openapi: 3.2.0 info: title: Harness STO Data Frontend API version: '1.0' description: The Harness Software Delivery Platform uses OpenAPI Specification v3.0. contact: name: API Support email: contact@harness.io url: https://harness.io/ x-logo: url: https://mma.prnewswire.com/media/779232/Harnes_logo_horizontal.jpg?p=facebook altText: Harness termsOfService: https://harness.io/terms-of-use/ servers: - url: https://app.harness.io description: Harness host URL - url: https://{vanity} description: Vanity URL variables: vanity: default: app.harness.io security: - x-api-key: [] tags: - name: STO Data Frontend description: Endpoints that power the other modules micro-frontend with STO data paths: /sto/api/v2/sto-data-frontend/all-issues/filters: x-internal: true post: description: Provides the distinct set of filter values (severity, scanner, target, issueType) available for the issues produced by the provided target name and variant combinations. Variant name may be empty, in which case the target's baseline variant is used. operationId: STO Data Frontend#AllIssuesFilters parameters: - allowEmptyValue: true description: Harness Account ID example: abcdef1234567890ghijkl in: query name: accountId required: true schema: description: Harness Account ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ type: string - allowEmptyValue: true description: Harness Organization ID example: example_org in: query name: orgId required: true schema: description: Harness Organization ID example: example_org maxLength: 128 pattern: ^[A-Za-z_][A-Za-z0-9_]*$ type: string - allowEmptyValue: true description: Harness Project ID example: example_project in: query name: projectId required: true schema: description: Harness Project ID example: example_project maxLength: 128 pattern: ^[A-Za-z_][A-Za-z0-9_]*$ type: string requestBody: content: application/json: example: artifactFingerprints: - 3uo - 4mb - 68n targetVariants: - targetName: Rerum eos omnis accusamus fuga commodi. targetType: repository targetVariantName: Hic dolor. - targetName: Rerum eos omnis accusamus fuga commodi. targetType: repository targetVariantName: Hic dolor. - targetName: Rerum eos omnis accusamus fuga commodi. targetType: repository targetVariantName: Hic dolor. schema: $ref: '#/components/schemas/ExecutionArtifactSummaryRequestBody' required: true responses: '200': content: application/json: example: exploitabilityFlag: true issueCategories: - Insecure Direct Object Reference (AI SAST) - SQL Injection latestBaselineScans: - pipelineId: pipeline_1 scanTool: owasp scanToolName: OWASP targetId: abcdef1234567890ghijkl targetName: The Target targetType: repository - pipelineId: pipeline_1 scanTool: owasp scanToolName: OWASP targetId: abcdef1234567890ghijkl targetName: The Target targetType: repository - pipelineId: pipeline_1 scanTool: owasp scanToolName: OWASP targetId: abcdef1234567890ghijkl targetName: The Target targetType: repository - pipelineId: pipeline_1 scanTool: owasp scanToolName: OWASP targetId: abcdef1234567890ghijkl targetName: The Target targetType: repository reachabilityFlag: true schema: $ref: '#/components/schemas/AllIssuesFiltersResultV2' description: OK response. '400': content: application/json: example: message: 'Bad Request: accountId parameter is required' status: 400 schema: $ref: '#/components/schemas/NotFound' description: 'BadRequest: Bad Request response.' '401': content: application/json: example: message: Unauthorized status: 401 schema: $ref: '#/components/schemas/NotFound' description: 'Unauthorized: Unauthorized response.' '403': content: application/json: example: message: Forbidden status: 403 schema: $ref: '#/components/schemas/NotFound' description: 'Forbidden: Forbidden response.' '404': content: application/json: example: message: Not Found status: 404 schema: $ref: '#/components/schemas/NotFound' description: 'NotFound: Not Found response.' '429': content: application/json: example: message: Too Many Requests status: 429 schema: $ref: '#/components/schemas/NotFound' description: 'TooManyRequests: Too Many Requests response.' '500': content: application/json: example: message: Internal Server Error status: 500 schema: $ref: '#/components/schemas/NotFound' description: 'InternalServerError: Internal Server Error response.' security: - jwt_header_Authorization: - sto_issue_view summary: Distinct filter values for selected targets and variants tags: - STO Data Frontend /sto/api/v2/sto-data-frontend/all-issues/issues: x-internal: true post: description: Provides a paginated list of issues for the provided target name and variant combinations operationId: STO Data Frontend#AllIssuesList parameters: - allowEmptyValue: true description: Harness Account ID example: abcdef1234567890ghijkl in: query name: accountId required: true schema: description: Harness Account ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ type: string - allowEmptyValue: true description: Harness Organization ID example: example_org in: query name: orgId required: true schema: description: Harness Organization ID example: example_org maxLength: 128 pattern: ^[A-Za-z_][A-Za-z0-9_]*$ type: string - allowEmptyValue: true description: Harness Project ID example: example_project in: query name: projectId required: true schema: description: Harness Project ID example: example_project maxLength: 128 pattern: ^[A-Za-z_][A-Za-z0-9_]*$ type: string requestBody: content: application/json: example: artifactFingerprints: - s33 - 03e - dyy issueTypes: SAST page: 4 pageSize: 50 scanTools: OWASP,Aqua Trivy,Snyk search: CWE-123 severityCodes: Critical,High,Medium targetNames: repo/abc,another-repo/xyz targetTypes: repository,container targetVariants: - targetName: Rerum eos omnis accusamus fuga commodi. targetType: repository targetVariantName: Hic dolor. - targetName: Rerum eos omnis accusamus fuga commodi. targetType: repository targetVariantName: Hic dolor. - targetName: Rerum eos omnis accusamus fuga commodi. targetType: repository targetVariantName: Hic dolor. schema: $ref: '#/components/schemas/AllIssuesListRequestBody' required: true responses: '200': content: application/json: example: hasRules: true issues: - aiTriaged: LikelyFP epssLastModified: '2025-05-01' epssPercentile: 0.15 epssScore: 0.035 exemptionExpiration: 1651578240 exemptionId: abcdef1234567890ghijkl exemptionStatus: Pending exploitability: 'yes' id: abcdef1234567890ghijkl issueType: Quis in qui accusantium. lastDetected: 1634836529 numOccurrences: 12 numTargetsImpacted: 2 overrides: - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname reachability: reachable severityCode: High status: Remediated title: 'Semgrep Finding: generic.secrets.security.detected-bcrypt-hash.detected-bcrypt-hash' - aiTriaged: LikelyFP epssLastModified: '2025-05-01' epssPercentile: 0.15 epssScore: 0.035 exemptionExpiration: 1651578240 exemptionId: abcdef1234567890ghijkl exemptionStatus: Pending exploitability: 'yes' id: abcdef1234567890ghijkl issueType: Quis in qui accusantium. lastDetected: 1634836529 numOccurrences: 12 numTargetsImpacted: 2 overrides: - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname reachability: reachable severityCode: High status: Remediated title: 'Semgrep Finding: generic.secrets.security.detected-bcrypt-hash.detected-bcrypt-hash' - aiTriaged: LikelyFP epssLastModified: '2025-05-01' epssPercentile: 0.15 epssScore: 0.035 exemptionExpiration: 1651578240 exemptionId: abcdef1234567890ghijkl exemptionStatus: Pending exploitability: 'yes' id: abcdef1234567890ghijkl issueType: Quis in qui accusantium. lastDetected: 1634836529 numOccurrences: 12 numTargetsImpacted: 2 overrides: - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname - created: 1651578240 fieldName: severityCode impactedTargetId: target1111111111111111 originalFieldValue: Low overrideFieldValue: Low overrideId: override1234 reason: Waiting on upstream bug fix requesterEmail: user@harness.io requesterId: user111111111111111111 requesterName: firstname lastname reachability: reachable severityCode: High status: Remediated title: 'Semgrep Finding: generic.secrets.security.detected-bcrypt-hash.detected-bcrypt-hash' pagination: link: '' page: 4 pageSize: 20 totalItems: 230 totalPages: 12 schema: $ref: '#/components/schemas/AllIssuesListResultV2' description: OK response. '400': content: application/json: example: message: 'Bad Request: accountId parameter is required' status: 400 schema: $ref: '#/components/schemas/NotFound' description: 'BadRequest: Bad Request response.' '401': content: application/json: example: message: Unauthorized status: 401 schema: $ref: '#/components/schemas/NotFound' description: 'Unauthorized: Unauthorized response.' '403': content: application/json: example: message: Forbidden status: 403 schema: $ref: '#/components/schemas/NotFound' description: 'Forbidden: Forbidden response.' '404': content: application/json: example: message: Not Found status: 404 schema: $ref: '#/components/schemas/NotFound' description: 'NotFound: Not Found response.' '429': content: application/json: example: message: Too Many Requests status: 429 schema: $ref: '#/components/schemas/NotFound' description: 'TooManyRequests: Too Many Requests response.' '500': content: application/json: example: message: Internal Server Error status: 500 schema: $ref: '#/components/schemas/NotFound' description: 'InternalServerError: Internal Server Error response.' security: - jwt_header_Authorization: - sto_issue_view summary: List of issues for selected targets and variants tags: - STO Data Frontend /sto/api/v2/sto-data-frontend/artifact-scan-summary: x-internal: true post: description: Returns counts of active Security Issues for one or more Pipeline Executions per scanner operationId: STO Data Frontend#ExecutionArtifactScanSummary parameters: - allowEmptyValue: true description: Harness Account ID example: abcdef1234567890ghijkl in: query name: accountId required: true schema: description: Harness Account ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ type: string - allowEmptyValue: true description: Harness Organization ID example: example_org in: query name: orgId required: true schema: description: Harness Organization ID example: example_org maxLength: 128 pattern: ^[A-Za-z_][A-Za-z0-9_]*$ type: string - allowEmptyValue: true description: Harness Project ID example: example_project in: query name: projectId required: true schema: description: Harness Project ID example: example_project maxLength: 128 pattern: ^[A-Za-z_][A-Za-z0-9_]*$ type: string requestBody: content: application/json: example: artifactFingerprints: - avq - ute - soc targetVariants: - targetName: Rerum eos omnis accusamus fuga commodi. targetType: repository targetVariantName: Hic dolor. - targetName: Rerum eos omnis accusamus fuga commodi. targetType: repository targetVariantName: Hic dolor. - targetName: Rerum eos omnis accusamus fuga commodi. targetType: repository targetVariantName: Hic dolor. schema: $ref: '#/components/schemas/ExecutionArtifactSummaryRequestBody' required: true responses: '200': content: application/json: example: - artifactFingerprint: tta executionId: abcdef1234567890ghijkl lastScanned: 1634836529 pipelineId: example_pipeline scanners: - critical: 1 high: 3 ignored: 1 info: 11 low: 39 medium: 17 scanner: Semgrep - critical: 1 high: 3 ignored: 1 info: 11 low: 39 medium: 17 scanner: Semgrep - critical: 1 high: 3 ignored: 1 info: 11 low: 39 medium: 17 scanner: Semgrep targetId: abcdef1234567890ghijkl targetName: NodeGoat targetVariantId: abcdef1234567890ghijkl targetVariantName: NodeGoat type: repository - artifactFingerprint: tta executionId: abcdef1234567890ghijkl lastScanned: 1634836529 pipelineId: example_pipeline scanners: - critical: 1 high: 3 ignored: 1 info: 11 low: 39 medium: 17 scanner: Semgrep - critical: 1 high: 3 ignored: 1 info: 11 low: 39 medium: 17 scanner: Semgrep - critical: 1 high: 3 ignored: 1 info: 11 low: 39 medium: 17 scanner: Semgrep targetId: abcdef1234567890ghijkl targetName: NodeGoat targetVariantId: abcdef1234567890ghijkl targetVariantName: NodeGoat type: repository schema: example: - artifactFingerprint: tta executionId: abcdef1234567890ghijkl lastScanned: 1634836529 pipelineId: example_pipeline scanners: - critical: 1 high: 3 ignored: 1 info: 11 low: 39 medium: 17 scanner: Semgrep - critical: 1 high: 3 ignored: 1 info: 11 low: 39 medium: 17 scanner: Semgrep - critical: 1 high: 3 ignored: 1 info: 11 low: 39 medium: 17 scanner: Semgrep targetId: abcdef1234567890ghijkl targetName: NodeGoat targetVariantId: abcdef1234567890ghijkl targetVariantName: NodeGoat type: repository - artifactFingerprint: tta executionId: abcdef1234567890ghijkl lastScanned: 1634836529 pipelineId: example_pipeline scanners: - critical: 1 high: 3 ignored: 1 info: 11 low: 39 medium: 17 scanner: Semgrep - critical: 1 high: 3 ignored: 1 info: 11 low: 39 medium: 17 scanner: Semgrep - critical: 1 high: 3 ignored: 1 info: 11 low: 39 medium: 17 scanner: Semgrep targetId: abcdef1234567890ghijkl targetName: NodeGoat targetVariantId: abcdef1234567890ghijkl targetVariantName: NodeGoat type: repository - artifactFingerprint: tta executionId: abcdef1234567890ghijkl lastScanned: 1634836529 pipelineId: example_pipeline scanners: - critical: 1 high: 3 ignored: 1 info: 11 low: 39 medium: 17 scanner: Semgrep - critical: 1 high: 3 ignored: 1 info: 11 low: 39 medium: 17 scanner: Semgrep - critical: 1 high: 3 ignored: 1 info: 11 low: 39 medium: 17 scanner: Semgrep targetId: abcdef1234567890ghijkl targetName: NodeGoat targetVariantId: abcdef1234567890ghijkl targetVariantName: NodeGoat type: repository items: $ref: '#/components/schemas/ScanIssueCountsWithExecutionInfo' type: array description: OK response. '400': content: application/json: example: message: 'Bad Request: accountId parameter is required' status: 400 schema: $ref: '#/components/schemas/NotFound' description: 'BadRequest: Bad Request response.' '401': content: application/json: example: message: Unauthorized status: 401 schema: $ref: '#/components/schemas/NotFound' description: 'Unauthorized: Unauthorized response.' '403': content: application/json: example: message: Forbidden status: 403 schema: $ref: '#/components/schemas/NotFound' description: 'Forbidden: Forbidden response.' '404': content: application/json: example: message: Not Found status: 404 schema: $ref: '#/components/schemas/NotFound' description: 'NotFound: Not Found response.' '429': content: application/json: example: message: Too Many Requests status: 429 schema: $ref: '#/components/schemas/NotFound' description: 'TooManyRequests: Too Many Requests response.' '500': content: application/json: example: message: Internal Server Error status: 500 schema: $ref: '#/components/schemas/NotFound' description: 'InternalServerError: Internal Server Error response.' security: - jwt_header_Authorization: - sto_issue_view tags: - STO Data Frontend summary: STO data Frontend#Execution artifact scan summary x-summary-source: derived /sto/api/v2/sto-data-frontend/artifact-summary: x-internal: true post: description: Returns counts of active Security Issues for one or more Pipeline Executions operationId: STO Data Frontend#ExecutionArtifactSummary parameters: - allowEmptyValue: true description: Harness Account ID example: abcdef1234567890ghijkl in: query name: accountId required: true schema: description: Harness Account ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ type: string - allowEmptyValue: true description: Harness Organization ID example: example_org in: query name: orgId required: true schema: description: Harness Organization ID example: example_org maxLength: 128 pattern: ^[A-Za-z_][A-Za-z0-9_]*$ type: string - allowEmptyValue: true description: Harness Project ID example: example_project in: query name: projectId required: true schema: description: Harness Project ID example: example_project maxLength: 128 pattern: ^[A-Za-z_][A-Za-z0-9_]*$ type: string requestBody: content: application/json: example: artifactFingerprints: - 9z5 - 4py - '228' targetVariants: - targetName: Rerum eos omnis accusamus fuga commodi. targetType: repository targetVariantName: Hic dolor. - targetName: Rerum eos omnis accusamus fuga commodi. targetType: repository targetVariantName: Hic dolor. - targetName: Rerum eos omnis accusamus fuga commodi. targetType: repository targetVariantName: Hic dolor. schema: $ref: '#/components/schemas/ExecutionArtifactSummaryRequestBody' required: true responses: '200': content: application/json: example: - artifactFingerprint: 65p critical: 1 executionId: abcdef1234567890ghijkl high: 3 ignored: 1 info: 11 lastScanned: 1634836529 low: 39 medium: 17 pipelineId: example_pipeline targetId: abcdef1234567890ghijkl targetName: NodeGoat targetVariantId: abcdef1234567890ghijkl targetVariantName: NodeGoat type: repository - artifactFingerprint: 65p critical: 1 executionId: abcdef1234567890ghijkl high: 3 ignored: 1 info: 11 lastScanned: 1634836529 low: 39 medium: 17 pipelineId: example_pipeline targetId: abcdef1234567890ghijkl targetName: NodeGoat targetVariantId: abcdef1234567890ghijkl targetVariantName: NodeGoat type: repository schema: example: - artifactFingerprint: 65p critical: 1 executionId: abcdef1234567890ghijkl high: 3 ignored: 1 info: 11 lastScanned: 1634836529 low: 39 medium: 17 pipelineId: example_pipeline targetId: abcdef1234567890ghijkl targetName: NodeGoat targetVariantId: abcdef1234567890ghijkl targetVariantName: NodeGoat type: repository - artifactFingerprint: 65p critical: 1 executionId: abcdef1234567890ghijkl high: 3 ignored: 1 info: 11 lastScanned: 1634836529 low: 39 medium: 17 pipelineId: example_pipeline targetId: abcdef1234567890ghijkl targetName: NodeGoat targetVariantId: abcdef1234567890ghijkl targetVariantName: NodeGoat type: repository - artifactFingerprint: 65p critical: 1 executionId: abcdef1234567890ghijkl high: 3 ignored: 1 info: 11 lastScanned: 1634836529 low: 39 medium: 17 pipelineId: example_pipeline targetId: abcdef1234567890ghijkl targetName: NodeGoat targetVariantId: abcdef1234567890ghijkl targetVariantName: NodeGoat type: repository items: $ref: '#/components/schemas/IssueCountsWithExecutionInfo' type: array description: OK response. '400': content: application/json: example: message: 'Bad Request: accountId parameter is required' status: 400 schema: $ref: '#/components/schemas/NotFound' description: 'BadRequest: Bad Request response.' '401': content: application/json: example: message: Unauthorized status: 401 schema: $ref: '#/components/schemas/NotFound' description: 'Unauthorized: Unauthorized response.' '403': content: application/json: example: message: Forbidden status: 403 schema: $ref: '#/components/schemas/NotFound' description: 'Forbidden: Forbidden response.' '404': content: application/json: example: message: Not Found status: 404 schema: $ref: '#/components/schemas/NotFound' description: 'NotFound: Not Found response.' '429': content: application/json: example: message: Too Many Requests status: 429 schema: $ref: '#/components/schemas/NotFound' description: 'TooManyRequests: Too Many Requests response.' '500': content: application/json: example: message: Internal Server Error status: 500 schema: $ref: '#/components/schemas/NotFound' description: 'InternalServerError: Internal Server Error response.' security: - jwt_header_Authorization: - sto_issue_view tags: - STO Data Frontend summary: STO data Frontend#Execution artifact summary x-summary-source: derived /sto/api/v2/sto-data-frontend/execution-summary/{executionId}: x-internal: true get: description: Returns counts of active Security Issues for a specific Pipeline Executions operationId: STO Data Frontend#ExecutionSummary parameters: - allowEmptyValue: true description: Harness Account ID example: abcdef1234567890ghijkl in: query name: accountId required: true schema: description: Harness Account ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ type: string - allowEmptyValue: true description: Harness Organization ID example: example_org in: query name: orgId required: true schema: description: Harness Organization ID example: example_org maxLength: 128 pattern: ^[A-Za-z_][A-Za-z0-9_]*$ type: string - allowEmptyValue: true description: Harness Project ID example: example_project in: query name: projectId required: true schema: description: Harness Project ID example: example_project maxLength: 128 pattern: ^[A-Za-z_][A-Za-z0-9_]*$ type: string - description: Harness pipeline execution ID example: abcdef1234567890ghijkl in: path name: executionId required: true schema: description: Harness pipeline execution ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ type: string responses: '200': content: application/json: example: - artifactFingerprint: 65p critical: 1 executionId: abcdef1234567890ghijkl high: 3 ignored: 1 info: 11 lastScanned: 1634836529 low: 39 medium: 17 pipelineId: example_pipeline targetId: abcdef1234567890ghijkl targetName: NodeGoat targetVariantId: abcdef1234567890ghijkl targetVariantName: NodeGoat type: repository - artifactFingerprint: 65p critical: 1 executionId: abcdef1234567890ghijkl high: 3 ignored: 1 info: 11 lastScanned: 1634836529 low: 39 medium: 17 pipelineId: example_pipeline targetId: abcdef1234567890ghijkl targetName: NodeGoat targetVariantId: abcdef1234567890ghijkl targetVariantName: NodeGoat type: repository schema: example: - artifactFingerprint: 65p critical: 1 executionId: abcdef1234567890ghijkl high: 3 ignored: 1 info: 11 lastScanned: 1634836529 low: 39 medium: 17 pipelineId: example_pipeline targetId: abcdef1234567890ghijkl targetName: NodeGoat targetVariantId: abcdef1234567890ghijkl targetVariantName: NodeGoat type: repository - artifactFingerprint: 65p critical: 1 executionId: abcdef1234567890ghijkl high: 3 ignored: 1 info: 11 lastScanned: 1634836529 low: 39 medium: 17 pipelineId: example_pipeline targetId: abcdef1234567890ghijkl targetName: NodeGoat targetVariantId: abcdef1234567890ghijkl targetVariantName: NodeGoat type: repository - artifactFingerprint: 65p critical: 1 executionId: abcdef1234567890ghijkl high: 3 ignored: 1 info: 11 lastScanned: 1634836529 low: 39 medium: 17 pipelineId: example_pipeline targetId: abcdef1234567890ghijkl targetName: NodeGoat targetVariantId: abcdef1234567890ghijkl targetVariantName: NodeGoat