openapi: 3.2.0 info: title: Harness Test Targets API version: '1.0' description: The Harness Software Delivery Platform uses OpenAPI Specification v3.0. contact: name: API Support email: contact@harness.io url: https://harness.io/ x-logo: url: https://mma.prnewswire.com/media/779232/Harnes_logo_horizontal.jpg?p=facebook altText: Harness termsOfService: https://harness.io/terms-of-use/ servers: - url: https://app.harness.io description: Harness host URL - url: https://{vanity} description: Vanity URL variables: vanity: default: app.harness.io security: - x-api-key: [] tags: - name: Test Targets description: Access and modify Scan Targets paths: /sto/api/v2/targets: get: tags: - Test Targets description: List a collection of Test Targets operationId: Targets#ListTargets parameters: - name: accountId in: query description: Harness Account ID allowEmptyValue: true required: true schema: type: string description: Harness Account ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ example: abcdef1234567890ghijkl - name: page in: query description: Page number to fetch (starting from 0) allowEmptyValue: true schema: type: integer description: Page number to fetch (starting from 0) default: 0 example: 4 format: int64 minimum: 0 example: 4 - name: pageSize in: query description: Number of results per page allowEmptyValue: true schema: type: integer description: Number of results per page default: 30 example: 50 format: int64 minimum: 1 maximum: 100 example: 50 - name: name in: query description: Resource name allowEmptyValue: true schema: type: string description: Resource name example: NodeGoat example: NodeGoat - name: orgId in: query description: Harness Organization ID allowEmptyValue: true required: true schema: type: string description: Harness Organization ID example: example_org pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 example: example_org - name: projectId in: query description: Harness Project ID allowEmptyValue: true required: true schema: type: string description: Harness Project ID example: example_project pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 example: example_project - name: X-Api-Key in: header description: Harness personal or service access token allowEmptyValue: true schema: type: string description: Harness personal or service access token example: Repellat itaque porro voluptatibus blanditiis dolore. example: Qui laborum. responses: '200': description: OK response. content: application/json: schema: $ref: '#/components/schemas/TargetsListTargetsResponseBody' example: pagination: link: '' page: 4 pageSize: 20 totalItems: 230 totalPages: 12 results: - baselineRegEx: release_.* baselineVariantId: abcdef1234567890ghijkl created: 1651578240 directory: app/src id: abcdef1234567890ghijkl lastModified: 1651578240 name: NodeGoat orgId: example_org projectId: example_project type: repository url: https://github.com/example/repo - baselineRegEx: release_.* baselineVariantId: abcdef1234567890ghijkl created: 1651578240 directory: app/src id: abcdef1234567890ghijkl lastModified: 1651578240 name: NodeGoat orgId: example_org projectId: example_project type: repository url: https://github.com/example/repo '400': description: 'BadRequest: Bad Request response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: 'Bad Request: accountId parameter is required' status: 400 '401': description: 'Unauthorized: Unauthorized response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Unauthorized status: 401 '403': description: 'Forbidden: Forbidden response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Forbidden status: 403 '404': description: 'NotFound: Not Found response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Not Found status: 404 '429': description: 'TooManyRequests: Too Many Requests response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Too Many Requests status: 429 '500': description: 'InternalServerError: Internal Server Error response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Internal Server Error status: 500 security: - X-Api-Key_header_X-Api-Key: [] jwt_header_Authorization: - sto_testtarget_view summary: Targets#List targets x-summary-source: derived post: tags: - Test Targets description: Create a new Test Target operationId: Targets#CreateTarget parameters: - name: accountId in: query description: Harness Account ID allowEmptyValue: true required: true schema: type: string description: Harness Account ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ example: abcdef1234567890ghijkl - name: orgId in: query description: Harness Organization ID allowEmptyValue: true required: true schema: type: string description: Harness Organization ID example: example_org pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 examples: default: summary: default value: example_org - name: projectId in: query description: Harness Project ID allowEmptyValue: true required: true schema: type: string description: Harness Project ID example: example_project pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 examples: default: summary: default value: example_project - name: X-Api-Key in: header description: Harness personal or service access token allowEmptyValue: true schema: type: string description: Harness personal or service access token example: Illum dolor recusandae ipsam. example: Quia et reprehenderit et excepturi expedita. requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/CreateTargetRequestBody' example: baselineRegEx: release_.* baselineVariantId: abcdef1234567890ghijkl directory: app/src name: NodeGoat type: repository url: https://github.com/example/repo responses: '200': description: OK response. content: application/json: schema: $ref: '#/components/schemas/IDResult' example: id: abcdef1234567890ghijkl '400': description: 'BadRequest: Bad Request response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: 'Bad Request: accountId parameter is required' status: 400 '401': description: 'Unauthorized: Unauthorized response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Unauthorized status: 401 '403': description: 'Forbidden: Forbidden response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Forbidden status: 403 '429': description: 'TooManyRequests: Too Many Requests response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Too Many Requests status: 429 '500': description: 'InternalServerError: Internal Server Error response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Internal Server Error status: 500 security: - X-Api-Key_header_X-Api-Key: [] jwt_header_Authorization: - sto_testtarget_edit summary: Targets#Create target x-summary-source: derived /sto/api/v2/targets/{id}: delete: description: Delete an existing Test Target operationId: Targets#DeleteTarget parameters: - allowEmptyValue: true description: Harness Account ID example: abcdef1234567890ghijkl in: query name: accountId required: true schema: description: Harness Account ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ type: string - allowEmptyValue: true description: Harness Organization ID examples: default: summary: default value: example_org in: query name: orgId required: true schema: description: Harness Organization ID example: example_org maxLength: 128 pattern: ^[A-Za-z_][A-Za-z0-9_]*$ type: string - allowEmptyValue: true description: Harness Project ID examples: default: summary: default value: example_project in: query name: projectId required: true schema: description: Harness Project ID example: example_project maxLength: 128 pattern: ^[A-Za-z_][A-Za-z0-9_]*$ type: string - description: The ID of the Test Target to delete example: abcdef1234567890ghijkl in: path name: id required: true schema: description: The ID of the Test Target to delete example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ type: string responses: '204': description: No Content response. '400': content: application/json: example: message: 'Bad Request: accountId parameter is required' status: 400 schema: $ref: '#/components/schemas/NotFound' description: 'BadRequest: Bad Request response.' '401': content: application/json: example: message: Unauthorized status: 401 schema: $ref: '#/components/schemas/NotFound' description: 'Unauthorized: Unauthorized response.' '403': content: application/json: example: message: Forbidden status: 403 schema: $ref: '#/components/schemas/NotFound' description: 'Forbidden: Forbidden response.' '404': content: application/json: example: message: Not Found status: 404 schema: $ref: '#/components/schemas/NotFound' description: 'NotFound: Not Found response.' '429': content: application/json: example: message: Too Many Requests status: 429 schema: $ref: '#/components/schemas/NotFound' description: 'TooManyRequests: Too Many Requests response.' '500': content: application/json: example: message: Internal Server Error status: 500 schema: $ref: '#/components/schemas/NotFound' description: 'InternalServerError: Internal Server Error response.' security: - jwt_header_Authorization: - sto_testtarget_delete tags: - Test Targets x-internal: true summary: Targets#Delete target x-summary-source: derived get: tags: - Test Targets description: Find Test Target by ID operationId: Targets#FindTargetById parameters: - name: accountId in: query description: Harness Account ID allowEmptyValue: true required: true schema: type: string description: Harness Account ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ example: abcdef1234567890ghijkl - name: orgId in: query description: Harness Organization ID allowEmptyValue: true required: true schema: type: string description: Harness Organization ID example: example_org pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 examples: default: summary: default value: example_org - name: projectId in: query description: Harness Project ID allowEmptyValue: true required: true schema: type: string description: Harness Project ID example: example_project pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 examples: default: summary: default value: example_project - name: id in: path description: The ID of the Test Target to retrieve required: true schema: type: string description: The ID of the Test Target to retrieve example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ example: abcdef1234567890ghijkl - name: X-Api-Key in: header description: Harness personal or service access token allowEmptyValue: true schema: type: string description: Harness personal or service access token example: Nesciunt temporibus. example: Et similique facere facilis et voluptatem. responses: '200': description: OK response. content: application/json: schema: $ref: '#/components/schemas/StoTarget' example: baselineRegEx: release_.* baselineVariantId: abcdef1234567890ghijkl created: 1651578240 directory: app/src id: abcdef1234567890ghijkl lastModified: 1651578240 name: NodeGoat orgId: example_org projectId: example_project type: repository url: https://github.com/example/repo '400': description: 'BadRequest: Bad Request response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: 'Bad Request: accountId parameter is required' status: 400 '401': description: 'Unauthorized: Unauthorized response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Unauthorized status: 401 '403': description: 'Forbidden: Forbidden response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Forbidden status: 403 '404': description: 'NotFound: Not Found response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Not Found status: 404 '429': description: 'TooManyRequests: Too Many Requests response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Too Many Requests status: 429 '500': description: 'InternalServerError: Internal Server Error response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Internal Server Error status: 500 security: - X-Api-Key_header_X-Api-Key: [] jwt_header_Authorization: - sto_testtarget_view summary: Targets#Find target by id x-summary-source: derived patch: tags: - Test Targets description: Update only certain fields on an existing Test Target operationId: Targets#PatchTarget parameters: - name: accountId in: query description: Harness Account ID allowEmptyValue: true required: true schema: type: string description: Harness Account ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ example: abcdef1234567890ghijkl - name: orgId in: query description: Harness Organization ID allowEmptyValue: true required: true schema: type: string description: Harness Organization ID example: example_org pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 examples: default: summary: default value: example_org - name: projectId in: query description: Harness Project ID allowEmptyValue: true required: true schema: type: string description: Harness Project ID example: example_project pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 examples: default: summary: default value: example_project - name: id in: path description: The ID of the Test Target to update required: true schema: type: string description: The ID of the Test Target to update example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ example: abcdef1234567890ghijkl - name: X-Api-Key in: header description: Harness personal or service access token allowEmptyValue: true schema: type: string description: Harness personal or service access token example: Veniam repellendus harum. example: Eligendi dolor. requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/PatchTargetRequestBody' example: baselineRegEx: release_.