openapi: 3.2.0 info: title: Palo Alto Networks Coderepos Ci API version: '1.0' description: 'Operations tagged Coderepos-Ci across 4 of this provider''s published API definitions: palo-alto-compute-34-03-openapi-34-03-138-sh-openapi.json, palo-alto-compute-openapi-34-04-145-sh-openapi.json, palo-alto-cwpp-34-03-openapi-34-03-138-saas-openapi.json, palo-alto-cwpp-openapi-34-04-145-saas-openapi.json. Each path carries the servers of the definition it was published in.' servers: - url: PATH_TO_CONSOLE tags: - name: Coderepos-Ci paths: /api/v34.03/coderepos-ci/evaluate: post: description: 'Resolve Code Repos. POST /api/v34.03/coderepos-ci/evaluate on the Coderepos-Ci API. Takes an optional request body. Documented responses: 200.' requestBody: content: application/json: schema: $ref: '#/components/schemas/coderepos.ScanResult' responses: '200': content: application/json: schema: $ref: '#/components/schemas/coderepos.ScanResult' description: ScanResult holds a specific repository data default: description: '' tags: - Coderepos-Ci x-prisma-cloud-target-env: permission: monitorCI operationId: post-coderepos-ci-evaluate summary: Resolve Code Repos x-description-source: desc/coderepos-ci/post_resolve.md /api/v34.04/coderepos-ci/evaluate: post: description: 'Resolve Code Repos. POST /api/v34.04/coderepos-ci/evaluate on the Coderepos-Ci API. Takes an optional request body. Documented responses: 200.' requestBody: content: application/json: schema: $ref: '#/components/schemas/coderepos.ScanResult' responses: '200': content: application/json: schema: $ref: '#/components/schemas/coderepos.ScanResult' description: ScanResult holds a specific repository data default: description: '' tags: - Coderepos-Ci x-prisma-cloud-target-env: permission: monitorCI operationId: post-coderepos-ci-evaluate summary: Resolve Code Repos x-description-source: desc/coderepos-ci/post_resolve.md components: schemas: vuln.Application: description: Application represents a detected application properties: installedFromPackage: description: 'Indicates that the app was installed as an OS package. ' type: boolean knownVulnerabilities: description: 'Total number of vulnerabilities for this application. ' type: integer layerTime: description: 'Image layer to which the application belongs - layer creation time. ' format: int64 type: integer md5: description: 'MD5 is the md5sum of the app. ' type: string name: description: 'Name of the application. ' type: string originPackageName: description: 'OriginPackageName is the name of the app origin package. ' type: string path: description: 'Path of the detected application. ' type: string rpmModule: description: 'RPMModule represents the RPM module in which this application is included. ' type: string service: description: 'Service indicates whether the application is installed as a service. ' type: boolean version: description: 'Version of the application. ' type: string type: object vulnerability.ExploitType: description: ExploitType represents the source of an exploit enum: - - '' - exploit-db - exploit-windows - cisa-kev type: string license.SPDXLicense: description: SPDXLicense represents a SPDX license ID enum: - - 0BSD - AAL - ADSL - AFL-1.1 - AFL-1.2 - AFL-2.0 - AFL-2.1 - AFL-3.0 - AGPL-1.0 - AGPL-1.0-only - AGPL-1.0-or-later - AGPL-3.0 - AGPL-3.0-only - AGPL-3.0-or-later - AMDPLPA - AML - AMPAS - ANTLR-PD - ANTLR-PD-fallback - APAFML - APL-1.0 - APSL-1.0 - APSL-1.1 - APSL-1.2 - APSL-2.0 - Abstyles - Adobe-2006 - Adobe-Glyph - Afmparse - Aladdin - Apache-1.0 - Apache-1.1 - Apache-2.0 - Artistic-1.0 - Artistic-1.0-Perl - Artistic-1.0-cl8 - Artistic-2.0 - BSD-1-Clause - BSD-2-Clause - BSD-2-Clause-FreeBSD - BSD-2-Clause-NetBSD - BSD-2-Clause-Patent - BSD-2-Clause-Views - BSD-3-Clause - BSD-3-Clause-Attribution - BSD-3-Clause-Clear - BSD-3-Clause-LBNL - BSD-3-Clause-No-Nuclear-License - BSD-3-Clause-No-Nuclear-License-2014 - BSD-3-Clause-No-Nuclear-Warranty - BSD-3-Clause-Open-MPI - BSD-4-Clause - BSD-4-Clause-UC - BSD-Protection - BSD-Source-Code - BSL-1.0 - BUSL-1.1 - Bahyph - Barr - Beerware - BitTorrent-1.0 - BitTorrent-1.1 - BlueOak-1.0.0 - Borceux - CAL-1.0 - CAL-1.0-Combined-Work-Exception - CATOSL-1.1 - CC-BY-1.0 - CC-BY-2.0 - CC-BY-2.5 - CC-BY-3.0 - CC-BY-3.0-AT - CC-BY-3.0-US - CC-BY-4.0 - CC-BY-NC-1.0 - CC-BY-NC-2.0 - CC-BY-NC-2.5 - CC-BY-NC-3.0 - CC-BY-NC-4.0 - CC-BY-NC-ND-1.0 - CC-BY-NC-ND-2.0 - CC-BY-NC-ND-2.5 - CC-BY-NC-ND-3.0 - CC-BY-NC-ND-3.0-IGO - CC-BY-NC-ND-4.0 - CC-BY-NC-SA-1.0 - CC-BY-NC-SA-2.0 - CC-BY-NC-SA-2.5 - CC-BY-NC-SA-3.0 - CC-BY-NC-SA-4.0 - CC-BY-ND-1.0 - CC-BY-ND-2.0 - CC-BY-ND-2.5 - CC-BY-ND-3.0 - CC-BY-ND-4.0 - CC-BY-SA-1.0 - CC-BY-SA-2.0 - CC-BY-SA-2.0-UK - CC-BY-SA-2.5 - CC-BY-SA-3.0 - CC-BY-SA-3.0-AT - CC-BY-SA-4.0 - CC-PDDC - CC0-1.0 - CDDL-1.0 - CDDL-1.1 - CDLA-Permissive-1.0 - CDLA-Sharing-1.0 - CECILL-1.0 - CECILL-1.1 - CECILL-2.0 - CECILL-2.1 - CECILL-B - CECILL-C - CERN-OHL-1.1 - CERN-OHL-1.2 - CERN-OHL-P-2.0 - CERN-OHL-S-2.0 - CERN-OHL-W-2.0 - CNRI-Jython - CNRI-Python - CNRI-Python-GPL-Compatible - CPAL-1.0 - CPL-1.0 - CPOL-1.02 - CUA-OPL-1.0 - Caldera - ClArtistic - Condor-1.1 - Crossword - CrystalStacker - Cube - D-FSL-1.0 - DOC - DSDP - Dotseqn - ECL-1.0 - ECL-2.0 - EFL-1.0 - EFL-2.0 - EPICS - EPL-1.0 - EPL-2.0 - EUDatagrid - EUPL-1.0 - EUPL-1.1 - EUPL-1.2 - Entessa - ErlPL-1.1 - Eurosym - FSFAP - FSFUL - FSFULLR - FTL - Fair - Frameworx-1.0 - FreeImage - GFDL-1.1 - GFDL-1.1-invariants-only - GFDL-1.1-invariants-or-later - GFDL-1.1-no-invariants-only - GFDL-1.1-no-invariants-or-later - GFDL-1.1-only - GFDL-1.1-or-later - GFDL-1.2 - GFDL-1.2-invariants-only - GFDL-1.2-invariants-or-later - GFDL-1.2-no-invariants-only - GFDL-1.2-no-invariants-or-later - GFDL-1.2-only - GFDL-1.2-or-later - GFDL-1.3 - GFDL-1.3-invariants-only - GFDL-1.3-invariants-or-later - GFDL-1.3-no-invariants-only - GFDL-1.3-no-invariants-or-later - GFDL-1.3-only - GFDL-1.3-or-later - GL2PS - GLWTPL - GPL-1.0 - GPL-1.0+ - GPL-1.0-only - GPL-1.0-or-later - GPL-2.0 - GPL-2.0+ - GPL-2.0-only - GPL-2.0-or-later - GPL-2.0-with-GCC-exception - GPL-2.0-with-autoconf-exception - GPL-2.0-with-bison-exception - GPL-2.0-with-classpath-exception - GPL-2.0-with-font-exception - GPL-3.0 - GPL-3.0+ - GPL-3.0-only - GPL-3.0-or-later - GPL-3.0-with-GCC-exception - GPL-3.0-with-autoconf-exception - Giftware - Glide - Glulxe - HPND - HPND-sell-variant - HTMLTIDY - HaskellReport - Hippocratic-2.1 - IBM-pibs - ICU - IJG - IPA - IPL-1.0 - ISC - ImageMagick - Imlib2 - Info-ZIP - Intel - Intel-ACPI - Interbase-1.0 - JPNIC - JSON - JasPer-2.0 - LAL-1.2 - LAL-1.3 - LGPL-2.0 - LGPL-2.0+ - LGPL-2.0-only - LGPL-2.0-or-later - LGPL-2.1 - LGPL-2.1+ - LGPL-2.1-only - LGPL-2.1-or-later - LGPL-3.0 - LGPL-3.0+ - LGPL-3.0-only - LGPL-3.0-or-later - LGPLLR - LPL-1.0 - LPL-1.02 - LPPL-1.0 - LPPL-1.1 - LPPL-1.2 - LPPL-1.3a - LPPL-1.3c - Latex2e - Leptonica - LiLiQ-P-1.1 - LiLiQ-R-1.1 - LiLiQ-Rplus-1.1 - Libpng - Linux-OpenIB - MIT - MIT-0 - MIT-CMU - MIT-advertising - MIT-enna - MIT-feh - MIT-open-group - MITNFA - MPL-1.0 - MPL-1.1 - MPL-2.0 - MPL-2.0-no-copyleft-exception - MS-PL - MS-RL - MTLL - MakeIndex - MirOS - Motosoto - MulanPSL-1.0 - MulanPSL-2.0 - Multics - Mup - NASA-1.3 - NBPL-1.0 - NCGL-UK-2.0 - NCSA - NGPL - NIST-PD - NIST-PD-fallback - NLOD-1.0 - NLPL - NOSL - NPL-1.0 - NPL-1.1 - NPOSL-3.0 - NRL - NTP - NTP-0 - Naumen - Net-SNMP - NetCDF - Newsletr - Nokia - Noweb - Nunit - O-UDA-1.0 - OCCT-PL - OCLC-2.0 - ODC-By-1.0 - ODbL-1.0 - OFL-1.0 - OFL-1.0-RFN - OFL-1.0-no-RFN - OFL-1.1 - OFL-1.1-RFN - OFL-1.1-no-RFN - OGC-1.0 - OGL-Canada-2.0 - OGL-UK-1.0 - OGL-UK-2.0 - OGL-UK-3.0 - OGTSL - OLDAP-1.1 - OLDAP-1.2 - OLDAP-1.3 - OLDAP-1.4 - OLDAP-2.0 - OLDAP-2.0.1 - OLDAP-2.1 - OLDAP-2.2 - OLDAP-2.2.1 - OLDAP-2.2.2 - OLDAP-2.3 - OLDAP-2.4 - OLDAP-2.5 - OLDAP-2.6 - OLDAP-2.7 - OLDAP-2.8 - OML - OPL-1.0 - OSET-PL-2.1 - OSL-1.0 - OSL-1.1 - OSL-2.0 - OSL-2.1 - OSL-3.0 - OpenSSL - PDDL-1.0 - PHP-3.0 - PHP-3.01 - PSF-2.0 - Parity-6.0.0 - Parity-7.0.0 - Plexus - PolyForm-Noncommercial-1.0.0 - PolyForm-Small-Business-1.0.0 - PostgreSQL - Python-2.0 - QPL-1.0 - Qhull - RHeCos-1.1 - RPL-1.1 - RPL-1.5 - RPSL-1.0 - RSA-MD - RSCPL - Rdisc - Ruby - SAX-PD - SCEA - SGI-B-1.0 - SGI-B-1.1 - SGI-B-2.0 - SHL-0.5 - SHL-0.51 - SISSL - SISSL-1.2 - SMLNJ - SMPPL - SNIA - SPL-1.0 - SSH-OpenSSH - SSH-short - SSPL-1.0 - SWL - Saxpath - Sendmail - Sendmail-8.23 - SimPL-2.0 - Sleepycat - Spencer-86 - Spencer-94 - Spencer-99 - StandardML-NJ - SugarCRM-1.1.3 - TAPR-OHL-1.0 - TCL - TCP-wrappers - TMate - TORQUE-1.1 - TOSL - TU-Berlin-1.0 - TU-Berlin-2.0 - UCL-1.0 - UPL-1.0 - Unicode-DFS-2015 - Unicode-DFS-2016 - Unicode-TOU - Unlicense - VOSTROM - VSL-1.0 - Vim - W3C - W3C-19980720 - W3C-20150513 - WTFPL - Watcom-1.0 - Wsuipa - X11 - XFree86-1.1 - XSkat - Xerox - Xnet - YPL-1.0 - YPL-1.1 - ZPL-1.1 - ZPL-2.0 - ZPL-2.1 - Zed - Zend-2.0 - Zimbra-1.3 - Zimbra-1.4 - Zlib - blessing - bzip2-1.0.5 - bzip2-1.0.6 - copyleft-next-0.3.0 - copyleft-next-0.3.1 - curl - diffmark - dvipdfm - eCos-2.0 - eGenix - etalab-2.0 - gSOAP-1.3b - gnuplot - iMatix - libpng-2.0 - libselinux-1.0 - libtiff - mpich2 - psfrag - psutils - wxWindows - xinetd - xpp - zlib-acknowledgement type: string shared.ImageTag: description: ImageTag represents an image repository and its associated tag or registry digest properties: digest: description: 'Image digest (requires V2 or later registry). ' type: string id: description: 'ID of the image. ' type: string registry: description: 'Registry name to which the image belongs. ' type: string repo: description: 'Repository name to which the image belongs. ' type: string tag: description: 'Image tag. ' type: string type: object common.CloudMetadata: description: CloudMetadata is the metadata for a cloud provider managed asset (e.g., as part of AWS/GCP/Azure/OCI) properties: accountID: description: 'Cloud account ID. ' type: string awsExecutionEnv: description: 'AWS execution environment (e.g. EC2/Fargate). ' type: string azure: $ref: '#/components/schemas/common.AzureMetadata' gcp: $ref: '#/components/schemas/common.GCPCloudMetadata' image: description: 'The name of the image the cloud managed host or container is based on. ' type: string labels: description: 'Cloud provider metadata labels. ' items: $ref: '#/components/schemas/common.ExternalLabel' type: array name: description: 'Resource name. ' type: string ociTenantID: description: 'OCI Tenant ID. ' type: string provider: $ref: '#/components/schemas/common.CloudProvider' region: description: 'Resource''s region. ' type: string resourceID: description: 'Unique ID of the resource. ' type: string resourceURL: description: 'Server-defined URL for the resource. ' type: string type: description: 'Instance type. ' type: string vmID: description: 'Azure unique vm ID. ' type: string vmImageID: description: 'VMImageID holds the VM instance''s image ID. ' type: string type: object common.NetworkDeviceIP: description: NetworkDeviceIP represents a network device name and address pair properties: ip: description: 'Network device IPv4 address. ' type: string name: description: 'Network device name. ' type: string type: object common.Color: description: Color is a hexadecimal representation of color code value type: string common.ACIMetadata: properties: containerGroup: description: '. ' type: string type: object secrets.SecretScanMetrics: description: SecretScanMetrics represents metrics collected during secret scan properties: failedScans: description: 'FailedScans represents number of failed scans caused by scanner errors. ' format: int64 type: integer foundSecrets: description: 'FoundSecrets represents number of detected secrets. ' type: integer scanTime: description: 'ScanTime represents cumulative secret scan time in microseconds. ' format: int64 type: integer scanTimeouts: description: 'ScanTimeouts represents number of failed scans caused by timeout. ' format: int64 type: integer scannedFileSize: description: 'ScannedFileSize represents accumulated size of scanned files. ' format: int64 type: integer scannedFiles: description: 'ScannedFiles represents number of text files scanned for secrets. ' format: int64 type: integer totalBytes: description: 'TotalBytes represents accumulated file size. ' format: int64 type: integer totalFiles: description: 'TotalFiles represents number of files read for secrets. ' format: int64 type: integer totalTime: description: 'TotalTime represents the total time in microseconds. ' format: int64 type: integer typesCount: additionalProperties: $ref: '#/components/schemas/int' description: 'TypesCount represents distribution of secrets by its type. ' type: object type: object shared.Packages: description: Packages is a collection of packages properties: pkgs: description: 'List of packages. ' items: $ref: '#/components/schemas/shared.Package' type: array pkgsType: $ref: '#/components/schemas/packages.Type' type: object vuln.ComplianceTemplate: description: ComplianceTemplate represents the compliance template enum: - - PCI - HIPAA - NIST SP 800-190 - GDPR - DISA STIG type: string shared.FileDetails: description: FileDetails contains file details as the file path, hash checksum properties: md5: description: 'Hash sum of the file using md5. ' type: string original_file_location: description: 'Path of the original file in a case of archive analysis. ' type: string path: description: 'Path of the file. ' type: string sha1: description: 'Hash sum of the file using SHA-1. ' type: string sha256: description: 'Hash sum of the file using SHA256. ' type: string type: object vuln.SecretType: description: SecretType represents a secret type enum: - - AWS Access Key ID - AWS Secret Key - AWS MWS Auth Token - Azure Storage Account Access Key - Azure Service Principal - GCP Service Account Auth Key - Private Encryption Key - Public Encryption Key - PEM X509 Certificate Header - SSH Authorized Keys - Artifactory API Token - Artifactory Password - Basic Auth Credentials - Mailchimp Access Key - NPM Token - Slack Token - Slack Webhook - Square OAuth Secret - Notion Integration Token - Airtable API Key - Atlassian Oauth2 Keys - CircleCI Personal Token - Databricks Authentication Token - GitHub Token - GitLab Token - Google API key - Grafana Token - Python Package Index Key (PYPI) - Typeform API Token - Scalr Token - Braintree Access Token - Braintree Payments Key - Paypal Token Key - Braintree Payments ID - Datadog Client Token - ClickUp Personal API Token - OpenAI API Key - Java DB Connectivity (JDBC) - MongoDB - .Net SQL Server type: string coderepos.PkgDependency: description: PkgDependency represents a required package properties: devDependency: description: 'Indicates if this dependency is used only for the development of the package (true) or not (false). ' type: boolean lastResolved: description: 'Date/time of the last version resolution. If the value is zero, it means the version is explicit and does not require resolving. ' format: date-time type: string licenseSeverity: description: 'Maximum severity of the detected licenses according to the compliance policy. ' type: string licenses: description: 'Detected licenses of the dependant package. ' items: $ref: '#/components/schemas/license.SPDXLicense' type: array name: description: 'Package name that the dependency refers to. ' type: string rawRequirement: description: 'Line in which the package is declared. ' type: string unsupported: description: 'Indicates if this package is unsupported by the remote package manager DB (e.g., due to a bad name or private package) (true) or not (false). ' type: boolean version: description: 'Package version, either explicitly specified in a manifest or resolved by the scanner. ' type: string vulnerabilities: description: 'Vulnerabilities in the package. ' items: $ref: '#/components/schemas/vuln.Vulnerability' type: array type: object common.CloudRunMetadata: properties: revision: description: '. ' type: string service: description: '. ' type: string type: object vulnerability.RiskFactors: additionalProperties: $ref: '#/components/schemas/string' description: RiskFactors maps the existence of vulnerability risk factors type: object vulnerability.Type: description: Type represents the vulnerability type enum: - - container - image - host_config - daemon_config - daemon_config_files - security_operations - k8s_master - k8s_worker - k8s_federation - linux - windows - istio - serverless - custom - docker_stig - openshift_master - openshift_worker - application_control_linux - gke_worker - image_malware - host_malware - aks_worker - eks_worker - image_secret - host_secret type: string common.CloudProvider: description: CloudProvider specifies the cloud provider name enum: - - aws - azure - gcp - alibaba - oci - others type: string common.GCPCloudMetadata: properties: cloudRun: $ref: '#/components/schemas/common.CloudRunMetadata' type: object vuln.AllCompliance: description: AllCompliance contains data regarding passed compliance checks properties: compliance: description: 'Compliance are all the passed compliance checks. ' items: $ref: '#/components/schemas/vuln.Vulnerability' type: array enabled: description: 'Enabled indicates whether passed compliance checks is enabled by policy. ' type: boolean type: object shared.PkgsTimes: description: PkgsTimes are the compressed layer times for pkgs of the specific type properties: pkgTimes: description: '. ' items: $ref: '#/components/schemas/int64' type: array pkgsType: $ref: '#/components/schemas/packages.Type' type: object vulnerability.ExploitData: description: ExploitData holds information about an exploit properties: kind: $ref: '#/components/schemas/vulnerability.ExploitKind' link: description: 'Link is a link to information about the exploit. ' type: string source: $ref: '#/components/schemas/vulnerability.ExploitType' type: object common.ExternalLabel: description: ExternalLabel holds an external label with a source and timestamp properties: key: description: 'Label key. ' type: string sourceName: description: 'Source name (e.g., for a namespace, the source name can be ''twistlock''). ' type: string sourceType: $ref: '#/components/schemas/common.ExternalLabelSourceType' timestamp: description: 'Time when the label was fetched. ' format: date-time type: string value: description: 'Value of the label. ' type: string type: object string: type: string vuln.WildFireMalware: description: WildFireMalware holds the data for WildFire malicious MD5 properties: md5: description: 'MD5 is the hash of the malicious binary. ' type: string path: description: 'Path is the path to malicious binary. ' type: string verdict: description: 'Verdict is the malicious source like grayware, malware and phishing. ' type: string type: object vuln.Secret: description: Secret represents a secret found on the scanned workload properties: group: description: 'Group is a group name or ID of owner the file metadata containing the secret. ' type: string locationInFile: description: 'LocationInFile is the line and offset in the file where the secret was found. ' type: string metadataModifiedTime: description: 'MetadataModifiedTime is the modification time of the file metadata containing the secret. ' format: int64 type: integer modifiedTime: description: 'ModifiedTime is the modification time of the file containing the secret. ' format: int64 type: integer originalFileLocation: description: '. ' type: string path: description: 'Path is the path of the file in which the secret was found. ' type: string permissions: description: 'Permissions are permission bits of the file metadata containing the secret. ' type: string secretID: description: 'SecretID is the SHA1 of the secret content. ' type: string size: description: 'Size is the size in bytes of the file in which the secret was found. ' format: int64 type: integer snippet: description: 'Snippet is the partial plain secret. ' type: string type: $ref: '#/components/schemas/vuln.SecretType' user: description: 'User is a username or ID of owner the file metadata containing the secret. ' type: string type: object shared.CodeRepoProviderType: description: CodeRepoProviderType is the type of provider for the code repository, e.g., GitHub, GitLab etc enum: - - github - CI type: string coderepos.ManifestFile: description: ManifestFile holds the data of a specific manifest file (can also be of a dependency manifest file) properties: dependencies: description: 'Packages listed in the manifest file. ' items: $ref: '#/components/schemas/coderepos.PkgDependency' type: array distribution: $ref: '#/components/schemas/vuln.Distribution' path: description: 'Path to the file. ' type: string type: $ref: '#/components/schemas/packages.Type' type: object vuln.Vulnerability: description: Vulnerability is a general schema for vulnerabilities (e.g., for compliance or packages) properties: applicableRules: description: 'Rules applied on the package. ' items: $ref: '#/components/schemas/string' type: array binaryPkgs: description: 'Names of the distro binary package names (packages which are built from the source of the package). ' items: $ref: '#/components/schemas/string' type: array block: description: 'Indicates if the vulnerability has a block effect (true) or not (false). ' type: boolean cause: description: 'Additional information regarding the root cause for the vulnerability. ' type: string cri: description: 'Indicates if this is a CRI-specific vulnerability (true) or not (false). ' type: boolean custom: description: 'Indicates if the vulnerability is a custom vulnerability (e.g., openscap, sandbox) (true) or not (false). ' type: boolean cve: description: 'CVE ID of the vulnerability (if applied). ' type: string cvss: description: 'CVSS score of the vulnerability. ' format: float type: number description: description: 'Description of the vulnerability. ' type: string discovered: description: 'Specifies the time of discovery for the vulnerability. ' format: date-time type: string exploit: $ref: '#/components/schemas/vulnerability.ExploitType' exploits: $ref: '#/components/schemas/vulnerability.Exploits' fixDate: description: 'Date/time when the vulnerability was fixed (in Unix time). ' format: int64 type: integer fixLink: description: 'Link to the vendor''s fixed-version information. ' type: string functionLayer: description: 'Specifies the serverless layer ID in which the vulnerability was discovered. ' type: string gracePeriodDays: description: 'Number of grace days left for a vulnerability, based on the configured grace period. Nil if no block vulnerability rule applies. ' type: integer id: description: 'ID of the violation. ' type: integer isRPMModule: description: 'IsRPMModule indicates whether this vulnerability is specific to an RPM module. ' type: boolean layerTime: description: 'Date/time of the image layer to which the CVE belongs. ' format: int64 type: integer link: description: 'Vendor link to the CVE. ' type: string packageName: description: 'Name of the package that caused the vulnerability. ' type: string packageType: $ref: '#/components/schemas/packages.Type' packageVersion: description: 'Version of the package that caused the vulnerability (or null). ' type: string published: description: 'Date/time when the vulnerability was published (in Unix time). ' format: int64 type: integer riskFactors: $ref: '#/components/schemas/vulnerability.RiskFactors' rpmModule: description: 'RPMModule specifies the RPM module containing the package affected by this vulnerability. ' type: string secret: $ref: '#/components/schemas/vuln.Secret' severity: description: 'Textual representation of the vulnerability''s severity. ' type: string status: description: 'Vendor status for the vulnerability. ' type: string templates: description: 'List of templates with which the vulnerability is associated. ' items: $ref: '#/components/schemas/vuln.ComplianceTemplate' type: array text: description: 'Description of the violation. ' type: string title: description: 'Compliance title. ' type: string twistlock: description: 'Indicates if this is a Twistlock-specific vulnerability (true) or not (false). ' type: boolean type: $ref: '#/components/schemas/vulnerability.Type' vecStr: description: 'Textual representation of the metric values used to score the vulnerability. ' type: string vulnTagInfos: description: 'Tag information for the vulnerability. ' items: $ref: '#/components/schemas/vuln.TagInfo' type: array wildfireMalware: $ref: '#/components/schemas/vuln.WildFireMalware' type: object vuln.Distribution: description: Distribution counts the number of vulnerabilities per type properties: critical: description: '. ' type: integer high: description: '. ' type: integer low: description: '. ' type: integer medium: description: '. ' type: integer total: description: '. ' type: integer type: object coderepos.ScanResult: description: ScanResult holds a specific repository data properties: _id: description: 'Scan report ID in the database. ' type: string collections: description: 'List of matching code repo collections. ' items: $ref: '#/components/schemas/string' type: array complianceRiskScore: description: 'Code repository''s compliance risk score. Used for sorting. ' format: float type: number files: description: 'Scan result for each manifest file in the repository. ' items: $ref: '#/components/schemas/coderepos.ManifestFile' type: array pass: description: 'Indicates whether the scan passed or failed. ' type: boolean repository: $ref: '#/components/schemas/coderepos.Repository' scanTime: description: 'Date/time when this repository was last scanned. The results might be from the DB and not updated if the repository contents have not changed. ' format: date-time type: string type: $ref: '#/components/schemas/shared.CodeRepoProviderType' updateTime: description: 'Date/time when this repository was last updated. ' format: date-time type: string vulnInfo: $ref: '#/components/schemas/shared.ImageInfo' vulnerabilityRiskScore: description: 'Code repository''s CVE risk score. Used for sorting. ' format: float type: number vulnerableFiles: description: 'Counts how many files have vulnerabilities. Vulnerability info is calculated on demand. ' type: integer type: object common.ExternalLabelSourceType: description: ExternalLabelSourceType indicates the source of the labels enum: - - namespace - deployment - pod - aws - azure - gcp - oci type: string shared.Binary: description: Binary represents a detected binary file (ELF) properties: altered: description: 'Indicates if the binary was installed from a package manager and modified/replaced (true) or not (false). ' type: boolean cveCount: description: 'Total number of CVEs for this specific binary. ' type: integer deps: description: 'Third-party package files which are used by the binary. ' items: $ref: '#/components/schemas/string' type: array fileMode: description: 'Represents the file''s mode and permission bits. ' type: integer functionLayer: description: 'ID of the serverless layer in which the package was discovered. ' type: string md5: description: 'Md5 hashset of the binary. ' type: string missingPkg: description: 'Indicates if this binary is not related to any package (true) or not (false). ' type: boolean name: description: 'Name of the binary. ' type: string path: description: 'Path is the path of the binary. ' type: string pkgRootDir: description: 'Path for searching packages used by the binary. ' type: string services: description: 'Names of services which use the binary. ' items: $ref: '#/components/schemas/string' type: array version: description: 'Version of