type: repository items: $ref: '#/components/schemas/IssueCountsWithExecutionInfo' type: array description: OK response. '400': content: application/json: example: message: 'Bad Request: accountId parameter is required' status: 400 schema: $ref: '#/components/schemas/NotFound' description: 'BadRequest: Bad Request response.' '401': content: application/json: example: message: Unauthorized status: 401 schema: $ref: '#/components/schemas/NotFound' description: 'Unauthorized: Unauthorized response.' '403': content: application/json: example: message: Forbidden status: 403 schema: $ref: '#/components/schemas/NotFound' description: 'Forbidden: Forbidden response.' '404': content: application/json: example: message: Not Found status: 404 schema: $ref: '#/components/schemas/NotFound' description: 'NotFound: Not Found response.' '429': content: application/json: example: message: Too Many Requests status: 429 schema: $ref: '#/components/schemas/NotFound' description: 'TooManyRequests: Too Many Requests response.' '500': content: application/json: example: message: Internal Server Error status: 500 schema: $ref: '#/components/schemas/NotFound' description: 'InternalServerError: Internal Server Error response.' security: - jwt_header_Authorization: - sto_issue_view tags: - STO Data Frontend summary: STO data Frontend#Execution summary x-summary-source: derived /sto/api/v2/sto-data-frontend/issue-counts: x-internal: true post: description: Returns counts of active Security Issues for one or more Pipeline Executions operationId: STO Data Frontend#ExecutionIssueCounts parameters: - allowEmptyValue: true description: Harness Account ID example: abcdef1234567890ghijkl in: query name: accountId required: true schema: description: Harness Account ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ type: string - allowEmptyValue: true description: Harness Organization ID example: example_org in: query name: orgId required: true schema: description: Harness Organization ID example: example_org maxLength: 128 pattern: ^[A-Za-z_][A-Za-z0-9_]*$ type: string - allowEmptyValue: true description: Harness Project ID example: example_project in: query name: projectId required: true schema: description: Harness Project ID example: example_project maxLength: 128 pattern: ^[A-Za-z_][A-Za-z0-9_]*$ type: string requestBody: content: application/json: example: targetVariants: - targetName: Voluptatem dolor ea ut doloremque deserunt. targetType: repository targetVariantName: Consequuntur minus asperiores facere. - targetName: Voluptatem dolor ea ut doloremque deserunt. targetType: repository targetVariantName: Consequuntur minus asperiores facere. - targetName: Voluptatem dolor ea ut doloremque deserunt. targetType: repository targetVariantName: Consequuntur minus asperiores facere. schema: $ref: '#/components/schemas/ExecutionIssueCountsRequestBody' required: true responses: '200': content: application/json: example: Ipsam qui voluptatibus est enim vel tempora.: Aliquid at quos cum officiis corporis nisi.: Consequatur architecto.: artifactFingerprint: 65p critical: 1 executionId: abcdef1234567890ghijkl high: 3 ignored: 1 info: 11 lastScanned: 1634836529 low: 39 medium: 17 pipelineId: example_pipeline targetId: abcdef1234567890ghijkl targetName: NodeGoat targetVariantId: abcdef1234567890ghijkl targetVariantName: NodeGoat type: repository Distinctio et et facere maxime eum.: artifactFingerprint: 65p critical: 1 executionId: abcdef1234567890ghijkl high: 3 ignored: 1 info: 11 lastScanned: 1634836529 low: 39 medium: 17 pipelineId: example_pipeline targetId: abcdef1234567890ghijkl targetName: NodeGoat targetVariantId: abcdef1234567890ghijkl targetVariantName: NodeGoat type: repository Tenetur ducimus at animi hic molestiae.: artifactFingerprint: 65p critical: 1 executionId: abcdef1234567890ghijkl high: 3 ignored: 1 info: 11 lastScanned: 1634836529 low: 39 medium: 17 pipelineId: example_pipeline targetId: abcdef1234567890ghijkl targetName: NodeGoat targetVariantId: abcdef1234567890ghijkl targetVariantName: NodeGoat type: repository Sed provident quidem dolor.: Dolore autem cupiditate.: artifactFingerprint: 65p critical: 1 executionId: abcdef1234567890ghijkl high: 3 ignored: 1 info: 11 lastScanned: 1634836529 low: 39 medium: 17 pipelineId: example_pipeline targetId: abcdef1234567890ghijkl targetName: NodeGoat targetVariantId: abcdef1234567890ghijkl targetVariantName: NodeGoat type: repository Omnis ea aut ipsam.: artifactFingerprint: 65p critical: 1 executionId: abcdef1234567890ghijkl high: 3 ignored: 1 info: 11 lastScanned: 1634836529 low: 39 medium: 17 pipelineId: example_pipeline targetId: abcdef1234567890ghijkl targetName: NodeGoat targetVariantId: abcdef1234567890ghijkl targetVariantName: NodeGoat type: repository Tempore quia nemo.: Consequatur harum quam perferendis temporibus minus.: artifactFingerprint: 65p critical: 1 executionId: abcdef1234567890ghijkl high: 3 ignored: 1 info: 11 lastScanned: 1634836529 low: 39 medium: 17 pipelineId: example_pipeline targetId: abcdef1234567890ghijkl targetName: NodeGoat targetVariantId: abcdef1234567890ghijkl targetVariantName: NodeGoat type: repository Molestiae quas et quia nam.: artifactFingerprint: 65p critical: 1 executionId: abcdef1234567890ghijkl high: 3 ignored: 1 info: 11 lastScanned: 1634836529 low: 39 medium: 17 pipelineId: example_pipeline targetId: abcdef1234567890ghijkl targetName: NodeGoat targetVariantId: abcdef1234567890ghijkl targetVariantName: NodeGoat type: repository Vero tempora fugiat dolore.: Hic velit.: Nulla ea qui saepe quos tempora.: artifactFingerprint: 65p critical: 1 executionId: abcdef1234567890ghijkl high: 3 ignored: 1 info: 11 lastScanned: 1634836529 low: 39 medium: 17 pipelineId: example_pipeline targetId: abcdef1234567890ghijkl targetName: NodeGoat targetVariantId: abcdef1234567890ghijkl targetVariantName: NodeGoat type: repository Optio ab.: Deserunt est.: artifactFingerprint: 65p critical: 1 executionId: abcdef1234567890ghijkl high: 3 ignored: 1 info: 11 lastScanned: 1634836529 low: 39 medium: 17 pipelineId: example_pipeline targetId: abcdef1234567890ghijkl targetName: NodeGoat targetVariantId: abcdef1234567890ghijkl targetVariantName: NodeGoat type: repository Id et laborum.: artifactFingerprint: 65p critical: 1 executionId: abcdef1234567890ghijkl high: 3 ignored: 1 info: 11 lastScanned: 1634836529 low: 39 medium: 17 pipelineId: example_pipeline targetId: abcdef1234567890ghijkl targetName: NodeGoat targetVariantId: abcdef1234567890ghijkl targetVariantName: NodeGoat type: repository Voluptates alias.: artifactFingerprint: 65p critical: 1 executionId: abcdef1234567890ghijkl high: 3 ignored: 1 info: 11 lastScanned: 1634836529 low: 39 medium: 17 pipelineId: example_pipeline targetId: abcdef1234567890ghijkl targetName: NodeGoat targetVariantId: abcdef1234567890ghijkl targetVariantName: NodeGoat type: repository schema: additionalProperties: additionalProperties: additionalProperties: $ref: '#/components/schemas/IssueCountsWithExecutionInfo' example: Fugit quo delectus in.: artifactFingerprint: 65p critical: 1 executionId: abcdef1234567890ghijkl high: 3 ignored: 1 info: 11 lastScanned: 1634836529 low: 39 medium: 17 pipelineId: example_pipeline targetId: abcdef1234567890ghijkl targetName: NodeGoat targetVariantId: abcdef1234567890ghijkl targetVariantName: NodeGoat type: repository Laboriosam id repudiandae sed.: artifactFingerprint: 65p critical: 