type: string description: Harness Account ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ example: abcdef1234567890ghijkl - name: orgId in: query description: Harness Organization ID allowEmptyValue: true required: true schema: type: string description: Harness Organization ID example: example_org pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 example: example_org - name: projectId in: query description: Harness Project ID allowEmptyValue: true required: true schema: type: string description: Harness Project ID example: example_project pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 example: example_project requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/BatchPersistResultsRequestBody' example: activeOccurrenceCount: 4545665853144719000 excludeRepoPatterns: - r0u - jhx - 4gy excludeUnreachable: false issueTypes: - SECRET - SAST - SECRET - SECRET jiraEnabled: false limit: 9976 modelName: s6a newOccurrenceIntroducedCount: 5176453322136649000 occurrenceRemediatedCount: 2356942026646855700 onlyTruePositive: true onlyTruePositiveIssueTypes: - SAST - SAST originalOccurrenceCount: 5461263239472025000 originalScanId: scan111111111111111111 promptVersion: d1r pullRequestMetadata: Ullam ducimus ducimus accusamus et nihil deserunt. severityCodes: - HIGH - CRITICAL targetId: target1111111111111111 targetName: 6hy targetVariantName: o6f userScanActiveCount: 3165306279197335000 validationMetadata: build: executionId: 7jc orgId: d6r pipelineId: nk5 projectId: sfg status: ov7 remediation: executionId: 84j orgId: r7c pipelineId: 4iy projectId: ncd scanId: scan222222222222222222 status: ak1 workflowExecutionId: k8z responses: '200': description: OK response. content: application/json: schema: $ref: '#/components/schemas/BatchPersistResultsResponseBody' example: summaryId: 7477287097079133000 ticketId: STO-34219 ticketUrl: https://jira.example.com/browse/STO-123 written: 2587196187131077600 '400': description: 'BadRequest: Bad Request response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: 'Bad Request: accountId parameter is required' status: 400 '401': description: 'Unauthorized: Unauthorized response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Unauthorized status: 401 '403': description: 'Forbidden: Forbidden response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Forbidden status: 403 '429': description: 'TooManyRequests: Too Many Requests response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Too Many Requests status: 429 '500': description: 'InternalServerError: Internal Server Error response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Internal Server Error status: 500 security: - jwt_header_Authorization: - sto_internal_use_only components: schemas: GetProjectRemediationConfigResponse: type: object properties: enabled: type: boolean description: Whether project-level remediation is enabled example: false pipeline_id: type: string description: Remediation pipeline identifier when enabled example: Libero consequatur ea quam officiis maxime occaecati. example: enabled: true pipeline_id: Accusantium accusantium molestias numquam et veniam. required: - enabled EnableProjectRemediationRequest: type: object properties: pipeline_id: type: string description: Optional remediation pipeline to attach or replace example: Voluptatem molestiae ut quasi eveniet. example: pipeline_id: Deleniti optio ratione animi impedit. IaCMError: type: object properties: fault: type: boolean description: Is the error a server-side fault? example: false id: type: string description: ID is a unique identifier for this particular occurrence of the problem. example: 123abc message: type: string description: Message is a human-readable explanation specific to this occurrence of the problem. example: parameter 'p' must be an integer name: type: string description: Name is the name of this class of errors. example: bad_request temporary: type: boolean description: Is the error temporary? example: false timeout: type: boolean description: Is the error a timeout? example: true example: fault: false