the binary. ' type: string type: object common.ClusterType: description: ClusterType is the cluster type enum: - - AKS - ECS - EKS - GKE - Kubernetes type: string shared.CompressedLayerTimes: description: CompressedLayerTimes represent the compressed layer times of the image apps and pkgs properties: appTimes: description: '. ' items: $ref: '#/components/schemas/int64' type: array pkgsTimes: description: '. ' items: $ref: '#/components/schemas/shared.PkgsTimes' type: array type: object shared.ImageHistory: description: ImageHistory represent a layer in the image's history properties: baseLayer: description: 'Indicates if this layer originated from the base image (true) or not (false). ' type: boolean created: description: 'Date/time when the image layer was created. ' format: int64 type: integer emptyLayer: description: 'Indicates if this instruction didn''t create a separate layer (true) or not (false). ' type: boolean id: description: 'ID of the layer. ' type: string instruction: description: 'Docker file instruction and arguments used to create this layer. ' type: string sizeBytes: description: 'Size of the layer (in bytes). ' format: int64 type: integer tags: description: 'Holds the image tags. ' items: $ref: '#/components/schemas/string' type: array vulnerabilities: description: 'Vulnerabilities which originated from this layer. ' items: $ref: '#/components/schemas/vuln.Vulnerability' type: array type: object packages.Type: description: Type describes the package type enum: - - nodejs - gem - python - jar - package - windows - binary - nuget - go - app - unknown type: string vuln.TagInfo: description: TagInfo is the tag info in a specific vulnerability context properties: color: $ref: '#/components/schemas/common.Color' comment: description: 'Tag comment in a specific vulnerability context. ' type: string name: description: 'Name of the tag. ' type: string type: object int: type: integer int16: type: integer shared.Image: description: Image represents a container image properties: created: description: 'Date/time when the image was created. ' format: date-time type: string entrypoint: description: 'Combined entrypoint of the image (entrypoint + CMD). ' items: $ref: '#/components/schemas/string' type: array env: description: 'Image environment variables. ' items: $ref: '#/components/schemas/string' type: array healthcheck: description: 'Indicates if health checks are enabled (true) or not (false). ' type: boolean history: description: 'Holds the image history. ' items: $ref: '#/components/schemas/shared.ImageHistory' type: array id: description: 'ID of the image. ' type: string labels: additionalProperties: $ref: '#/components/schemas/string' description: 'Image labels. ' type: object layers: description: 'Image filesystem layers. ' items: $ref: '#/components/schemas/string' type: array os: description: 'Image os type. ' type: string repoDigest: description: 'Image repo digests. ' items: $ref: '#/components/schemas/string' type: array repoTags: description: 'Image repo tags. ' items: $ref: '#/components/schemas/string' type: array user: description: 'Image user. ' type: string workingDir: description: 'Base working directory of the image. ' type: string type: object shared.InstalledProducts: description: 'InstalledProducts contains data regarding products running in environment TODO #34713: Swarm support was deprecated in Joule, remove swarm node/manager boolean (and related compliance) in Lagrange' properties: agentless: description: 'Agentless indicates whether the scan was performed with agentless approach. ' type: boolean apache: description: 'Apache indicates the apache server version, empty in case apache not running. ' type: string awsCloud: description: 'AWSCloud indicates whether AWS cloud is used. ' type: boolean clusterType: $ref: '#/components/schemas/common.ClusterType' crio: description: 'CRI indicates whether the container runtime is CRI (and not docker). ' type: boolean docker: description: 'Docker represents the docker daemon version. ' type: string dockerEnterprise: description: 'DockerEnterprise indicates whether the enterprise version of Docker is installed. ' type: boolean hasPackageManager: description: 'HasPackageManager indicates whether package manager is installed on the OS. ' type: boolean k8sApiServer: description: 'K8sAPIServer indicates whether a kubernetes API server is running. ' type: boolean k8sControllerManager: description: 'K8sControllerManager indicates whether a kubernetes controller manager is running. ' type: boolean k8sEtcd: description: 'K8sEtcd indicates whether etcd is running. ' type: boolean k8sFederationApiServer: description: 'K8sFederationAPIServer indicates whether a federation API server is running. ' type: boolean k8sFederationControllerManager: description: 'K8sFederationControllerManager indicates whether a federation controller manager is running. ' type: boolean k8sKubelet: description: 'K8sKubelet indicates whether kubelet is running. ' type: boolean k8sProxy: description: 'K8sProxy indicates whether a kubernetes proxy is running. ' type: boolean k8sScheduler: description: 'K8sScheduler indicates whether the kubernetes scheduler is running. ' type: boolean kubernetes: description: 'Kubernetes represents the kubernetes version. ' type: string managedClusterVersion: description: 'ManagedClusterVersion is the version of the managed Kubernetes service, e.g. AKS/EKS/GKE/etc. ' type: string openshift: description: 'Openshift indicates whether openshift is deployed. ' type: boolean openshiftVersion: description: 'OpenshiftVersion represents the running openshift version. ' type: string osDistro: description: 'OSDistro specifies the os distribution. ' type: string serverless: description: 'Serverless indicates whether evaluated on a serverless environment. ' type: boolean swarmManager: description: 'SwarmManager indicates whether a swarm manager is running. ' type: boolean swarmNode: description: 'SwarmNode indicates whether the node is part of an active swarm. ' type: boolean type: object int64: format: int64 type: integer shared.Package: description: Package stores relevant package information properties: author: description: 'Author is the package''s author. ' type: string binaryIdx: description: 'Indexes of the top binaries which use the package. ' items: $ref: '#/components/schemas/int16' type: array binaryPkgs: description: 'Names of the distro binary packages (packages which are built on the source of the package). ' items: $ref: '#/components/schemas/string' type: array cveCount: description: 'Total number of CVEs for this specific package. ' type: integer defaultGem: description: 'DefaultGem indicates this is a gem default package (and not a bundled package). ' type: boolean files: description: 'List of package-related files and their hashes. Only included when the appropriate scan option is set. ' items: $ref: '#/components/schemas/shared.FileDetails' type: array functionLayer: description: 'ID of the serverless layer in which the package was discovered. ' type: string goPkg: description: 'GoPkg indicates this is a Go package (and not module). ' type: boolean isRPMModule: description: 'IsRPMModule indicates whether this package data represents an RPM module. ' type: boolean jarIdentifier: description: 'JarIdentifier holds an additional identification detail of a JAR package. ' type: string layerTime: description: 'Image layer to which the package belongs (layer creation time). ' format: int64 type: integer license: description: 'License information for the package. ' type: string md5: description: 'MD5SUM is the md5sum of the package - currently only relevant for go main modules. ' type: string name: description: 'Name of the package. ' type: string originPackageName: description: 'OriginPackageName is the name of the third-party origin package. ' type: string osPackage: description: 'OSPackage indicates that a python/java package was installed as an OS package. ' type: boolean path: description: 'Full package path (e.g., JAR or Node.js package path). ' type: string purl: description: 'PURL is a package URL identifier for this package. ' type: string rpmModule: description: 'RPMModule represents the RPM module in which this package is included. ' type: string securityRepoPkg: description: 'SecurityRepoPkg determines if this package is available in a security repository. ' type: boolean symbols: description: 'Symbols contains names of vulnerable functions that are linked in the executable binary, empty if the entire package is vulnerable. ' items: $ref: '#/components/schemas/string' type: array version: description: 'Package version. ' type: string type: object common.AzureMetadata: properties: aci: $ref: '#/components/schemas/common.ACIMetadata' resourceGroup: description: '. ' type: string type: object coderepos.Repository: description: Repository is the metadata for a code repository properties: build: description: 'CI build. ' type: string defaultBranch: description: 'Default branch in the repository, usually master. ' type: string digest: description: 'Repository content digest. Used to indicate if the content of the repository has changed. ' type: string fullName: description: 'Full name that represents the repository (/). ' type: string jobName: description: 'CI job name. ' type: string name: description: 'Repository name. ' type: string owner: description: 'GitHub username or organization name of the repository''s owner. ' type: string private: description: 'Indicates if the repository is private (true) or not (false). ' type: boolean size: description: 'Size of the repository (in KB). ' type: integer url: description: 'URL is the repository address. ' type: string type: object shared.ImageInfo: description: ImageInfo contains image information collected during image scan properties: Secrets: description: 'Secrets are paths to embedded secrets inside the image Note: capital letter JSON annotation is kept to avoid converting all images for backward-compatibility support. ' items: $ref: '#/components/schemas/string' type: array allCompliance: $ref: '#/components/schemas/vuln.AllCompliance' applications: description: 'Products in the image. ' items: $ref: '#/components/schemas/vuln.Application' type: array baseImage: description: 'Image’s base image name. Used when filtering the vulnerabilities by base images. ' type: string binaries: description: 'Binaries in the image. ' items: $ref: '#/components/schemas/shared.Binary' type: array cloudMetadata: $ref: '#/components/schemas/common.CloudMetadata' clusterType: $ref: '#/components/schemas/common.ClusterType' clusters: description: 'Cluster names. ' items: $ref: '#/components/schemas/string' type: array complianceDistribution: $ref: '#/components/schemas/vuln.Distribution' complianceIssues: description: 'All the compliance issues. ' items: $ref: '#/components/schemas/vuln.Vulnerability' type: array complianceIssuesCount: description: 'Number of compliance issues. ' type: integer complianceRiskScore: description: 'Compliance risk score for the image. ' format: float type: number compressed: description: 'Compressed indicates if this image seems to be compressed - currently only relevant for buildah images. ' type: boolean compressedLayerTimes: $ref: '#/components/schemas/shared.CompressedLayerTimes' creationTime: description: 'Specifies the time of creation for the latest version of the image. ' format: date-time type: string distro: description: 'Full name of the distribution. ' type: string ecsClusterName: description: 'ECS cluster name. ' type: string externalLabels: description: 'Kubernetes external labels of all containers running this image. ' items: $ref: '#/components/schemas/common.ExternalLabel' type: array files: description: 'Files in the container. ' items: $ref: '#/components/schemas/shared.FileDetails' type: array firstScanTime: description: 'Specifies the time of the scan for the first version of the image. This time is preserved even after the version update. ' format: date-time type: string foundSecrets: description: 'FoundSecrets are secrets with metadata that were found in the secrets'' scan. Requires json tag for reporting secrets from image scan. ' items: $ref: '#/components/schemas/vuln.Secret' type: array history: description: 'Docker image history. ' items: $ref: '#/components/schemas/shared.ImageHistory' type: array hostDevices: description: 'Map from host network device name to IP address. ' items: $ref: '#/components/schemas/common.NetworkDeviceIP' type: array id: description: 'Image ID. ' type: string image: $ref: '#/components/schemas/shared.Image' installedProducts: $ref: '#/components/schemas/shared.InstalledProducts' isARM64: description: 'IsARM64 indicates if the architecture of the image is aarch64. ' type: boolean k8sClusterAddr: description: 'Endpoint of the Kubernetes API server. ' type: string labels: description: 'Image labels. ' items: $ref: '#/components/schemas/string' type: array layers: description: 'Image''s filesystem layers. Each layer is a SHA256 digest of the filesystem diff See: https://windsock.io/explaining-docker-image-ids/. ' items: $ref: '#/components/schemas/string' type: array missingDistroVulnCoverage: description: 'Indicates if the image OS is covered in the IS (true) or not (false). ' type: boolean namespaces: description: 'k8s namespaces of all the containers running this image. ' items: $ref: '#/components/schemas/string' type: array osDistro: description: 'Name of the OS distribution. ' type: string osDistroRelease: description: 'OS distribution release. ' type: string osDistroVersion: description: 'OS distribution version. ' type: string packageManager: description: 'Indicates if the package manager is installed for the OS. ' type: boolean packages: description: 'Packages which exist in the image. ' items: $ref: '#/components/schemas/shared.Packages' type: array pushTime: description: 'PushTime is the image push time to the registry. ' format: date-time type: string redHatNonRPMImage: description: 'RedHatNonRPMImage indicates whether the image is a Red Hat image with non-RPM content. ' type: boolean registryNamespace: description: 'IBM cloud namespace to which the image belongs. ' type: string registryTags: description: 'RegistryTags are the tags of the registry this image is stored. ' items: $ref: '#/components/schemas/string' type: array registryType: description: 'RegistryType indicates the registry type where the image is stored. ' type: string repoDigests: description: 'Digests of the image. Used for content trust (notary). Has one digest per tag. ' items: $ref: '#/components/schemas/string' type: array repoTag: $ref: '#/components/schemas/shared.ImageTag' rhelRepos: description: 'RhelRepositories are the (RPM) repositories IDs from which the packages in this image were installed Used for matching vulnerabilities by Red Hat CPEs. ' items: $ref: '#/components/schemas/string' type: array rhelReposRelativeURLs: description: 'RhelRepositoriesRelativeURLs are the relative URLs of the repositories from which the packages in this image were installed Used for matching vulnerabilities by Red Hat CPEs when the repository IDs are not available in the repository-to-cpe mapping file. ' items: $ref: '#/components/schemas/string' type: array riskFactors: $ref: '#/components/schemas/vulnerability.RiskFactors' scanBuildDate: description: 'Scanner build date that published the image. ' type: string scanVersion: description: 'Scanner version that published the image. ' type: string secretScanMetrics: $ref: '#/components/schemas/secrets.SecretScanMetrics' startupBinaries: description: 'Binaries which are expected to run when the container is created from this image. ' items: $ref: '#/components/schemas/shared.Binary' type: array tags: description: 'Tags associated with the given image. ' items: $ref: '#/components/schemas/shared.ImageTag' type: array topLayer: description: 'SHA256 of the image''s last layer that is the last element of the Layers field. ' type: string twistlockImage: description: 'Indicates if the image is a Twistlock image (true) or not (false). ' type: boolean underlyingDistro: description: 'UnderlyingDistro is used in cases OS an OS is built on top of another, and we need to know both. ' type: string underlyingDistroRelease: description: 'UnderlyingDistroRelease is used in cases OS an OS is built on top of another, and we need to know both. ' type: string vulnerabilities: description: 'CVE vulnerabilities of the image. ' items: $ref: '#/components/schemas/vuln.Vulnerability' type: array vulnerabilitiesCount: description: 'Total number of vulnerabilities. ' type: integer vulnerabilityDistribution: $ref: '#/components/schemas/vuln.Distribution' vulnerabilityRiskScore: description: 'Image''s CVE risk score. ' format: float type: number type: object vulnerability.ExploitKind: description: ExploitKind represents the kind of the exploit enum: - - poc - in-the-wild type: string vulnerability.Exploits: description: Exploits represents the exploits data found for a CVE items: $ref: '#/components/schemas/vulnerability.ExploitData' type: array vulnerability.VulnerabilityAttribute: description: VulnerabilityAttribute represents a specific vulnerability property whose value may come from different sources type: integer vuln.Vulnerability_2: description: Vulnerability is a general schema for vulnerabilities (e.g., for compliance or packages) properties: applicableRules: description: 'Rules applied on the package. ' items: $ref: '#/components/schemas/string' type: array binaryPkgs: description: 'Names of the distro binary package names (packages which are built from the source of the package). ' items: $ref: '#/components/schemas/string' type: array block: description: 'Indicates if the vulnerability has a block effect (true) or not (false). ' type: boolean cause: description: 'Additional information regarding the root cause for the vulnerability. ' type: string cri: description: 'Indicates if this is a CRI-specific vulnerability (true) or not (false). ' type: boolean custom: description: 'Indicates if the vulnerability is a custom vulnerability (e.g., openscap, sandbox) (true) or not (false). ' type: boolean cve: description: 'CVE ID of the vulnerability (if applied). ' type: string cvss: description: 'CVSS score of the vulnerability. ' format: float type: number description: description: 'Description of the vulnerability. ' type: string discovered: description: 'Specifies the time of discovery for the vulnerability. ' format: date-time type: string exploit: $ref: '#/components/schemas/vulnerability.ExploitType' exploits: $ref: '#/components/schemas/vulnerability.Exploits' fixDate: description: 'Date/time when the vulnerability was fixed (in Unix time). ' format: int64 type: integer fixLink: description: 'Link to the vendor''s fixed-version information. ' type: string functionLayer: description: 'Specifies the serverless layer ID in which the vulnerability was discovered. ' type: string gracePeriodDays: description: 'Number of grace days left for a vulnerability, based on the configured grace period. Nil if no block vulnerability rule applies. ' type: integer id: description: 'ID of the violation. ' type: integer layerTime: description: 'Date/time of the image layer to which the CVE belongs. ' format: int64 type: integer link: description: 'Vendor link to the CVE. ' type: string packageName: description: 'Name of the package that caused the vulnerability. ' type: string packageType: $ref: '#/components/schemas/packages.Type' packageVersion: description: 'Version of the package that caused the vulnerability (or null). ' type: string published: description: 'Date/time when the vulnerability was published (in Unix time). ' format: int64 type: integer riskFactors: $ref: '#/components/schemas/vulnerability.RiskFactors' rpmModule: description: 'RPMModule specifies the RPM module containing the package affected by this vulnerability. ' type: string secret: $ref: '#/components/schemas/vuln.Secret' severity: description: 'Textual representation of the vulnerability''s severity. ' type: string status: description: 'Vendor status for the vulnerability. ' type: string templates: description: 'List of templates with which the vulnerability is associated. ' items: $ref: '#/components/schemas/vuln.ComplianceTemplate' type: array text: description: 'Description of the violation. ' type: string title: description: 'Compliance title. ' type: string twistlock: description: 'Indicates if this is a Twistlock-specific vulnerability (true) or not (false). ' type: boolean type: $ref: '#/components/schemas/vulnerability.Type' vecStr: description: 'Textual representation of the metric values used to score the vulnerability. ' type: string vulnTagInfos: description: 'Tag information for the vulnerability. ' items: $ref: '#/components/schemas/vuln.TagInfo' type: array vulnerabilityDataSources: $ref: '#/components/schemas/vulnerability.VulnerabilityDataSources' wildfireMalware: $ref: '#/components/schemas/vuln.WildFireMalware' type: object vulnerability.VulnerabilityDataSource: description: 'VulnerabilityDataSource identifies the source of a specific vulnerability attribute. Example: CVSS from NVD, Severity from RedHat.' properties: attribute: $ref: '#/components/schemas/vulnerability.VulnerabilityAttribute' source: $ref: '#/components/schemas/vulnerability.VulnerabilitySource' type: object vulnerability.VulnerabilityDataSources: description: VulnerabilityDataSources is a slice of VulnerabilityDataSource that implements the sql.Scanner and driver.Valuer interfaces items: $ref: '#/components/schemas/vulnerability.VulnerabilityDataSource' type: array vulnerability.VulnerabilitySource: description: VulnerabilitySource represents the authority that provided vulnerability-related data (severity, CVSS, links). type: integer shared.InstalledProducts_2: description: 'InstalledProducts contains data regarding products running in environment TODO #34713: Swarm support was deprecated in Joule, remove swarm node/manager boolean (and related compliance) in Lagrange' properties: agentless: description: 'Agentless indicates whether the scan was performed with agentless approach. ' type: boolean apache: description: 'Apache indicates the apache server version, empty in case apache not running. ' type: string awsCloud: description: 'AWSCloud indicates whether AWS cloud is used. ' type: boolean clusterType: $ref: '#/components/schemas/common.ClusterType' crio: description: 'CRI indicates whether the container runtime is CRI (and not docker). ' type: boolean distroName: description: 'DistroName specifies the distribution name. ' type: string docker: description: 'Docker represents the docker daemon version. ' type: string dockerEnterprise: description: 'DockerEnterprise indicates whether the enterprise version of Docker is installed. ' type: boolean hasPackageManager: description: 'HasPackageManager indicates whether package manager is installed on the OS. ' type: boolean k8sApiServer: description: 'K8sAPIServer indicates whether a kubernetes API server is running. ' type: boolean k8sControllerManager: description: 'K8sControllerManager indicates whether a kubernetes controller manager is running. ' type: boolean k8sEtcd: description: 'K8sEtcd indicates whether etcd is running. ' type: boolean k8sFederationApiServer: description: 'K8sFederationAPIServer indicates whether a federation API server is running. ' type: boolean k8sFederationControllerManager: description: 'K8sFederationControllerManager indicates whether a federation controller manager is running. ' type: boolean k8sKubelet: description: 'K8sKubelet indicates whether kubelet is running. ' type: boolean k8sProxy: description: 'K8sProxy indicates whether a kubernetes proxy is running. ' type: boolean k8sScheduler: description: 'K8sScheduler indicates whether the kubernetes scheduler is running. ' type: boolean kubernetes: description: 'Kubernetes represents the kubernetes version. ' type: string managedClusterVersion: description: 'ManagedClusterVersion is the version of the managed Kubernetes service, e.g. AKS/EKS/GKE/etc. ' type: string openshift: description: 'Openshift indicates whether openshift is deployed. ' type: boolean openshiftVersion: description: 'OpenshiftVersion represents the running openshift version. ' type: string osDistro: description: 'OSDistro specifies the os distribution. ' type: string serverless: description: 'Serverless indicates whether evaluated on a serverless environment. ' type: boolean swarmManager: description: 'SwarmManager indicates whether a swarm manager is running. ' type: boolean swarmNode: description: 'SwarmNode indicates whether the node is part of an active swarm. ' type: boolean type: object shared.Package_2: description: Package stores relevant package information properties: author: description: 'Author is the package''s author. ' type: string binaryIdx: description: 'Indexes of the top binaries which use the package. ' items: $ref: '#/components/schemas/int16' type: array binaryPkgs: description: 'Names of the distro binary packages (packages which are built on the source of the package). ' items: $ref: '#/components/schemas/string' type: array cveCount: description: 'Total number of CVEs for this specific package. ' type: integer defaultGem: description: 'DefaultGem indicates this is a gem default package (and not a bundled package). ' type: boolean files: description: 'List of package-related files and their hashes. Only included when the appropriate scan option is set. ' items: $ref: '#/components/schemas/shared.FileDetails' type: array functionLayer: description: 'ID of the serverless layer in which the package was discovered. ' type: string goPkg: description: 'GoPkg indicates this is a Go package (and not module). ' type: boolean jarIdentifier: description: 'JarIdentifier holds an additional identification detail of a JAR package. ' type: string layerTime: description: 'Image layer to which the package belongs (layer creation time). ' format: int64 type: integer license: description: 'License information for the package. ' type: string md5: description: 'MD5SUM is the md5sum of the package - currently only relevant for go main modules and python packages. ' type: string name: description: 'Name of the package. ' type: string originPackageName: description: 'OriginPackageName is the name of the third-party origin package. ' type: string osPackage: description: 'OSPackage indicates that a python/java package was installed as an OS package. ' type: boolean path: description: 'Full package path (e.g., JAR or Node.js package path). ' type: string purl: description: 'PURL is a package URL identifier for this package. ' type: string rpmModule: description: 'RPMModule represents the RPM module in which this package is included. ' type: string securityRepoPkg: description: 'SecurityRepoPkg determines if this package is available in a security repository. ' type: boolean symbols: description: 'Symbols contains names of vulnerable functions that are linked in the executable binary, empty if the entire package is vulnerable. ' items: $ref: '#/components/schemas/string' type: array version: description: 'Package version. ' type: string type: object shared.ImageInfo_2: description: ImageInfo contains image information collected during image scan properties: Secrets: description: 'Secrets are paths to embedded secrets inside the image Note: capital letter JSON annotation is kept to avoid converting all images for