openapi: 3.2.0 info: title: Harness Scans API version: '1.0' description: The Harness Software Delivery Platform uses OpenAPI Specification v3.0. contact: name: API Support email: contact@harness.io url: https://harness.io/ x-logo: url: https://mma.prnewswire.com/media/779232/Harnes_logo_horizontal.jpg?p=facebook altText: Harness termsOfService: https://harness.io/terms-of-use/ servers: - url: https://app.harness.io description: Harness host URL - url: https://{vanity} description: Vanity URL variables: vanity: default: app.harness.io security: - x-api-key: [] tags: - name: Scans description: Access and modify Security Test Scans paths: /sto/api/v2/scans: get: tags: - Scans description: List a collection of Security Test Scans operationId: Scans#ListScans parameters: - name: accountId in: query description: Harness Account ID allowEmptyValue: true required: true schema: type: string description: Harness Account ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ example: abcdef1234567890ghijkl - name: page in: query description: Page number to fetch (starting from 0) allowEmptyValue: true schema: type: integer description: Page number to fetch (starting from 0) default: 0 example: 4 format: int64 minimum: 0 example: 4 - name: pageSize in: query description: Number of results per page allowEmptyValue: true schema: type: integer description: Number of results per page default: 30 example: 50 format: int64 minimum: 1 maximum: 100 example: 50 - name: executionId in: query description: Harness Execution ID allowEmptyValue: true schema: type: string description: Harness Execution ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ example: abcdef1234567890ghijkl - name: X-Api-Key in: header description: Harness personal or service access token allowEmptyValue: true schema: type: string description: Harness personal or service access token example: Ullam aut quo autem. example: Ab asperiores earum iste asperiores dolores. responses: '200': description: OK response. content: application/json: schema: $ref: '#/components/schemas/ScansListScansResponseBody' example: pagination: link: '' page: 4 pageSize: 20 totalItems: 230 totalPages: 12 results: - codeCoverage: 65.5 created: 1651578240 executionId: abcdef1234567890ghijkl gitMetadata: commit: '0000000000000000000000000000000000000001' detectedName: Assumenda repellendus neque nostrum autem dolor. detectedVariant: Quam iure corrupti non cupiditate. droneCorrelated: false provider: Voluptatibus consequatur. pullRequestNumber: 11 repositoryHttp: https://github.com/harness/drone-cli.git repositoryPath: - Earum sed in neque nihil ut incidunt. - Magnam ratione vero a. repositorySsh: git@github.com:harness/drone-cli.git sourceBranch: feat/shiny-object targetBranch: develop workspace: /harness id: abcdef1234567890ghijkl lastModified: 1651578240 metadata: baseImageDigest: sha256:abcdef1234567890ghijkl baseImageName: my-image baseImageTag: 1.0.0 orgId: your_harness_org pipelineId: your_harness_pipeline productId: product111111111111111 productName: snyk productPrettyName: Snyk projectId: your_harness_project refinementVersion: 1.0.5 scannerDiffKey: sast stageId: stage_id status: Succeeded stepId: step_id subproduct: owasp targetVariantId: variant111111111111111 - codeCoverage: 65.5 created: 1651578240 executionId: abcdef1234567890ghijkl gitMetadata: commit: '0000000000000000000000000000000000000001' detectedName: Assumenda repellendus neque nostrum autem dolor. detectedVariant: Quam iure corrupti non cupiditate. droneCorrelated: false provider: Voluptatibus consequatur. pullRequestNumber: 11 repositoryHttp: https://github.com/harness/drone-cli.git repositoryPath: - Earum sed in neque nihil ut incidunt. - Magnam ratione vero a. repositorySsh: git@github.com:harness/drone-cli.git sourceBranch: feat/shiny-object targetBranch: develop workspace: /harness id: abcdef1234567890ghijkl lastModified: 1651578240 metadata: baseImageDigest: sha256:abcdef1234567890ghijkl baseImageName: my-image baseImageTag: 1.0.0 orgId: your_harness_org pipelineId: your_harness_pipeline productId: product111111111111111 productName: snyk productPrettyName: Snyk projectId: your_harness_project refinementVersion: 1.0.5 scannerDiffKey: sast stageId: stage_id status: Succeeded stepId: step_id subproduct: owasp targetVariantId: variant111111111111111 - codeCoverage: 65.5 created: 1651578240 executionId: abcdef1234567890ghijkl gitMetadata: commit: '0000000000000000000000000000000000000001' detectedName: Assumenda repellendus neque nostrum autem dolor. detectedVariant: Quam iure corrupti non cupiditate. droneCorrelated: false provider: Voluptatibus consequatur. pullRequestNumber: 11 repositoryHttp: https://github.com/harness/drone-cli.git repositoryPath: - Earum sed in neque nihil ut incidunt. - Magnam ratione vero a. repositorySsh: git@github.com:harness/drone-cli.git sourceBranch: feat/shiny-object targetBranch: develop workspace: /harness id: abcdef1234567890ghijkl lastModified: 1651578240 metadata: baseImageDigest: sha256:abcdef1234567890ghijkl baseImageName: my-image baseImageTag: 1.0.0 orgId: your_harness_org pipelineId: your_harness_pipeline productId: product111111111111111 productName: snyk productPrettyName: Snyk projectId: your_harness_project refinementVersion: 1.0.5 scannerDiffKey: sast stageId: stage_id status: Succeeded stepId: step_id subproduct: owasp targetVariantId: variant111111111111111 - codeCoverage: 65.5 created: 1651578240 executionId: abcdef1234567890ghijkl gitMetadata: commit: '0000000000000000000000000000000000000001' detectedName: Assumenda repellendus neque nostrum autem dolor. detectedVariant: Quam iure corrupti non cupiditate. droneCorrelated: false provider: Voluptatibus consequatur. pullRequestNumber: 11 repositoryHttp: https://github.com/harness/drone-cli.git repositoryPath: - Earum sed in neque nihil ut incidunt. - Magnam ratione vero a. repositorySsh: git@github.com:harness/drone-cli.git sourceBranch: feat/shiny-object targetBranch: develop workspace: /harness id: abcdef1234567890ghijkl lastModified: 1651578240 metadata: baseImageDigest: sha256:abcdef1234567890ghijkl baseImageName: my-image baseImageTag: 1.0.0 orgId: your_harness_org pipelineId: your_harness_pipeline productId: product111111111111111 productName: snyk productPrettyName: Snyk projectId: your_harness_project refinementVersion: 1.0.5 scannerDiffKey: sast stageId: stage_id status: Succeeded stepId: step_id subproduct: owasp targetVariantId: variant111111111111111 '400': description: 'BadRequest: Bad Request response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: 'Bad Request: accountId parameter is required' status: 400 '401': description: 'Unauthorized: Unauthorized response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Unauthorized status: 401 '403': description: 'Forbidden: Forbidden response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Forbidden status: 403 '404': description: 'NotFound: Not Found response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Not Found status: 404 '429': description: 'TooManyRequests: Too Many Requests response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Too Many Requests status: 429 '500': description: 'InternalServerError: Internal Server Error response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Internal Server Error status: 500 security: - X-Api-Key_header_X-Api-Key: [] jwt_header_Authorization: - sto_scan_view summary: Scans#List scans x-summary-source: derived post: tags: - Scans description: Create a new Security Test Scan operationId: Scans#CreateScan parameters: - name: accountId in: query description: Harness Account ID allowEmptyValue: true required: true schema: type: string description: Harness Account ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ example: abcdef1234567890ghijkl - name: X-Api-Key in: header description: Harness personal or service access token allowEmptyValue: true schema: type: string description: Harness personal or service access token example: Repellendus placeat sint. example: Tempore voluptatibus ex est est. - name: X-Harness-User-Id in: header description: Harness User ID allowEmptyValue: true schema: type: string description: Harness User ID example: abcdef1234567890ghijkl example: abcdef1234567890ghijkl requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/CreateScanRequestBody' example: codeCoverage: 65.5 executionId: abcdef1234567890ghijkl gitMetadata: commit: '0000000000000000000000000000000000000001' detectedName: Aut animi provident similique dignissimos mollitia deleniti. detectedVariant: Asperiores velit ut. droneCorrelated: true provider: Fugiat molestiae sit. pullRequestNumber: 11 repositoryHttp: https://github.com/harness/drone-cli.git repositoryPath: - Pariatur eos voluptatibus nesciunt similique dolor placeat. - Magnam assumenda. - Consectetur veniam rem ullam explicabo rerum. - Reiciendis labore quis et laborum nulla. repositorySsh: git@github.com:harness/drone-cli.git sourceBranch: feat/shiny-object targetBranch: develop workspace: /harness orgId: your_harness_org pipelineId: your_harness_pipeline productId: product111111111111111 productName: snyk productPrettyName: Snyk projectId: your_harness_project refinementVersion: 1.0.5 scannerDiffKey: sast stageId: stage_id status: Succeeded stepId: step_id subproduct: owasp targetVariantId: variant111111111111111 responses: '200': description: OK response. content: application/json: schema: $ref: '#/components/schemas/IDResult' example: id: abcdef1234567890ghijkl '400': description: 'BadRequest: Bad Request response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: 'Bad Request: accountId parameter is required' status: 400 '401': description: 'Unauthorized: Unauthorized response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Unauthorized status: 401 '403': description: 'Forbidden: Forbidden response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Forbidden status: 403 '429': description: 'TooManyRequests: Too Many Requests response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Too Many Requests status: 429 '500': description: 'InternalServerError: Internal Server Error response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Internal Server Error status: 500 security: - X-Api-Key_header_X-Api-Key: [] jwt_header_Authorization: - sto_scan_edit summary: Scans#Create scan x-summary-source: derived /sto/api/v2/scans/{id}: delete: description: Delete an existing Security Test Scan operationId: Scans#DeleteScan parameters: - allowEmptyValue: true description: Harness Account ID example: abcdef1234567890ghijkl in: query name: accountId required: true schema: description: Harness Account ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ type: string - description: The ID of the Security Test Scan to delete example: abcdef1234567890ghijkl in: path name: id required: true schema: description: The ID of the Security Test Scan to delete example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ type: string responses: '204': description: No Content response. '400': content: application/json: example: message: 'Bad Request: accountId parameter is required' status: 400 schema: $ref: '#/components/schemas/NotFound' description: 'BadRequest: Bad Request response.' '401': content: application/json: example: message: Unauthorized status: 401 schema: $ref: '#/components/schemas/NotFound' description: 'Unauthorized: Unauthorized response.' '403': content: application/json: example: message: Forbidden status: 403 schema: $ref: '#/components/schemas/NotFound' description: 'Forbidden: Forbidden response.' '404': content: application/json: example: message: Not Found status: 404 schema: $ref: '#/components/schemas/NotFound' description: 'NotFound: Not Found response.' '429': content: application/json: example: message: Too Many Requests status: 429 schema: $ref: '#/components/schemas/NotFound' description: 'TooManyRequests: Too Many Requests response.' '500': content: application/json: example: message: Internal Server Error status: 500 schema: $ref: '#/components/schemas/NotFound' description: 'InternalServerError: Internal Server Error response.' security: - jwt_header_Authorization: - sto_scan_delete tags: - Scans x-internal: true summary: Scans#Delete scan x-summary-source: derived get: tags: - Scans description: Find Security Test Scan by ID operationId: Scans#FindScanById parameters: - name: accountId in: query description: Harness Account ID allowEmptyValue: true required: true schema: type: string description: Harness Account ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ example: abcdef1234567890ghijkl - name: id in: path description: The ID of the Security Test Scan to retrieve required: true schema: type: string description: The ID of the Security Test Scan to retrieve example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ example: abcdef1234567890ghijkl - name: X-Api-Key in: header description: Harness personal or service access token allowEmptyValue: true schema: type: string description: Harness personal or service access token example: Voluptatibus ut nihil dolorem eaque neque. example: Facilis distinctio ex. responses: '200': description: OK response. content: application/json: schema: $ref: '#/components/schemas/Scan' example: codeCoverage: 65.5 created: 1651578240 executionId: abcdef1234567890ghijkl gitMetadata: commit: '0000000000000000000000000000000000000001' detectedName: Assumenda repellendus neque nostrum autem dolor. detectedVariant: Quam iure corrupti non cupiditate. droneCorrelated: false provider: Voluptatibus consequatur. pullRequestNumber: 11 repositoryHttp: https://github.com/harness/drone-cli.git repositoryPath: - Earum sed in neque nihil ut incidunt. - Magnam ratione vero a. repositorySsh: git@github.com:harness/drone-cli.git sourceBranch: feat/shiny-object targetBranch: develop workspace: /harness id: abcdef1234567890ghijkl lastModified: 1651578240 metadata: baseImageDigest: sha256:abcdef1234567890ghijkl baseImageName: my-image baseImageTag: 1.0.0 orgId: your_harness_org pipelineId: your_harness_pipeline productId: product111111111111111 productName: snyk productPrettyName: Snyk projectId: your_harness_project refinementVersion: 1.0.5 scannerDiffKey: sast stageId: stage_id status: Succeeded stepId: step_id subproduct: owasp targetVariantId: variant111111111111111 '400': description: 'BadRequest: Bad Request response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: 'Bad Request: accountId parameter is required' status: 400 '401': description: 'Unauthorized: Unauthorized response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Unauthorized status: 401 '403': description: 'Forbidden: Forbidden response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Forbidden status: 403 '404': description: 'NotFound: Not Found response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Not Found status: 404 '429': description: 'TooManyRequests: Too Many Requests response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Too Many Requests status: 429 '500': description: 'InternalServerError: Internal Server Error response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Internal Server Error status: 500 security: - X-Api-Key_header_X-Api-Key: [] jwt_header_Authorization: - sto_scan_view summary: Scans#Find scan by id x-summary-source: derived put: tags: - Scans description: Update an existing Security Test Scan operationId: Scans#UpdateScan parameters: - name: accountId in: query description: Harness Account ID allowEmptyValue: true required: true schema: type: string description: Harness Account ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ example: abcdef1234567890ghijkl - name: id in: path description: The ID of the Security Test Scan to update required: true schema: type: string description: The ID of the Security Test Scan to update example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ example: abcdef1234567890ghijkl - name: X-Api-Key in: header description: Harness personal or service access token allowEmptyValue: true schema: type: string description: Harness personal or service access token example: Voluptate ipsam ut beatae qui. example: Soluta eaque unde sint vero. requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/UpdateScanRequestBody' example: artifactFingerprint: abcdef1234567890ghijkl codeCoverage: 65.5 executionId: abcdef1234567890ghijkl gitMetadata: commit: '0000000000000000000000000000000000000001' detectedName: Aut animi provident similique dignissimos mollitia deleniti. detectedVariant: Asperiores velit ut. droneCorrelated: true provider: Fugiat molestiae sit. pullRequestNumber: 11 repositoryHttp: https://github.com/harness/drone-cli.git repositoryPath: - Pariatur eos voluptatibus nesciunt similique dolor placeat. - Magnam assumenda. - Consectetur veniam rem ullam explicabo rerum. - Reiciendis labore quis et laborum nulla. repositorySsh: git@github.com:harness/drone-cli.git sourceBranch: feat/shiny-object targetBranch: develop workspace: /harness metadata: baseImageDigest: sha256:abcdef1234567890ghijkl baseImageName: my-image baseImageTag: 1.0.0 orgId: your_harness_org pipelineId: your_harness_pipeline productId: product111111111111111 productName: snyk productPrettyName: Snyk projectId: your_harness_project refinementVersion: 1.0.5 scannerDiffKey: sast stageId: stage_id status: Succeeded stepId: step_id subproduct: owasp targetVariantId: variant111111111111111 responses: '200': description: OK response. content: application/json: schema: $ref: '#/components/schemas/Scan' example: codeCoverage: 65.5 created: 1651578240 executionId: abcdef1234567890ghijkl gitMetadata: commit: '0000000000000000000000000000000000000001' detectedName: Assumenda repellendus neque nostrum autem dolor. detectedVariant: Quam iure corrupti non cupiditate. droneCorrelated: false provider: Voluptatibus consequatur. pullRequestNumber: 11 repositoryHttp: https://github.com/harness/drone-cli.git repositoryPath: - Earum sed in neque nihil ut incidunt. - Magnam ratione vero a. repositorySsh: git@github.com:harness/drone-cli.git sourceBranch: feat/shiny-object targetBranch: develop workspace: /harness id: abcdef1234567890ghijkl lastModified: 1651578240 metadata: baseImageDigest: sha256:abcdef1234567890ghijkl baseImageName: my-image baseImageTag: 1.0.0 orgId: your_harness_org pipelineId: your_harness_pipeline productId: product111111111111111 productName: snyk productPrettyName: Snyk projectId: your_harness_project refinementVersion: 1.0.5 scannerDiffKey: sast stageId: stage_id status: Succeeded stepId: step_id subproduct: owasp targetVariantId: variant111111111111111 '400': description: 'BadRequest: Bad Request response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: 'Bad Request: accountId parameter is required' status: 400 '401': description: 'Unauthorized: Unauthorized response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Unauthorized status: 401 '403': description: 'Forbidden: Forbidden response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Forbidden status: 403 '404': description: 'NotFound: Not Found response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Not Found status: 404 '429': description: 'TooManyRequests: Too Many Requests response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Too Many Requests status: 429 '500': description: 'InternalServerError: Internal Server Error response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Internal Server Error status: 500 security: - X-Api-Key_header_X-Api-Key: [] jwt_header_Authorization: - sto_scan_edit summary: Scans#Update scan x-summary-source: derived /sto/api/v2/scans/{id}/issue/{issueId}: get: tags: - Scans description: Returns a scan specific issue operationId: Scans#ScanIssue parameters: - name: accountId in: query description: Harness Account ID allowEmptyValue: true required: true schema: type: string description: Harness Account ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ example: abcdef1234567890ghijkl - name: orgId in: query description: Harness Organization ID allowEmptyValue: true schema: type: string description: Harness Organization ID example: example_org pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 example: example_org - name: projectId in: query description: Harness Project ID allowEmptyValue: true schema: type: string description: Harness Project ID example: example_project pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 example: example_project - name: page in: query description: Page number to fetch (starting from 0) allowEmptyValue: true schema: type: integer description: Page number to fetch (starting from 0) default: 0 example: 4 format: int64 minimum: 0 example: 4 - name: pageSize in: query description: Number of results per page allowEmptyValue: true schema: type: integer description: Number of results per page default: 30 example: 50 format: int64 minimum: 1 maximum: 100 example: 50 - name: sort in: query description: The field to sort by allowEmptyValue: true schema: type: string description: The field to sort by example: Reiciendis sed ut sunt. example: Magni sapiente consequatur. - name: order in: query description: The order to sort by allowEmptyValue: true schema: type: string description: The order to sort by example: DESC enum: - ASC - DESC example: DESC - name: id in: path description: The ID of the Security Test Scan required: true schema: type: string description: The ID of the Security Test Scan example: Esse voluptas. example: Officia sed. - name: issueId in: path description: The ID of the Security Test Issue required: true schema: type: string description: The ID of the Security Test Issue example: Recusandae numquam est quia vel aut omnis. example: Aut officiis earum. - name: X-Api-Key in: header description: Harness personal or service access token allowEmptyValue: true schema: type: string description: Harness personal or service access token example: Eligendi ab enim ad ratione. example: Non eum commodi. responses: '200': description: OK response. content: application/json: schema: $ref: '#/components/schemas/IssueInScan' example: aiTriaged: LikelyFP aiTriagedReasoning: The argument to path.join is __dirname, a constant, not user input. baseImageName: baseImageName baseImageOrgId: default baseImageProjectId: STO baselineVariantId: abcdef1234567890ghijkl created: 1651578240 currentStatus: Approved details: package: json-schema version: v0.2.3 epssLastModified: '2025-05-01' epssPercentile: 0.15 epssScore: 0.035 exemptionCoverage: PartiallyExempted exemptionId: abcdef1234567890ghijkl exemptionStatusAtScan: Expired exploitability: 'yes' fallbackSeverityCode: High gitMetadata: commit: '0000000000000000000000000000000000000001' detectedName: Assumenda repellendus neque nostrum autem dolor. detectedVariant: Quam iure corrupti non cupiditate. droneCorrelated: false provider: Voluptatibus consequatur. pullRequestNumber: 11 repositoryHttp: https://github.com/harness/drone-cli.git repositoryPath: - Earum sed in neque nihil ut incidunt. - Magnam ratione vero a. repositorySsh: git@github.com:harness/drone-cli.git sourceBranch: feat/shiny-object targetBranch: develop workspace: /harness gracePeriodDays: 13 harnessAugmentation: Fugiat quos temporibus et.: Suscipit nemo ipsa et voluptate. Reiciendis reiciendis voluptatem hic aut.: Quo delectus minima. Velit omnis et et voluptatem ipsam.: Qui quae. hasRules: true id: abcdef1234567890ghijkl inGrace: true key: json-schema@0.2.3 lastBaseImageScanAt: 1651578240 numNonExemptedOccurrences: 10 numOccurrences: 10 occurrenceId: 12345 occurrences: - line: '42' - line: '666' occurrencesPagination: link: '' page: 4 pageSize: 20 totalItems: 230 totalPages: 12 originStatus: approved origins: - app - base overrides: - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname overridesAtScan: - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname pipelineId: example_pipeline primaryOccurrenceId: 12345 productId: product1234567890abcde reachability: reachable recentActivities: - actorName: Priya Nair created: 1781391060 id: hist111111111111111111 isAutoExpiry: false status: Expired - actorName: Priya Nair created: 1781391060 id: hist111111111111111111 isAutoExpiry: false status: Expired - actorName: Priya Nair created: 1781391060 id: hist111111111111111111 isAutoExpiry: false status: Expired remediationAgentPullRequests: - buildId: '4' commits: 3 createdAt: '2026-07-04T12:45:00Z' executionId: execution1111111111111 fixVerified: success id: '42' jiraTicketId: STO-87236 jiraTicketUrl: https://jira.example.com/browse/STO-87236 prNumber: 13114 prTitle: '[13114] Security fix' prUrl: https://github.com/harness/example/pull/13114 regression: success repository: harness/nodegoat scanId: scan111111111111111111 sourceBranch: remediation/sast-13114 status: Open targetBranch: master - buildId: '4' commits: 3 createdAt: '2026-07-04T12:45:00Z' executionId: execution1111111111111 fixVerified: success id: '42' jiraTicketId: STO-87236 jiraTicketUrl: https://jira.example.com/browse/STO-87236 prNumber: 13114 prTitle: '[13114] Security fix' prUrl: https://github.com/harness/example/pull/13114 regression: success repository: harness/nodegoat scanId: scan111111111111111111 sourceBranch: remediation/sast-13114 status: Open targetBranch: master - buildId: '4' commits: 3 createdAt: '2026-07-04T12:45:00Z' executionId: execution1111111111111 fixVerified: success id: '42' jiraTicketId: STO-87236 jiraTicketUrl: https://jira.example.com/browse/STO-87236 prNumber: 13114 prTitle: '[13114] Security fix' prUrl: https://github.com/harness/example/pull/13114 regression: success repository: harness/nodegoat scanId: scan111111111111111111 sourceBranch: remediation/sast-13114 status: Open targetBranch: master - buildId: '4' commits: 3 createdAt: '2026-07-04T12:45:00Z' executionId: execution1111111111111 fixVerified: success id: '42' jiraTicketId: STO-87236 jiraTicketUrl: https://jira.example.com/browse/STO-87236 prNumber: 13114 prTitle: '[13114] Security fix' prUrl: https://github.com/harness/example/pull/13114 regression: success repository: harness/nodegoat scanId: scan111111111111111111 sourceBranch: remediation/sast-13114 status: Open targetBranch: master severity: 8.5 severityCode: High status: Remediated subproduct: product targetId: abcdef1234567890ghijkl targetName: abcdef1234567890ghijkl targetType: repository targetVariantId: abcdef1234567890ghijkl targetVariantName: nodegoat:master title: 'Semgrep Finding: generic.secrets.security.detected-bcrypt-hash.detected-bcrypt-hash' type: SAST '400': description: 'BadRequest: Bad Request response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: 'Bad Request: accountId parameter is required' status: 400 '401': description: 'Unauthorized: Unauthorized response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Unauthorized status: 401 '403': description: 'Forbidden: Forbidden response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Forbidden status: 403 '404': description: 'NotFound: Not Found response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Not Found status: 404 '429': description: 'TooManyRequests: Too Many Requests response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Too Many Requests status: 429 '500': description: 'InternalServerError: Internal Server Error response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Internal Server Error status: 500 security: - X-Api-Key_header_X-Api-Key: [] jwt_header_Authorization: - sto_issue_view summary: Scans#Scan issue x-summary-source: derived /sto/api/v2/scans/{id}/issue/{issueId}/occurrences: get: tags: - Scans description: Returns occurrences for a scan specific issue operationId: Scans#ScanIssueOccurrences parameters: - name: accountId in: query description: Harness Account ID allowEmptyValue: true required: true schema: type: string description: Harness Account ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ example: abcdef1234567890ghijkl - name: orgId in: query description: Harness Organization ID allowEmptyValue: true schema: type: string description: Harness Organization ID example: example_org pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 example: example_org - name: projectId in: query description: Harness Project ID allowEmptyValue: true schema: type: string description: Harness Project ID example: example_project pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 example: example_project - name: page in: query description: Page number to fetch (starting from 0) allowEmptyValue: true schema: type: integer description: Page number to fetch (starting from 0) default: 0 example: 4 format: int64 minimum: 0 example: 4 - name: pageSize in: query description: Number of results per page allowEmptyValue: true schema: type: integer description: Number of results per page default: 30 example: 50 format: int64 minimum: 1 maximum: 100 example: 50 - name: search in: query allowEmptyValue: true schema: type: string example: CWE-123,5 maxLength: 256 example: CWE-123,5 - name: exemptionStatus in: query allowEmptyValue: true schema: type: string example: EXEMPTED,REJECTED pattern: ^(EXEMPTED|NOT_EXEMPTED|REJECTED|PENDING)(,EXEMPTED|,NOT_EXEMPTED|,REJECTED|,PENDING)*$ example: EXEMPTED,REJECTED - name: occurrenceId in: query allowEmptyValue: true schema: type: integer example: 12345 format: int64 minimum: 1 example: 12345 - name: sort in: query description: The field to sort by allowEmptyValue: true schema: type: string description: The field to sort by example: Id omnis id et optio facilis qui. example: Quia perspiciatis debitis quia commodi. - name: order in: query description: The order to sort by allowEmptyValue: true schema: type: string description: The order to sort by example: ASC enum: - ASC - DESC example: ASC - name: exemptionId in: query description: ID of Security Test Exemption allowEmptyValue: true schema: type: string description: ID of Security Test Exemption example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ example: abcdef1234567890ghijkl - name: id in: path description: The ID of the Security Test Scan required: true schema: type: string description: The ID of the Security Test Scan example: Quis excepturi. example: Eaque voluptas numquam. - name: issueId in: path description: The ID of the Security Test Issue required: true schema: type: string description: The ID of the Security Test Issue example: Voluptas amet. example: Cum non nisi harum qui perspiciatis. - name: X-Api-Key in: header description: Harness personal or service access token allowEmptyValue: true schema: type: string description: Harness personal or service access token example: Voluptas possimus. example: Aut neque illum accusantium et. responses: '200': description: OK response. content: application/json: schema: $ref: '#/components/schemas/IssueInScan' example: aiTriaged: LikelyFP aiTriagedReasoning: The argument to path.join is __dirname, a constant, not user input. baseImageName: baseImageName baseImageOrgId: default baseImageProjectId: STO baselineVariantId: abcdef1234567890ghijkl created: 1651578240 currentStatus: Approved details: package: json-schema version: v0.2.3 epssLastModified: '2025-05-01' epssPercentile: 0.15 epssScore: 0.035 exemptionCoverage: PartiallyExempted exemptionId: abcdef1234567890ghijkl exemptionStatusAtScan: Expired exploitability: 'yes' fallbackSeverityCode: High gitMetadata: commit: '0000000000000000000000000000000000000001' detectedName: Assumenda repellendus neque nostrum autem dolor. detectedVariant: Quam iure corrupti non cupiditate. droneCorrelated: false provider: Voluptatibus consequatur. pullRequestNumber: 11 repositoryHttp: https://github.com/harness/drone-cli.git repositoryPath: - Earum sed in neque nihil ut incidunt. - Magnam ratione vero a. repositorySsh: git@github.com:harness/drone-cli.git sourceBranch: feat/shiny-object targetBranch: develop workspace: /harness gracePeriodDays: 13 harnessAugmentation: Fugiat quos temporibus et.: Suscipit nemo ipsa et voluptate. Reiciendis reiciendis voluptatem hic aut.: Quo delectus minima. Velit omnis et et voluptatem ipsam.: Qui quae. hasRules: true id: abcdef1234567890ghijkl inGrace: true key: json-schema@0.2.3 lastBaseImageScanAt: 1651578240 numNonExemptedOccurrences: 10 numOccurrences: 10 occurrenceId: 12345 occurrences: - line: '42' - line: '666' occurrencesPagination: link: '' page: 4 pageSize: 20 totalItems: 230 totalPages: 12 originStatus: approved origins: - app - base overrides: - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname overridesAtScan: - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname pipelineId: example_pipeline primaryOccurrenceId: 12345 productId: product1234567890abcde reachability: reachable recentActivities: - actorName: Priya Nair created: 1781391060 id: hist111111111111111111 isAutoExpiry: false status: Expired - actorName: Priya Nair created: 1781391060 id: hist111111111111111111 isAutoExpiry: false status: Expired - actorName: Priya Nair created: 1781391060 id: hist111111111111111111 isAutoExpiry: false status: Expired remediationAgentPullRequests: - buildId: '4' commits: 3 createdAt: '2026-07-04T12:45:00Z' executionId: execution1111111111111 fixVerified: success id: '42' jiraTicketId: STO-87236 jiraTicketUrl: https://jira.example.com/browse/STO-87236 prNumber: 13114 prTitle: '[13114] Security fix' prUrl: https://github.com/harness/example/pull/13114 regression: success repository: harness/nodegoat scanId: scan111111111111111111 sourceBranch: remediation/sast-13114 status: Open targetBranch: master - buildId: '4' commits: 3 createdAt: '2026-07-04T12:45:00Z' executionId: execution1111111111111 fixVerified: success id: '42' jiraTicketId: STO-87236 jiraTicketUrl: https://jira.example.com/browse/STO-87236 prNumber: 13114 prTitle: '[13114] Security fix' prUrl: https://github.com/harness/example/pull/13114 regression: success repository: harness/nodegoat scanId: scan111111111111111111 sourceBranch: remediation/sast-13114 status: Open targetBranch: master - buildId: '4' commits: 3 createdAt: '2026-07-04T12:45:00Z' executionId: execution1111111111111 fixVerified: success id: '42' jiraTicketId: STO-87236 jiraTicketUrl: https://jira.example.com/browse/STO-87236 prNumber: 13114 prTitle: '[13114] Security fix' prUrl: https://github.com/harness/example/pull/13114 regression: success repository: harness/nodegoat scanId: scan111111111111111111 sourceBranch: remediation/sast-13114 status: Open targetBranch: master - buildId: '4' commits: 3 createdAt: '2026-07-04T12:45:00Z' executionId: execution1111111111111 fixVerified: success id: '42' jiraTicketId: STO-87236 jiraTicketUrl: https://jira.example.com/browse/STO-87236 prNumber: 13114 prTitle: '[13114] Security fix' prUrl: https://github.com/harness/example/pull/13114 regression: success repository: harness/nodegoat scanId: scan111111111111111111 sourceBranch: remediation/sast-13114 status: Open targetBranch: master severity: 8.5 severityCode: High status: Remediated subproduct: product targetId: abcdef1234567890ghijkl targetName: abcdef1234567890ghijkl targetType: repository targetVariantId: abcdef1234567890ghijkl targetVariantName: nodegoat:master title: 'Semgrep Finding: generic.secrets.security.detected-bcrypt-hash.detected-bcrypt-hash' type: SAST '400': description: 'BadRequest: Bad Request response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: 'Bad Request: accountId parameter is required' status: 400 '401': description: 'Unauthorized: Unauthorized response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Unauthorized status: 401 '403': description: 'Forbidden: Forbidden response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Forbidden status: 403 '404': description: 'NotFound: Not Found response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Not Found status: 404 '429': description: 'TooManyRequests: Too Many Requests response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Too Many Requests status: 429 '500': description: 'InternalServerError: Internal Server Error response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Internal Server Error status: 500 security: - X-Api-Key_header_X-Api-Key: [] jwt_header_Authorization: - sto_issue_view summary: Scans#Scan issue occurrences x-summary-source: derived /sto/api/v2/scans/{id}/issues: get: tags: - Scans description: List Issues by Scan ID operationId: Scans#ScanIssues parameters: - name: accountId in: query description: Harness Account ID allowEmptyValue: true required: true schema: type: string description: Harness Account ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ example: abcdef1234567890ghijkl - name: exempted in: query description: Chooses whether to show exempted issues ("only"), or non-exempted issues ("0" or "false") allowEmptyValue: true schema: type: string description: Chooses whether to show exempted issues ("only"), or non-exempted issues ("0" or "false") default: 'false' example: '0' enum: - 'false' - only - '0' example: only - name: id in: path description: The Scan ID required: true schema: type: string description: The Scan ID example: abcdefghijkl1234567890 pattern: ^[a-zA-Z0-9_-]{22}$ example: abcdefghijkl1234567890 - name: X-Api-Key in: header description: Harness personal or service access token allowEmptyValue: true schema: type: string description: Harness personal or service access token example: Odit ut. example: Eos ullam labore explicabo veniam in dolorum. responses: '200': description: OK response. content: application/json: schema: $ref: '#/components/schemas/ScanIssuesResult' example: issues: - baseImageName: baseImageName baselineVariantId: abcdef1234567890ghijkl created: 1651578240 currentStatus: Rejected details: package: json-schema version: v0.2.3 epssLastModified: '2025-05-01' epssPercentile: 0.15 epssScore: 0.035 exemptionCoverage: PartiallyExempted exemptionId: abcdef1234567890ghijkl exemptionStatusAtScan: Rejected exploitability: 'yes' fallbackSeverityCode: High gracePeriodDays: 13 harnessAugmentation: Et sed labore voluptatibus.: Id corporis facilis. id: abcdef1234567890ghijkl inGrace: true key: json-schema@0.2.3 numOccurrences: 10 occurrenceId: 12345 occurrences: - line: '42' - line: '666' originStatus: approved origins: - app - base overrides: - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname overridesAtScan: - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname productId: product1234567890abcde reachability: reachable severity: 8.5 severityCode: High status: Remediated subproduct: product targetId: abcdef1234567890ghijkl targetName: abcdef1234567890ghijkl targetType: repository targetVariantId: abcdef1234567890ghijkl targetVariantName: nodegoat:master title: 'Semgrep Finding: generic.secrets.security.detected-bcrypt-hash.detected-bcrypt-hash' type: SAST - baseImageName: baseImageName baselineVariantId: abcdef1234567890ghijkl created: 1651578240 currentStatus: Rejected details: package: json-schema version: v0.2.3 epssLastModified: '2025-05-01' epssPercentile: 0.15 epssScore: 0.035 exemptionCoverage: PartiallyExempted exemptionId: abcdef1234567890ghijkl exemptionStatusAtScan: Rejected exploitability: 'yes' fallbackSeverityCode: High gracePeriodDays: 13 harnessAugmentation: Et sed labore voluptatibus.: Id corporis facilis. id: abcdef1234567890ghijkl inGrace: true key: json-schema@0.2.3 numOccurrences: 10 occurrenceId: 12345 occurrences: - line: '42' - line: '666' originStatus: approved origins: - app - base overrides: - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname overridesAtScan: - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname productId: product1234567890abcde reachability: reachable severity: 8.5 severityCode: High status: Remediated subproduct: product targetId: abcdef1234567890ghijkl targetName: abcdef1234567890ghijkl targetType: repository targetVariantId: abcdef1234567890ghijkl targetVariantName: nodegoat:master title: 'Semgrep Finding: generic.secrets.security.detected-bcrypt-hash.detected-bcrypt-hash' type: SAST - baseImageName: baseImageName baselineVariantId: abcdef1234567890ghijkl created: 1651578240 currentStatus: Rejected details: package: json-schema version: v0.2.3 epssLastModified: '2025-05-01' epssPercentile: 0.15 epssScore: 0.035 exemptionCoverage: PartiallyExempted exemptionId: abcdef1234567890ghijkl exemptionStatusAtScan: Rejected exploitability: 'yes' fallbackSeverityCode: High gracePeriodDays: 13 harnessAugmentation: Et sed labore voluptatibus.: Id corporis facilis. id: abcdef1234567890ghijkl inGrace: true key: json-schema@0.2.3 numOccurrences: 10 occurrenceId: 12345 occurrences: - line: '42' - line: '666' originStatus: approved origins: - app - base overrides: - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname overridesAtScan: - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname productId: product1234567890abcde reachability: reachable severity: 8.5 severityCode: High status: Remediated subproduct: product targetId: abcdef1234567890ghijkl targetName: abcdef1234567890ghijkl targetType: repository targetVariantId: abcdef1234567890ghijkl targetVariantName: nodegoat:master title: 'Semgrep Finding: generic.secrets.security.detected-bcrypt-hash.detected-bcrypt-hash' type: SAST '400': description: 'BadRequest: Bad Request response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: 'Bad Request: accountId parameter is required' status: 400 '401': description: 'Unauthorized: Unauthorized response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Unauthorized status: 401 '403': description: 'Forbidden: Forbidden response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Forbidden status: 403 '429': description: 'TooManyRequests: Too Many Requests response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Too Many Requests status: 429 '500': description: 'InternalServerError: Internal Server Error response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Internal Server Error status: 500 security: - X-Api-Key_header_X-Api-Key: [] jwt_header_Authorization: - sto_issue_view summary: Scans#Scan issues x-summary-source: derived /sto/api/v2/scans/{id}/issues/counts: get: tags: - Scans description: Returns counts of active Security Issues for a Security Test Scan operationId: Scans#ScanIssueCounts parameters: - name: accountId in: query description: Harness Account ID allowEmptyValue: true required: true schema: type: string description: Harness Account ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ example: abcdef1234567890ghijkl - name: orgId in: query description: Harness Organization ID allowEmptyValue: true required: true schema: type: string description: Harness Organization ID example: example_org pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 example: example_org - name: projectId in: query description: Harness Project ID allowEmptyValue: true required: true schema: type: string description: Harness Project ID example: example_project pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 example: example_project - name: id in: path description: The ID of the Security Test Scan for which to count issues required: true schema: type: string description: The ID of the Security Test Scan for which to count issues example: Ut est. example: Ut voluptas. - name: X-Api-Key in: header description: Harness personal or service access token allowEmptyValue: true schema: type: string description: Harness personal or service access token example: Velit esse esse debitis. example: Laudantium modi excepturi ex. responses: '200': description: OK response. content: application/json: schema: $ref: '#/components/schemas/FullIssueCounts' example: appCritical: 1 appHigh: 3 appInfo: 11 appLow: 39 appMedium: 17 baseCritical: 1 baseHigh: 3 baseImageApproved: true baseImageDetected: true baseInfo: 11 baseLow: 39 baseMedium: 17 codeCoverage: 65.5 critical: 1 externalPolicyFailures: 0 high: 3 ignored: 1 ignoredCritical: 1 ignoredHigh: 3 ignoredInfo: 11 ignoredLow: 39 ignoredMedium: 17 ignoredUnassigned: 0 info: 11 low: 39 medium: 17 newAppCritical: 1 newAppHigh: 3 newAppInfo: 11 newAppLow: 39 newAppMedium: 17 newBaseCritical: 1 newBaseHigh: 3 newBaseInfo: 11 newBaseLow: 39 newBaseMedium: 17 newCritical: 1 newHigh: 3 newIgnoredCritical: 1 newIgnoredHigh: 3 newIgnoredInfo: 11 newIgnoredLow: 39 newIgnoredMedium: 17 newIgnoredOccurrencesCritical: 1 newIgnoredOccurrencesHigh: 3 newIgnoredOccurrencesInfo: 11 newIgnoredOccurrencesLow: 39 newIgnoredOccurrencesMedium: 17 newIgnoredOccurrencesUnassigned: 0 newIgnoredUnassigned: 0 newInfo: 11 newLow: 39 newMedium: 17 newOccurrencesCritical: 1 newOccurrencesHigh: 3 newOccurrencesInfo: 11 newOccurrencesLow: 39 newOccurrencesMedium: 17 newOccurrencesUnassigned: 0 newTotal: 3 newTotalBase: 3 newUnassigned: 0 scannerConsoleUrl: https://app.shiftleft.io/apps/myapp/summary?scan=12345 total: 10 totalBase: 10 unassigned: 0 '400': description: 'BadRequest: Bad Request response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: 'Bad Request: accountId parameter is required' status: 400 '401': description: 'Unauthorized: Unauthorized response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Unauthorized status: 401 '403': description: 'Forbidden: Forbidden response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Forbidden status: 403 '404': description: 'NotFound: Not Found response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Not Found status: 404 '429': description: 'TooManyRequests: Too Many Requests response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Too Many Requests status: 429 '500': description: 'InternalServerError: Internal Server Error response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Internal Server Error status: 500 security: - X-Api-Key_header_X-Api-Key: [] jwt_header_Authorization: - sto_issue_view summary: Scans#Scan issue counts x-summary-source: derived /sto/api/v2/scans/latest: get: tags: - Scans summary: Get Latest Scans description: Get the most recent successful scan for each product/subproduct of a target variant. A single product can emit multiple subproducts (e.g. SnykCode vs snykContainer), each of which is a distinct scan stream, so the result is an array with the latest succeeded scan per (product, subproduct). The optional productId and subproduct query params narrow the result to a single product and/or subproduct. Used by scanners needing previous scan context and by UIs to show latest scan status. operationId: Scans#LatestScan parameters: - name: accountId in: query description: Harness Account ID allowEmptyValue: true required: true schema: type: string description: Harness Account ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ example: abcdef1234567890ghijkl - name: targetVariantId in: query description: The Target Variant ID allowEmptyValue: true required: true schema: type: string description: The Target Variant ID example: abcdefghijkl1234567890 pattern: ^[a-zA-Z0-9_-]{22}$ example: abcdefghijkl1234567890 - name: productId in: query description: Optional Product ID (scanner) filter. When omitted, the latest scan for every product of the target variant is returned. allowEmptyValue: true schema: type: string description: Optional Product ID (scanner) filter. When omitted, the latest scan for every product of the target variant is returned. example: abcdefghijkl1234567890 pattern: ^[a-zA-Z0-9_-]{22}$ example: abcdefghijkl1234567890 - name: subproduct in: query description: Optional subproduct filter to disambiguate scans within a product (e.g. SnykCode vs snykContainer). When omitted, the latest scan for every subproduct is returned. allowEmptyValue: true schema: type: string description: Optional subproduct filter to disambiguate scans within a product (e.g. SnykCode vs snykContainer). When omitted, the latest scan for every subproduct is returned. example: SnykCode example: SnykCode - name: X-Api-Key in: header description: Harness personal or service access token allowEmptyValue: true schema: type: string description: Harness personal or service access token example: Voluptas mollitia nisi blanditiis nesciunt exercitationem. example: Aut doloribus. responses: '200': description: OK response. content: application/json: schema: $ref: '#/components/schemas/LatestScansResult' example: scans: - codeCoverage: 65.5 created: 1651578240 executionId: abcdef1234567890ghijkl gitMetadata: commit: '0000000000000000000000000000000000000001' detectedName: Assumenda repellendus neque nostrum autem dolor. detectedVariant: Quam iure corrupti non cupiditate. droneCorrelated: false provider: Voluptatibus consequatur. pullRequestNumber: 11 repositoryHttp: https://github.com/harness/drone-cli.git repositoryPath: - Earum sed in neque nihil ut incidunt. - Magnam ratione vero a. repositorySsh: git@github.com:harness/drone-cli.git sourceBranch: feat/shiny-object