* baselineVariantId: abcdef1234567890ghijkl directory: app/src name: NodeGoat type: repository url: https://github.com/example/repo responses: '200': description: OK response. content: application/json: schema: $ref: '#/components/schemas/StoTarget' example: baselineRegEx: release_.* baselineVariantId: abcdef1234567890ghijkl created: 1651578240 directory: app/src id: abcdef1234567890ghijkl lastModified: 1651578240 name: NodeGoat orgId: example_org projectId: example_project type: repository url: https://github.com/example/repo '400': description: 'BadRequest: Bad Request response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: 'Bad Request: accountId parameter is required' status: 400 '401': description: 'Unauthorized: Unauthorized response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Unauthorized status: 401 '403': description: 'Forbidden: Forbidden response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Forbidden status: 403 '404': description: 'NotFound: Not Found response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Not Found status: 404 '429': description: 'TooManyRequests: Too Many Requests response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Too Many Requests status: 429 '500': description: 'InternalServerError: Internal Server Error response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Internal Server Error status: 500 security: - X-Api-Key_header_X-Api-Key: [] jwt_header_Authorization: - sto_testtarget_edit summary: Targets#Patch target x-summary-source: derived put: tags: - Test Targets description: Update an existing Test Target operationId: Targets#UpdateTarget parameters: - name: accountId in: query description: Harness Account ID allowEmptyValue: true required: true schema: type: string description: Harness Account ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ example: abcdef1234567890ghijkl - name: orgId in: query description: Harness Organization ID allowEmptyValue: true required: true schema: type: string description: Harness Organization ID example: example_org pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 examples: default: summary: default value: example_org - name: projectId in: query description: Harness Project ID allowEmptyValue: true required: true schema: type: string description: Harness Project ID example: example_project pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 examples: default: summary: default value: example_project - name: id in: path description: The ID of the Test Target to update required: true schema: type: string description: The ID of the Test Target to update example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ example: abcdef1234567890ghijkl - name: X-Api-Key in: header description: Harness personal or service access token allowEmptyValue: true schema: type: string description: Harness personal or service access token example: Occaecati nulla sequi odio ea. example: Illo et culpa dolor odit ea in. requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/UpdateTargetRequestBody' example: baselineRegEx: release_.* baselineVariantId: abcdef1234567890ghijkl directory: app/src name: NodeGoat type: repository url: https://github.com/example/repo responses: '200': description: OK response. content: application/json: schema: $ref: '#/components/schemas/StoTarget' example: baselineRegEx: release_.* baselineVariantId: abcdef1234567890ghijkl created: 1651578240 directory: app/src id: abcdef1234567890ghijkl lastModified: 1651578240 name: NodeGoat orgId: example_org projectId: example_project type: repository url: https://github.com/example/repo '400': description: 'BadRequest: Bad Request response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: 'Bad Request: accountId parameter is required' status: 400 '401': description: 'Unauthorized: Unauthorized response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Unauthorized status: 401 '403': description: 'Forbidden: Forbidden response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Forbidden status: 403 '404': description: 'NotFound: Not Found response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Not Found status: 404 '429': description: 'TooManyRequests: Too Many Requests response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Too Many Requests status: 429 '500': description: 'InternalServerError: Internal Server Error response.' content: application/json: schema: $ref: '#/components/schemas/NotFound' example: message: Internal Server Error status: 500 security: - X-Api-Key_header_X-Api-Key: [] jwt_header_Authorization: - sto_testtarget_edit summary: Targets#Update target x-summary-source: derived /sto/api/v2/targets/{id}/executions: get: description: 'Paginated target scan history for UI 3.0: build id, pipeline, branch, scan types, and severity counts per execution. Sorted by startedAt DESC (dummy data until store wiring).' operationId: Targets#ListTargetExecutions parameters: - allowEmptyValue: true description: Harness Account ID example: abcdef1234567890ghijkl in: query name: accountId required: true schema: description: Harness Account ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ type: string - allowEmptyValue: true description: Harness Organization ID example: example_org in: query name: orgId required: true schema: description: Harness Organization ID example: example_org maxLength: 128 pattern: ^[A-Za-z_][A-Za-z0-9_]*$ type: string - allowEmptyValue: true description: Harness Project ID example: example_project in: query name: projectId required: true schema: description: Harness Project ID example: example_project maxLength: 128 pattern: ^[A-Za-z_][A-Za-z0-9_]*$ type: string - description: Target ID example: abcdef1234567890ghijkl in: path name: id required: true schema: description: Target ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ type: string - allowEmptyValue: true description: Page number to fetch (starting from 0) example: 4 in: query name: page schema: default: 0 description: Page number to fetch (starting from 0) example: 4 format: int64 minimum: 0 type: integer - allowEmptyValue: true description: Number of results per page example: 50 in: query name: pageSize schema: default: 30 description: Number of results per page example: 50 format: int64 maximum: 100 minimum: 1 type: integer - allowEmptyValue: true description: Keep executions whose CI/CD source is in this comma-separated set (e.g. Harness, Jenkins, GithubActions). Empty/absent means no filter. example: Harness,Jenkins,GithubActions in: query name: source schema: description: Keep executions whose CI/CD source is in this comma-separated set (e.g. Harness, Jenkins, GithubActions). Empty/absent means no filter. example: Harness,Jenkins,GithubActions maxLength: 1024 pattern: ^([^,]+(,[^,]+)*)?$ type: string - allowEmptyValue: true description: Keep executions whose branch is in this comma-separated set. Empty/absent means no filter. example: main,develop in: query name: branch schema: description: Keep executions whose branch is in this comma-separated set. Empty/absent means no filter. example: main,develop maxLength: 1024 pattern: ^([^,]+(,[^,]+)*)?$ type: string - allowEmptyValue: true description: Keep executions that include any of these comma-separated scan types. Empty/absent means no filter. example: SAST,SCA in: query name: scanTypes schema: description: Keep executions that include any of these comma-separated scan types. Empty/absent means no filter. example: SAST,SCA maxLength: 256 pattern: ^([^,]+(,[^,]+)*)?$ type: string responses: '200': content: application/json: example: pagination: link: '' page: 4 pageSize: 20 totalItems: 230 totalPages: 12 results: - branch: main buildId: '222' commitSha: deadbeefdeadbeefdeadbeefdeadbeefdeadbeef durationMs: 593000 executionId: abcdef1234567890ghijkl executionUrl: https://qa.harness.io/ng/account/acct/ci/orgs/default/projects/STO/pipelines/p/executions/e/pipeline issueSeverityCounts: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 occurrenceSeverityCounts: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 pipelineName: Security Gate scanTypes: - SAST - SCA - SECRET source: harness startedAt: 1751184000000 triggeredBy: user@harness.io - branch: main buildId: '222' commitSha: deadbeefdeadbeefdeadbeefdeadbeefdeadbeef durationMs: 593000 executionId: abcdef1234567890ghijkl executionUrl: https://qa.harness.io/ng/account/acct/ci/orgs/default/projects/STO/pipelines/p/executions/e/pipeline issueSeverityCounts: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 occurrenceSeverityCounts: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 pipelineName: Security Gate scanTypes: - SAST - SCA - SECRET source: harness startedAt: 1751184000000 triggeredBy: user@harness.io - branch: main buildId: '222' commitSha: deadbeefdeadbeefdeadbeefdeadbeefdeadbeef durationMs: 593000 executionId: abcdef1234567890ghijkl executionUrl: https://qa.harness.io/ng/account/acct/ci/orgs/default/projects/STO/pipelines/p/executions/e/pipeline issueSeverityCounts: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 occurrenceSeverityCounts: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 pipelineName: Security Gate scanTypes: - SAST - SCA - SECRET source: harness startedAt: 1751184000000 triggeredBy: user@harness.io schema: $ref: '#/components/schemas/TargetsListTargetExecutionsResponseBody' description: OK response. '400': content: application/json: example: message: 'Bad Request: accountId parameter is required' status: 400 schema: $ref: '#/components/schemas/NotFound' description: 'BadRequest: Bad Request response.' '401': content: application/json: example: message: Unauthorized status: 401 schema: $ref: '#/components/schemas/NotFound' description: 'Unauthorized: Unauthorized response.' '403': content: application/json: example: message: Forbidden status: 403 schema: $ref: '#/components/schemas/NotFound' description: 'Forbidden: Forbidden response.' '404': content: application/json: example: message: Not Found status: 404 schema: $ref: '#/components/schemas/NotFound' description: 'NotFound: Not Found response.' '429': content: application/json: example: message: Too Many Requests status: 429 schema: $ref: '#/components/schemas/NotFound' description: 'TooManyRequests: Too Many Requests response.' '500': content: application/json: example: message: Internal Server Error status: 500 schema: $ref: '#/components/schemas/NotFound' description: 'InternalServerError: Internal Server Error response.' security: - jwt_header_Authorization: - sto_issue_view summary: List target executions tags: - Test Targets x-internal: true /sto/api/v2/targets/{id}/executions/{executionId}: get: description: 'Header metadata for one target execution on the scan history detail page: build id, CI source, pipeline name, findings