1 executionId: abcdef1234567890ghijkl high: 3 ignored: 1 info: 11 lastScanned: 1634836529 low: 39 medium: 17 pipelineId: example_pipeline targetId: abcdef1234567890ghijkl targetName: NodeGoat targetVariantId: abcdef1234567890ghijkl targetVariantName: NodeGoat type: repository type: object example: Et ullam non rerum maxime.: Et eveniet.: artifactFingerprint: 65p critical: 1 executionId: abcdef1234567890ghijkl high: 3 ignored: 1 info: 11 lastScanned: 1634836529 low: 39 medium: 17 pipelineId: example_pipeline targetId: abcdef1234567890ghijkl targetName: NodeGoat targetVariantId: abcdef1234567890ghijkl targetVariantName: NodeGoat type: repository Fugit dolorum unde voluptate consequatur vel sint.: artifactFingerprint: 65p critical: 1 executionId: abcdef1234567890ghijkl high: 3 ignored: 1 info: 11 lastScanned: 1634836529 low: 39 medium: 17 pipelineId: example_pipeline targetId: abcdef1234567890ghijkl targetName: NodeGoat targetVariantId: abcdef1234567890ghijkl targetVariantName: NodeGoat type: repository Officia nulla est fugiat accusamus illum.: Laboriosam est ut rerum possimus soluta.: artifactFingerprint: 65p critical: 1 executionId: abcdef1234567890ghijkl high: 3 ignored: 1 info: 11 lastScanned: 1634836529 low: 39 medium: 17 pipelineId: example_pipeline targetId: abcdef1234567890ghijkl targetName: NodeGoat targetVariantId: abcdef1234567890ghijkl targetVariantName: NodeGoat type: repository Porro quam.: Ea facere tempore et aut.: artifactFingerprint: 65p critical: 1 executionId: abcdef1234567890ghijkl high: 3 ignored: 1 info: 11 lastScanned: 1634836529 low: 39 medium: 17 pipelineId: example_pipeline targetId: abcdef1234567890ghijkl targetName: NodeGoat targetVariantId: abcdef1234567890ghijkl targetVariantName: NodeGoat type: repository Quam accusantium occaecati quod aperiam et.: artifactFingerprint: 65p critical: 1 executionId: abcdef1234567890ghijkl high: 3 ignored: 1 info: 11 lastScanned: 1634836529 low: 39 medium: 17 pipelineId: example_pipeline targetId: abcdef1234567890ghijkl targetName: NodeGoat targetVariantId: abcdef1234567890ghijkl targetVariantName: NodeGoat type: repository type: object example: Animi sint ut hic.: Quae est assumenda minima.: Aut enim molestiae.: artifactFingerprint: 65p critical: 1 executionId: abcdef1234567890ghijkl high: 3 ignored: 1 info: 11 lastScanned: 1634836529 low: 39 medium: 17 pipelineId: example_pipeline targetId: abcdef1234567890ghijkl targetName: NodeGoat targetVariantId: abcdef1234567890ghijkl targetVariantName: NodeGoat type: repository Dolorem reiciendis voluptatem nihil et quibusdam dolores.: artifactFingerprint: 65p critical: 1 executionId: abcdef1234567890ghijkl high: 3 ignored: 1 info: 11 lastScanned: 1634836529 low: 39 medium: 17 pipelineId: example_pipeline targetId: abcdef1234567890ghijkl targetName: NodeGoat targetVariantId: abcdef1234567890ghijkl targetVariantName: NodeGoat type: repository Incidunt harum quas deleniti quis commodi ipsum.: artifactFingerprint: 65p critical: 1 executionId: abcdef1234567890ghijkl high: 3 ignored: 1 info: 11 lastScanned: 1634836529 low: 39 medium: 17 pipelineId: example_pipeline targetId: abcdef1234567890ghijkl targetName: NodeGoat targetVariantId: abcdef1234567890ghijkl targetVariantName: NodeGoat type: repository Et voluptas quam.: Omnis placeat.: Error ratione qui.: artifactFingerprint: 65p critical: 1 executionId: abcdef1234567890ghijkl high: 3 ignored: 1 info: 11 lastScanned: 1634836529 low: 39 medium: 17 pipelineId: example_pipeline targetId: abcdef1234567890ghijkl targetName: NodeGoat targetVariantId: abcdef1234567890ghijkl targetVariantName: NodeGoat type: repository Minima soluta.: artifactFingerprint: 65p critical: 1 executionId: abcdef1234567890ghijkl high: 3 ignored: 1 info: 11 lastScanned: 1634836529 low: 39 medium: 17 pipelineId: example_pipeline targetId: abcdef1234567890ghijkl targetName: NodeGoat targetVariantId: abcdef1234567890ghijkl targetVariantName: NodeGoat type: repository Rerum ut ut unde non.: Nisi voluptatem vitae exercitationem.: artifactFingerprint: 65p critical: 1 executionId: abcdef1234567890ghijkl high: 3 ignored: 1 info: 11 lastScanned: 1634836529 low: 39 medium: 17 pipelineId: example_pipeline targetId: abcdef1234567890ghijkl targetName: NodeGoat targetVariantId: abcdef1234567890ghijkl targetVariantName: NodeGoat type: repository type: object description: OK response. '400': content: application/json: example: message: 'Bad Request: accountId parameter is required' status: 400 schema: $ref: '#/components/schemas/NotFound' description: 'BadRequest: Bad Request response.' '401': content: application/json: example: message: Unauthorized status: 401 schema: $ref: '#/components/schemas/NotFound' description: 'Unauthorized: Unauthorized response.' '403': content: application/json: example: message: Forbidden status: 403 schema: $ref: '#/components/schemas/NotFound' description: 'Forbidden: Forbidden response.' '404': content: application/json: example: message: Not Found status: 404 schema: $ref: '#/components/schemas/NotFound' description: 'NotFound: Not Found response.' '429': content: application/json: example: message: Too Many Requests status: 429 schema: $ref: '#/components/schemas/NotFound' description: 'TooManyRequests: Too Many Requests response.' '500': content: application/json: example: message: Internal Server Error status: 500 schema: $ref: '#/components/schemas/NotFound' description: 'InternalServerError: Internal Server Error response.' security: - jwt_header_Authorization: - sto_issue_view tags: - STO Data Frontend summary: STO data Frontend#Execution issue counts x-summary-source: derived components: schemas: TargetAndVariantName: type: object properties: targetName: type: string description: Target name example: Id dolorem ut et ducimus veritatis nobis. targetType: type: string description: Type of target example: repository enum: - container - repository - instance - configuration targetVariantName: type: string description: Variant name example: Rerum et tempore neque corporis exercitationem. example: targetName: Porro voluptatem ab. targetType: repository targetVariantName: Ut nulla consequatur. FrontendIssueCounts: type: object properties: active: type: integer description: The total of active Issues example: 150 format: int32 critical: type: integer description: The number of Critical-severity Issues example: 1 format: int32 high: type: integer description: The number of High-severity Issues example: 3 format: int32 ignored: type: integer description: The number of Issues ignored due to Exemptions, and therefore not included in other counts example: 1 format: int32 info: type: integer description: The number of Informational Issues example: 11 format: int32 low: type: integer description: The number of Low-severity Issues example: 39 format: int32 medium: type: integer description: The number of Medium-severity Issues example: 17 format: int32 example: active: 150 critical: 1 high: 3 ignored: 1 info: 11 low: 39 medium: 17 required: - active - critical - high - medium - low - info ScanIssueCountsWithExecutionInfo: type: object properties: artifactFingerprint: type: string description: Fingerprint which identifies an artifact example: azw maxLength: 64 executionId: type: string description: Harness Execution ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ lastScanned: type: integer description: Timestamp at which the target variant was last scanned