targetBranch: develop workspace: /harness id: abcdef1234567890ghijkl lastModified: 1651578240 metadata: baseImageDigest: sha256:abcdef1234567890ghijkl baseImageName: my-image baseImageTag: 1.0.0 orgId: your_harness_org pipelineId: your_harness_pipeline productId: product111111111111111 productName: snyk productPrettyName: Snyk projectId: your_harness_project refinementVersion: 1.0.5 scannerDiffKey: sast stageId: stage_id status: Succeeded stepId: step_id subproduct: owasp targetVariantId: variant111111111111111 - codeCoverage: 65.5 created: 1651578240 executionId: abcdef1234567890ghijkl gitMetadata: commit: '0000000000000000000000000000000000000001' detectedName: Assumenda repellendus neque nostrum autem dolor. detectedVariant: Quam iure corrupti non cupiditate. droneCorrelated: false provider: Voluptatibus consequatur. pullRequestNumber: 11 repositoryHttp: https://github.com/harness/drone-cli.git repositoryPath: - Earum sed in neque nihil ut incidunt. - Magnam ratione vero a. repositorySsh: git@github.com:harness/drone-cli.git sourceBranch: feat/shiny-object targetBranch: develop workspace: /harness id: abcdef1234567890ghijkl lastModified: 1651578240 metadata: baseImageDigest: sha256:abcdef1234567890ghijkl baseImageName: my-image baseImageTag: 1.0.0 orgId: your_harness_org pipelineId: your_harness_pipeline productId: product111111111111111 productName: snyk productPrettyName: Snyk projectId: your_harness_project refinementVersion: 1.0.5 scannerDiffKey: sast stageId: stage_id status: Succeeded stepId: step_id subproduct: owasp targetVariantId: variant111111111111111 '400': description: 'BadRequest: Bad Request response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: 'Bad Request: accountId parameter is required' status: 400 '401': description: 'Unauthorized: Unauthorized response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Unauthorized status: 401 '403': description: 'Forbidden: Forbidden response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Forbidden status: 403 '429': description: 'TooManyRequests: Too Many Requests response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Too Many Requests status: 429 '500': description: 'InternalServerError: Internal Server Error response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Internal Server Error status: 500 security: - X-Api-Key_header_X-Api-Key: [] jwt_header_Authorization: - sto_scan_view components: schemas: ScanIssuesResult: type: object properties: issues: type: array items: $ref: '#/components/schemas/Issue' description: List of Issues example: - baseImageName: baseImageName baselineVariantId: abcdef1234567890ghijkl created: 1651578240 currentStatus: Rejected details: package: json-schema version: v0.2.3 epssLastModified: '2025-05-01' epssPercentile: 0.15 epssScore: 0.035 exemptionCoverage: PartiallyExempted exemptionId: abcdef1234567890ghijkl exemptionStatusAtScan: Rejected exploitability: 'yes' fallbackSeverityCode: High gracePeriodDays: 13 harnessAugmentation: Et sed labore voluptatibus.: Id corporis facilis. id: abcdef1234567890ghijkl inGrace: true key: json-schema@0.2.3 numOccurrences: 10 occurrenceId: 12345 occurrences: - line: '42' - line: '666' originStatus: approved origins: - app - base overrides: - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname overridesAtScan: - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname productId: product1234567890abcde reachability: reachable severity: 8.5 severityCode: High status: Remediated subproduct: product targetId: abcdef1234567890ghijkl targetName: abcdef1234567890ghijkl targetType: repository targetVariantId: abcdef1234567890ghijkl targetVariantName: nodegoat:master title: 'Semgrep Finding: generic.secrets.security.detected-bcrypt-hash.detected-bcrypt-hash' type: SAST - baseImageName: baseImageName baselineVariantId: abcdef1234567890ghijkl created: 1651578240 currentStatus: Rejected details: package: json-schema version: v0.2.3 epssLastModified: '2025-05-01' epssPercentile: 0.15 epssScore: 0.035 exemptionCoverage: PartiallyExempted exemptionId: abcdef1234567890ghijkl exemptionStatusAtScan: Rejected exploitability: 'yes' fallbackSeverityCode: High gracePeriodDays: 13 harnessAugmentation: Et sed labore voluptatibus.: Id corporis facilis. id: abcdef1234567890ghijkl inGrace: true key: json-schema@0.2.3 numOccurrences: 10 occurrenceId: 12345 occurrences: - line: '42' - line: '666' originStatus: approved origins: - app - base overrides: - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname overridesAtScan: - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname productId: product1234567890abcde reachability: reachable severity: 8.5 severityCode: High status: Remediated subproduct: product targetId: abcdef1234567890ghijkl targetName: abcdef1234567890ghijkl targetType: repository targetVariantId: abcdef1234567890ghijkl targetVariantName: nodegoat:master title: 'Semgrep Finding: generic.secrets.security.detected-bcrypt-hash.detected-bcrypt-hash' type: SAST - baseImageName: baseImageName baselineVariantId: abcdef1234567890ghijkl created: 1651578240 currentStatus: Rejected details: package: json-schema version: v0.2.3 epssLastModified: '2025-05-01' epssPercentile: 0.15 epssScore: 0.035 exemptionCoverage: PartiallyExempted exemptionId: abcdef1234567890ghijkl exemptionStatusAtScan: Rejected exploitability: 'yes' fallbackSeverityCode: High gracePeriodDays: 13 harnessAugmentation: Et sed labore voluptatibus.: Id corporis facilis. id: abcdef1234567890ghijkl inGrace: true key: json-schema@0.2.3 numOccurrences: 10 occurrenceId: 12345 occurrences: - line: '42' - line: '666' originStatus: approved origins: - app - base overrides: - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname overridesAtScan: - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname productId: product1234567890abcde reachability: reachable severity: 8.5 severityCode: High status: Remediated subproduct: product targetId: abcdef1234567890ghijkl targetName: abcdef1234567890ghijkl targetType: repository targetVariantId: abcdef1234567890ghijkl targetVariantName: nodegoat:master title: 'Semgrep Finding: generic.secrets.security.detected-bcrypt-hash.detected-bcrypt-hash' type: SAST - baseImageName: baseImageName baselineVariantId: abcdef1234567890ghijkl created: 1651578240 currentStatus: Rejected details: package: json-schema version: v0.2.3 epssLastModified: '2025-05-01' epssPercentile: 0.15 epssScore: 0.035 exemptionCoverage: PartiallyExempted exemptionId: abcdef1234567890ghijkl exemptionStatusAtScan: Rejected exploitability: 'yes' fallbackSeverityCode: High gracePeriodDays: 13 harnessAugmentation: Et sed labore voluptatibus.: Id corporis facilis. id: abcdef1234567890ghijkl inGrace: true key: json-schema@0.2.3 numOccurrences: 10 occurrenceId: 12345 occurrences: - line: '42' - line: '666' originStatus: approved origins: - app - base overrides: - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname overridesAtScan: - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname productId: product1234567890abcde reachability: reachable severity: 8.5 severityCode: High status: Remediated subproduct: product targetId: abcdef1234567890ghijkl targetName: abcdef1234567890ghijkl targetType: repository targetVariantId: abcdef1234567890ghijkl targetVariantName: nodegoat:master title: 'Semgrep Finding: generic.secrets.security.detected-bcrypt-hash.detected-bcrypt-hash' type: SAST description: List of Issues example: issues: - baseImageName: baseImageName baselineVariantId: abcdef1234567890ghijkl created: 1651578240 currentStatus: Rejected details: package: json-schema version: v0.2.3 epssLastModified: '2025-05-01' epssPercentile: 0.15 epssScore: 0.035 exemptionCoverage: PartiallyExempted exemptionId: abcdef1234567890ghijkl exemptionStatusAtScan: Rejected exploitability: 'yes' fallbackSeverityCode: High gracePeriodDays: 13 harnessAugmentation: Et sed labore voluptatibus.: Id corporis facilis. id: abcdef1234567890ghijkl inGrace: true key: json-schema@0.2.3 numOccurrences: 10 occurrenceId: 12345 occurrences: - line: '42' - line: '666' originStatus: approved origins: - app - base overrides: - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname overridesAtScan: - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname productId: product1234567890abcde reachability: reachable severity: 8.5 severityCode: High status: Remediated subproduct: product targetId: abcdef1234567890ghijkl targetName: abcdef1234567890ghijkl targetType: repository targetVariantId: abcdef1234567890ghijkl targetVariantName: nodegoat:master title: 'Semgrep Finding: generic.secrets.security.detected-bcrypt-hash.detected-bcrypt-hash' type: SAST - baseImageName: baseImageName baselineVariantId: abcdef1234567890ghijkl created: 1651578240 currentStatus: Rejected details: package: json-schema version: v0.2.3 epssLastModified: '2025-05-01' epssPercentile: 0.15 epssScore: 0.035 exemptionCoverage: PartiallyExempted exemptionId: abcdef1234567890ghijkl exemptionStatusAtScan: Rejected exploitability: 'yes' fallbackSeverityCode: High gracePeriodDays: 13 harnessAugmentation: Et sed labore voluptatibus.: Id corporis facilis. id: abcdef1234567890ghijkl inGrace: true key: json-schema@0.2.3 numOccurrences: 10 occurrenceId: 12345 occurrences: - line: '42' - line: '666' originStatus: approved origins: - app - base overrides: - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname overridesAtScan: - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname productId: product1234567890abcde reachability: reachable severity: 8.5 severityCode: High status: Remediated subproduct: product targetId: abcdef1234567890ghijkl targetName: abcdef1234567890ghijkl targetType: repository targetVariantId: abcdef1234567890ghijkl targetVariantName: nodegoat:master title: 'Semgrep Finding: generic.secrets.security.detected-bcrypt-hash.detected-bcrypt-hash' type: SAST - baseImageName: baseImageName baselineVariantId: abcdef1234567890ghijkl created: 1651578240 currentStatus: Rejected details: package: json-schema version: v0.2.3 epssLastModified: '2025-05-01' epssPercentile: 0.15 epssScore: 0.035 exemptionCoverage: PartiallyExempted exemptionId: abcdef1234567890ghijkl exemptionStatusAtScan: Rejected exploitability: 'yes' fallbackSeverityCode: High gracePeriodDays: 13 harnessAugmentation: Et sed labore voluptatibus.: Id corporis facilis. id: abcdef1234567890ghijkl inGrace: true key: json-schema@0.2.3 numOccurrences: 10 occurrenceId: 12345 occurrences: - line: '42' - line: '666' originStatus: approved origins: - app - base overrides: - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname overridesAtScan: - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname productId: product1234567890abcde reachability: reachable severity: 8.5 severityCode: High status: Remediated subproduct: product targetId: abcdef1234567890ghijkl targetName: abcdef1234567890ghijkl targetType: repository targetVariantId: abcdef1234567890ghijkl targetVariantName: nodegoat:master title: 'Semgrep Finding: generic.secrets.security.detected-bcrypt-hash.detected-bcrypt-hash' type: SAST required: - issues ScanMetadata: type: object properties: baseImageDigest: type: string description: Digest of the base image example: sha256:1234567890abcdefghijkl baseImageName: type: string description: Name of the base image example: alpine baseImageTag: type: string description: Tag of the base image example: '3.18' buildId: type: string description: CI build/sequence id for the run that produced this scan (Harness HARNESS_BUILD_ID / <+pipeline.sequenceId>; non-Harness BUILD_ID). Not a product/scanner build id. example: '222' maxLength: 128 deduplicatedCount: type: integer description: Total number of deduplicated issues found in the scan example: 80 format: int32 executionSource: type: string description: CI/CD platform that ran the scan (harness, jenkins, github_actions, gitlab_ci, ...) example: jenkins executionUrl: type: string description: URL of the CI execution that orchestrated the scan (Harness DRONE_BUILD_LINK, Jenkins/GHA BUILD_URL) example: https://qa.harness.io/ng/account/acct/ci/orgs/default/projects/STO/pipelines/p/executions/e/pipeline honorGracePeriod: type: boolean description: Honor vendor-issued grace period when bucketing issue counts (Prisma/Twistlock only) example: true imageDomain: type: string description: Domain of the container image registry example: docker.io imageName: type: string description: Name of the container image example: my-application imageTag: type: string description: Tag of the container image example: v1.2.3 ingestToolSeverityFlag: type: boolean description: Scan ran with ingest_tool_severity enabled in the pipeline example: true normalizedCount: type: integer description: Total number of normalized issues found in the scan example: 100 format: int32 polyglotScanId: type: string description: ShiftLeft/Qwiet polyglot scan ID for SCA package lookups example: '413' scanConfig: type: string description: Scan configuration selected for this scan (e.g. default, oss, code, iac) example: oss scannerConsoleUrl: type: string description: URL to view scan results in the scanner's console example: https://app.shiftleft.io/apps/myapp/summary?scan=12345 description: Metadata specific to the entity being scanned example: baseImageDigest: sha256:1234567890abcdefghijkl baseImageName: alpine baseImageTag: '3.18' buildId: '222' deduplicatedCount: 80 executionSource: jenkins executionUrl: https://qa.harness.io/ng/account/acct/ci/orgs/default/projects/STO/pipelines/p/executions/e/pipeline honorGracePeriod: true imageDomain: docker.io imageName: my-application imageTag: v1.2.3 ingestToolSeverityFlag: true normalizedCount: 100 polyglotScanId: '413' scanConfig: oss scannerConsoleUrl: https://app.shiftleft.io/apps/myapp/summary?scan=12345 IDResult: type: object properties: id: type: string description: Resource identifier example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ example: id: abcdef1234567890ghijkl required: - id ExemptionRecentActivity: type: object properties: actorName: type: string description: Display name of commenter. Omitted for auto-expiry. example: Priya Nair created: type: integer description: Unix timestamp (seconds) example: 1781391060 format: int64 id: type: string description: exemption_history.id — pass to Exemption Log drawer as selectedEventId example: hist111111111111111111 pattern: ^[a-zA-Z0-9_-]{22}$ isAutoExpiry: type: boolean description: True when status=Expired and commenter_id IS NULL default: false example: false status: type: string example: Expired enum: - Pending - Approved - Rejected - Expired - Canceled description: Compact exemption history preview for issue detail panels example: actorName: Priya Nair created: 1781391060 id: hist111111111111111111 isAutoExpiry: false status: Pending required: - id - status - created - isAutoExpiry Issue: type: object properties: baseImageName: type: string description: base image name of the issue example: baseImageName baselineVariantId: type: string description: The Baseline Target Variant related to this Security Issue example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ created: type: integer description: Unix timestamp at which the resource was created example: 1651578240 format: int64 currentStatus: type: string description: Current status of the Exemption example: Pending enum: - Pending - Approved - Rejected - Expired details: type: object description: Issue details common to all occurrences example: package: json-schema version: v0.2.3 additionalProperties: true epssLastModified: type: string description: Last date the issue EPSS data was last modified example: '2025-05-01' epssPercentile: type: number description: EPSS percentile of the issue CVE identifier example: 0.15 format: double epssScore: type: number description: EPSS score of the issue CVE identifier example: 0.035 format: double exemptionCoverage: type: string description: Indicates if the Security Issue was found to be Exempted or PartiallyExempted. example: PartiallyExempted exemptionId: type: string description: ID of Security Test Exemption example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ exemptionStatusAtScan: type: string description: Exemption's status at the Security Scan created