count, sbom count, and whether a ShiftLeft/Qwiet scan ran.' operationId: Targets#GetTargetExecution parameters: - allowEmptyValue: true description: Harness Account ID example: abcdef1234567890ghijkl in: query name: accountId required: true schema: description: Harness Account ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ type: string - allowEmptyValue: true description: Harness Organization ID example: example_org in: query name: orgId required: true schema: description: Harness Organization ID example: example_org maxLength: 128 pattern: ^[A-Za-z_][A-Za-z0-9_]*$ type: string - allowEmptyValue: true description: Harness Project ID example: example_project in: query name: projectId required: true schema: description: Harness Project ID example: example_project maxLength: 128 pattern: ^[A-Za-z_][A-Za-z0-9_]*$ type: string - description: Target ID example: abcdef1234567890ghijkl in: path name: id required: true schema: description: Target ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ type: string - description: Harness Execution ID example: abcdef1234567890ghijkl in: path name: executionId required: true schema: description: Harness Execution ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ type: string responses: '200': content: application/json: example: buildId: '222' executionId: abcdef1234567890ghijkl findingsCount: 39 hasShiftLeftScan: true pipelineName: Security Gate sbomCount: 0 source: harness schema: $ref: '#/components/schemas/TargetExecutionMetadata' description: OK response. '400': content: application/json: example: message: 'Bad Request: accountId parameter is required' status: 400 schema: $ref: '#/components/schemas/NotFound' description: 'BadRequest: Bad Request response.' '401': content: application/json: example: message: Unauthorized status: 401 schema: $ref: '#/components/schemas/NotFound' description: 'Unauthorized: Unauthorized response.' '403': content: application/json: example: message: Forbidden status: 403 schema: $ref: '#/components/schemas/NotFound' description: 'Forbidden: Forbidden response.' '404': content: application/json: example: message: Not Found status: 404 schema: $ref: '#/components/schemas/NotFound' description: 'NotFound: Not Found response.' '429': content: application/json: example: message: Too Many Requests status: 429 schema: $ref: '#/components/schemas/NotFound' description: 'TooManyRequests: Too Many Requests response.' '500': content: application/json: example: message: Internal Server Error status: 500 schema: $ref: '#/components/schemas/NotFound' description: 'InternalServerError: Internal Server Error response.' security: - jwt_header_Authorization: - sto_issue_view summary: Get target execution metadata tags: - Test Targets x-internal: true /sto/api/v2/targets/{id}/executions/{executionId}/occurrences: get: description: Returns a paginated list of findings for one target execution. Each scan that reported an occurrence is returned as its own row (no cross-scan dedupe); FE can dedupe with occurrenceInternalId + scanId. Each row includes issueId, scanId, occurrenceInternalId, and optional exemptionId (occurrence-scoped) so the UI can use existing ticket/exemption APIs. operationId: Targets#ListTargetExecutionOccurrences parameters: - allowEmptyValue: true description: Harness Account ID example: abcdef1234567890ghijkl in: query name: accountId required: true schema: description: Harness Account ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ type: string - allowEmptyValue: true description: Harness Organization ID example: example_org in: query name: orgId required: true schema: description: Harness Organization ID example: example_org maxLength: 128 pattern: ^[A-Za-z_][A-Za-z0-9_]*$ type: string - allowEmptyValue: true description: Harness Project ID example: example_project in: query name: projectId required: true schema: description: Harness Project ID example: example_project maxLength: 128 pattern: ^[A-Za-z_][A-Za-z0-9_]*$ type: string - description: Target ID example: abcdef1234567890ghijkl in: path name: id required: true schema: description: Target ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ type: string - description: Harness Execution ID example: abcdef1234567890ghijkl in: path name: executionId required: true schema: description: Harness Execution ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ type: string - allowEmptyValue: true description: Page number to fetch (starting from 0) example: 4 in: query name: page schema: default: 0 description: Page number to fetch (starting from 0) example: 4 format: int64 minimum: 0 type: integer - allowEmptyValue: true description: Number of results per page example: 50 in: query name: pageSize schema: default: 30 description: Number of results per page example: 50 format: int64 maximum: 100 minimum: 1 type: integer - allowEmptyValue: true description: Search finding titles and occurrence details example: SQL injection in: query name: search schema: description: Search finding titles and occurrence details example: SQL injection maxLength: 256 type: string - allowEmptyValue: true description: Keep findings whose severity is in this comma-separated set example: Critical,High in: query name: severityCodes schema: description: Keep findings whose severity is in this comma-separated set example: Critical,High maxLength: 256 pattern: ^(Critical|High|Medium|Low|Info)(,Critical|,High|,Medium|,Low|,Info)*$ type: string - allowEmptyValue: true description: Keep findings whose issue type is in this comma-separated set example: SAST,SCA,SECRET in: query name: issueTypes schema: description: Keep findings whose issue type is in this comma-separated set example: SAST,SCA,SECRET maxLength: 256 pattern: ^(SAST|DAST|SCA|IAC|SECRET|MISCONFIG|BUG_SMELLS|CODE_SMELLS|CODE_COVERAGE|EXTERNAL_POLICY)(,SAST|,DAST|,SCA|,IAC|,SECRET|,MISCONFIG|,BUG_SMELLS|,CODE_SMELLS|,CODE_COVERAGE|,EXTERNAL_POLICY)*$ type: string responses: '200': content: application/json: example: pagination: link: '' page: 4 pageSize: 20 totalItems: 230 totalPages: 12 results: - exemptionId: abcdef1234567890ghijkl issueId: abcdef1234567890ghijkl issueType: SAST occurrenceInternalId: 12345 scanId: scan111111111111111111 severityCode: Critical title: SQL injection enables authentication bypass - exemptionId: abcdef1234567890ghijkl issueId: abcdef1234567890ghijkl issueType: SAST occurrenceInternalId: 12345 scanId: scan111111111111111111 severityCode: Critical title: SQL injection enables authentication bypass - exemptionId: abcdef1234567890ghijkl issueId: abcdef1234567890ghijkl issueType: SAST occurrenceInternalId: 12345 scanId: scan111111111111111111 severityCode: Critical title: SQL injection enables authentication bypass schema: $ref: '#/components/schemas/TargetsListTargetExecutionOccurrencesResponseBody' description: OK response. '400': content: application/json: example: message: 'Bad Request: accountId parameter is required' status: 400 schema: $ref: '#/components/schemas/NotFound' description: 'BadRequest: Bad Request response.' '401': content: application/json: example: message: Unauthorized status: 401 schema: $ref: '#/components/schemas/NotFound' description: 'Unauthorized: Unauthorized response.' '403': content: application/json: example: message: Forbidden status: 403 schema: $ref: '#/components/schemas/NotFound' description: 'Forbidden: Forbidden response.' '404': content: application/json: example: message: Not Found status: 404 schema: $ref: '#/components/schemas/NotFound' description: 'NotFound: Not Found response.' '429': content: application/json: example: message: Too Many Requests status: 429 schema: $ref: '#/components/schemas/NotFound' description: 'TooManyRequests: Too Many Requests response.' '500': content: application/json: example: message: Internal Server Error status: 500 schema: $ref: '#/components/schemas/NotFound' description: 'InternalServerError: Internal Server Error response.' security: - jwt_header_Authorization: - sto_issue_view summary: List target execution findings tags: - Test Targets x-internal: true /sto/api/v2/targets/{id}/executions/{executionId}/occurrences/{occurrenceInternalId}: get: description: Returns one occurrence from a target execution by occurrenceInternalId for a specific scan. Pass scanId from the findings list row — the same occurrenceInternalId may appear once per scan in an execution. The response is the same occurrence Details object used by the vulnerabilities and Issue Page V2 APIs. operationId: Targets#GetTargetExecutionOccurrence parameters: - allowEmptyValue: true description: Harness Account ID example: abcdef1234567890ghijkl in: query name: accountId required: true schema: description: Harness Account ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ type: string - allowEmptyValue: true description: Harness Organization ID example: example_org in: query name: orgId required: true schema: description: Harness Organization ID example: example_org maxLength: 128 pattern: ^[A-Za-z_][A-Za-z0-9_]*$ type: string - allowEmptyValue: true description: Harness Project ID example: example_project in: query name: projectId required: true schema: description: Harness Project ID example: example_project maxLength: 128 pattern: ^[A-Za-z_][A-Za-z0-9_]*$ type: string - description: Target ID example: abcdef1234567890ghijkl in: path name: id required: true schema: description: Target ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ type: string - description: Harness Execution ID example: abcdef1234567890ghijkl in: path name: executionId required: true schema: description: Harness Execution ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ type: string - description: Internal ID of the occurrence example: 12345 in: path name: occurrenceInternalId required: true schema: description: Internal ID of the occurrence example: 12345 format: int64 minimum: 1 type: integer - allowEmptyValue: true description: Scan ID from the findings list row. Required so detail matches the clicked scan when the same occurrence appears in multiple scans of one execution. example: scan111111111111111111 in: query name: scanId required: true schema: description: Scan ID from the findings list row. Required so detail matches the clicked scan when the same occurrence appears in multiple scans of one execution. example: scan111111111111111111 pattern: ^[a-zA-Z0-9_-]{22}$ type: string responses: '200': content: application/json: example: Est sed accusamus dolor nemo.: Corrupti quia quia rem. Et ipsa qui culpa.: Eaque odit. Sunt illum.: Veniam eaque est ipsa doloribus. schema: additionalProperties: true example: Asperiores eos expedita esse eos.: Nihil eaque optio provident id. Laboriosam sit nihil laborum enim qui neque.: Nemo sapiente nobis molestiae atque. type: object description: OK response. '400': content: application/json: example: message: 'Bad Request: accountId parameter is required' status: 400 schema: $ref: '#/components/schemas/NotFound' description: 'BadRequest: Bad Request response.' '401': content: application/json: example: message: Unauthorized status: 401 schema: $ref: '#/components/schemas/NotFound' description: 'Unauthorized: Unauthorized response.' '403': content: application/json: example: message: Forbidden status: 403 schema: $ref: '#/components/schemas/NotFound' description: 'Forbidden: Forbidden response.' '404': content: application/json: example: message: Not Found status: 404 schema: $ref: '#/components/schemas/NotFound' description: 'NotFound: Not Found response.' '429': content: application/json: example: message: Too Many Requests status: 429 schema: $ref: '#/components/schemas/NotFound' description: 'TooManyRequests: Too Many Requests response.' '500': content: application/json: example: message: Internal Server Error status: 500 schema: $ref: '#/components/schemas/NotFound' description: 'InternalServerError: Internal Server Error response.' security: - jwt_header_Authorization: - sto_issue_view summary: Get target execution occurrence tags: - Test Targets x-internal: true /sto/api/v2/targets/{id}/overview: get: description: 'Target detail overview for UI 3.0: findings/issues