example: 1634836529 format: int64 pipelineId: type: string description: Harness Pipeline ID example: example_pipeline pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 scanners: type: array items: $ref: '#/components/schemas/MinimalIssueCountsPerScanner' description: List of security issue counts grouped by scanner example: - critical: 1 high: 3 ignored: 1 info: 11 low: 39 medium: 17 scanner: Semgrep - critical: 1 high: 3 ignored: 1 info: 11 low: 39 medium: 17 scanner: Semgrep targetId: type: string description: Associated Target ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ targetName: type: string description: Name of the Scan Target example: NodeGoat targetVariantId: type: string description: Associated Target Variant ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ targetVariantName: type: string description: Name of the Scan Target example: NodeGoat type: type: string description: Scan Target's type example: repository enum: - container - repository - instance - configuration description: The count of Security Issues, by severity code, for a given Harness Pipeline Execution along with this execution info example: artifactFingerprint: e7g executionId: abcdef1234567890ghijkl lastScanned: 1634836529 pipelineId: example_pipeline scanners: - critical: 1 high: 3 ignored: 1 info: 11 low: 39 medium: 17 scanner: Semgrep - critical: 1 high: 3 ignored: 1 info: 11 low: 39 medium: 17 scanner: Semgrep - critical: 1 high: 3 ignored: 1 info: 11 low: 39 medium: 17 scanner: Semgrep - critical: 1 high: 3 ignored: 1 info: 11 low: 39 medium: 17 scanner: Semgrep targetId: abcdef1234567890ghijkl targetName: NodeGoat targetVariantId: abcdef1234567890ghijkl targetVariantName: NodeGoat type: repository required: - scanners - targetId - targetVariantId - type - targetName - targetVariantName - executionId - pipelineId - lastScanned StoPagination: type: object properties: link: type: string description: Link-based paging example: '' page: type: integer description: Page number (starting from 0) example: 4 format: int64 pageSize: type: integer description: Requested page size example: 20 format: int64 totalItems: type: integer description: Total results available example: 230 format: int64 totalPages: type: integer description: Total pages available example: 12 format: int64 example: link: '' page: 4 pageSize: 20 totalItems: 230 totalPages: 12 required: - page - pageSize - totalPages - totalItems MinimalIssueCountsPerScanner: type: object properties: critical: type: integer description: The number of Critical-severity Issues example: 1 format: int32 high: type: integer description: The number of High-severity Issues example: 3 format: int32 ignored: type: integer description: The number of Issues ignored due to Exemptions, and therefore not included in other counts example: 1 format: int32 info: type: integer description: The number of Informational Issues example: 11 format: int32 low: type: integer description: The number of Low-severity Issues example: 39 format: int32 medium: type: integer description: The number of Medium-severity Issues example: 17 format: int32 scanner: type: string description: Name of the scanner that produced these issues example: Semgrep description: The count of Security Issues, by severity code, for a given Harness Pipeline Execution example: critical: 1 high: 3 ignored: 1 info: 11 low: 39 medium: 17 scanner: Semgrep required: - critical - high - medium - low - info - scanner AllIssuesListRequestBody: type: object properties: artifactFingerprints: type: array items: type: string example: rj5 maxLength: 64 description: Artifact fingerprints for lookup example: - fgy - pyt - mpi maxItems: 100 issueTypes: type: string example: SAST pattern: ^(SAST|DAST|SCA|IAC|SECRET|MISCONFIG|BUG_SMELLS|CODE_SMELLS|CODE_COVERAGE|EXTERNAL_POLICY)(,SAST|,DAST|,SCA|,IAC|,SECRET|,MISCONFIG|,BUG_SMELLS|,CODE_SMELLS|,CODE_COVERAGE|,EXTERNAL_POLICY)*$ page: type: integer description: Page number to fetch (starting from 0) default: 0 example: 4 format: int64 minimum: 0 pageSize: type: integer description: Number of results per page default: 30 example: 50 format: int64 minimum: 1 maximum: 100 scanTools: type: string example: OWASP,Aqua Trivy,Snyk pattern: ^[a-zA-Z0-9](?:[a-zA-Z0-9 ._-]*[a-zA-Z0-9])?(?:,[a-zA-Z0-9](?:[a-zA-Z0-9 ._-]*[a-zA-Z0-9])?)*$ search: type: string example: CWE-123 maxLength: 256 severityCodes: type: string example: Critical,High,Medium pattern: ^(Critical|High|Medium|Low|Info)(,Critical|,High|,Medium|,Low|,Info)*$ targetNames: type: string example: repo/abc,another-repo/xyz pattern: ^([a-zA-Z0-9/_-]+)(,[a-zA-Z0-9/_-]+)*$ targetTypes: type: string example: repository,container pattern: ^(repository|container|instance|configuration)(,repository|,container|,instance|,configuration)*$ targetVariants: type: array items: $ref: '#/components/schemas/TargetAndVariantNameRequired' description: Target-variant pairs for lookup example: - targetName: Rerum eos omnis accusamus fuga commodi. targetType: repository targetVariantName: Hic dolor. - targetName: Rerum eos omnis accusamus fuga commodi. targetType: repository targetVariantName: Hic dolor. - targetName: Rerum eos omnis accusamus fuga commodi. targetType: repository targetVariantName: Hic dolor. maxItems: 100 example: artifactFingerprints: - h4i - qiv - 2hf issueTypes: SAST page: 4 pageSize: 50 scanTools: OWASP,Aqua Trivy,Snyk search: CWE-123 severityCodes: Critical,High,Medium targetNames: repo/abc,another-repo/xyz targetTypes: repository,container targetVariants: - targetName: Rerum eos omnis accusamus fuga commodi. targetType: repository targetVariantName: Hic dolor. - targetName: Rerum eos omnis accusamus fuga commodi. targetType: repository targetVariantName: Hic dolor. - targetName: Rerum eos omnis accusamus fuga commodi. targetType: repository targetVariantName: Hic dolor. AllIssuesListResultV2: type: object properties: counts: $ref: '#/components/schemas/FrontendIssueCounts' issues: type: array items: $ref: '#/components/schemas/AllIssueSummaryV2' description: Issues related to the latest scans of specified target and variant example: - id: abcdef1234567890ghijkl issueDescription: Et quo consectetur eius. issueType: Esse eos. lastDetected: 1634836529 scanner: Rerum magnam voluptatem assumenda molestiae. severityCode: High targetName: NodeGoat targetVariantName: NodeGoat title: 'Semgrep Finding: generic.secrets.security.detected-bcrypt-hash.detected-bcrypt-hash' - id: abcdef1234567890ghijkl issueDescription: Et quo consectetur eius. issueType: Esse eos. lastDetected: 1634836529 scanner: Rerum magnam voluptatem assumenda molestiae. severityCode: High targetName: NodeGoat targetVariantName: NodeGoat title: 'Semgrep Finding: generic.secrets.security.detected-bcrypt-hash.detected-bcrypt-hash' pagination: $ref: '#/components/schemas/StoPagination' example: counts: active: 150 critical: 1 high: 3 ignored: 1 info: 11 low: 39 medium: 17 issues: - id: abcdef1234567890ghijkl issueDescription: Et quo consectetur eius. issueType: Esse eos. lastDetected: 1634836529 scanner: Rerum magnam voluptatem assumenda molestiae. severityCode: High targetName: NodeGoat targetVariantName: NodeGoat title: 'Semgrep Finding: generic.secrets.security.detected-bcrypt-hash.detected-bcrypt-hash' - id: abcdef1234567890ghijkl issueDescription: Et quo consectetur eius. issueType: Esse eos. lastDetected: 1634836529 scanner: Rerum magnam voluptatem