time example: Expired enum: - Pending - Approved - Rejected - Expired exploitability: type: string description: Exploitability status of the issue (yes or no) example: 'yes' fallbackSeverityCode: type: string description: Issue-table severity code used as occurrence fallback at read time; omitted from API responses example: High enum: - Critical - High - Medium - Low - Info - Unassigned gracePeriodDays: type: integer description: Issue-level grace period rollup in days. Only populated when scan honorGracePeriod is enabled. example: 13 format: int64 harnessAugmentation: type: object description: Harness Augmentation details example: Dolores et illum repellat.: Est suscipit architecto eum voluptatem. Rerum quia facere at.: Nesciunt ratione et natus voluptas voluptatem placeat. Tempore eius cum.: Aliquid similique qui hic molestias quia aut. additionalProperties: true id: type: string description: Resource identifier example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ inGrace: type: boolean description: 'True when the displayed severity is grace-sheltered: at the display-max severity band, all non-exempt occurrences are in grace. Only populated when scan honorGracePeriod is enabled.' example: true key: type: string description: Compression/deduplication key example: json-schema@0.2.3 maxLength: 512 numOccurrences: type: integer description: Indicates the number of Occurrences on the Issue example: 10 format: int32 occurrenceId: type: integer example: 12345 format: int64 minimum: 1 occurrences: type: array items: type: object example: Aliquam omnis itaque laboriosam quis eos.: Et dolores aut rerum facere quae. Dolor consequatur.: Nobis et aut laboriosam amet reprehenderit. Repellendus ratione voluptas alias eveniet.: Unde cum ipsum accusamus. additionalProperties: true description: Array of details unique to each occurrence example: - line: '42' - line: '666' originStatus: type: string description: The status of the origin, either 'approved' or 'unapproved' example: approved origins: type: array items: type: string example: Neque expedita et nam quis debitis aut. description: The origins of the issue example: - app - base overrides: type: array items: $ref: '#/components/schemas/OverrideResult' description: List of issue overrides example: - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname overridesAtScan: type: array items: $ref: '#/components/schemas/OverrideResult' description: List of issue overrides at scan time example: - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname productId: type: string description: The scan tool that identified this Security Issue example: product1234567890abcde pattern: ^[a-zA-Z0-9_-]{22}$ reachability: type: string description: Reachability status of the issue (reachable or unreachable) example: reachable severity: type: number description: Numeric severity, from 0 (lowest) to 10 (highest) example: 8.5 format: float severityCode: type: string description: Severity code example: High enum: - Critical - High - Medium - Low - Info - Unassigned status: type: string description: Indicates if the Security Issue was found to be remediated, ignored, etc. example: Remediated enum: - Remediated - Compensating Controls - Acceptable Use - Acceptable Risk - False Positive - Fix Unavailable - Exempted subproduct: type: string description: The subproduct that identified this Security Issue example: product targetId: type: string description: The Target that this Security Issue affects example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ targetName: type: string description: The Name of the Target that this Security Issue affects example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ targetType: type: string description: The type of the Target that this Security Issue affects example: repository enum: - container - repository - instance - configuration targetVariantId: type: string description: The Target Variant that this Security Issue affects example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ targetVariantName: type: string description: Name of the associated Target and Variant example: nodegoat:master pattern: ^[a-zA-Z0-9_-]{22}$ title: type: string description: Title of the Security Issue example: 'Semgrep Finding: generic.secrets.security.detected-bcrypt-hash.detected-bcrypt-hash' maxLength: 128 type: type: string description: The type of vulnerability or quality issue for this Issue example: SAST enum: - SAST - DAST - SCA - IAC - SECRET - MISCONFIG - BUG_SMELLS - CODE_SMELLS - CODE_COVERAGE - EXTERNAL_POLICY description: Information about a Security Issue example: baseImageName: baseImageName baselineVariantId: abcdef1234567890ghijkl created: 1651578240 currentStatus: Approved details: package: json-schema version: v0.2.3 epssLastModified: '2025-05-01' epssPercentile: 0.15 epssScore: 0.035 exemptionCoverage: PartiallyExempted exemptionId: abcdef1234567890ghijkl exemptionStatusAtScan: Rejected exploitability: 'yes' fallbackSeverityCode: High gracePeriodDays: 13 harnessAugmentation: Enim nisi inventore reiciendis omnis excepturi in.: Illum perspiciatis nam esse perferendis excepturi. Quod aut excepturi explicabo.: Rerum dolorem perspiciatis. id: abcdef1234567890ghijkl inGrace: true key: json-schema@0.2.3 numOccurrences: 10 occurrenceId: 12345 occurrences: - line: '42' - line: '666' originStatus: approved origins: - app - base overrides: - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname overridesAtScan: - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname productId: product1234567890abcde reachability: reachable severity: 8.5 severityCode: High status: Remediated subproduct: product targetId: abcdef1234567890ghijkl targetName: abcdef1234567890ghijkl targetType: repository targetVariantId: abcdef1234567890ghijkl targetVariantName: nodegoat:master title: 'Semgrep Finding: generic.secrets.security.detected-bcrypt-hash.detected-bcrypt-hash' type: SAST required: - title - key - severity - severityCode - productId - details - id - created CreateScanRequestBody: type: object properties: codeCoverage: type: number description: The Code Coverage value for the Scan example: 65.5 format: float executionId: type: string description: Pipeline Execution ID associated with the Scan example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ gitMetadata: $ref: '#/components/schemas/GitMetadata' orgId: type: string description: Harness Organization ID example: your_harness_org pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 pipelineId: type: string description: Harness Organization ID example: your_harness_pipeline pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 productId: type: string description: The Scan Product used for the Scan example: product111111111111111 pattern: ^[a-zA-Z0-9_-]{22}$ productName: type: string description: The machine name of the Scan Product (scanner), e.g. snyk. Optional; populated by endpoints that join the product table. example: snyk productPrettyName: type: string description: The human-readable display name of the Scan Product (scanner), e.g. Snyk. Optional; populated by endpoints that join the product table. example: Snyk projectId: type: string description: Harness Project ID example: your_harness_project pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 refinementVersion: type: string description: The Issue refinement version used for this Scan example: 1.0.5 scannerDiffKey: type: string description: Key used to differentiate scanner configurations for scan comparison (e.g. sast, sca, sast_sca) example: sast stageId: type: string description: Pipeline Stage ID associated with the Scan example: stage_id pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 status: type: string description: Current status of the Scan example: Succeeded enum: - Pending - Running - Succeeded - Failed stepId: type: string description: Pipeline Step ID associated with the Scan example: step_id pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 subproduct: type: string description: The Scan Subproduct used for the Scan example: owasp format: binary targetVariantId: type: string description: The Target Variant associated with the Scan example: variant111111111111111 pattern: ^[a-zA-Z0-9_-]{22}$ example: codeCoverage: 65.5 executionId: abcdef1234567890ghijkl gitMetadata: commit: '0000000000000000000000000000000000000001' detectedName: Aut animi provident similique dignissimos mollitia deleniti. detectedVariant: Asperiores velit ut. droneCorrelated: true provider: Fugiat molestiae sit. pullRequestNumber: 11 repositoryHttp: https://github.com/harness/drone-cli.git repositoryPath: - Pariatur eos voluptatibus nesciunt similique dolor placeat. - Magnam assumenda. - Consectetur veniam rem ullam explicabo rerum. - Reiciendis labore quis et laborum nulla. repositorySsh: git@github.com:harness/drone-cli.git sourceBranch: feat/shiny-object targetBranch: develop workspace: /harness orgId: your_harness_org pipelineId: your_harness_pipeline productId: product111111111111111 productName: snyk productPrettyName: Snyk projectId: your_harness_project refinementVersion: 1.0.5 scannerDiffKey: sast stageId: stage_id status: Succeeded stepId: step_id subproduct: owasp targetVariantId: variant111111111111111 required: - targetVariantId - orgId - projectId - pipelineId - executionId - stageId - stepId - productId - status - refinementVersion - id - created - lastModified RemediationAgentActivity: type: object properties: buildId: type: string description: pr_metadata.BuildId from post-plugin example: '4' commits: type: integer description: pr_metadata.CommitsCount from post-plugin example: 3 format: int64 createdAt: type: string description: RFC3339 remediation_agent_summary.created example: '2026-07-04T12:45:00Z' format: date-time executionId: type: string description: Pipeline execution id of original_scan_id (for PSI V2) example: execution1111111111111 pattern: ^[a-zA-Z0-9_-]{22}$ fixVerified: type: string description: Mapped validation_metadata.remediation.status example: success enum: - success - failure - unverified id: type: string description: remediation_agent_summary.internal_id as string (remAgentSummaryId) example: '42' jiraTicketId: type: string example: STO-87236 jiraTicketUrl: type: string example: https://jira.example.com/browse/STO-87236 prNumber: type: integer example: 13114 format: int64 prTitle: type: string example: '[13114] Security fix' prUrl: type: string example: https://github.com/harness/example/pull/13114 regression: type: string description: Mapped validation_metadata.build.status example: success enum: - success - failure - unverified repository: type: string example: harness/nodegoat scanId: type: string example: scan111111111111111111 pattern: ^[a-zA-Z0-9_-]{22}$ sourceBranch: type: string example: remediation/sast-13114 status: type: string description: PR status for View Remediations (Open|Merged|Closed; synced by background task into pr_metadata) example: Open enum: - Open - Merged - Closed targetBranch: type: string example: master description: One remediation-agent PR activity for the View Remediations drawer example: buildId: '4' commits: 3 createdAt: '2026-07-04T12:45:00Z' executionId: execution1111111111111 fixVerified: success id: '42' jiraTicketId: STO-87236 jiraTicketUrl: https://jira.example.com/browse/STO-87236 prNumber: 13114 prTitle: '[13114] Security fix' prUrl: https://github.com/harness/example/pull/13114 regression: success repository: harness/nodegoat scanId: scan111111111111111111 sourceBranch: remediation/sast-13114 status: Open targetBranch: master required: - id - scanId - executionId - repository - prNumber - prTitle - prUrl - status - commits - sourceBranch - targetBranch - buildId - createdAt - fixVerified - regression StoPagination: type: object properties: link: type: string description: Link-based paging example: '' page: type: integer description: Page number (starting from 0) example: 4 format: int64 pageSize: type: integer description: Requested page size example: 20 format: int64 totalItems: type: integer description: Total results available example: 230 format: int64 totalPages: type: integer description: Total pages available example: 12 format: int64 example: link: '' page: 4 pageSize: 20 totalItems: 230 totalPages: 12 required: - page - pageSize - totalPages - totalItems LatestScansResult: type: object properties: scans: type: array items: $ref: '#/components/schemas/Scan' description: Latest succeeded scan per (product, subproduct), optionally narrowed by the productId and subproduct filters example: - codeCoverage: 65.5 created: 1651578240 executionId: abcdef1234567890ghijkl gitMetadata: commit: '0000000000000000000000000000000000000001' detectedName: Assumenda repellendus neque nostrum autem dolor. detectedVariant: Quam iure corrupti non cupiditate. droneCorrelated: false provider: Voluptatibus consequatur. pullRequestNumber: 11 repositoryHttp: https://github.com/harness/drone-cli.git repositoryPath: - Earum sed in neque nihil ut incidunt. - Magnam ratione vero a. repositorySsh: git@github.com:harness/drone-cli.git sourceBranch: feat/shiny-object targetBranch: develop workspace: /harness id: abcdef1234567890ghijkl lastModified: 1651578240 metadata: baseImageDigest: sha256:abcdef1234567890ghijkl baseImageName: my-image baseImageTag: 1.0.0 orgId: your_harness_org pipelineId: your_harness_pipeline productId: product111111111111111 productName: snyk productPrettyName: Snyk projectId: your_harness_project refinementVersion: 1.0.5 scannerDiffKey: sast stageId: stage_id status: Succeeded stepId: step_id subproduct: owasp targetVariantId: variant111111111111111 - codeCoverage: 65.5 created: 1651578240 executionId: abcdef1234567890ghijkl gitMetadata: commit: '0000000000000000000000000000000000000001' detectedName: Assumenda repellendus neque nostrum autem dolor. detectedVariant: Quam iure corrupti non cupiditate. droneCorrelated: false provider: Voluptatibus consequatur. pullRequestNumber: 11 repositoryHttp: https://github.com/harness/drone-cli.git repositoryPath: - Earum sed in neque nihil ut incidunt. - Magnam ratione vero a. repositorySsh: git@github.com:harness/drone-cli.git sourceBranch: feat/shiny-object targetBranch: develop workspace: /harness id: abcdef1234567890ghijkl lastModified: 1651578240 metadata: baseImageDigest: sha256:abcdef1234567890ghijkl baseImageName: my-image baseImageTag: 1.0.0 orgId: your_harness_org pipelineId: your_harness_pipeline productId: product111111111111111 productName: snyk productPrettyName: Snyk projectId: your_harness_project refinementVersion: 1.0.5 scannerDiffKey: sast stageId: stage_id status: Succeeded stepId: step_id subproduct: owasp targetVariantId: variant111111111111111 description: The latest succeeded scan for each product/subproduct of a target variant example: scans: - codeCoverage: 65.5 created: 1651578240 executionId: abcdef1234567890ghijkl gitMetadata: commit: '0000000000000000000000000000000000000001' detectedName: Assumenda repellendus neque nostrum autem dolor. detectedVariant: Quam iure corrupti non cupiditate. droneCorrelated: false provider: Voluptatibus consequatur. pullRequestNumber: 11 repositoryHttp: https://github.com/harness/drone-cli.git repositoryPath: - Earum sed in neque nihil ut incidunt. - Magnam ratione vero a. repositorySsh: git@github.com:harness/drone-cli.git sourceBranch: feat/shiny-object targetBranch: develop workspace: /harness id: abcdef1234567890ghijkl lastModified: 1651578240 metadata: baseImageDigest: sha256:abcdef1234567890ghijkl baseImageName: my-image baseImageTag: 1.0.0 orgId: your_harness_org pipelineId: your_harness_pipeline productId: product111111111111111 productName: snyk productPrettyName: Snyk projectId: your_harness_project refinementVersion: 1.0.5 scannerDiffKey: sast stageId: stage_id status: Succeeded stepId: step_id subproduct: owasp targetVariantId: variant111111111111111 - codeCoverage: 65.5 created: 1651578240 executionId: abcdef1234567890ghijkl gitMetadata: commit: '0000000000000000000000000000000000000001' detectedName: Assumenda repellendus neque nostrum autem dolor. detectedVariant: Quam iure corrupti non cupiditate. droneCorrelated: false provider: Voluptatibus consequatur. pullRequestNumber: 11 repositoryHttp: https://github.com/harness/drone-cli.git repositoryPath: - Earum sed in neque nihil ut incidunt. - Magnam ratione vero a. repositorySsh: git@github.com:harness/drone-cli.git sourceBranch: feat/shiny-object targetBranch: develop workspace: /harness id: abcdef1234567890ghijkl lastModified: 1651578240 metadata: baseImageDigest: sha256:abcdef1234567890ghijkl baseImageName: my-image baseImageTag: 1.0.0 orgId: your_harness_org pipelineId: your_harness_pipeline productId: product111111111111111 productName: snyk productPrettyName: Snyk projectId: your_harness_project refinementVersion: 1.0.5 scannerDiffKey: sast stageId: stage_id status: Succeeded stepId: step_id subproduct: owasp targetVariantId: variant111111111111111 - codeCoverage: 65.5 created: 1651578240 executionId: abcdef1234567890ghijkl gitMetadata: commit: '0000000000000000000000000000000000000001' detectedName: Assumenda repellendus neque nostrum autem dolor. detectedVariant: Quam iure corrupti non cupiditate. droneCorrelated: false provider: Voluptatibus consequatur. pullRequestNumber: 11 repositoryHttp: https://github.com/harness/drone-cli.git repositoryPath: - Earum sed in neque nihil ut incidunt. - Magnam ratione vero a. repositorySsh: git@github.com:harness/drone-cli.git sourceBranch: feat/shiny-object targetBranch: develop workspace: /harness id: abcdef1234567890ghijkl lastModified: 1651578240 metadata: baseImageDigest: sha256:abcdef1234567890ghijkl baseImageName: my-image baseImageTag: 1.0.0 orgId: your_harness_org pipelineId: your_harness_pipeline productId: product111111111111111 productName: snyk productPrettyName: Snyk projectId: your_harness_project refinementVersion: 1.0.5 scannerDiffKey: sast stageId: stage_id status: Succeeded stepId: step_id subproduct: owasp targetVariantId: variant111111111111111 required: - scans NotFound: type: object properties: message: type: string example: Not Found status: type: integer default: 404 example: 404 format: int64 example: message: Not Found status: 404 required: - message Scan: type: object properties: codeCoverage: type: number description: The Code Coverage value for the Scan example: 65.5 format: float created: type: integer description: Unix timestamp at which the resource was created example: 1651578240 format: int64 executionId: type: string description: Pipeline Execution ID associated with the Scan example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ gitMetadata: $ref: '#/components/schemas/GitMetadata' id: type: string description: Resource identifier example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ lastModified: type: integer description: Unix timestamp at which the resource was most recently modified example: 1651578240 format: int64 metadata: $ref: '#/components/schemas/ScanMetadata' orgId: type: string description: Harness Organization ID example: your_harness_org pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 pipelineId: type: string description: Harness Organization ID example: your_harness_pipeline pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 productId: type: string description: The Scan Product used for the Scan example: product111111111111111 pattern: ^[a-zA-Z0-9_-]{22}$ productName: type: string description: The machine name of the Scan Product (scanner), e.g. snyk. Optional; populated by endpoints that join the product table. example: snyk productPrettyName: type: string description: The human-readable display name of the Scan Product (scanner), e.g. Snyk. Optional; populated by endpoints that join the product table. example: Snyk projectId: type: string description: Harness Project ID example: your_harness_project pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 refinementVersion: type: string description: The Issue refinement version used for this Scan example: 1.0.5 scannerDiffKey: type: string description: Key used to differentiate scanner configurations for scan comparison (e.g. sast, sca, sast_sca) example: sast stageId: type: string description: Pipeline Stage ID associated with the Scan example: stage_id pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 status: type: string description: Current status of the Scan example: Succeeded enum: - Pending - Running - Succeeded - Failed stepId: type: string description: Pipeline Step ID associated with the Scan example: step_id pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 subproduct: type: string description: The Scan Subproduct used for the Scan example: owasp format: binary targetVariantId: type: string description: The Target Variant associated with the Scan example: variant111111111111111 pattern: ^[a-zA-Z0-9_-]{22}$ description: Information about a Security Test Scan example: codeCoverage: 65.5 created: 1651578240 executionId: abcdef1234567890ghijkl gitMetadata: commit: '0000000000000000000000000000000000000001' detectedName: Assumenda repellendus neque nostrum autem dolor. detectedVariant: Quam iure corrupti non cupiditate. droneCorrelated: false provider: Voluptatibus consequatur. pullRequestNumber: 11 repositoryHttp: https://github.com/harness/drone-cli.git repositoryPath: - Earum sed in neque nihil ut incidunt. - Magnam ratione vero a. repositorySsh: git@github.com:harness/drone-cli.git sourceBranch: feat/shiny-object targetBranch: develop workspace: /harness id: abcdef1234567890ghijkl lastModified: 1651578240 metadata: baseImageDigest: sha256:abcdef1234567890ghijkl baseImageName: my-image baseImageTag: 1.0.0 orgId: your_harness_org pipelineId: your_harness_pipeline productId: product111111111111111 productName: snyk productPrettyName: Snyk projectId: your_harness_project refinementVersion: 1.0.5 scannerDiffKey: sast stageId: stage_id status: Succeeded stepId: step_id subproduct: owasp targetVariantId: variant111111111111111 required: - targetVariantId - orgId - projectId - pipelineId - executionId - stageId - stepId - productId - status - refinementVersion - id - created - lastModified FullIssueCounts: type: object properties: appCritical: type: integer description: The number of Critical-severity Issues in the App Image example: 1 format: int32 appHigh: type: integer description: The number of High-severity Issues in the App Image example: 3 format: int32 appInfo: type: integer description: The number of Informational Issues in the App Image example: 11 format: int32 appLow: type: integer description: The number of Low-severity Issues in the App Image example: 39 format: int32 appMedium: type: integer description: The number of Medium-severity Issues in the App Image example: 17 format: int32 baseCritical: type: integer description: The number of Critical-severity Issues in the Base Image example: 1 format: int32 baseHigh: type: integer description: The number of High-severity Issues in the Base Image example: 3 format: int32 baseImageApproved: type: boolean description: The approval status of the Base Image for the Scan example: true baseImageDetected: type: boolean description: The status of the Base Image for the Scan example: true baseInfo: type: integer description: The number of Informational Issues in the Base Image example: 11 format: int32 baseLow: type: integer description: The number of Low-severity Issues in the Base Image example: 39 format: int32 baseMedium: type: integer description: The number of Medium-severity Issues in the Base Image example: 17 format: int32 codeCoverage: type: number description: The Code Coverage value for the Scan example: 65.5 format: float critical: type: integer description: The number of Critical-severity Issues example: 1 format: int32 externalPolicyFailures: type: integer description: The number of EXTERNAL_POLICY Issues example: 0 format: int32 high: type: integer description: The number of High-severity Issues example: 3 format: int32 ignored: type: integer description: The number of Issues ignored due to Exemptions, and therefore not included in other counts example: 1 format: int32 ignoredCritical: type: integer description: The number of ignored Critical-severity Issues example: 1 format: int32 ignoredHigh: type: integer description: The number of ignored High-severity Issues example: 3 format: int32 ignoredInfo: type: integer description: The number of ignored Informational Issues example: 11 format: int32 ignoredLow: type: integer description: The number of ignored Low-severity Issues example: 39 format: int32 ignoredMedium: type: integer description: The number of ignored Medium-severity Issues example: 17 format: int32 ignoredUnassigned: type: integer description: The number of Issues with no associated severity code example: 0 format: int32 info: type: integer description: The number of Informational Issues example: 11 format: int32 low: type: integer description: The number of Low-severity Issues example: 39 format: int32 medium: type: integer description: The number of Medium-severity Issues example: 17 format: int32 newAppCritical: type: integer description: The number of new Critical-severity Issues in the App Image example: 1 format: int32 newAppHigh: type: integer description: The number of new High-severity Issues in the App Image example: 3 format: int32 newAppInfo: type: integer description: The number of new Informational Issues in the App Image example: 11 format: int32 newAppLow: type: integer description: The number of new Low-severity Issues in the App Image example: 39 format: int32 newAppMedium: type: integer description: The number of new Medium-severity Issues in the App Image example: 17 format: int32 newBaseCritical: type: integer description: The number of new Critical-severity Issues in the Base Image example: 1 format: int32 newBaseHigh: type: integer description: The number of new High-severity Issues in the Base Image example: 3 format: int32 newBaseInfo: type: integer description: The number of new Informational Issues in the Base Image example: 11 format: int32 newBaseLow: type: integer description: The number of new Low-severity Issues in the Base Image example: 39 format: int32 newBaseMedium: type: integer description: The number of new Medium-severity Issues in the Base Image example: 17 format: int32 newCritical: type: integer description: The number of new Critical-severity Issues example: 1 format: int32 newHigh: type: integer description: The number of new High-severity Issues example: 3 format: int32 newIgnoredCritical: type: integer description: The number of ignored Critical-severity Issues example: 1 format: int32 newIgnoredHigh: type: integer description: The number of ignored High-severity Issues example: 3 format: int32 newIgnoredInfo: type: integer description: The number of ignored Informational Issues example: 11 format: int32 newIgnoredLow: type: integer description: The number of ignored Low-severity Issues example: 39 format: int32 newIgnoredMedium: type: integer description: The number of ignored Medium-severity Issues example: 17 format: int32 newIgnoredOccurrencesCritical: type: integer description: The number of ignored Critical-severity Occurrences example: 1 format: int32 newIgnoredOccurrencesHigh: type: integer description: The number of ignored High-severity Occurrences example: 3 format: int32 newIgnoredOccurrencesInfo: type: integer description: The number of ignored Informational Occurrences example: 11 format: int32 newIgnoredOccurrencesLow: type: integer description: The number of ignored Low-severity Occurrences example: 39 format: int32 newIgnoredOccurrencesMedium: type: integer description: The number of ignored Medium-severity Occurrences example: 17 format: int32 newIgnoredOccurrencesUnassigned: type: integer description: The number of ignored Occurrences with no associated severity code example: 0 format: int32 newIgnoredUnassigned: type: integer description: The number of Issues with no associated severity code example: 0 format: int32 newInfo: type: integer description: The number of new Informational Issues example: 11 format: int32 newLow: type: integer description: The number of new Low-severity Issues example: 39 format: int32 newMedium: type: integer description: The number of new Medium-severity Issues example: 17 format: int32 newOccurrencesCritical: type: integer description: The number of new Critical-severity Occurrences example: 1 format: int32 newOccurrencesHigh: type: integer description: The number of new High-severity Occurrences example: 3 format: int32 newOccurrencesInfo: type: integer description: The number of new Informational Occurrences example: 11 format: int32 newOccurrencesLow: type: integer description: The number of new Low-severity Occurrences example: 39 format: int32 newOccurrencesMedium: type: integer description: The number of new Medium-severity Occurrences example: 17 format: int32 newOccurrencesUnassigned: type: integer description: The number of new Occurrences with no associated severity code example: 0 format: int32 newTotal: type: integer description: The total number new Issues example: 3 format: int32 newTotalBase: type: integer description: The total number new Issues in the Base Image example: 3 format: int32 newUnassigned: type: integer description: The number of new Issues with no associated severity code example: 0 format: int32 scannerConsoleUrl: type: string description: The scanner console URL for viewing scan results example: https://app.shiftleft.io/apps/myapp/summary?scan=12345 total: type: integer description: The total number of Issues example: 10 format: int32 totalBase: type: integer description: The total number of Issues in the Base Image example: 10 format: int32 unassigned: type: integer description: The number of Issues with no associated severity code example: 0 format: int32 example: appCritical: 1 appHigh: 3 appInfo: 11 appLow: 39 appMedium: 17 baseCritical: 1 baseHigh: 3 baseImageApproved: true baseImageDetected: true baseInfo: 11 baseLow: 39 baseMedium: 17 codeCoverage: 65.5 critical: 1 externalPolicyFailures: 0 high: 3 ignored: 1 ignoredCritical: 1 ignoredHigh: 3 ignoredInfo: 11 ignoredLow: 39 ignoredMedium: 17 ignoredUnassigned: 0 info: 11 low: 39 medium: 17 newAppCritical: 1 newAppHigh: 3 newAppInfo: 11 newAppLow: 39 newAppMedium: 17 newBaseCritical: 1 newBaseHigh: 3 newBaseInfo: 11 newBaseLow: 39 newBaseMedium: 17 newCritical: 1 newHigh: 3 newIgnoredCritical: 1 newIgnoredHigh: 3 newIgnoredInfo: 11 newIgnoredLow: 39 newIgnoredMedium: 17 newIgnoredOccurrencesCritical: 1 newIgnoredOccurrencesHigh: 3 newIgnoredOccurrencesInfo: 11 newIgnoredOccurrencesLow: 39 newIgnoredOccurrencesMedium: 17 newIgnoredOccurrencesUnassigned: 0 newIgnoredUnassigned: 0 newInfo: 11 newLow: 39 newMedium: 17 newOccurrencesCritical: 1 newOccurrencesHigh: 3 newOccurrencesInfo: 11 newOccurrencesLow: 39 newOccurrencesMedium: 17 newOccurrencesUnassigned: 0 newTotal: 3 newTotalBase: 3 newUnassigned: 0 scannerConsoleUrl: https://app.shiftleft.io/apps/myapp/summary?scan=12345 total: 10 totalBase: 10 unassigned: 0 required: - newCritical - newHigh - newMedium - newLow - newInfo - unassigned - newUnassigned - externalPolicyFailures - ignored - ignoredCritical - ignoredHigh - ignoredMedium - ignoredLow - ignoredInfo - ignoredUnassigned - newIgnoredCritical - newIgnoredHigh - newIgnoredMedium - newIgnoredLow - newIgnoredInfo - newIgnoredUnassigned - newOccurrencesCritical - newOccurrencesHigh - newOccurrencesMedium - newOccurrencesLow - newOccurrencesInfo - newOccurrencesUnassigned - newIgnoredOccurrencesCritical - newIgnoredOccurrencesHigh - newIgnoredOccurrencesMedium - newIgnoredOccurrencesLow - newIgnoredOccurrencesInfo - newIgnoredOccurrencesUnassigned - total - newTotal - critical - high - medium - low - info GitMetadata: type: object properties: commit: type: string description: Git Commit SHA scanned example: '0000000000000000000000000000000000000001' detectedName: type: string description: Detected Name example: Consequatur ipsa quia eos suscipit et sint. detectedVariant: type: string description: Detected Variant example: Consequuntur sequi. droneCorrelated: type: boolean description: Drone Correlated example: false provider: type: string description: Git Provider example: Quibusdam est. pullRequestNumber: type: integer description: Git Pull Request Number example: 11 format: int64 repositoryHttp: type: string description: Git HTTP Repository example: https://github.com/harness/drone-cli.git