tiles, scan coverage, and issue-type x severity matrix. Served from target_summary + latest execution (dummy data until store wiring).' operationId: Targets#TargetOverview parameters: - allowEmptyValue: true description: Harness Account ID example: abcdef1234567890ghijkl in: query name: accountId required: true schema: description: Harness Account ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ type: string - allowEmptyValue: true description: Harness Organization ID example: example_org in: query name: orgId required: true schema: description: Harness Organization ID example: example_org maxLength: 128 pattern: ^[A-Za-z_][A-Za-z0-9_]*$ type: string - allowEmptyValue: true description: Harness Project ID example: example_project in: query name: projectId required: true schema: description: Harness Project ID example: example_project maxLength: 128 pattern: ^[A-Za-z_][A-Za-z0-9_]*$ type: string - description: Target ID example: abcdef1234567890ghijkl in: path name: id required: true schema: description: Target ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ type: string - allowEmptyValue: true description: Optional variant scope; when set, overview reflects that variant's latest execution example: xyz987zyx654wvu321tsr9 in: query name: variantId schema: description: Optional variant scope; when set, overview reflects that variant's latest execution example: xyz987zyx654wvu321tsr9 pattern: ^[a-zA-Z0-9_-]{22}$ type: string responses: '200': content: application/json: example: baselineVariantId: abcdef1234567890ghijkl branchesCount: 3 executionId: abcdef1234567890ghijkl hasShiftLeftScan: false isBaseline: true issueFindingsMatrix: columnTotals: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 grandTotal: 31 rows: - issueType: SAST severityCounts: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 total: 14 - issueType: SAST severityCounts: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 total: 14 - issueType: SAST severityCounts: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 total: 14 issueNewDelta: 3 issueRemediatedDelta: 1 issueSeverityCounts: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 name: NodeGoat occurrenceFindingsMatrix: columnTotals: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 grandTotal: 31 rows: - issueType: SAST severityCounts: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 total: 14 - issueType: SAST severityCounts: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 total: 14 - issueType: SAST severityCounts: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 total: 14 occurrenceNewDelta: 4 occurrenceRemediatedDelta: 2 occurrenceSeverityCounts: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 packages: container: 0 oss: 128 risky_oss: 1 vulnerable_container: 0 vulnerable_oss: 18 scanTypes: - SAST - SCA - SECRET scannedAt: 1751793300000 targetId: abcdef1234567890ghijkl targetUrl: https://github.com/example/NodeGoat type: repository variantId: xyz987zyx654wvu321tsr9 variantName: main schema: $ref: '#/components/schemas/TargetOverviewResult' description: OK response. '400': content: application/json: example: message: 'Bad Request: accountId parameter is required' status: 400 schema: $ref: '#/components/schemas/NotFound' description: 'BadRequest: Bad Request response.' '401': content: application/json: example: message: Unauthorized status: 401 schema: $ref: '#/components/schemas/NotFound' description: 'Unauthorized: Unauthorized response.' '403': content: application/json: example: message: Forbidden status: 403 schema: $ref: '#/components/schemas/NotFound' description: 'Forbidden: Forbidden response.' '404': content: application/json: example: message: Not Found status: 404 schema: $ref: '#/components/schemas/NotFound' description: 'NotFound: Not Found response.' '429': content: application/json: example: message: Too Many Requests status: 429 schema: $ref: '#/components/schemas/NotFound' description: 'TooManyRequests: Too Many Requests response.' '500': content: application/json: example: message: Internal Server Error status: 500 schema: $ref: '#/components/schemas/NotFound' description: 'InternalServerError: Internal Server Error response.' security: - jwt_header_Authorization: - sto_issue_view summary: Get target overview tags: - Test Targets x-internal: true /sto/api/v2/targets/{id}/sbom: get: description: Proxy ShiftLeft/Qwiet compound BOM for a target. Resolves polyglot scan and compound from ShiftLeft scan metadata, then calls Qwiet v4 compounds/named/{compound}/bom. operationId: Targets#TargetSbom parameters: - allowEmptyValue: true description: Harness Account ID example: abcdef1234567890ghijkl in: query name: accountId required: true schema: description: Harness Account ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ type: string - allowEmptyValue: true description: Harness Organization ID example: example_org in: query name: orgId required: true schema: description: Harness Organization ID example: example_org maxLength: 128 pattern: ^[A-Za-z_][A-Za-z0-9_]*$ type: string - allowEmptyValue: true description: Harness Project ID example: example_project in: query name: projectId required: true schema: description: Harness Project ID example: example_project maxLength: 128 pattern: ^[A-Za-z_][A-Za-z0-9_]*$ type: string - description: Target ID example: abcdef1234567890ghijkl in: path name: id required: true schema: description: Target ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ type: string - allowEmptyValue: true description: Optional variant scope example: xyz987zyx654wvu321tsr9 in: query name: variantId schema: description: Optional variant scope example: xyz987zyx654wvu321tsr9 pattern: ^[a-zA-Z0-9_-]{22}$ type: string - allowEmptyValue: true description: Harness Execution ID example: abcdef1234567890ghijkl in: query name: executionId schema: description: Harness Execution ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ type: string - allowEmptyValue: true description: The format to return the BOM in example: cyclonedx-1.2-json in: query name: format required: true schema: description: The format to return the BOM in enum: - cyclonedx-1.2-xml - cyclonedx-1.2-json - cyclonedx-1.4-xml - cyclonedx-1.4-json - spdx-2.3-tag-value - spdx-2.3-json - spdx-2.3-yaml example: cyclonedx-1.2-json type: string - allowEmptyValue: true description: The finding types to look at example: package in: query name: type schema: default: package description: The finding types to look at enum: - package - container_package example: package type: string - allowEmptyValue: true description: Limit the SBOM to packages with this license example: MIT in: query name: license schema: description: Limit the SBOM to packages with this license example: MIT type: string - allowEmptyValue: true description: Pretty-print the output example: false in: query name: pretty schema: default: false description: Pretty-print the output example: false type: boolean responses: '200': content: application/json: schema: format: binary type: string description: OK response. headers: Content-Type: description: Content-Type of the BOM body example: application/json schema: description: Content-Type of the BOM body example: application/json type: string '400': content: application/json: example: message: 'Bad Request: accountId parameter is required' status: 400 schema: $ref: '#/components/schemas/NotFound' description: 'BadRequest: Bad Request response.' '401': content: application/json: example: message: Unauthorized status: 401 schema: $ref: '#/components/schemas/NotFound' description: 'Unauthorized: Unauthorized response.' '403': content: application/json: example: message: Forbidden status: 403 schema: $ref: '#/components/schemas/NotFound' description: 'Forbidden: Forbidden response.' '404': content: application/json: example: message: Not Found status: 404 schema: $ref: '#/components/schemas/NotFound' description: 'NotFound: Not Found response.' '429': content: application/json: example: message: Too Many Requests status: 429 schema: $ref: '#/components/schemas/NotFound' description: 'TooManyRequests: Too Many Requests response.' '500': content: application/json: example: message: Internal Server Error status: 500 schema: $ref: '#/components/schemas/NotFound' description: 'InternalServerError: Internal Server Error response.' security: - jwt_header_Authorization: - sto_issue_view summary: Get target SBOM tags: - Test Targets x-internal: true /sto/api/v2/targets/{id}/sca/packages: get: description: Proxy ShiftLeft/Qwiet SCA packages for a target. Resolves polyglot scan and compound from ShiftLeft scan metadata, then calls Qwiet v4 compounds/named/{compound}/sca/packages. operationId: Targets#TargetScaPackages parameters: - allowEmptyValue: true description: Harness Account ID example: abcdef1234567890ghijkl in: query name: accountId required: true schema: description: Harness Account ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ type: string - allowEmptyValue: true description: Harness Organization ID example: example_org in: query name: orgId required: true schema: description: Harness Organization ID example: example_org maxLength: 128 pattern: ^[A-Za-z_][A-Za-z0-9_]*$ type: string - allowEmptyValue: true description: Harness Project ID example: example_project in: query name: projectId required: true schema: description: Harness Project ID example: example_project maxLength: 128 pattern: ^[A-Za-z_][A-Za-z0-9_]*$ type: string - description: Target ID example: abcdef1234567890ghijkl in: path name: id required: true schema: description: Target ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ type: string - allowEmptyValue: true description: Optional variant scope example: xyz987zyx654wvu321tsr9 in: query name: variantId schema: description: Optional variant scope example: xyz987zyx654wvu321tsr9 pattern: ^[a-zA-Z0-9_-]{22}$ type: string - allowEmptyValue: true description: Harness Execution ID example: abcdef1234567890ghijkl in: query name: executionId schema: description: Harness Execution ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ type: string - allowEmptyValue: true description: Page number to fetch (starting from 1) example: 1 in: query name: page schema: default: 1 description: Page number to fetch (starting from 1) example: 1 format: int64 minimum: 1 type: integer - allowEmptyValue: true description: Number of results per page example: 10 in: query name: per_page schema: default: 10 description: Number of results per page example: 10 format: int64 maximum: 10000 minimum: 1 type: integer - allowEmptyValue: true description: 'Package search: substring match, or name@version (split on last @) for name+version filter' example: log4j@1.2.3 in: query name: search schema: description: 'Package search: substring match, or name@version (split on last @) for name+version filter' example: log4j@1.2.3 maxLength: 256 type: string - allowEmptyValue: true description: Package finding type filter. All omits Qwiet type; SCA maps to package; Container maps to container_package example: SCA in: query name: type schema: default: All description: Package finding type filter. All omits Qwiet type; SCA maps to package; Container maps to container_package enum: - All - SCA - Container example: SCA type: string - allowEmptyValue: true description: Comma-separated licenses mapped to Qwiet tag package_license__in__... example: APACHE-2,BSD-3-Clause in: query name: licenses schema: description: Comma-separated licenses mapped to Qwiet tag package_license__in__... example: APACHE-2,BSD-3-Clause maxLength: 1024 type: string responses: '200': content: application/json: example: compound_id: Sunt odit sit aut. has_more: true packages: - created_at: Mollitia sit ex cumque harum quis. exploitable: - Aut consequatur reiciendis facere sint fugit nesciunt. - Repudiandae omnis non necessitatibus et culpa. - Quia voluptatum autem doloribus. - Ut dolor voluptatem omnis alias fugit. finding_details: Perferendis vel laboriosam amet quia dicta.: Sint sequi nesciunt. finding_type: Illum laudantium sed. license: Et doloribus vel sit sint reprehenderit iste. name: Omnis voluptas fuga nobis aperiam