id: 123abc message: parameter 'p' must be an integer name: bad_request temporary: false timeout: true required: - name - id - message - temporary - timeout - fault RemAgentValidationMetadata: type: object properties: build: $ref: '#/components/schemas/RemAgentValidationBuildMeta' remediation: $ref: '#/components/schemas/RemAgentValidationRemediationMeta' example: build: executionId: 7jc orgId: d6r pipelineId: nk5 projectId: sfg status: ov7 remediation: executionId: 84j orgId: r7c pipelineId: 4iy projectId: ncd scanId: scan222222222222222222 status: ak1 BatchPersistResultsResponseBody: type: object properties: summaryId: type: integer description: remediation_agent_summary.internal_id for this run example: 6633843552957881000 format: int64 ticketId: type: string description: External ticket key/id (e.g. Jira STO-34219) when ticket creation succeeds; omit when not created example: STO-34219 maxLength: 128 ticketUrl: type: string description: URL of the summary ticket created for this remediation run, when ticket creation succeeds example: https://jira.example.com/browse/STO-123 format: uri written: type: integer description: Number of per-occurrence augmentation rows written example: 2703454828185584600 format: int64 example: summaryId: 5615289776238308000 ticketId: STO-34219 ticketUrl: https://jira.example.com/browse/STO-123 written: 4143076283143936000 required: - written - summaryId RemAgentOccurrenceRef: type: object properties: issueId: type: string example: issue11111111111111111 pattern: ^[a-zA-Z0-9_-]{22}$ issueTitle: type: string example: SQL Injection issueType: type: string description: STO issue type for this occurrence (i.type) example: SAST occurrenceDetails: type: string description: Issue details merged under occurrence unique_details overrides example: Eum ut est aliquam quis. format: binary occurrenceInternalId: type: integer example: 2002 format: int64 severityCode: type: string example: HIGH description: In-scope occurrence for the remediation pre-plugin. occurrenceDetails is issue+occurrence hydrated so each row is self-contained. Fingerprint stays server-side for Diff matching only — not on the wire. example: issueId: issue11111111111111111 issueTitle: SQL Injection issueType: SAST occurrenceDetails: Nihil culpa est. occurrenceInternalId: 2002 severityCode: HIGH required: - issueId - occurrenceInternalId - issueTitle - severityCode DiffOccurrencesResponseBody: type: object properties: existingCount: type: integer example: 3782630300043004000 format: int64 existingOccurrences: type: array items: $ref: '#/components/schemas/RemAgentOccurrenceRef' description: Validation-scan occurrences whose fingerprint was also in the original scan's in-scope set example: - issueId: issue11111111111111111 issueTitle: SQL Injection issueType: SAST occurrenceDetails: Id consequatur ut. occurrenceInternalId: 2002 severityCode: HIGH - issueId: issue11111111111111111 issueTitle: SQL Injection issueType: SAST occurrenceDetails: Id consequatur ut. occurrenceInternalId: 2002 severityCode: HIGH - issueId: issue11111111111111111 issueTitle: SQL Injection issueType: SAST occurrenceDetails: Id consequatur ut. occurrenceInternalId: 2002 severityCode: HIGH - issueId: issue11111111111111111 issueTitle: SQL Injection issueType: SAST occurrenceDetails: Id consequatur ut. occurrenceInternalId: 2002 severityCode: HIGH matchedCount: type: integer description: existingCount + newCount example: 6315887462576821000 format: int64 newCount: type: integer example: 3193769006847567400 format: int64 newOccurrences: type: array items: $ref: '#/components/schemas/RemAgentOccurrenceRef' description: Validation-scan occurrences introduced after the original scan (not in original in-scope or ignored) example: - issueId: issue11111111111111111 issueTitle: SQL Injection issueType: SAST occurrenceDetails: Id consequatur ut. occurrenceInternalId: 2002 severityCode: HIGH - issueId: issue11111111111111111 issueTitle: SQL Injection issueType: SAST occurrenceDetails: Id consequatur ut. occurrenceInternalId: 2002 severityCode: HIGH validationScanId: type: string example: scan222222222222222222 pattern: ^[a-zA-Z0-9_-]{22}$ example: existingCount: 4464985583061968400 existingOccurrences: - issueId: issue11111111111111111 issueTitle: SQL Injection issueType: SAST occurrenceDetails: Id consequatur ut. occurrenceInternalId: 2002 severityCode: HIGH - issueId: issue11111111111111111 issueTitle: SQL Injection issueType: SAST occurrenceDetails: Id consequatur ut. occurrenceInternalId: 2002 severityCode: HIGH - issueId: issue11111111111111111 issueTitle: SQL Injection issueType: SAST occurrenceDetails: Id consequatur ut. occurrenceInternalId: 2002 severityCode: HIGH - issueId: issue11111111111111111 issueTitle: SQL Injection issueType: SAST occurrenceDetails: Id consequatur ut. occurrenceInternalId: 2002 severityCode: HIGH matchedCount: 3896889484445018600 newCount: 7450117799556665000 newOccurrences: - issueId: issue11111111111111111 issueTitle: SQL Injection issueType: SAST occurrenceDetails: Id consequatur ut. occurrenceInternalId: 2002 severityCode: HIGH - issueId: issue11111111111111111 issueTitle: SQL Injection issueType: SAST occurrenceDetails: Id consequatur ut. occurrenceInternalId: 2002 severityCode: HIGH - issueId: issue11111111111111111 issueTitle: SQL Injection issueType: SAST occurrenceDetails: Id consequatur ut. occurrenceInternalId: 2002 severityCode: HIGH - issueId: issue11111111111111111 issueTitle: SQL Injection issueType: SAST occurrenceDetails: Id consequatur ut. occurrenceInternalId: 2002 severityCode: HIGH validationScanId: scan222222222222222222 required: - validationScanId - existingOccurrences - newOccurrences - existingCount - newCount - matchedCount RemAgentValidationBuildMeta: type: object properties: executionId: type: string example: eu4 maxLength: 128 orgId: type: string example: 11q maxLength: 128 pipelineId: type: string example: fsx maxLength: 128 projectId: type: string example: 3z2 maxLength: 128 status: type: string description: Free-form validation status from the plugin; null stays null. example: jxh maxLength: 64 example: executionId: x5b orgId: tuy pipelineId: vw3 projectId: 60q status: 7nv NotFound: type: object properties: message: type: string example: Not Found status: type: integer default: 404 example: 404 format: int64 example: message: Not Found status: 404 required: - message RemAgentValidationRemediationMeta: type: object properties: executionId: type: string example: 26c maxLength: 128 orgId: type: string example: 9sv maxLength: 128 pipelineId: type: string example: ew4 maxLength: 128 projectId: type: string example: hwl maxLength: 128 scanId: type: string example: scan222222222222222222 pattern: ^[a-zA-Z0-9_-]{22}$ status: type: string description: Free-form validation status from the plugin; null stays null. example: 0uq maxLength: 64 example: executionId: ap4 orgId: xzo pipelineId: 4tg projectId: 9id scanId: scan222222222222222222 status: y93 ListOccurrencesInScopeResponseBody2: type: object properties: ignoredOccurrenceIds: type: array items: type: integer example: 1774871447296016600 format: int64 description: Occurrence internal IDs excluded from scope because they already have remediation agent augmentation for this target variant example: - 6631149810113844000 - 8839971465397730000 - 4615920709468749000 originalOccurrenceCount: type: integer description: Uncapped SUM(issue_scan.num_occurrences) for the scoped issue type on the scan; not limited by the result list cap example: 8723115429104575000 format: int64 results: type: array items: $ref: '#/components/schemas/RemAgentOccurrenceRef' example: - issueId: issue11111111111111111 issueTitle: SQL Injection issueType: SAST occurrenceDetails: Id consequatur ut. occurrenceInternalId: 2002 severityCode: HIGH - issueId: issue11111111111111111 issueTitle: SQL Injection issueType: SAST occurrenceDetails: Id consequatur ut. occurrenceInternalId: 2002 severityCode: HIGH example: ignoredOccurrenceIds: - 6939128800878907000 - 4060525593986811400 - 1164127336868440800 - 2280919119232125200 originalOccurrenceCount: 5820933303578398000 results: - issueId: issue11111111111111111 