repositoryPath: type: array items: type: string example: Sint ipsa ducimus inventore quis ut. description: Git Repository Path example: - Quam quia illo quasi. - Unde voluptatem est voluptates minus iure necessitatibus. - Sapiente molestiae quos doloribus iste neque iusto. repositorySsh: type: string description: Git SSH Repository example: git@github.com:harness/drone-cli.git sourceBranch: type: string description: Git Source Branch example: feat/shiny-object targetBranch: type: string description: Git Target Branch example: develop workspace: type: string description: Git Workspace Root example: /harness description: Git Metadata associated with the Scan example: commit: '0000000000000000000000000000000000000001' detectedName: Fugit repellat officia ratione omnis. detectedVariant: Molestiae molestiae. droneCorrelated: false provider: Voluptatem qui recusandae illum molestiae. pullRequestNumber: 11 repositoryHttp: https://github.com/harness/drone-cli.git repositoryPath: - Nisi et. - Autem eaque eius quia. - In sapiente placeat aliquam alias maiores. - Ex quaerat. repositorySsh: git@github.com:harness/drone-cli.git sourceBranch: feat/shiny-object targetBranch: develop workspace: /harness ScansListScansResponseBody: type: object properties: pagination: $ref: '#/components/schemas/StoPagination' results: type: array items: $ref: '#/components/schemas/Scan' example: - codeCoverage: 65.5 created: 1651578240 executionId: abcdef1234567890ghijkl gitMetadata: commit: '0000000000000000000000000000000000000001' detectedName: Assumenda repellendus neque nostrum autem dolor. detectedVariant: Quam iure corrupti non cupiditate. droneCorrelated: false provider: Voluptatibus consequatur. pullRequestNumber: 11 repositoryHttp: https://github.com/harness/drone-cli.git repositoryPath: - Earum sed in neque nihil ut incidunt. - Magnam ratione vero a. repositorySsh: git@github.com:harness/drone-cli.git sourceBranch: feat/shiny-object targetBranch: develop workspace: /harness id: abcdef1234567890ghijkl lastModified: 1651578240 metadata: baseImageDigest: sha256:abcdef1234567890ghijkl baseImageName: my-image baseImageTag: 1.0.0 orgId: your_harness_org pipelineId: your_harness_pipeline productId: product111111111111111 productName: snyk productPrettyName: Snyk projectId: your_harness_project refinementVersion: 1.0.5 scannerDiffKey: sast stageId: stage_id status: Succeeded stepId: step_id subproduct: owasp targetVariantId: variant111111111111111 - codeCoverage: 65.5 created: 1651578240 executionId: abcdef1234567890ghijkl gitMetadata: commit: '0000000000000000000000000000000000000001' detectedName: Assumenda repellendus neque nostrum autem dolor. detectedVariant: Quam iure corrupti non cupiditate. droneCorrelated: false provider: Voluptatibus consequatur. pullRequestNumber: 11 repositoryHttp: https://github.com/harness/drone-cli.git repositoryPath: - Earum sed in neque nihil ut incidunt. - Magnam ratione vero a. repositorySsh: git@github.com:harness/drone-cli.git sourceBranch: feat/shiny-object targetBranch: develop workspace: /harness id: abcdef1234567890ghijkl lastModified: 1651578240 metadata: baseImageDigest: sha256:abcdef1234567890ghijkl baseImageName: my-image baseImageTag: 1.0.0 orgId: your_harness_org pipelineId: your_harness_pipeline productId: product111111111111111 productName: snyk productPrettyName: Snyk projectId: your_harness_project refinementVersion: 1.0.5 scannerDiffKey: sast stageId: stage_id status: Succeeded stepId: step_id subproduct: owasp targetVariantId: variant111111111111111 - codeCoverage: 65.5 created: 1651578240 executionId: abcdef1234567890ghijkl gitMetadata: commit: '0000000000000000000000000000000000000001' detectedName: Assumenda repellendus neque nostrum autem dolor. detectedVariant: Quam iure corrupti non cupiditate. droneCorrelated: false provider: Voluptatibus consequatur. pullRequestNumber: 11 repositoryHttp: https://github.com/harness/drone-cli.git repositoryPath: - Earum sed in neque nihil ut incidunt. - Magnam ratione vero a. repositorySsh: git@github.com:harness/drone-cli.git sourceBranch: feat/shiny-object targetBranch: develop workspace: /harness id: abcdef1234567890ghijkl lastModified: 1651578240 metadata: baseImageDigest: sha256:abcdef1234567890ghijkl baseImageName: my-image baseImageTag: 1.0.0 orgId: your_harness_org pipelineId: your_harness_pipeline productId: product111111111111111 productName: snyk productPrettyName: Snyk projectId: your_harness_project refinementVersion: 1.0.5 scannerDiffKey: sast stageId: stage_id status: Succeeded stepId: step_id subproduct: owasp targetVariantId: variant111111111111111 example: pagination: link: '' page: 4 pageSize: 20 totalItems: 230 totalPages: 12 results: - codeCoverage: 65.5 created: 1651578240 executionId: abcdef1234567890ghijkl gitMetadata: commit: '0000000000000000000000000000000000000001' detectedName: Assumenda repellendus neque nostrum autem dolor. detectedVariant: Quam iure corrupti non cupiditate. droneCorrelated: false provider: Voluptatibus consequatur. pullRequestNumber: 11 repositoryHttp: https://github.com/harness/drone-cli.git repositoryPath: - Earum sed in neque nihil ut incidunt. - Magnam ratione vero a. repositorySsh: git@github.com:harness/drone-cli.git sourceBranch: feat/shiny-object targetBranch: develop workspace: /harness id: abcdef1234567890ghijkl lastModified: 1651578240 metadata: baseImageDigest: sha256:abcdef1234567890ghijkl baseImageName: my-image baseImageTag: 1.0.0 orgId: your_harness_org pipelineId: your_harness_pipeline productId: product111111111111111 productName: snyk productPrettyName: Snyk projectId: your_harness_project refinementVersion: 1.0.5 scannerDiffKey: sast stageId: stage_id status: Succeeded stepId: step_id subproduct: owasp targetVariantId: variant111111111111111 - codeCoverage: 65.5 created: 1651578240 executionId: abcdef1234567890ghijkl gitMetadata: commit: '0000000000000000000000000000000000000001' detectedName: Assumenda repellendus neque nostrum autem dolor. detectedVariant: Quam iure corrupti non cupiditate. droneCorrelated: false provider: Voluptatibus consequatur. pullRequestNumber: 11 repositoryHttp: https://github.com/harness/drone-cli.git repositoryPath: - Earum sed in neque nihil ut incidunt. - Magnam ratione vero a. repositorySsh: git@github.com:harness/drone-cli.git sourceBranch: feat/shiny-object targetBranch: develop workspace: /harness id: abcdef1234567890ghijkl lastModified: 1651578240 metadata: baseImageDigest: sha256:abcdef1234567890ghijkl baseImageName: my-image baseImageTag: 1.0.0 orgId: your_harness_org pipelineId: your_harness_pipeline productId: product111111111111111 productName: snyk productPrettyName: Snyk projectId: your_harness_project refinementVersion: 1.0.5 scannerDiffKey: sast stageId: stage_id status: Succeeded stepId: step_id subproduct: owasp targetVariantId: variant111111111111111 required: - results - pagination IssueInScan: type: object properties: aiTriaged: type: string description: Aggregate AI triage verdict. 'LikelyFP' if every occurrence is FALSE_POSITIVE; 'LikelyTP' if any is TRUE_POSITIVE; 'NotEvaluatedYet' if only some are triaged. Field is absent when no occurrence has been triaged yet. example: LikelyFP enum: - LikelyFP - LikelyTP - NotEvaluatedYet aiTriagedReasoning: type: string description: Representative LLM reasoning quoted from one of the per-occurrence triaged verdicts (FP-verdict reasoning preferred). Field is absent when no occurrence has been triaged yet. example: The argument to path.join is __dirname, a constant, not user input. baseImageName: type: string description: base image name of the issue example: baseImageName baseImageOrgId: type: string description: org id of the issue from where the base image is being referred example: default baseImageProjectId: type: string description: project id of the issue from where the base image is being referred example: STO baselineVariantId: type: string description: The Baseline Target Variant related to this Security Issue example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ created: type: integer description: Unix timestamp at which the resource was created example: 1651578240 format: int64 currentStatus: type: string description: Current status of the Exemption example: Rejected enum: - Pending - Approved - Rejected - Expired details: type: object description: Issue details common to all occurrences example: package: json-schema version: v0.2.3 additionalProperties: true epssLastModified: type: string description: Last date the issue EPSS data was last modified example: '2025-05-01' epssPercentile: type: number description: EPSS percentile of the issue CVE identifier example: 0.15 format: double epssScore: type: number description: EPSS score of the issue CVE identifier example: 0.035 format: double exemptionCoverage: type: string description: Indicates if the Security Issue was found to be Exempted or PartiallyExempted. example: PartiallyExempted exemptionId: type: string description: ID of Security Test Exemption example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ exemptionStatusAtScan: type: string description: Exemption's status at the Security Scan created time example: Pending enum: - Pending - Approved - Rejected - Expired exploitability: type: string description: Exploitability status of the issue (yes or no) example: 'yes' fallbackSeverityCode: type: string description: Issue-table severity code used as occurrence fallback at read time; omitted from API responses example: High enum: - Critical - High - Medium - Low - Info - Unassigned gitMetadata: $ref: '#/components/schemas/GitMetadata' gracePeriodDays: type: integer description: Issue-level grace period rollup in days. Only populated when scan honorGracePeriod is enabled. example: 13 format: int64 harnessAugmentation: type: object description: Harness Augmentation details example: Ad harum ullam ut.: Sint voluptatum voluptatem error rerum sit. Fugit veritatis inventore odit praesentium.: Hic eum. Illum id maxime sit sunt beatae.: Omnis quia ut. additionalProperties: true hasRules: type: boolean description: Whether the account has at least one exemption rule. When false, clients can skip exemption rule evaluation (no rule-eval loaders). example: true id: type: string description: Resource identifier example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ inGrace: type: boolean description: 'True when the displayed severity is grace-sheltered: at the display-max severity band, all non-exempt occurrences are in grace. Only populated when scan honorGracePeriod is enabled.' example: true key: type: string description: Compression/deduplication key example: json-schema@0.2.3 maxLength: 512 lastBaseImageScanAt: type: integer description: last scan timestamp of the base image being referred example: 1651578240 format: int64 numNonExemptedOccurrences: type: integer description: Indicates the number of Occurrences which dont have an active exemption on the Occurrence default: 0 example: 10 format: int32 numOccurrences: type: integer description: Indicates the number of Occurrences on the Issue example: 10 format: int32 occurrenceId: type: integer example: 12345 format: int64 minimum: 1 occurrences: type: array items: type: object example: Laborum velit error sint.: Totam cumque reiciendis at. Odit harum occaecati et.: In veritatis ut voluptatem eveniet aut. additionalProperties: true description: Array of details unique to each occurrence example: - line: '42' - line: '666' occurrencesPagination: $ref: '#/components/schemas/StoPagination' originStatus: type: string description: The status of the origin, either 'approved' or 'unapproved' example: approved origins: type: array items: type: string example: Ipsum minima odio. description: The origins of the issue example: - app - base overrides: type: array items: $ref: '#/components/schemas/OverrideResult' description: List of issue overrides example: - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname overridesAtScan: type: array items: $ref: '#/components/schemas/OverrideResult' description: List of issue overrides at scan time example: - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname pipelineId: type: string description: Harness Pipeline ID example: example_pipeline pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 primaryOccurrenceId: type: integer description: The primary occurrence's ID example: 12345 format: int64 productId: type: string description: The scan tool that identified this Security Issue example: product1234567890abcde pattern: ^[a-zA-Z0-9_-]{22}$ reachability: type: string description: Reachability status of the issue (reachable or unreachable) example: reachable recentActivities: type: array items: $ref: '#/components/schemas/ExemptionRecentActivity' description: Up to 3 most recent exemption history events for this issue, newest first example: - actorName: Priya Nair created: 1781391060 id: hist111111111111111111 isAutoExpiry: false status: Expired - actorName: Priya Nair created: 1781391060 id: hist111111111111111111 isAutoExpiry: false status: Expired remediationAgentPullRequests: type: array items: $ref: '#/components/schemas/RemediationAgentActivity' description: Unique rem-agent PRs for this issue in this scan (from issue_augmentation.pr_metadata where remediation_agent_summary_id is set). Deduped by PR URL across occurrences. Ordered by creation time descending (newest first). example: - buildId: '4' commits: 3 createdAt: '2026-07-04T12:45:00Z' executionId: execution1111111111111 fixVerified: success id: '42' jiraTicketId: STO-87236 jiraTicketUrl: https://jira.example.com/browse/STO-87236 prNumber: 13114 prTitle: '[13114] Security fix' prUrl: https://github.com/harness/example/pull/13114 regression: success repository: harness/nodegoat scanId: scan111111111111111111 sourceBranch: remediation/sast-13114 status: Open targetBranch: master - buildId: '4' commits: 3 createdAt: '2026-07-04T12:45:00Z' executionId: execution1111111111111 fixVerified: success id: '42' jiraTicketId: STO-87236 jiraTicketUrl: https://jira.example.com/browse/STO-87236 prNumber: 13114 prTitle: '[13114] Security fix' prUrl: https://github.com/harness/example/pull/13114 regression: success repository: harness/nodegoat scanId: scan111111111111111111 sourceBranch: remediation/sast-13114 status: Open targetBranch: master severity: type: number description: Numeric severity, from 0 (lowest) to 10 (highest) example: 8.5 format: float severityCode: type: string description: Severity code example: High enum: - Critical - High - Medium - Low - Info - Unassigned status: type: string description: Indicates if the Security Issue was found to be remediated, ignored, etc. example: Remediated enum: - Remediated - Compensating Controls - Acceptable Use - Acceptable Risk - False Positive - Fix Unavailable - Exempted subproduct: type: string description: The subproduct that identified this Security Issue example: product targetId: type: string description: The Target that this Security Issue affects example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ targetName: type: string description: The Name of the Target that this Security Issue affects example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ targetType: type: string description: The type of the Target that this Security Issue affects example: repository enum: - container - repository - instance - configuration targetVariantId: type: string description: The Target Variant that this Security Issue affects example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ targetVariantName: type: string description: Name of the associated Target and Variant example: nodegoat:master pattern: ^[a-zA-Z0-9_-]{22}$ title: type: string description: Title of the Security Issue example: 'Semgrep Finding: generic.secrets.security.detected-bcrypt-hash.detected-bcrypt-hash' maxLength: 128 type: type: string description: The type of vulnerability or quality issue for this Issue example: SAST enum: - SAST - DAST - SCA - IAC - SECRET - MISCONFIG - BUG_SMELLS - CODE_SMELLS - CODE_COVERAGE - EXTERNAL_POLICY example: aiTriaged: LikelyFP aiTriagedReasoning: The argument to path.join is __dirname, a constant, not user input. baseImageName: baseImageName baseImageOrgId: default