assumenda et. namespace: Sit est est minima voluptas. num_exploitable: 7424730667882409000 num_reachable: 2381916510335179300 num_vulns: 1966980579282087200 package: Vitae laboriosam magni maiores cupiditate fuga magni. tags: Nulla a impedit.: - Accusantium dolores aliquid distinctio. - Molestias ut quos at. - Non ut ut occaecati soluta voluptas. - Velit necessitatibus laboriosam maxime explicabo est. Quasi eos quaerat occaecati aperiam possimus fuga.: - Sapiente neque sequi. - Vero ea et ut ipsa eum. Tempora asperiores sed beatae asperiores.: - Qui aut veritatis ab sed aut voluptates. - Nemo ipsam aspernatur quia eveniet. type: Ad illum. url: Iure aut vero aut rerum voluptas. version: Quas ut iusto explicabo molestiae perferendis ex. vulns: - Aspernatur veritatis voluptas natus et aut. - Voluptatem id dolor laudantium laudantium laudantium. - Similique porro odio totam. - created_at: Mollitia sit ex cumque harum quis. exploitable: - Aut consequatur reiciendis facere sint fugit nesciunt. - Repudiandae omnis non necessitatibus et culpa. - Quia voluptatum autem doloribus. - Ut dolor voluptatem omnis alias fugit. finding_details: Perferendis vel laboriosam amet quia dicta.: Sint sequi nesciunt. finding_type: Illum laudantium sed. license: Et doloribus vel sit sint reprehenderit iste. name: Omnis voluptas fuga nobis aperiam assumenda et. namespace: Sit est est minima voluptas. num_exploitable: 7424730667882409000 num_reachable: 2381916510335179300 num_vulns: 1966980579282087200 package: Vitae laboriosam magni maiores cupiditate fuga magni. tags: Nulla a impedit.: - Accusantium dolores aliquid distinctio. - Molestias ut quos at. - Non ut ut occaecati soluta voluptas. - Velit necessitatibus laboriosam maxime explicabo est. Quasi eos quaerat occaecati aperiam possimus fuga.: - Sapiente neque sequi. - Vero ea et ut ipsa eum. Tempora asperiores sed beatae asperiores.: - Qui aut veritatis ab sed aut voluptates. - Nemo ipsam aspernatur quia eveniet. type: Ad illum. url: Iure aut vero aut rerum voluptas. version: Quas ut iusto explicabo molestiae perferendis ex. vulns: - Aspernatur veritatis voluptas natus et aut. - Voluptatem id dolor laudantium laudantium laudantium. - Similique porro odio totam. polyglot_scan_id: Non tempore asperiores eius impedit earum. scans: - app: owasp_nodegoat id: '298' - app: owasp_nodegoat id: '298' total_count: 3980700334892786700 schema: $ref: '#/components/schemas/TargetScaPackagesResult' description: OK response. '400': content: application/json: example: message: 'Bad Request: accountId parameter is required' status: 400 schema: $ref: '#/components/schemas/NotFound' description: 'BadRequest: Bad Request response.' '401': content: application/json: example: message: Unauthorized status: 401 schema: $ref: '#/components/schemas/NotFound' description: 'Unauthorized: Unauthorized response.' '403': content: application/json: example: message: Forbidden status: 403 schema: $ref: '#/components/schemas/NotFound' description: 'Forbidden: Forbidden response.' '404': content: application/json: example: message: Not Found status: 404 schema: $ref: '#/components/schemas/NotFound' description: 'NotFound: Not Found response.' '429': content: application/json: example: message: Too Many Requests status: 429 schema: $ref: '#/components/schemas/NotFound' description: 'TooManyRequests: Too Many Requests response.' '500': content: application/json: example: message: Internal Server Error status: 500 schema: $ref: '#/components/schemas/NotFound' description: 'InternalServerError: Internal Server Error response.' security: - jwt_header_Authorization: - sto_issue_view summary: Get target SCA packages tags: - Test Targets x-internal: true components: schemas: StoTarget: type: object properties: baselineRegEx: type: string description: RegEx to match for dynamically selecting the Baseline for this Scan Target. Must be compatible with the RE2 standard. example: release_.* maxLength: 128 baselineVariantId: type: string description: ID of baseline Target Variant for Issue comparison example: abcdef1234567890ghijkl pattern: ^([a-zA-Z0-9_-]{22}|)$ created: type: integer description: Unix timestamp at which the resource was created example: 1651578240 format: int64 directory: type: string description: Directory within the Test Target to be scanned example: app/src maxLength: 1024 id: type: string description: Resource identifier example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ lastModified: type: integer description: Unix timestamp at which the resource was most recently modified example: 1651578240 format: int64 name: type: string description: Name of the Test Target example: NodeGoat pattern: ^[a-zA-Z0-9_.:/|()-]+$ maxLength: 128 orgId: type: string description: Harness Organization ID example: example_org pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 projectId: type: string description: Harness Project ID example: example_project pattern: ^[A-Za-z_][A-Za-z0-9_]*$ maxLength: 128 type: type: string description: Test Target's type example: repository enum: - container - repository - instance - configuration url: type: string description: URL used to access the Test Target example: https://github.com/example/repo maxLength: 1024 example: baselineRegEx: release_.* baselineVariantId: abcdef1234567890ghijkl created: 1651578240 directory: app/src id: abcdef1234567890ghijkl lastModified: 1651578240 name: NodeGoat orgId: example_org projectId: example_project type: repository url: https://github.com/example/repo required: - id - created - lastModified - name - type - orgId - projectId TargetsListTargetsResponseBody: type: object properties: pagination: $ref: '#/components/schemas/StoPagination' results: type: array items: $ref: '#/components/schemas/StoTarget' example: - baselineRegEx: release_.* baselineVariantId: abcdef1234567890ghijkl created: 1651578240 directory: app/src id: abcdef1234567890ghijkl lastModified: 1651578240 name: NodeGoat orgId: example_org projectId: example_project type: repository url: https://github.com/example/repo - baselineRegEx: release_.* baselineVariantId: abcdef1234567890ghijkl created: 1651578240 directory: app/src id: abcdef1234567890ghijkl lastModified: 1651578240 name: NodeGoat orgId: example_org projectId: example_project type: repository url: https://github.com/example/repo - baselineRegEx: release_.* baselineVariantId: abcdef1234567890ghijkl created: 1651578240 directory: app/src id: abcdef1234567890ghijkl lastModified: 1651578240 name: NodeGoat orgId: example_org projectId: example_project type: repository url: https://github.com/example/repo - baselineRegEx: release_.* baselineVariantId: abcdef1234567890ghijkl created: 1651578240 directory: app/src id: abcdef1234567890ghijkl lastModified: 1651578240 name: NodeGoat orgId: example_org projectId: example_project type: repository url: https://github.com/example/repo example: pagination: link: '' page: 4 pageSize: 20 totalItems: 230 totalPages: 12 results: - baselineRegEx: release_.* baselineVariantId: abcdef1234567890ghijkl created: 1651578240 directory: app/src id: abcdef1234567890ghijkl lastModified: 1651578240 name: NodeGoat orgId: example_org projectId: example_project type: repository url: https://github.com/example/repo - baselineRegEx: release_.* baselineVariantId: abcdef1234567890ghijkl created: 1651578240 directory: app/src id: abcdef1234567890ghijkl lastModified: 1651578240 name: NodeGoat orgId: example_org projectId: example_project type: repository url: https://github.com/example/repo - baselineRegEx: release_.* baselineVariantId: abcdef1234567890ghijkl created: 1651578240 directory: app/src id: abcdef1234567890ghijkl lastModified: 1651578240 name: NodeGoat orgId: example_org projectId: example_project type: repository url: https://github.com/example/repo required: - results - pagination PatchTargetRequestBody: type: object properties: baselineRegEx: type: string description: RegEx to match for dynamically selecting the Baseline for this Scan Target. Must be compatible with the RE2 standard. example: release_.* maxLength: 128 baselineVariantId: type: string description: ID of baseline Target Variant for Issue comparison example: abcdef1234567890ghijkl pattern: ^([a-zA-Z0-9_-]{22}|)$ directory: type: string description: Directory within the Test Target to be scanned example: app/src maxLength: 1024 name: type: string description: Name of the Test Target example: NodeGoat pattern: ^[a-zA-Z0-9_.:/|()-]+$ maxLength: 128 type: type: string description: Test Target's type example: repository enum: - container - repository - instance - configuration url: type: string description: URL used to access the Test Target example: https://github.com/example/repo maxLength: 1024 example: baselineRegEx: release_.* baselineVariantId: abcdef1234567890ghijkl directory: app/src name: NodeGoat type: repository url: https://github.com/example/repo ScaPackage: type: object properties: created_at: type: string example: Rerum aliquid placeat. exploitable: type: array items: type: string example: Natus id voluptates ut omnis magni. example: - Saepe ullam impedit. - Tenetur sint. - Sunt et repellat cupiditate sed fuga rerum. finding_details: type: object example: Exercitationem qui at illum ex sed.: Beatae facilis aut dolorem aut. Voluptatem ipsam debitis odio omnis.: Amet earum laudantium quis. additionalProperties: true finding_type: type: string example: Iste ea dolorem et labore cupiditate provident. license: type: string example: Nihil totam voluptatem unde. name: type: string example: Qui asperiores non nostrum quis doloribus. namespace: type: string example: Dignissimos nostrum est exercitationem delectus tempora vel. num_exploitable: type: integer example: 8010811787350149000 format: int64 num_reachable: type: integer example: 3133441743886966300 format: int64 num_vulns: type: integer example: 7870224083663304000 format: int64 package: type: string example: Amet voluptatem corrupti. tags: type: object example: Iure quis.: - Veniam ex nihil maiores. - Temporibus quis architecto voluptate quae dolores. - Necessitatibus dolore dicta assumenda. additionalProperties: type: array items: type: string example: In odit eum ut voluptatibus. example: - Minima et. - Occaecati ut est molestiae sunt ea sed. - Facilis eaque cum alias ut. type: type: string example: Unde repudiandae. url: type: string example: Odio totam iusto. version: type: string example: Consequatur aut veritatis adipisci ducimus. vulns: type: array items: type: string example: Modi cupiditate sed excepturi error veniam. example: - Officiis atque magni velit omnis. - Voluptates veniam in. - Aspernatur facilis qui natus nostrum. example: created_at: Est neque occaecati aut praesentium libero. exploitable: - Enim distinctio nesciunt quis incidunt. - Sint est ipsam eos. - Occaecati odio. - Qui expedita odio et autem sit ut. finding_details: Earum nesciunt.: Dicta est illo deleniti sed veniam. finding_type: Eligendi veritatis sunt voluptates. license: Necessitatibus quos perspiciatis. name: Aut sit aliquid vel non facere molestias. namespace: Harum voluptatem sapiente. num_exploitable: 9177666144428143000 num_reachable: 5815512415644161000 num_vulns: 7623516851526729000 package: Et ratione laudantium. tags: Aliquam velit atque sit iste sunt.: - Id mollitia. - Et beatae. - Aliquam omnis quod incidunt dolores non. - Repellendus omnis consequuntur. Reprehenderit aut dolorem autem qui.: - Sed sequi ullam blanditiis nulla modi quia. - Minima dolorem quo. - Dignissimos non at. - Quisquam qui. type: Laudantium consequatur optio magnam molestiae aut qui. url: Aut est eaque facere. version: Asperiores ipsum. vulns: - Doloremque iste. - Autem magni beatae enim dicta fuga fugiat. - Rem dolores iusto quia alias. TargetFindingsMatrix: type: object properties: columnTotals: $ref: '#/components/schemas/RepositorySeverityCounts' grandTotal: type: integer description: Sum of all cells example: 31 format: int64 minimum: 0 rows: type: array items: $ref: '#/components/schemas/TargetFindingsMatrixRow' description: One row per issue type example: - issueType: SAST severityCounts: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 