issueTitle: SQL Injection issueType: SAST occurrenceDetails: Id consequatur ut. occurrenceInternalId: 2002 severityCode: HIGH - issueId: issue11111111111111111 issueTitle: SQL Injection issueType: SAST occurrenceDetails: Id consequatur ut. occurrenceInternalId: 2002 severityCode: HIGH required: - results - ignoredOccurrenceIds - originalOccurrenceCount BatchPersistResultsRequestBody: type: object properties: activeOccurrenceCount: type: integer description: original + new_introduced - remediated example: 861966606749393800 format: int64 minimum: 0 excludeRepoPatterns: type: array items: type: string example: 4by maxLength: 256 description: Glob patterns matching target.name on repository targets example: - 9vt - lbj - cwh excludeUnreachable: type: boolean description: When true, exclude occurrences whose reachability is 'unreachable' (SAST). Missing/unknown reachability stays in scope. default: false example: false issueTypes: type: array items: type: string example: SAST enum: - SAST - SECRET description: 'Issue types to scope (v1: SAST, SECRET). Filters i.type. Empty defaults to SAST+SECRET in service.' example: - SAST - SAST - SECRET jiraEnabled: type: boolean description: When true, create a summary ticket after persist (still requires project External Tickets settings). Mirrors agent.jiraEnabled / pipeline setting jira_enabled. Default false when unset (older plugins omit → no ticket). Result is written to remediation_agent_summary.notification_metadata.jira {creationEnabled, ticketId, ticketUrl}. default: false example: false limit: type: integer description: Maximum number of occurrences default: 1000 example: 9084 format: int64 minimum: 1 maximum: 10000 modelName: type: string example: n3j maxLength: 256 newOccurrenceIntroducedCount: type: integer description: New findings introduced by the fix branch that were not in the original scope example: 1518729737068940800 format: int64 minimum: 0 occurrenceRemediatedCount: type: integer description: Occurrences with verdict REMEDIATED example: 3641352589549449000 format: int64 minimum: 0 onlyTruePositive: type: boolean description: 'Legacy: when true and onlyTruePositiveIssueTypes is empty, apply TP filter to all resolved issueTypes. Prefer onlyTruePositiveIssueTypes for per-type Exclude False Positives.' default: false example: true onlyTruePositiveIssueTypes: type: array items: type: string example: SECRET enum: - SAST - SECRET description: Issue types that must have a TRUE_POSITIVE triage verdict to stay in scope. Other scoped types are not TP-filtered. Empty + onlyTruePositive=false → no TP filter. Empty + onlyTruePositive=true (legacy) → all resolved issueTypes. example: - SECRET - SAST - SAST originalOccurrenceCount: type: integer description: In-scope occurrence count from the pre-plugin (original_occurrence_count) example: 794665262257321600 format: int64 minimum: 0 originalScanId: type: string description: STO scan id the agent remediated example: scan111111111111111111 pattern: ^[a-zA-Z0-9_-]{22}$ promptVersion: type: string example: c93 maxLength: 64 pullRequestMetadata: type: string description: 'Run-level PR stamp (PascalCase keys matching types.PullRequestMetadata): Provider, AccountID, OrgID, ProjectID, RepositoryName, Number, Title, SourceBranch, TargetBranch, Url, CommentUrl, BuildId, CommitsCount, ConnectorRef. ConnectorRef (SCM connector that opened the PR) enables live status refresh. BuildId = TRIGGERING_PIPELINE_BUILD_NUMBER (not parsed from SourceBranch). CommitsCount = fix commits on the PR. Copied onto issue_augmentation.pr_metadata for every in-scope occurrence.' example: Eius et praesentium. format: binary severityCodes: type: array items: type: string example: CRITICAL enum: - CRITICAL - HIGH - MEDIUM - LOW - INFO description: 'Subset of severities: CRITICAL, HIGH, MEDIUM, LOW, INFO. Empty means all.' example: - CRITICAL - INFO - LOW - HIGH targetId: type: string description: Target id the agent remediated; supplied by the plugin example: target1111111111111111 pattern: ^[a-zA-Z0-9_-]{22}$ targetName: type: string description: Target