assumenda molestiae. severityCode: High targetName: NodeGoat targetVariantName: NodeGoat title: 'Semgrep Finding: generic.secrets.security.detected-bcrypt-hash.detected-bcrypt-hash' pagination: link: '' page: 4 pageSize: 20 totalItems: 230 totalPages: 12 required: - issues - pagination NotFound: type: object properties: message: type: string example: Not Found status: type: integer default: 404 example: 404 format: int64 example: message: Not Found status: 404 required: - message AllIssuesFiltersResultV2: type: object properties: issueTypes: type: array items: type: string example: Optio dolores. description: Distinct issue types present in the matching issues example: - SAST - SCA scanners: type: array items: type: string example: Sit minima commodi sed consequuntur ipsam. description: Distinct scanner (product) names present in the matching issues example: - semgrep - trivy severities: type: array items: type: string example: Rerum eius nesciunt veniam officiis quia eum. description: Distinct severity codes present in the matching issues example: - Critical - High - Medium targets: type: array items: type: string example: Minus temporibus debitis dolores blanditiis. description: Distinct target names present in the matching issues example: - NodeGoat - juice-shop description: Distinct filter values available for the issues produced by the requested target and variant combinations example: issueTypes: - SAST - SCA scanners: - semgrep - trivy severities: - Critical - High - Medium targets: - NodeGoat - juice-shop required: - severities - scanners - targets - issueTypes ExecutionArtifactSummaryRequestBody: type: object properties: artifactFingerprints: type: array items: type: string example: guo maxLength: 64 description: Artifact fingerprints for lookup example: - ooh - itg - 7es maxItems: 100 targetVariants: type: array items: $ref: '#/components/schemas/TargetAndVariantNameRequired' description: Target-variant pairs for lookup example: - targetName: Rerum eos omnis accusamus fuga commodi. targetType: repository targetVariantName: Hic dolor. - targetName: Rerum eos omnis accusamus fuga commodi. targetType: repository targetVariantName: Hic dolor. - targetName: Rerum eos omnis accusamus fuga commodi. targetType: repository targetVariantName: Hic dolor. maxItems: 100 example: artifactFingerprints: - 7oa - ujm - lxv targetVariants: - targetName: Rerum eos omnis accusamus fuga commodi. targetType: repository targetVariantName: Hic dolor. - targetName: Rerum eos omnis accusamus fuga commodi. targetType: repository targetVariantName: Hic dolor. - targetName: Rerum eos omnis accusamus fuga commodi. targetType: repository targetVariantName: Hic dolor. IssueCountsWithExecutionInfo: type: object properties: artifactFingerprint: type: string description: Fingerprint which identifies an artifact example: xpo maxLength: 64 critical: type: integer description: The number of Critical-severity Issues example: 1 format: int32 executionId: type: string description: Harness Execution ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ high: type: integer description: The number of High-severity Issues example: 3 format: int32 ignored: type: integer description: The number of Issues ignored due to Exemptions, and therefore not included in other counts example: 1 format: int32 info: type: integer description: The number of Informational Issues example: 11 format: int32 lastScanned: type: integer description: Timestamp at which the target variant was last scanned example: 1634836529 format: int64 low: type: integer description: The number of Low-severity Issues example: 39 format: int32 medium: type: integer description: The number of Medium-severity Issues example: 17 format: int32 pipelineId: type: string description: Harness Pipeline ID example: example_pipeline pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 targetId: type: string description: Associated Target ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ targetName: type: string description: Name of the Scan Target example: NodeGoat targetVariantId: type: string description: Associated Target Variant ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ targetVariantName: type: string description: Name of the Scan Target example: NodeGoat type: type: string description: Scan Target's type example: repository enum: - container - repository - instance - configuration description: The count of Security Issues, by severity code, for a given Harness Pipeline Execution along with this execution info example: artifactFingerprint: ms0 critical: 1 executionId: abcdef1234567890ghijkl high: 3 ignored: 1 info: 11 lastScanned: 1634836529 low: 39 medium: 17 pipelineId: example_pipeline targetId: abcdef1234567890ghijkl targetName: NodeGoat targetVariantId: abcdef1234567890ghijkl targetVariantName: NodeGoat type: repository required: - critical - high - medium - low - info - targetId - targetVariantId - type - targetName - targetVariantName - executionId - pipelineId - lastScanned TargetAndVariantNameRequired: type: object properties: targetName: type: string description: Target name example: Impedit consectetur est. targetType: type: string description: Type of target example: repository enum: - container - repository - instance - configuration targetVariantName: type: string description: Variant name example: Commodi veniam. example: targetName: Modi dolorem fuga officiis. targetType: repository targetVariantName: Exercitationem distinctio est possimus. required: - targetName - targetVariantName ExecutionIssueCountsRequestBody: type: object properties: targetVariants: type: array items: $ref: '#/components/schemas/TargetAndVariantName' description: Target-variant pairs for lookup example: - targetName: Voluptatem dolor ea ut doloremque deserunt. targetType: repository targetVariantName: Consequuntur minus asperiores facere. - targetName: Voluptatem dolor ea ut doloremque deserunt. targetType: repository targetVariantName: Consequuntur minus asperiores facere. - targetName: Voluptatem dolor ea ut doloremque deserunt. targetType: repository targetVariantName: Consequuntur minus asperiores facere. maxItems: 100 example: targetVariants: - targetName: Voluptatem dolor ea ut doloremque deserunt. targetType: repository targetVariantName: Consequuntur minus asperiores facere. - targetName: Voluptatem dolor ea ut doloremque deserunt. targetType: repository targetVariantName: Consequuntur minus asperiores facere. - targetName: Voluptatem dolor ea ut doloremque deserunt. targetType: repository targetVariantName: Consequuntur minus asperiores facere. AllIssueSummaryV2: type: object properties: id: type: string description: Resource identifier example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ issueDescription: type: string description: Issue Description example: Officiis ut dignissimos veniam. issueType: type: string description: Issue Type example: Itaque occaecati voluptatum culpa adipisci. lastDetected: type: integer description: Timestamp of the last detection of this issue example: 1634836529 format: int64 scanner: type: string description: Scanner example: Quibusdam non est est velit eveniet laboriosam. severityCode: type: string description: Severity code example: High enum: - Critical - High - Medium - Low - Info - Unassigned targetName: type: string description: Name of the Scan Target example: NodeGoat targetVariantName: type: string