total: 14 - issueType: SAST severityCounts: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 total: 14 - issueType: SAST severityCounts: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 total: 14 description: Cross-tab of counts by issue type and severity, with column totals and grand total. example: columnTotals: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 grandTotal: 31 rows: - issueType: SAST severityCounts: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 total: 14 - issueType: SAST severityCounts: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 total: 14 - issueType: SAST severityCounts: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 total: 14 - issueType: SAST severityCounts: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 total: 14 required: - rows - columnTotals - grandTotal TargetExecutionOccurrenceSummary: type: object properties: exemptionId: type: string description: ID of an occurrence-scoped exemption for this finding on the target, matched via exemption_occurrence fingerprint. Null/omitted when none exists. Issue-level exemptions are not returned. example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ issueId: type: string description: Issue ID used by the existing ticket and exemption APIs example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ issueType: type: string description: Finding issue type example: SAST enum: - SAST - DAST - SCA - IAC - SECRET - MISCONFIG - BUG_SMELLS - CODE_SMELLS - CODE_COVERAGE - EXTERNAL_POLICY occurrenceInternalId: type: integer description: Internal ID used to fetch occurrence details or request an occurrence-level exemption example: 12345 format: int64 minimum: 1 scanId: type: string description: ID of the scan containing this occurrence example: scan111111111111111111 pattern: ^[a-zA-Z0-9_-]{22}$ severityCode: type: string description: Finding severity example: Critical enum: - Critical - High - Medium - Low - Info - Unassigned title: type: string description: Finding title example: SQL injection enables authentication bypass description: An occurrence summary for one scan within a target execution. example: exemptionId: abcdef1234567890ghijkl issueId: abcdef1234567890ghijkl issueType: SAST occurrenceInternalId: 12345 scanId: scan111111111111111111 severityCode: Critical title: SQL injection enables authentication bypass required: - occurrenceInternalId - issueId - scanId - title - severityCode - issueType IDResult: type: object properties: id: type: string description: Resource identifier example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ example: id: abcdef1234567890ghijkl required: - id RepositorySeverityCounts: type: object properties: critical: type: integer description: Critical severity count example: 3 format: int64 minimum: 0 high: type: integer description: High severity count example: 4 format: int64 minimum: 0 info: type: integer description: Info severity count example: 1 format: int64 minimum: 0 low: type: integer description: Low severity count example: 2 format: int64 minimum: 0 medium: type: integer description: Medium severity count example: 5 format: int64 minimum: 0 unassigned: type: integer description: Unassigned severity count example: 0 format: int64 minimum: 0 description: Counts by severity, sourced from target_summary. example: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 required: - critical - high - medium - low - info - unassigned TargetExecutionMetadata: type: object properties: buildId: type: string description: 'CI build id/number shown in UI (e.g. #222). Falls back to executionId when build id is unset.' example: '222' executionId: type: string description: Harness Execution ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ findingsCount: type: integer description: Open findings (occurrence) count for this execution from execution_summary example: 39 format: int64 minimum: 0 hasShiftLeftScan: type: boolean description: True when this execution includes at least one Succeeded ShiftLeft/Qwiet scan (shiftleftsast, shiftleftsca, or shiftleft). UI uses this to show/hide the SBOM tab. example: true pipelineName: type: string description: Pipeline name shown under the build id example: Security Gate maxLength: 256 sbomCount: type: integer description: SBOM package count for this execution (ShiftLeft packages.oss + packages.container). 0 when unavailable. example: 0 format: int64 minimum: 0 source: type: string description: CI/CD platform that ran this execution (harness, jenkins, github_actions, gitlab_ci, ...) example: harness maxLength: 64 description: Header fields for the target scan history detail page. example: buildId: '222' executionId: abcdef1234567890ghijkl findingsCount: 39 hasShiftLeftScan: true pipelineName: Security Gate sbomCount: 0 source: harness required: - buildId - executionId - source - pipelineName - findingsCount - sbomCount - hasShiftLeftScan UpdateTargetRequestBody: type: object properties: baselineRegEx: type: string description: RegEx to match for dynamically selecting the Baseline for this Scan Target. Must be compatible with the RE2 standard. example: release_.* maxLength: 128 baselineVariantId: type: string description: ID of baseline Target Variant for Issue comparison example: abcdef1234567890ghijkl pattern: ^([a-zA-Z0-9_-]{22}|)$ directory: type: string description: Directory within the Test Target to be scanned example: app/src maxLength: 1024 name: type: string description: Name of the Test Target example: NodeGoat pattern: ^[a-zA-Z0-9_.:/|()-]+$ maxLength: 128 type: type: string description: Test Target's type example: repository enum: - container - repository - instance - configuration url: type: string description: URL used to access the Test Target example: https://github.com/example/repo maxLength: 1024 example: baselineRegEx: release_.* baselineVariantId: abcdef1234567890ghijkl directory: app/src name: NodeGoat type: repository url: https://github.com/example/repo required: - created - lastModified - name - type CreateTargetRequestBody: type: object properties: baselineRegEx: type: string description: RegEx to match for dynamically selecting the Baseline for this Scan Target. Must be compatible with the RE2 standard. example: release_.* maxLength: 128 baselineVariantId: type: string description: ID of baseline Target Variant for Issue comparison example: abcdef1234567890ghijkl pattern: ^([a-zA-Z0-9_-]{22}|)$ directory: type: string description: Directory within the Test Target to be scanned example: app/src maxLength: 1024 name: type: string description: Name of the Test Target example: NodeGoat pattern: ^[a-zA-Z0-9_.:/|()-]+$ maxLength: 128 type: type: string description: Test Target's type example: repository enum: - container - repository - instance - configuration url: type: string description: URL used to access the Test Target example: https://github.com/example/repo maxLength: 1024 example: baselineRegEx: release_.* baselineVariantId: abcdef1234567890ghijkl directory: app/src name: NodeGoat type: repository url: https://github.com/example/repo required: - id - created - lastModified - name - type StoPagination: type: object properties: link: type: string description: Link-based paging example: '' page: type: integer description: Page number (starting from 0) example: 4 format: int64 pageSize: type: integer description: Requested page size example: 20 format: int64 totalItems: type: integer description: Total results available example: 230 format: int64 totalPages: type: integer description: Total pages available example: 12 format: int64 example: link: '' page: 4 pageSize: 20 totalItems: 230 totalPages: 12 required: - page - pageSize - totalPages - totalItems TargetOverviewResult: type: object properties: baselineVariantId: type: string description: Baseline variant id when set example: abcdef1234567890ghijkl pattern: ^([a-zA-Z0-9_-]{22}|)$ branchesCount: type: integer description: Number of scanned variants/branches for this target example: 3 format: int64 minimum: 0 executionId: type: string description: Harness Execution ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ hasShiftLeftScan: type: boolean description: True when the scoped execution includes at least one ShiftLeft product scan default: false example: false isBaseline: type: boolean description: Whether the scoped variant is the baseline example: true issueFindingsMatrix: $ref: '#/components/schemas/TargetFindingsMatrix' issueNewDelta: type: integer description: Change in cumulative_open_issues_count vs the previous execution of the same target variant (current - previous). Issues card 'new' delta. Null when no previous execution exists. example: 3 format: int64 issueRemediatedDelta: type: integer description: Change in cumulative_remediated_issues_count vs the previous execution of the same target variant (current - previous). Issues card 'remediated' delta. Null when no previous execution exists. example: 1 format: int64 issueSeverityCounts: $ref: '#/components/schemas/RepositorySeverityCounts' name: type: string description: Target name example: NodeGoat occurrenceFindingsMatrix: $ref: '#/components/schemas/TargetFindingsMatrix' occurrenceNewDelta: type: integer description: Change in cumulative_open_occurrences_count vs the previous execution of the same target variant (current - previous). Findings card 'new' delta. Null when no previous execution exists. example: 4 format: int64 occurrenceRemediatedDelta: type: integer description: Change in cumulative_remediated_occurrences_count vs the previous execution of the same target variant (current - previous). Findings card 'remediated' delta. Null when no previous execution exists. example: 2 format: int64 occurrenceSeverityCounts: $ref: '#/components/schemas/RepositorySeverityCounts' packages: $ref: '#/components/schemas/ShiftLeftPackageCounts' scanTypes: type: array items: type: string example: Impedit soluta impedit consequuntur a quam. description: Scan types present (scan coverage chips) example: - SAST - SCA - SECRET scannedAt: type: integer description: Timestamp of the most recent scan, in milliseconds since Unix epoch example: 1751793300000 format: int64 targetId: type: string description: Target id (echoes path {id}) example: abcdef1234567890ghijkl targetUrl: type: string description: Target URL from execution_summary metadata.repositoryUrl for the scoped variant's latest execution. Omitted when not set. example: https://github.com/example/NodeGoat maxLength: 1024 type: type: string description: Target type example: repository enum: - container - repository - instance - configuration variantId: type: string description: Variant id for the scoped overview row (requested variant, or target_summary.variant_id on the default path) example: xyz987zyx654wvu321tsr9 pattern: ^[a-zA-Z0-9_-]{22}$ variantName: type: string description: Variant name for the scoped row (e.g. branch name) example: main description: 'Target detail overview: identity, findings/issues tiles, scan coverage, and severity matrices.' example: baselineVariantId: abcdef1234567890ghijkl branchesCount: 3 executionId: abcdef1234567890ghijkl hasShiftLeftScan: false isBaseline: true issueFindingsMatrix: columnTotals: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 grandTotal: 31 rows: - issueType: SAST severityCounts: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 total: 14 - issueType: SAST severityCounts: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 total: 14 - issueType: SAST severityCounts: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 total: 14 issueNewDelta: 3 issueRemediatedDelta: 1 issueSeverityCounts: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 name: NodeGoat occurrenceFindingsMatrix: columnTotals: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 grandTotal: 31 rows: - issueType: SAST severityCounts: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 total: 14 - issueType: SAST severityCounts: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 total: 14 - issueType: SAST severityCounts: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 total: 14 occurrenceNewDelta: 4 occurrenceRemediatedDelta: 2 