backward-compatibility support. ' items: $ref: '#/components/schemas/string' type: array additionalDistroReleaseData: description: 'AdditionalDistroReleaseData contains extra metadata about the distro release (e.g., the "9.6" version for AlmaLinux TuxCare ESU supported image). ' type: string allCompliance: $ref: '#/components/schemas/vuln.AllCompliance' applications: description: 'Products in the image. ' items: $ref: '#/components/schemas/vuln.Application' type: array baseImage: description: 'Image’s base image name. Used when filtering the vulnerabilities by base images. ' type: string binaries: description: 'Binaries in the image. ' items: $ref: '#/components/schemas/shared.Binary' type: array cloudMetadata: $ref: '#/components/schemas/common.CloudMetadata' clusterType: $ref: '#/components/schemas/common.ClusterType' clusters: description: 'Cluster names. ' items: $ref: '#/components/schemas/string' type: array complianceDistribution: $ref: '#/components/schemas/vuln.Distribution' complianceIssues: description: 'All the compliance issues. ' items: $ref: '#/components/schemas/vuln.Vulnerability_2' type: array complianceIssuesCount: description: 'Number of compliance issues. ' type: integer complianceRiskScore: description: 'Compliance risk score for the image. ' format: float type: number compressed: description: 'Compressed indicates if this image seems to be compressed - currently only relevant for buildah images. ' type: boolean compressedLayerTimes: $ref: '#/components/schemas/shared.CompressedLayerTimes' creationTime: description: 'Specifies the time of creation for the latest version of the image. ' format: date-time type: string distro: description: 'Full name of the distribution. ' type: string ecsClusterName: description: 'ECS cluster name. ' type: string externalLabels: description: 'Kubernetes external labels of all containers running this image. ' items: $ref: '#/components/schemas/common.ExternalLabel' type: array files: description: 'Files in the container. ' items: $ref: '#/components/schemas/shared.FileDetails' type: array firstScanTime: description: 'Specifies the time of the scan for the first version of the image. This time is preserved even after the version update. ' format: date-time type: string foundSecrets: description: 'FoundSecrets are secrets with metadata that were found in the secrets'' scan. Requires json tag for reporting secrets from image scan. ' items: $ref: '#/components/schemas/vuln.Secret' type: array history: description: 'Docker image history. ' items: $ref: '#/components/schemas/shared.ImageHistory' type: array hostDevices: description: 'Map from host network device name to IP address. ' items: $ref: '#/components/schemas/common.NetworkDeviceIP' type: array id: description: 'Image ID. ' type: string image: $ref: '#/components/schemas/shared.Image' installedProducts: $ref: '#/components/schemas/shared.InstalledProducts_2' isARM64: description: 'IsARM64 indicates if the architecture of the image is aarch64. ' type: boolean k8sClusterAddr: description: 'Endpoint of the Kubernetes API server. ' type: string labels: description: 'Image labels. ' items: $ref: '#/components/schemas/string' type: array layers: description: 'Image''s filesystem layers. Each layer is a SHA256 digest of the filesystem diff See: https://windsock.io/explaining-docker-image-ids/. ' items: $ref: '#/components/schemas/string' type: array missingDistroVulnCoverage: description: 'Indicates if the image OS is covered in the IS (true) or not (false). ' type: boolean namespaces: description: 'k8s namespaces of all the containers running this image. ' items: $ref: '#/components/schemas/string' type: array osDistro: description: 'Name of the OS distribution. ' type: string osDistroRelease: description: 'OS distribution release. ' type: string osDistroVersion: description: 'OS distribution version. ' type: string packageManager: description: 'Indicates if the package manager is installed for the OS. ' type: boolean packages: description: 'Packages which exist in the image. ' items: $ref: '#/components/schemas/shared.Packages' type: array pushTime: description: 'PushTime is the image push time to the registry. ' format: date-time type: string redHatNonRPMImage: description: 'RedHatNonRPMImage indicates whether the image is a Red Hat image with non-RPM content. ' type: boolean registryNamespace: description: 'IBM cloud namespace to which the image belongs. ' type: string registryTags: description: 'RegistryTags are the tags of the registry this image is stored. ' items: $ref: '#/components/schemas/string' type: array registryType: description: 'RegistryType indicates the registry type where the image is stored. ' type: string repoDigests: description: 'Digests of the image. Used for content trust (notary). Has one digest per tag. ' items: $ref: '#/components/schemas/string' type: array repoTag: $ref: '#/components/schemas/shared.ImageTag' rhelRepos: description: 'RhelRepositories are the (RPM) repositories IDs from which the packages in this image were installed Used for matching vulnerabilities by Red Hat CPEs. ' items: $ref: '#/components/schemas/string' type: array rhelReposRelativeURLs: description: 'RhelRepositoriesRelativeURLs are the relative URLs of the repositories from which the packages in this image were installed Used for matching vulnerabilities by Red Hat CPEs when the repository IDs are not available in the repository-to-cpe mapping file. ' items: $ref: '#/components/schemas/string' type: array riskFactors: $ref: '#/components/schemas/vulnerability.RiskFactors' scanBuildDate: description: 'Scanner build date that published the image. ' type: string scanVersion: description: 'Scanner version that published the image. ' type: string secretScanMetrics: $ref: '#/components/schemas/secrets.SecretScanMetrics' startupBinaries: description: 'Binaries which are expected to run when the container is created from this image. ' items: $ref: '#/components/schemas/shared.Binary' type: array tags: description: 'Tags associated with the given image. ' items: $ref: '#/components/schemas/shared.ImageTag' type: array topLayer: description: 'SHA256 of the image''s last layer that is the last element of the Layers field. ' type: string twistlockImage: description: 'Indicates if the image is a Twistlock image (true) or not (false). ' type: boolean underlyingDistro: description: 'UnderlyingDistro is used in cases OS an OS is built on top of another, and we need to know both. ' type: string underlyingDistroRelease: description: 'UnderlyingDistroRelease is used in cases OS an OS is built on top of another, and we need to know both. ' type: string vulnerabilities: description: 'CVE vulnerabilities of the image. ' items: $ref: '#/components/schemas/vuln.Vulnerability_2' type: array vulnerabilitiesCount: description: 'Total number of vulnerabilities. ' type: integer vulnerabilityDistribution: $ref: '#/components/schemas/vuln.Distribution' vulnerabilityRiskScore: description: 'Image''s CVE risk score. ' format: float type: number type: object vuln.Vulnerability_3: description: Vulnerability is a general schema for vulnerabilities (e.g., for compliance or packages) properties: applicableRules: description: 'Rules applied on the package. ' items: $ref: '#/components/schemas/string' type: array binaryPkgs: description: 'Names of the distro binary package names (packages which are built from the source of the package). ' items: $ref: '#/components/schemas/string' type: array block: description: 'Indicates if the vulnerability has a block effect (true) or not (false). ' type: boolean cause: description: 'Additional information regarding the root cause for the vulnerability. ' type: string cri: description: 'Indicates if this is a CRI-specific vulnerability (true) or not (false). ' type: boolean custom: description: 'Indicates if the vulnerability is a custom vulnerability (e.g., openscap, sandbox) (true) or not (false). ' type: boolean cve: description: 'CVE ID of the vulnerability (if applied). ' type: string cvss: description: 'CVSS score of the vulnerability. ' format: float type: number description: description: 'Description of the vulnerability. ' type: string discovered: description: 'Specifies the time of discovery for the vulnerability. ' format: date-time type: string exploit: $ref: '#/components/schemas/vulnerability.ExploitType' exploits: $ref: '#/components/schemas/vulnerability.Exploits' fixDate: description: 'Date/time when the vulnerability was fixed (in Unix time). ' format: int64 type: integer fixLink: description: 'Link to the vendor''s fixed-version information. ' type: string functionLayer: description: 'Specifies the serverless layer ID in which the vulnerability was discovered. ' type: string gracePeriodDays: description: 'Number of grace days left for a vulnerability, based on the configured grace period. Nil if no block vulnerability rule applies. ' type: integer id: description: 'ID of the violation. ' type: integer layerTime: description: 'Date/time of the image layer to which the CVE belongs. ' format: int64 type: integer link: description: 'Vendor link to the CVE. ' type: string packageName: description: 