description: Name of the Scan Target example: NodeGoat title: type: string description: Title of the Security Issue example: 'Semgrep Finding: generic.secrets.security.detected-bcrypt-hash.detected-bcrypt-hash' maxLength: 128 description: All issue summary V2 example: id: abcdef1234567890ghijkl issueDescription: Debitis quia dolorem ut quis sint ducimus. issueType: Neque debitis. lastDetected: 1634836529 scanner: Est ipsa. severityCode: High targetName: NodeGoat targetVariantName: NodeGoat title: 'Semgrep Finding: generic.secrets.security.detected-bcrypt-hash.detected-bcrypt-hash' required: - id - severityCode - issueDescription - issueType - scanner - targetName - targetVariantName securitySchemes: x-api-key: name: x-api-key type: apiKey in: header description: API key is a token provided while making the API calls. This is used to authenticate the client at the exposed endpoint. externalDocs: description: Find out more about Swagger url: http://swagger.io x-stoplight: id: oc91t4vrfnjyi x-tagGroups: - name: Organizations tags: - Organization - name: Projects tags: - Org Project - Project - name: Secrets tags: - Account Secret - Org Secret - Project Secret - Secrets - name: Connectors tags: - Account Connector - Org Connector - Project Connector - Connectors - GoogleSecretManagerConnector - name: Roles tags: - Account Roles - Organization Roles - Project Roles - Roles - name: Resource Groups tags: - Account Resource Groups - Organization Resource Groups - Project Resource Groups - Filter Resource Groups - Harness Resource Group - Zendesk - name: Role Assignments tags: - Account Role Assignments - Org Role Assignments - Project Role Assignments - Role Assignments - name: Platform tags: - Access Control List - Account Banner - Account Banner - Account Licensed Modules - Account License Type - Account Webhooks - AccountSetting - Accounts - Analyze Account Access Policy - Analyze Organization Access Policy - Analyze Project Access Policy - ApiKey - Audit - AuditFilters - Authentication Settings - Canny - Devops Essentials License Data By Account - EULA - Filter - Harness Resource Type - Invite - IP Allowlist - Nextgen Ldap - Notification Channels - Notification Rules - OIDC - Oidc-Access-Token - Oidc-ID-Token - Org Webhooks - Permissions - Project Webhooks - Secret Managers - Service Account - Setting - SMTP - Source Code Manager - Token - User - User Group - Variables - name: Delegate tags: - Agent mTLS Endpoint Management - Delegate Download Resource - Delegate Group Tags Resource - Delegate Setup Resource - Delegate Token Resource - name: Pipelines tags: - Pipelines - Input Sets - Approvals - Pipeline Execution - Pipeline Dashboard - Pipeline Input Set - Pipeline - Pipeline Execution Details - Pipeline Execute - Pipeline Refresh - Pipeline data retention - Triggers - TriggersEvents - Webhook Triggers - Webhook Event Handler - DryRunPipeline - name: Artifact Registry tags: - Registries - Artifacts - Docker Artifacts - Helm Artifacts - quarantine - Webhooks - Spaces - Replication - Registry V3 - Registries - Registry V3 - Packages - Registry V3 - Versions - Registry V3 - Files - Registry V3 - Metadata - Registry V3 - Firewall - Registry V3 - Transfer - name: Database DevOps tags: - Database Schema - Database Instance - Deployed State - Execution Config - Migration State - name: CD tags: - K8s Release Service Mapping - CustomDeployment - Environments - EnvironmentGroup - Infrastructures - Usage - File Store - Service Dashboard - ServiceOverrides - Rollback - tas - name: Deployment Freeze tags: - Freeze CRUD - Freeze Evaluation - Freeze Schema - name: Services tags: - Account Services - Org Services - Project Services - Services - name: Rancher Infrastructures tags: - Account Rancher Infrastructure - Org Rancher Infrastructure - Project Rancher Infrastructure - name: Templates tags: - Account Template - Org Template - Project Template - Templates - Global Templates - name: GitOps tags: - Agents - Application - Applications - Certificates - Clusters - Dashboard Aggregates - Dashboards - GnuPGP Keys - GPG Keys - Hosts - Project mappings - Projects - Reconciler - Repositories - Repository Certificates - Repository credentials - ValidateHost - name: GitX tags: - GitX Webhooks - Org Gitx Webhooks - Project Gitx Webhooks - name: CACM tags: - Anomalies Ignorelist Rule - Anomalies - BI Dashboards - Budgets - Budget Groups - Cost Categories - Cloud Accounts - K8S Connectors Metadata - Notification Settings v2 - Overview - Data Job Status - Recommendation cost settings - Unit Metric - Anomaly Comments - Cloud and AI cost anomaly details - Cloud and AI cost anomalies v2 - Cost Details - Currency Preferences - External Data Provider - AiEngine - CACM governance cost settings - Governance Enforcement Recommendation APIs - Governance Alert - Governance Overview - Governance Recommendation APIs - RuleEnforcement - Rule Executions - Rule - Rule Sets - Perspectives Folders - Perspective Reports - Perspectives - Cost Category Jira Project Mapping - Recommendations Details - Recommendations - Recommendation Jira - Recommendation Preferences - Recommendation Presets - Recommendation Servicenow - Recommendation Tags - Recommendation Ignore List - AutoStopping Rules - AutoStopping Rules V2 - AutoStopping Load Balancers - AutoStopping Fixed Schedules - AutoStopping Alerts - Commitment Orchestrator Events APIs - name: Feature Flags tags: - API Keys - Feature Flags - Targets - Target Groups - Environment Perspectives - Anomalies - Proxy - Tags - name: SRM tags: - Monitored Services - SLOs dashboard - NG SLOs - SLOs - Downtime - Srm Notification - name: Internal Developer Portal - IDP tags: - Entities - Teams - CatalogCustomProperties - Scores - DataSource - KubernetesDataPoints - AggregationRules - AppConfig - PluginInfo - LayoutProxy - Kinds - LayoutsV3 - LayoutsV4 - name: Environment Management - IDP tags: - Environment - Infrastructure - Instance - name: Custom Dashboards tags: - aida - dashboards - downloads - embed - folders - name: Policy Management tags: - dashboard - examples - policies - evaluate - evaluations - policysets - system - name: Code tags: - repository - status_checks - pullreq - upload - webhook - resource - rules - labels - name: IaCM tags: - usage - approvals - costs - executions - module-registry - workspaces - settings - tf-standard-backend - variables - name: STO tags: - Exemptions - Issues - Scans - Products - Test Targets - Target Variants - name: SEI tags: - Collection categories - Collections - Contributors - DORA - name: Git Sync (deprecated) tags: - Git Branches - Git Full Sync - Git Sync Settings - Git Sync - Git Sync Errors - name: Error Models tags: - Error Response - Governance Metadata - name: Supply Chain Security tags: - integration - PipelineInfraConfig - SBOM - Integration Step Config - Delete Step Config - Delete Repositories - Pipeline Store Config - Evidence Vault [Beta] - name: Release Management tags: - Release Groups - Releases - Orchestration Processes - Orchestration Activities - Orchestration Executions - Conflicts - Freeze - Reports - Uploads - name: Resilience Testing tags: - Actions - Action Templates - Chaos Components - Chaos Hubs - ChaosGuard Conditions - ChaosGuard Rules - DR Tests - Experiments - Experiment Templates - Faults - Fault Templates - Chaos Infrastructure - Health - Network Maps - Onboarding - Probes - Probe Templates - Chaos Recommendations - Risks