occurrenceSeverityCounts: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 packages: container: 0 oss: 128 risky_oss: 1 vulnerable_container: 0 vulnerable_oss: 18 scanTypes: - SAST - SCA - SECRET scannedAt: 1751793300000 targetId: abcdef1234567890ghijkl targetUrl: https://github.com/example/NodeGoat type: repository variantId: xyz987zyx654wvu321tsr9 variantName: main required: - targetId - name - type - branchesCount - isBaseline - scanTypes - occurrenceSeverityCounts - issueSeverityCounts - occurrenceFindingsMatrix - issueFindingsMatrix - hasShiftLeftScan NotFound: type: object properties: message: type: string example: Not Found status: type: integer default: 404 example: 404 format: int64 example: message: Not Found status: 404 required: - message ShiftLeftPackageCounts: type: object properties: container: type: integer description: Total number of container packages example: 0 format: int64 minimum: 0 oss: type: integer description: Total number of OSS packages example: 128 format: int64 minimum: 0 risky_oss: type: integer description: Number of OSS packages with at least one OSS risk example: 1 format: int64 minimum: 0 vulnerable_container: type: integer description: Number of container packages with at least one vulnerability example: 0 format: int64 minimum: 0 vulnerable_oss: type: integer description: Number of OSS packages with at least one vulnerability example: 18 format: int64 minimum: 0 description: OSS and container package counts from Qwiet streamlined scan. example: container: 0 oss: 128 risky_oss: 1 vulnerable_container: 0 vulnerable_oss: 18 required: - oss - vulnerable_oss - risky_oss - container - vulnerable_container TargetScaPackagesResult: type: object properties: compound_id: type: string example: Eaque et velit praesentium et. has_more: type: boolean example: true packages: type: array items: $ref: '#/components/schemas/ScaPackage' example: - created_at: Mollitia sit ex cumque harum quis. exploitable: - Aut consequatur reiciendis facere sint fugit nesciunt. - Repudiandae omnis non necessitatibus et culpa. - Quia voluptatum autem doloribus. - Ut dolor voluptatem omnis alias fugit. finding_details: Perferendis vel laboriosam amet quia dicta.: Sint sequi nesciunt. finding_type: Illum laudantium sed. license: Et doloribus vel sit sint reprehenderit iste. name: Omnis voluptas fuga nobis aperiam assumenda et. namespace: Sit est est minima voluptas. num_exploitable: 7424730667882409000 num_reachable: 2381916510335179300 num_vulns: 1966980579282087200 package: Vitae laboriosam magni maiores cupiditate fuga magni. tags: Nulla a impedit.: - Accusantium dolores aliquid distinctio. - Molestias ut quos at. - Non ut ut occaecati soluta voluptas. - Velit necessitatibus laboriosam maxime explicabo est. Quasi eos quaerat occaecati aperiam possimus fuga.: - Sapiente neque sequi. - Vero ea et ut ipsa eum. Tempora asperiores sed beatae asperiores.: - Qui aut veritatis ab sed aut voluptates. - Nemo ipsam aspernatur quia eveniet. type: Ad illum. url: Iure aut vero aut rerum voluptas. version: Quas ut iusto explicabo molestiae perferendis ex. vulns: - Aspernatur veritatis voluptas natus et aut. - Voluptatem id dolor laudantium laudantium laudantium. - Similique porro odio totam. - created_at: Mollitia sit ex cumque harum quis. exploitable: - Aut consequatur reiciendis facere sint fugit nesciunt. - Repudiandae omnis non necessitatibus et culpa. - Quia voluptatum autem doloribus. - Ut dolor voluptatem omnis alias fugit. finding_details: Perferendis vel laboriosam amet quia dicta.: Sint sequi nesciunt. finding_type: Illum laudantium sed. license: Et doloribus vel sit sint reprehenderit iste. name: Omnis voluptas fuga nobis aperiam assumenda et. namespace: Sit est est minima voluptas. num_exploitable: 7424730667882409000 num_reachable: 2381916510335179300 num_vulns: 1966980579282087200 package: Vitae laboriosam magni maiores cupiditate fuga magni. tags: Nulla a impedit.: - Accusantium dolores aliquid distinctio. - Molestias ut quos at. - Non ut ut occaecati soluta voluptas. - Velit necessitatibus laboriosam maxime explicabo est. Quasi eos quaerat occaecati aperiam possimus fuga.: - Sapiente neque sequi. - Vero ea et ut ipsa eum. Tempora asperiores sed beatae asperiores.: - Qui aut veritatis ab sed aut voluptates. - Nemo ipsam aspernatur quia eveniet. type: Ad illum. url: Iure aut vero aut rerum voluptas. version: Quas ut iusto explicabo molestiae perferendis ex. vulns: - Aspernatur veritatis voluptas natus et aut. - Voluptatem id dolor laudantium laudantium laudantium. - Similique porro odio totam. - created_at: Mollitia sit ex cumque harum quis. exploitable: - Aut consequatur reiciendis facere sint fugit nesciunt. - Repudiandae omnis non necessitatibus et culpa. - Quia voluptatum autem doloribus. - Ut dolor voluptatem omnis alias fugit. finding_details: Perferendis vel laboriosam amet quia dicta.: Sint sequi nesciunt. finding_type: Illum laudantium sed. license: Et doloribus vel sit sint reprehenderit iste. name: Omnis voluptas fuga nobis aperiam assumenda et. namespace: Sit est est minima voluptas. num_exploitable: 7424730667882409000 num_reachable: 2381916510335179300 num_vulns: 1966980579282087200 package: Vitae laboriosam magni maiores cupiditate fuga magni. tags: Nulla a impedit.: - Accusantium dolores aliquid distinctio. - Molestias ut quos at. - Non ut ut occaecati soluta voluptas. - Velit necessitatibus laboriosam maxime explicabo est. Quasi eos quaerat occaecati aperiam possimus fuga.: - Sapiente neque sequi. - Vero ea et ut ipsa eum. Tempora asperiores sed beatae asperiores.: - Qui aut veritatis ab sed aut voluptates. - Nemo ipsam aspernatur quia eveniet. type: Ad illum. url: Iure aut vero aut rerum voluptas. version: Quas ut iusto explicabo molestiae perferendis ex. vulns: - Aspernatur veritatis voluptas natus et aut. - Voluptatem id dolor laudantium laudantium laudantium. - Similique porro odio totam. polyglot_scan_id: type: string example: Voluptatem et aut quia quia. scans: type: array items: $ref: '#/components/schemas/ScaScanRef' example: - app: owasp_nodegoat id: '298' - app: owasp_nodegoat id: '298' - app: owasp_nodegoat id: '298' - app: owasp_nodegoat id: '298' total_count: type: integer example: 3461914158197187600 format: int64 description: Qwiet SCA packages response for a target scan. example: compound_id: Id eum rem quibusdam. has_more: false packages: - created_at: Mollitia sit ex cumque harum quis. exploitable: - Aut consequatur reiciendis facere sint fugit nesciunt. - Repudiandae omnis non necessitatibus et culpa. - Quia voluptatum autem doloribus. - Ut dolor voluptatem omnis alias fugit. finding_details: Perferendis vel laboriosam amet quia dicta.: Sint sequi nesciunt. finding_type: Illum laudantium sed. license: Et doloribus vel sit sint reprehenderit iste. name: Omnis voluptas fuga nobis aperiam assumenda et. namespace: Sit est est minima voluptas. num_exploitable: 7424730667882409000 num_reachable: 2381916510335179300 num_vulns: 1966980579282087200 package: Vitae laboriosam magni maiores cupiditate fuga magni. tags: Nulla a impedit.: - Accusantium dolores aliquid distinctio. - Molestias ut quos at. - Non ut ut occaecati soluta voluptas. - Velit necessitatibus laboriosam maxime explicabo est. Quasi eos quaerat occaecati aperiam possimus fuga.: - Sapiente neque sequi. - Vero ea et ut ipsa eum. Tempora asperiores sed beatae asperiores.: - Qui aut veritatis ab sed aut voluptates. - Nemo ipsam aspernatur quia eveniet. type: Ad illum. url: Iure aut vero aut rerum voluptas. version: Quas ut iusto explicabo molestiae perferendis ex. vulns: - Aspernatur veritatis voluptas natus et aut. - Voluptatem id dolor laudantium laudantium laudantium. - Similique porro odio totam. - created_at: Mollitia sit ex cumque harum quis. exploitable: - Aut consequatur reiciendis facere sint fugit nesciunt. - Repudiandae omnis non necessitatibus et culpa. - Quia voluptatum autem doloribus. - Ut dolor voluptatem omnis alias fugit. finding_details: Perferendis vel laboriosam amet quia dicta.: Sint sequi nesciunt. finding_type: Illum laudantium sed. license: Et doloribus vel sit sint reprehenderit iste. name: Omnis voluptas fuga nobis aperiam assumenda et. namespace: Sit est est minima voluptas. num_exploitable: 7424730667882409000 num_reachable: 2381916510335179300 num_vulns: 1966980579282087200 package: Vitae laboriosam magni maiores cupiditate fuga magni. tags: Nulla a impedit.: - Accusantium dolores aliquid distinctio. - Molestias ut quos at. - Non ut ut occaecati soluta voluptas. - Velit necessitatibus laboriosam maxime explicabo est. Quasi eos quaerat occaecati aperiam possimus fuga.: - Sapiente neque sequi. - Vero ea et ut ipsa eum. Tempora asperiores sed beatae asperiores.: - Qui aut veritatis ab sed aut voluptates. - Nemo ipsam aspernatur quia eveniet. type: Ad illum. url: Iure aut vero aut rerum voluptas. version: Quas ut iusto explicabo molestiae perferendis ex. vulns: - Aspernatur veritatis voluptas natus et aut. - Voluptatem id dolor laudantium laudantium laudantium. - Similique porro odio totam. polyglot_scan_id: Laboriosam ut adipisci. scans: - app: owasp_nodegoat id: '298' - app: owasp_nodegoat id: '298' - app: owasp_nodegoat id: '298' total_count: 6560883881997615000 required: - packages - total_count - has_more - scans ScaScanRef: type: object properties: app: type: string description: App/compound name for this scan example: owasp_nodegoat id: type: string description: Scan ID example: '298' example: app: owasp_nodegoat id: '298' required: - id - app TargetExecution: type: object properties: branch: type: string description: Git branch scanned example: main maxLength: 256 buildId: type: string description: 'CI build id/number shown in UI (e.g. #222)' example: '222' commitSha: type: string description: Git commit SHA example: deadbeefdeadbeefdeadbeefdeadbeefdeadbeef maxLength: 64 durationMs: type: integer description: Execution duration in milliseconds example: 593000 format: int64 minimum: 0 executionId: type: string description: Harness Execution ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ executionUrl: type: string description: Deep link to the pipeline execution example: https://qa.harness.io/ng/account/acct/ci/orgs/default/projects/STO/pipelines/p/executions/e/pipeline maxLength: 1024 issueSeverityCounts: $ref: '#/components/schemas/RepositorySeverityCounts' occurrenceSeverityCounts: $ref: '#/components/schemas/RepositorySeverityCounts' pipelineName: type: string description: Pipeline name shown under the build id example: Security Gate maxLength: 256 scanTypes: type: array items: type: string example: Voluptatem veritatis illum est. description: Scan types run in this execution example: - SAST - SCA - SECRET source: type: string description: CI/CD platform that ran this execution (harness, jenkins, github_actions, gitlab_ci, ...) example: harness maxLength: 64 startedAt: type: integer description: Execution start time, milliseconds since Unix epoch example: 1751184000000 format: int64 triggeredBy: type: string description: User or bot that triggered the execution example: user@harness.io maxLength: 256 description: A single pipeline execution / build row on the target scan history page. example: branch: main buildId: '222' commitSha: deadbeefdeadbeefdeadbeefdeadbeefdeadbeef durationMs: 593000 executionId: abcdef1234567890ghijkl executionUrl: https://qa.harness.io/ng/account/acct/ci/orgs/default/projects/STO/pipelines/p/executions/e/pipeline issueSeverityCounts: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 occurrenceSeverityCounts: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 pipelineName: Security Gate scanTypes: - SAST - SCA - SECRET source: harness startedAt: 1751184000000 triggeredBy: user@harness.io required: - buildId - executionId - pipelineName - branch - commitSha - scanTypes - occurrenceSeverityCounts - issueSeverityCounts - triggeredBy - startedAt - durationMs TargetsListTargetExecutionOccurrencesResponseBody: type: object properties: pagination: $ref: '#/components/schemas/StoPagination' results: type: array items: $ref: '#/components/schemas/TargetExecutionOccurrenceSummary' example: - exemptionId: abcdef1234567890ghijkl issueId: abcdef1234567890ghijkl issueType: SAST occurrenceInternalId: 12345 scanId: scan111111111111111111 severityCode: Critical title: SQL injection enables authentication bypass - exemptionId: abcdef1234567890ghijkl issueId: abcdef1234567890ghijkl issueType: SAST occurrenceInternalId: 12345 scanId: scan111111111111111111 severityCode: Critical title: SQL injection enables authentication bypass - exemptionId: abcdef1234567890ghijkl issueId: abcdef1234567890ghijkl issueType: SAST occurrenceInternalId: 12345 scanId: scan111111111111111111 severityCode: Critical title: SQL injection enables authentication bypass - exemptionId: abcdef1234567890ghijkl issueId: abcdef1234567890ghijkl issueType: SAST occurrenceInternalId: 12345 scanId: scan111111111111111111 severityCode: Critical title: SQL injection enables authentication bypass example: pagination: link: '' page: 4 pageSize: 20 totalItems: 230 totalPages: 12 results: - exemptionId: abcdef1234567890ghijkl issueId: abcdef1234567890ghijkl issueType: SAST occurrenceInternalId: 12345 scanId: scan111111111111111111 severityCode: Critical title: SQL injection enables authentication bypass - exemptionId: abcdef1234567890ghijkl issueId: abcdef1234567890ghijkl issueType: SAST occurrenceInternalId: 12345 scanId: scan111111111111111111 severityCode: Critical title: SQL injection enables authentication bypass - exemptionId: abcdef1234567890ghijkl issueId: abcdef1234567890ghijkl issueType: SAST occurrenceInternalId: 12345 scanId: scan111111111111111111 severityCode: Critical title: SQL injection enables authentication bypass - exemptionId: abcdef1234567890ghijkl issueId: abcdef1234567890ghijkl issueType: SAST occurrenceInternalId: 12345 scanId: scan111111111111111111 severityCode: Critical title: SQL injection enables authentication bypass required: - results - pagination TargetFindingsMatrixRow: type: object properties: issueType: type: string description: Issue/scan type (e.g. SAST, SCA, SECRET) example: SAST severityCounts: $ref: '#/components/schemas/RepositorySeverityCounts' total: type: integer description: Row total (sum of severity buckets) example: 14 format: int64 minimum: 0 description: Findings or issues for one issue type, broken down by severity. example: issueType: SAST severityCounts: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 total: 14 required: - issueType - severityCounts - total TargetsListTargetExecutionsResponseBody: type: object properties: pagination: $ref: '#/components/schemas/StoPagination' results: type: array items: $ref: '#/components/schemas/TargetExecution' example: - branch: main buildId: '222' commitSha: deadbeefdeadbeefdeadbeefdeadbeefdeadbeef durationMs: 593000 executionId: abcdef1234567890ghijkl executionUrl: https://qa.harness.io/ng/account/acct/ci/orgs/default/projects/STO/pipelines/p/executions/e/pipeline issueSeverityCounts: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 occurrenceSeverityCounts: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 pipelineName: Security Gate scanTypes: - SAST - SCA - SECRET source: harness startedAt: 1751184000000 triggeredBy: user@harness.io - branch: main buildId: '222' commitSha: deadbeefdeadbeefdeadbeefdeadbeefdeadbeef durationMs: 593000 executionId: abcdef1234567890ghijkl executionUrl: https://qa.harness.io/ng/account/acct/ci/orgs/default/projects/STO/pipelines/p/executions/e/pipeline issueSeverityCounts: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 occurrenceSeverityCounts: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 pipelineName: Security Gate scanTypes: - SAST - SCA - SECRET source: harness startedAt: 1751184000000 triggeredBy: user@harness.io example: pagination: link: '' page: 4 pageSize: 20 totalItems: 230 totalPages: 12 results: - branch: main buildId: '222' commitSha: deadbeefdeadbeefdeadbeefdeadbeefdeadbeef durationMs: 593000 executionId: abcdef1234567890ghijkl executionUrl: https://qa.harness.io/ng/account/acct/ci/orgs/default/projects/STO/pipelines/p/executions/e/pipeline issueSeverityCounts: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 occurrenceSeverityCounts: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 pipelineName: Security Gate scanTypes: - SAST - SCA - SECRET source: harness startedAt: 1751184000000 triggeredBy: user@harness.io - branch: main buildId: '222' commitSha: deadbeefdeadbeefdeadbeefdeadbeefdeadbeef durationMs: 593000 executionId: abcdef1234567890ghijkl executionUrl: https://qa.harness.io/ng/account/acct/ci/orgs/default/projects/STO/pipelines/p/executions/e/pipeline issueSeverityCounts: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 occurrenceSeverityCounts: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 pipelineName: Security Gate scanTypes: - SAST - SCA - SECRET source: harness startedAt: 1751184000000 triggeredBy: user@harness.io - branch: main buildId: '222' commitSha: deadbeefdeadbeefdeadbeefdeadbeefdeadbeef durationMs: 593000 executionId: abcdef1234567890ghijkl executionUrl: https://qa.harness.io/ng/account/acct/ci/orgs/default/projects/STO/pipelines/p/executions/e/pipeline issueSeverityCounts: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 occurrenceSeverityCounts: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 pipelineName: Security Gate scanTypes: - SAST - SCA - SECRET source: harness startedAt: 1751184000000 triggeredBy: user@harness.io required: - results - pagination securitySchemes: x-api-key: name: x-api-key type: apiKey in: header description: API key is a token provided while making the API calls. This is used to authenticate the client at the exposed endpoint. externalDocs: description: Find out more about Swagger url: http://swagger.io x-stoplight: id: oc91t4vrfnjyi x-tagGroups: - name: Organizations tags: - Organization - name: Projects tags: - Org Project - Project - name: Secrets tags: - Account Secret - Org Secret - Project Secret - Secrets - name: Connectors tags: - Account Connector - Org Connector - Project Connector - Connectors - GoogleSecretManagerConnector - name: Roles tags: - Account Roles - Organization Roles - Project Roles - Roles - name: Resource Groups tags: - Account Resource Groups - Organization Resource Groups - Project Resource Groups - Filter Resource Groups - Harness Resource Group - Zendesk - name: Role Assignments tags: - Account Role Assignments - Org Role Assignments - Project Role Assignments - Role Assignments - name: Platform tags: - Access Control List - Account Banner - Account Banner - Account Licensed Modules - Account License Type - Account Webhooks - AccountSetting - Accounts - Analyze Account Access Policy - Analyze Organization Access Policy - Analyze Project Access Policy - ApiKey - Audit - AuditFilters - Authentication Settings - Canny - Devops Essentials License Data By Account - EULA - Filter - Harness Resource Type - Invite - IP Allowlist - Nextgen Ldap - Notification Channels - Notification Rules - OIDC - Oidc-Access-Token - Oidc-ID-Token - Org Webhooks - Permissions - Project Webhooks - Secret Managers - Service Account - Setting - SMTP - Source Code Manager - Token - User - User Group - Variables - name: Delegate tags: - Agent mTLS Endpoint Management - Delegate Download Resource - Delegate Group Tags Resource - Delegate Setup Resource - Delegate Token Resource - name: Pipelines tags: - Pipelines - Input Sets - Approvals - Pipeline Execution - Pipeline Dashboard - Pipeline Input Set - Pipeline - Pipeline Execution Details - Pipeline Execute - Pipeline Refresh - Pipeline data retention - Triggers - TriggersEvents - Webhook Triggers - Webhook Event Handler - DryRunPipeline - name: Artifact Registry tags: - Registries - Artifacts - Docker Artifacts - Helm Artifacts - quarantine - Webhooks - Spaces - Replication - Registry V3 - Registries - Registry V3 - Packages - Registry V3 - Versions - Registry V3 - Files - Registry V3 - Metadata - Registry V3 - Firewall - Registry V3 - Transfer - name: Database DevOps tags: - Database Schema - Database Instance - Deployed State - Execution Config - Migration State - name: CD tags: - K8s Release Service Mapping - CustomDeployment - Environments - EnvironmentGroup - Infrastructures - Usage - File Store - Service Dashboard - ServiceOverrides - Rollback - tas - name: Deployment Freeze tags: - Freeze CRUD - Freeze Evaluation - Freeze Schema - name: Services tags: - Account Services - Org Services - Project Services - Services - name: Rancher Infrastructures tags: - Account Rancher Infrastructure - Org Rancher Infrastructure - Project Rancher Infrastructure - name: Templates tags: - Account Template - Org Template - Project Template - Templates - Global Templates - name: GitOps tags: - Agents - Application - Applications - Certificates - Clusters - Dashboard Aggregates - Dashboards - GnuPGP Keys - GPG Keys - Hosts - Project mappings - Projects - Reconciler - Repositories - Repository Certificates - Repository credentials - ValidateHost - name: GitX tags: - GitX Webhooks - Org Gitx Webhooks - Project Gitx Webhooks - name: CACM tags: - Anomalies Ignorelist Rule - Anomalies - BI Dashboards - Budgets - Budget Groups - Cost Categories - Cloud Accounts - K8S Connectors Metadata - Notification Settings v2 - Overview - Data Job Status - Recommendation cost settings - Unit Metric - Anomaly Comments - Cloud and AI cost anomaly details - Cloud and AI cost anomalies v2 - Cost Details - Currency Preferences - External Data Provider - AiEngine - CACM governance cost settings - Governance Enforcement Recommendation APIs - Governance Alert - Governance Overview - Governance Recommendation APIs - RuleEnforcement - Rule Executions - Rule - Rule Sets - Perspectives Folders - Perspective Reports - Perspectives - Cost Category Jira Project Mapping - Recommendations Details - Recommendations - Recommendation Jira - Recommendation Preferences - Recommendation Presets - Recommendation Servicenow - Recommendation Tags - Recommendation Ignore List - AutoStopping Rules - AutoStopping Rules V2 - AutoStopping Load Balancers - AutoStopping Fixed Schedules - AutoStopping Alerts - Commitment Orchestrator Events APIs - name: Feature Flags tags: - API Keys - Feature Flags - Targets - Target Groups - Environment Perspectives - Anomalies - Proxy - Tags - name: SRM tags: - Monitored Services - SLOs dashboard - NG SLOs - SLOs - Downtime - Srm Notification - name: Internal Developer Portal - IDP tags: - Entities - Teams - CatalogCustomProperties - Scores - DataSource - KubernetesDataPoints - AggregationRules - AppConfig - PluginInfo - LayoutProxy - Kinds - LayoutsV3 - LayoutsV4 - name: Environment Management - IDP tags: - Environment - Infrastructure - Instance - name: Custom Dashboards tags: - aida - dashboards - downloads - embed - folders - name: Policy Management tags: - dashboard - examples - policies - evaluate - evaluations - policysets - system - name: Code tags: - repository - status_checks - pullreq - upload - webhook - resource - rules - labels - name: IaCM tags: - usage - approvals - costs - executions - module-registry - workspaces - settings - tf-standard-backend - variables - name: STO tags: - Exemptions - Issues - Scans - Products - Test Targets - Target Variants - name: SEI tags: - Collection categories - Collections - Contributors - DORA - name: Git Sync (deprecated) tags: - Git Branches - Git Full Sync - Git Sync Settings - Git Sync - Git Sync Errors - name: Error Models tags: - Error Response - Governance Metadata - name: Supply Chain Security tags: - integration - PipelineInfraConfig - SBOM - Integration Step Config - Delete Step Config - Delete Repositories - Pipeline Store Config - Evidence Vault [Beta] - name: Release Management tags: - Release Groups - Releases - Orchestration Processes - Orchestration Activities - Orchestration Executions - Conflicts - Freeze - Reports - Uploads - name: Resilience Testing tags: - Actions - Action Templates - Chaos Components - Chaos Hubs - ChaosGuard Conditions - ChaosGuard Rules - DR Tests - Experiments - Experiment Templates - Faults - Fault Templates - Chaos Infrastructure - Health - Network Maps - Onboarding - Probes - Probe Templates - Chaos Recommendations - Risks