baseImageProjectId: STO baselineVariantId: abcdef1234567890ghijkl created: 1651578240 currentStatus: Pending details: package: json-schema version: v0.2.3 epssLastModified: '2025-05-01' epssPercentile: 0.15 epssScore: 0.035 exemptionCoverage: PartiallyExempted exemptionId: abcdef1234567890ghijkl exemptionStatusAtScan: Pending exploitability: 'yes' fallbackSeverityCode: High gitMetadata: commit: '0000000000000000000000000000000000000001' detectedName: Assumenda repellendus neque nostrum autem dolor. detectedVariant: Quam iure corrupti non cupiditate. droneCorrelated: false provider: Voluptatibus consequatur. pullRequestNumber: 11 repositoryHttp: https://github.com/harness/drone-cli.git repositoryPath: - Earum sed in neque nihil ut incidunt. - Magnam ratione vero a. repositorySsh: git@github.com:harness/drone-cli.git sourceBranch: feat/shiny-object targetBranch: develop workspace: /harness gracePeriodDays: 13 harnessAugmentation: Dignissimos totam facilis ut quae quia.: Molestiae magni libero ex. Error eligendi molestiae et distinctio at dolores.: Officia consequatur delectus dolor omnis ut quae. hasRules: true id: abcdef1234567890ghijkl inGrace: true key: json-schema@0.2.3 lastBaseImageScanAt: 1651578240 numNonExemptedOccurrences: 10 numOccurrences: 10 occurrenceId: 12345 occurrences: - line: '42' - line: '666' occurrencesPagination: link: '' page: 4 pageSize: 20 totalItems: 230 totalPages: 12 originStatus: approved origins: - app - base overrides: - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname overridesAtScan: - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname pipelineId: example_pipeline primaryOccurrenceId: 12345 productId: product1234567890abcde reachability: reachable recentActivities: - actorName: Priya Nair created: 1781391060 id: hist111111111111111111 isAutoExpiry: false status: Expired - actorName: Priya Nair created: 1781391060 id: hist111111111111111111 isAutoExpiry: false status: Expired - actorName: Priya Nair created: 1781391060 id: hist111111111111111111 isAutoExpiry: false status: Expired remediationAgentPullRequests: - buildId: '4' commits: 3 createdAt: '2026-07-04T12:45:00Z' executionId: execution1111111111111 fixVerified: success id: '42' jiraTicketId: STO-87236 jiraTicketUrl: https://jira.example.com/browse/STO-87236 prNumber: 13114 prTitle: '[13114] Security fix' prUrl: https://github.com/harness/example/pull/13114 regression: success repository: harness/nodegoat scanId: scan111111111111111111 sourceBranch: remediation/sast-13114 status: Open targetBranch: master - buildId: '4' commits: 3 createdAt: '2026-07-04T12:45:00Z' executionId: execution1111111111111 fixVerified: success id: '42' jiraTicketId: STO-87236 jiraTicketUrl: https://jira.example.com/browse/STO-87236 prNumber: 13114 prTitle: '[13114] Security fix' prUrl: https://github.com/harness/example/pull/13114 regression: success repository: harness/nodegoat scanId: scan111111111111111111 sourceBranch: remediation/sast-13114 status: Open targetBranch: master - buildId: '4' commits: 3 createdAt: '2026-07-04T12:45:00Z' executionId: execution1111111111111 fixVerified: success id: '42' jiraTicketId: STO-87236 jiraTicketUrl: https://jira.example.com/browse/STO-87236 prNumber: 13114 prTitle: '[13114] Security fix' prUrl: https://github.com/harness/example/pull/13114 regression: success repository: harness/nodegoat scanId: scan111111111111111111 sourceBranch: remediation/sast-13114 status: Open targetBranch: master - buildId: '4' commits: 3 createdAt: '2026-07-04T12:45:00Z' executionId: execution1111111111111 fixVerified: success id: '42' jiraTicketId: STO-87236 jiraTicketUrl: https://jira.example.com/browse/STO-87236 prNumber: 13114 prTitle: '[13114] Security fix' prUrl: https://github.com/harness/example/pull/13114 regression: success repository: harness/nodegoat scanId: scan111111111111111111 sourceBranch: remediation/sast-13114 status: Open targetBranch: master severity: 8.5 severityCode: High status: Remediated subproduct: product targetId: abcdef1234567890ghijkl targetName: abcdef1234567890ghijkl targetType: repository targetVariantId: abcdef1234567890ghijkl targetVariantName: nodegoat:master title: 'Semgrep Finding: generic.secrets.security.detected-bcrypt-hash.detected-bcrypt-hash' type: SAST required: - primaryOccurrenceId - occurrencesPagination - numOccurrences - numNonExemptedOccurrences - hasRules - title - key - severity - severityCode - productId - details - id - created UpdateScanRequestBody: type: object properties: artifactFingerprint: type: string description: The Artifact Fingerprint used use to identify the target example: abcdef1234567890ghijkl pattern: ^[A-Za-z0-9_]*$ maxLength: 64 codeCoverage: type: number description: The Code Coverage value for the Scan example: 65.5 format: float executionId: type: string description: Pipeline Execution ID associated with the Scan example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ gitMetadata: $ref: '#/components/schemas/GitMetadata' metadata: $ref: '#/components/schemas/ScanMetadata' orgId: type: string description: Harness Organization ID example: your_harness_org pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 pipelineId: type: string description: Harness Organization ID example: your_harness_pipeline pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 productId: type: string description: The Scan Product used for the Scan example: product111111111111111 pattern: ^[a-zA-Z0-9_-]{22}$ productName: type: string description: The machine name of the Scan Product (scanner), e.g. snyk. Optional; populated by endpoints that join the product table. example: snyk productPrettyName: type: string description: The human-readable display name of the Scan Product (scanner), e.g. Snyk. Optional; populated by endpoints that join the product table. example: Snyk projectId: type: string description: Harness Project ID example: your_harness_project pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 refinementVersion: type: string description: The Issue refinement version used for this Scan example: 1.0.5 scannerDiffKey: type: string description: Key used to differentiate scanner configurations for scan comparison (e.g. sast, sca, sast_sca) example: sast stageId: type: string description: Pipeline Stage ID associated with the Scan example: stage_id pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 status: type: string description: Current status of the Scan example: Succeeded enum: - Pending - Running - Succeeded - Failed stepId: type: string description: Pipeline Step ID associated with the Scan example: step_id pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 subproduct: type: string description: The Scan Subproduct used for the Scan example: owasp format: binary targetVariantId: type: string description: The Target Variant associated with the Scan example: variant111111111111111 pattern: ^[a-zA-Z0-9_-]{22}$ example: artifactFingerprint: abcdef1234567890ghijkl codeCoverage: 65.5 executionId: abcdef1234567890ghijkl gitMetadata: commit: '0000000000000000000000000000000000000001' detectedName: Aut animi provident similique dignissimos mollitia deleniti. detectedVariant: Asperiores velit ut. droneCorrelated: true provider: Fugiat molestiae sit. pullRequestNumber: 11 repositoryHttp: https://github.com/harness/drone-cli.git repositoryPath: - Pariatur eos voluptatibus nesciunt similique dolor placeat. - Magnam assumenda. - Consectetur veniam rem ullam explicabo rerum. - Reiciendis labore quis et laborum nulla. repositorySsh: git@github.com:harness/drone-cli.git sourceBranch: feat/shiny-object targetBranch: develop workspace: /harness metadata: baseImageDigest: sha256:abcdef1234567890ghijkl baseImageName: my-image baseImageTag: 1.0.0 orgId: your_harness_org pipelineId: your_harness_pipeline productId: product111111111111111 productName: snyk productPrettyName: Snyk projectId: your_harness_project refinementVersion: 1.0.5 scannerDiffKey: sast stageId: stage_id status: Succeeded stepId: step_id subproduct: owasp targetVariantId: variant111111111111111 required: - targetVariantId - orgId - projectId - pipelineId - executionId - stageId - stepId - productId - status - refinementVersion - created - lastModified OverrideResult: type: object properties: created: type: integer description: Unix timestamp at which the resource was created example: 1651578240 format: int64 fieldName: type: string description: Name of the field that is being overridden example: severityCode impactedTargetId: type: string description: ID of the impacted target example: target1111111111111111 originalFieldValue: type: string description: Original value of the field that is being overridden example: Low overrideFieldValue: type: string description: Value of the field that is being overridden example: Low maxLength: 1024 overrideId: type: string description: Override Id of the override example: override1234 reason: type: string description: Text describing why this override is necessary example: Waiting on upstream bug fix maxLength: 1024 requesterEmail: type: string description: Email of the user who requested this Exemption example: user@harness.io requesterId: type: string description: User ID of the user who requested the override example: user111111111111111111 requesterName: type: string description: Name of the user who requested this Exemption example: firstname lastname example: created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname required: - fieldName - originalFieldValue - overrideFieldValue - reason - created securitySchemes: x-api-key: name: x-api-key type: apiKey in: header description: API key is a token provided while making the API calls. This is used to authenticate the client at the exposed endpoint. externalDocs: description: Find out more about Swagger url: http://swagger.io x-stoplight: id: oc91t4vrfnjyi x-tagGroups: - name: Organizations tags: - Organization - name: Projects tags: - Org Project - Project - name: Secrets tags: - Account Secret - Org Secret - Project Secret - Secrets - name: Connectors tags: - Account Connector - Org Connector - Project Connector - Connectors - GoogleSecretManagerConnector - name: Roles tags: - Account Roles - Organization Roles - Project Roles - Roles - name: Resource Groups tags: - Account Resource Groups - Organization Resource Groups - Project Resource Groups - Filter Resource Groups - Harness Resource Group - Zendesk - name: Role Assignments tags: - Account Role Assignments - Org Role Assignments - Project Role Assignments - Role Assignments - name: Platform tags: - Access Control List - Account Banner - Account Banner - Account Licensed Modules - Account License Type - Account Webhooks - AccountSetting - Accounts - Analyze Account Access Policy - Analyze Organization Access Policy - Analyze Project Access Policy - ApiKey - Audit - AuditFilters - Authentication Settings - Canny - Devops Essentials License Data By Account - EULA - Filter - Harness Resource Type - Invite - IP Allowlist - Nextgen Ldap - Notification Channels - Notification Rules - OIDC - Oidc-Access-Token - Oidc-ID-Token - Org Webhooks - Permissions - Project Webhooks - Secret Managers - Service Account - Setting - SMTP - Source Code Manager - Token - User - User Group - Variables - name: Delegate tags: - Agent mTLS Endpoint Management - Delegate Download Resource - Delegate Group Tags Resource - Delegate Setup Resource - Delegate Token Resource - name: Pipelines tags: - Pipelines - Input Sets - Approvals - Pipeline Execution - Pipeline Dashboard - Pipeline Input Set - Pipeline - Pipeline Execution Details - Pipeline Execute - Pipeline Refresh - Pipeline data retention - Triggers - TriggersEvents - Webhook Triggers - Webhook Event Handler - DryRunPipeline - name: Artifact Registry tags: - Registries - Artifacts - Docker Artifacts - Helm Artifacts - quarantine - Webhooks - Spaces - Replication - Registry V3 - Registries - Registry V3 - Packages - Registry V3 - Versions - Registry V3 - Files - Registry V3 - Metadata - Registry V3 - Firewall - Registry V3 - Transfer - name: Database DevOps tags: - Database Schema - Database Instance - Deployed State - Execution Config - Migration State - name: CD tags: - K8s Release Service Mapping - CustomDeployment - Environments - EnvironmentGroup - Infrastructures - Usage - File Store - Service Dashboard - ServiceOverrides - Rollback - tas - name: Deployment Freeze tags: - Freeze CRUD - Freeze Evaluation - Freeze Schema - name: Services tags: - Account Services - Org Services - Project Services - Services - name: Rancher Infrastructures tags: - Account Rancher Infrastructure - Org Rancher Infrastructure - Project Rancher Infrastructure - name: Templates tags: - Account Template - Org Template - Project Template - Templates - Global Templates - name: GitOps tags: - Agents - Application - Applications - Certificates - Clusters - Dashboard Aggregates - Dashboards - GnuPGP Keys - GPG Keys - Hosts - Project mappings - Projects - Reconciler - Repositories - Repository Certificates - Repository credentials - ValidateHost - name: GitX tags: - GitX Webhooks - Org Gitx Webhooks - Project Gitx Webhooks - name: CACM tags: - Anomalies Ignorelist Rule - Anomalies - BI Dashboards - Budgets - Budget Groups - Cost Categories - Cloud Accounts - K8S Connectors Metadata - Notification Settings v2 - Overview - Data Job Status - Recommendation cost settings - Unit Metric - Anomaly Comments - Cloud and AI cost anomaly details - Cloud and AI cost anomalies v2 - Cost Details - Currency Preferences - External Data Provider - AiEngine - CACM governance cost settings - Governance Enforcement Recommendation APIs - Governance Alert - Governance Overview - Governance Recommendation APIs - RuleEnforcement - Rule Executions - Rule - Rule Sets - Perspectives Folders - Perspective Reports - Perspectives - Cost Category Jira Project Mapping - Recommendations Details - Recommendations - Recommendation Jira - Recommendation Preferences - Recommendation Presets - Recommendation Servicenow - Recommendation Tags - Recommendation Ignore List - AutoStopping Rules - AutoStopping Rules V2 - AutoStopping Load Balancers - AutoStopping Fixed Schedules - AutoStopping Alerts - Commitment Orchestrator Events APIs - name: Feature Flags tags: - API Keys - Feature Flags - Targets - Target Groups - Environment Perspectives - Anomalies - Proxy - Tags - name: SRM tags: - Monitored Services - SLOs dashboard - NG SLOs - SLOs - Downtime - Srm Notification - name: Internal Developer Portal - IDP tags: - Entities - Teams - CatalogCustomProperties - Scores - DataSource - KubernetesDataPoints - AggregationRules - AppConfig - PluginInfo - LayoutProxy - Kinds - LayoutsV3 - LayoutsV4 - name: Environment Management - IDP tags: - Environment - Infrastructure - Instance - name: Custom Dashboards tags: - aida - dashboards - downloads - embed - folders - name: Policy Management tags: - dashboard - examples - policies - evaluate - evaluations - policysets - system - name: Code tags: - repository - status_checks - pullreq - upload - webhook - resource - rules - labels - name: IaCM tags: - usage - approvals - costs - executions - module-registry - workspaces - settings - tf-standard-backend - variables - name: STO tags: - Exemptions - Issues - Scans - Products - Test Targets - Target Variants - name: SEI tags: - Collection categories - Collections - Contributors - DORA - name: Git Sync (deprecated) tags: - Git Branches - Git Full Sync - Git Sync Settings - Git Sync - Git Sync Errors - name: Error Models tags: - Error Response - Governance Metadata - name: Supply Chain Security tags: - integration - PipelineInfraConfig - SBOM - Integration Step Config - Delete Step Config - Delete Repositories - Pipeline Store Config - Evidence Vault [Beta] - name: Release Management tags: - Release Groups - Releases - Orchestration Processes - Orchestration Activities - Orchestration Executions - Conflicts - Freeze - Reports - Uploads - name: Resilience Testing tags: - Actions - Action Templates - Chaos Components - Chaos Hubs - ChaosGuard Conditions - ChaosGuard Rules - DR Tests - Experiments - Experiment Templates - Faults - Fault Templates - Chaos Infrastructure - Health - Network Maps - Onboarding - Probes - Probe Templates - Chaos Recommendations - Risks