name the agent remediated; supplied by the plugin example: gw8 maxLength: 128 targetVariantName: type: string description: Target variant name the agent remediated; supplied by the plugin example: hb5 maxLength: 128 userScanActiveCount: type: integer example: 1995154547178026000 format: int64 minimum: 0 validationMetadata: $ref: '#/components/schemas/RemAgentValidationMetadata' workflowExecutionId: type: string description: Opaque ssca-manager workflow execution id example: wrb maxLength: 64 example: activeOccurrenceCount: 7957270666598104000 excludeRepoPatterns: - s33 - ucl - zyq excludeUnreachable: false issueTypes: - SECRET - SAST - SAST - SAST jiraEnabled: false limit: 8037 modelName: xw2 newOccurrenceIntroducedCount: 6734718316828870000 occurrenceRemediatedCount: 5772056798702351000 onlyTruePositive: true onlyTruePositiveIssueTypes: - SECRET - SAST originalOccurrenceCount: 6420724083532613000 originalScanId: scan111111111111111111 promptVersion: pbw pullRequestMetadata: Repellat ea quis culpa iure et non. severityCodes: - INFO - INFO - LOW targetId: target1111111111111111 targetName: sm5 targetVariantName: j26 userScanActiveCount: 8004010395604360000 validationMetadata: build: executionId: 7jc orgId: d6r pipelineId: nk5 projectId: sfg status: ov7 remediation: executionId: 84j orgId: r7c pipelineId: 4iy projectId: ncd scanId: scan222222222222222222 status: ak1 workflowExecutionId: kdi required: - originalScanId securitySchemes: x-api-key: name: x-api-key type: apiKey in: header description: API key is a token provided while making the API calls. This is used to authenticate the client at the exposed endpoint. externalDocs: description: Find out more about Swagger url: http://swagger.io x-stoplight: id: oc91t4vrfnjyi x-tagGroups: - name: Organizations tags: - Organization - name: Projects tags: - Org Project - Project - name: Secrets tags: - Account Secret - Org Secret - Project Secret - Secrets - name: Connectors tags: - Account Connector - Org Connector - Project Connector - Connectors - GoogleSecretManagerConnector - name: Roles tags: - Account Roles - Organization Roles - Project Roles - Roles - name: Resource Groups tags: - Account Resource Groups - Organization Resource Groups - Project Resource Groups - Filter Resource Groups - Harness Resource Group - Zendesk - name: Role Assignments tags: - Account Role Assignments - Org Role Assignments - Project Role Assignments - Role Assignments - name: Platform tags: - Access Control List - Account Banner - Account Banner - Account Licensed Modules - Account License Type - Account Webhooks - AccountSetting - Accounts - Analyze Account Access Policy - Analyze Organization Access Policy - Analyze Project Access Policy - ApiKey - Audit - AuditFilters - Authentication Settings - Canny - Devops Essentials License Data By Account - EULA - Filter - Harness Resource Type - Invite - IP Allowlist - Nextgen Ldap - Notification Channels - Notification Rules - OIDC - Oidc-Access-Token - Oidc-ID-Token - Org Webhooks - Permissions - Project Webhooks - Secret Managers - Service Account - Setting - SMTP - Source Code Manager - Token - User - User Group - Variables - name: Delegate tags: - Agent mTLS Endpoint Management - Delegate Download Resource - Delegate Group Tags Resource - Delegate Setup Resource - Delegate Token Resource - name: Pipelines tags: - Pipelines - Input Sets - Approvals - Pipeline Execution - Pipeline Dashboard - Pipeline Input Set - Pipeline - Pipeline Execution Details - Pipeline Execute - Pipeline Refresh - Pipeline data retention - Triggers - TriggersEvents - Webhook Triggers - Webhook Event Handler - DryRunPipeline - name: Artifact Registry tags: - Registries - Artifacts - Docker Artifacts - Helm Artifacts - quarantine - Webhooks - Spaces - Replication - Registry V3 - Registries - Registry V3 - Packages - Registry V3 - Versions - Registry V3 - Files - Registry V3 - Metadata - Registry V3 - Firewall - Registry V3 - Transfer - name: Database DevOps tags: - Database Schema - Database Instance - Deployed State - Execution Config - Migration State - name: CD tags: - K8s Release Service Mapping - CustomDeployment - Environments - EnvironmentGroup - Infrastructures - Usage - File Store - Service Dashboard - ServiceOverrides - Rollback - tas - name: Deployment Freeze tags: - Freeze CRUD - Freeze Evaluation - Freeze Schema - name: Services tags: - Account Services - Org Services - Project Services - Services - name: Rancher Infrastructures tags: - Account Rancher Infrastructure - Org Rancher Infrastructure - Project Rancher Infrastructure - name: Templates tags: - Account Template - Org Template - Project Template - Templates - Global Templates - name: GitOps tags: - Agents - Application - Applications - Certificates - Clusters - Dashboard Aggregates - Dashboards - GnuPGP Keys - GPG Keys - Hosts - Project mappings - Projects - Reconciler - Repositories - Repository Certificates - Repository credentials - ValidateHost - name: GitX tags: - GitX Webhooks - Org Gitx Webhooks - Project Gitx Webhooks - name: CACM tags: - Anomalies Ignorelist Rule - Anomalies - BI Dashboards - Budgets - Budget Groups - Cost Categories - Cloud Accounts - K8S Connectors Metadata - Notification Settings v2 - Overview - Data Job Status - Recommendation cost settings - Unit Metric - Anomaly Comments - Cloud and AI cost anomaly details - Cloud and AI cost anomalies v2 - Cost Details - Currency Preferences - External Data Provider - AiEngine - CACM governance cost settings - Governance Enforcement Recommendation APIs - Governance Alert - Governance Overview - Governance Recommendation APIs - RuleEnforcement - Rule Executions - Rule - Rule Sets - Perspectives Folders - Perspective Reports - Perspectives - Cost Category Jira Project Mapping - Recommendations Details - Recommendations - Recommendation Jira - Recommendation Preferences - Recommendation Presets - Recommendation Servicenow - Recommendation Tags - Recommendation Ignore List - AutoStopping Rules - AutoStopping Rules V2 - AutoStopping Load Balancers - AutoStopping Fixed Schedules - AutoStopping Alerts - Commitment Orchestrator Events APIs - name: Feature Flags tags: - API Keys - Feature Flags - Targets - Target Groups - Environment Perspectives - Anomalies - Proxy - Tags - name: SRM tags: - Monitored Services - SLOs dashboard - NG SLOs - SLOs - Downtime - Srm Notification - name: Internal Developer Portal - IDP tags: - Entities - Teams - CatalogCustomProperties - Scores - DataSource - KubernetesDataPoints - AggregationRules - AppConfig - PluginInfo - LayoutProxy - Kinds - LayoutsV3 - LayoutsV4 - name: Environment Management - IDP tags: - Environment - Infrastructure - Instance - name: Custom Dashboards tags: - aida - dashboards - downloads - embed - folders - name: Policy Management tags: - dashboard - examples - policies - evaluate - evaluations - policysets - system - name: Code tags: - repository - status_checks - pullreq - upload - webhook - resource - rules - labels - name: IaCM tags: - usage - approvals - costs - executions - module-registry - workspaces - settings - tf-standard-backend - variables - name: STO tags: - Exemptions - Issues - Scans - Products - Test Targets - Target Variants - name: SEI tags: - Collection categories - Collections - Contributors - DORA - name: Git Sync (deprecated) tags: - Git Branches - Git Full Sync - Git Sync Settings - Git Sync - Git Sync Errors - name: Error Models tags: - Error Response - Governance Metadata - name: Supply Chain Security tags: - integration - PipelineInfraConfig - SBOM - Integration Step Config - Delete Step Config - Delete Repositories - Pipeline Store Config - Evidence Vault [Beta] - name: Release Management tags: - Release Groups - Releases - Orchestration Processes - Orchestration Activities - Orchestration Executions - Conflicts - Freeze - Reports - Uploads - name: Resilience Testing tags: - Actions - Action Templates - Chaos Components - Chaos Hubs - ChaosGuard Conditions - ChaosGuard Rules - DR Tests - Experiments - Experiment Templates - Faults - Fault Templates - Chaos Infrastructure - Health - Network Maps - Onboarding - Probes - Probe Templates - Chaos Recommendations - Risks