'Name of the package that caused the vulnerability. ' type: string packageType: $ref: '#/components/schemas/packages.Type' packageVersion: description: 'Version of the package that caused the vulnerability (or null). ' type: string published: description: 'Date/time when the vulnerability was published (in Unix time). ' format: int64 type: integer riskFactors: $ref: '#/components/schemas/vulnerability.RiskFactors' rpmModule: description: 'RPMModule specifies the RPM module containing the package affected by this vulnerability. ' type: string secret: $ref: '#/components/schemas/vuln.Secret' severity: description: 'Textual representation of the vulnerability''s severity. ' type: string status: description: 'Vendor status for the vulnerability. ' type: string templates: description: 'List of templates with which the vulnerability is associated. ' items: $ref: '#/components/schemas/vuln.ComplianceTemplate' type: array text: description: 'Description of the violation. ' type: string title: description: 'Compliance title. ' type: string twistlock: description: 'Indicates if this is a Twistlock-specific vulnerability (true) or not (false). ' type: boolean type: $ref: '#/components/schemas/vulnerability.Type' vecStr: description: 'Textual representation of the metric values used to score the vulnerability. ' type: string vulnTagInfos: description: 'Tag information for the vulnerability. ' items: $ref: '#/components/schemas/vuln.TagInfo' type: array vulnerabilityDataSources: $ref: '#/components/schemas/vulnerability.VulnerabilityDataSources' wildfireMalware: $ref: '#/components/schemas/vuln.WildFireMalware' type: object shared.InstalledProducts_3: description: 'InstalledProducts contains data regarding products running in environment TODO #34713: Swarm support was deprecated in Joule, remove swarm node/manager boolean (and related compliance) in Lagrange' properties: agentless: description: 'Agentless indicates whether the scan was performed with agentless approach. ' type: boolean apache: description: 'Apache indicates the apache server version, empty in case apache not running. ' type: string awsCloud: description: 'AWSCloud indicates whether AWS cloud is used. ' type: boolean clusterType: $ref: '#/components/schemas/common.ClusterType' crio: description: 'CRI indicates whether the container runtime is CRI (and not docker). ' type: boolean distroName: description: 'DistroName specifies the distribution name. ' type: string docker: description: 'Docker represents the docker daemon version. ' type: string dockerEnterprise: description: 'DockerEnterprise indicates whether the enterprise version of Docker is installed. ' type: boolean hasPackageManager: description: 'HasPackageManager indicates whether package manager is installed on the OS. ' type: boolean k8sApiServer: description: 'K8sAPIServer indicates whether a kubernetes API server is running. ' type: boolean k8sControllerManager: description: 'K8sControllerManager indicates whether a kubernetes controller manager is running. ' type: boolean k8sEtcd: description: 'K8sEtcd indicates whether etcd is running. ' type: boolean k8sFederationApiServer: description: 'K8sFederationAPIServer indicates whether a federation API server is running. ' type: boolean k8sFederationControllerManager: description: 'K8sFederationControllerManager indicates whether a federation controller manager is running. ' type: boolean k8sKubelet: description: 'K8sKubelet indicates whether kubelet is running. ' type: boolean k8sProxy: description: 'K8sProxy indicates whether a kubernetes proxy is running. ' type: boolean k8sScheduler: description: 'K8sScheduler indicates whether the kubernetes scheduler is running. ' type: boolean kubernetes: description: 'Kubernetes represents the kubernetes version. ' type: string managedClusterVersion: description: 'ManagedClusterVersion is the version of the managed Kubernetes service, e.g. AKS/EKS/GKE/etc. ' type: string openshift: description: 'Openshift indicates whether openshift is deployed. ' type: boolean openshiftVersion: description: 'OpenshiftVersion represents the running openshift version. ' type: string osDistro: description: 'OSDistro specifies the os distribution. ' type: string serverless: description: 'Serverless indicates whether evaluated on a serverless environment. ' type: boolean swarmManager: description: 'SwarmManager indicates whether a swarm manager is running. ' type: boolean swarmNode: description: 'SwarmNode indicates whether the node is part of an active swarm. ' type: boolean type: object shared.Package_3: description: Package stores relevant package information properties: author: description: 'Author is the package''s author. ' type: string binaryIdx: description: 'Indexes of the top binaries which use the package. ' items: $ref: '#/components/schemas/int16' type: array binaryPkgs: description: 'Names of the distro binary packages (packages which are built on the source of the package). ' items: $ref: '#/components/schemas/string' type: array cveCount: description: 'Total number of CVEs for this specific package. ' type: integer defaultGem: description: 'DefaultGem indicates this is a gem default package (and not a bundled package). ' type: boolean files: description: 'List of package-related files and their hashes. Only included when the appropriate scan option is set. ' items: $ref: '#/components/schemas/shared.FileDetails' type: array functionLayer: description: 'ID of the serverless layer in which the package was discovered. ' type: string goPkg: description: 'GoPkg indicates this is a Go package (and not module). ' type: boolean jarIdentifier: description: 'JarIdentifier holds an additional identification detail of a JAR package. ' type: string layerTime: description: 'Image layer to which the package belongs (layer creation time). ' format: int64 type: integer license: description: 'License information for the package. ' type: string md5: description: 'MD5SUM is the md5sum of the package - currently only relevant for go main modules and python packages. ' type: string name: description: 'Name of the package. ' type: string originPackageName: description: 'OriginPackageName is the name of the third-party origin package. ' type: string osPackage: description: 'OSPackage indicates that a python/java package was installed as an OS package. ' type: boolean path: description: 'Full package path (e.g., JAR or Node.js package path). ' type: string purl: description: 'PURL is a package URL identifier for this package. ' type: string rpmModule: description: 'RPMModule represents the RPM module in which this package is included. ' type: string securityRepoPkg: description: 'SecurityRepoPkg determines if this package is available in a security repository. ' type: boolean symbols: description: 'Symbols contains names of vulnerable functions that are linked in the executable binary, empty if the entire package is vulnerable. ' items: $ref: '#/components/schemas/string' type: array version: description: 'Package version. ' type: string type: object shared.ImageInfo_3: description: ImageInfo contains image information collected during image scan properties: Secrets: description: 'Secrets are paths to embedded secrets inside the image Note: capital letter JSON annotation is kept to avoid converting all images for backward-compatibility support. ' items: $ref: '#/components/schemas/string' type: array additionalDistroReleaseData: description: 'AdditionalDistroReleaseData contains extra metadata about the distro release (e.g., the "9.6" version for AlmaLinux TuxCare ESU supported image). ' type: string allCompliance: $ref: '#/components/schemas/vuln.AllCompliance' applications: description: 'Products in the image. ' items: $ref: '#/components/schemas/vuln.Application' type: array baseImage: description: 'Image’s base image name. Used when filtering the vulnerabilities by base images. ' type: string binaries: description: 'Binaries in the image. ' items: $ref: '#/components/schemas/shared.Binary' type: array cloudMetadata: $ref: '#/components/schemas/common.CloudMetadata' clusterType: $ref: '#/components/schemas/common.ClusterType' clusters: description: 'Cluster names. ' items: $ref: '#/components/schemas/string' type: array complianceDistribution: $ref: '#/components/schemas/vuln.Distribution' complianceIssues: description: 'All the compliance issues. ' items: $ref: '#/components/schemas/vuln.Vulnerability_3' type: array complianceIssuesCount: description: 'Number of compliance issues. ' type: integer complianceRiskScore: description: 'Compliance risk score for the image. ' format: float type: number compressed: description: 'Compressed indicates if this image seems to be compressed - currently only relevant for buildah images. ' type: boolean compressedLayerTimes: $ref: '#/components/schemas/shared.CompressedLayerTimes' creationTime: description: 'Specifies the time of creation for the latest version of the image. ' format: date-time type: string distro: description: 'Full name of the distribution. ' type: string ecsClusterName: description: 'ECS cluster name. ' type: string externalLabels: description: 'Kubernetes external labels of all containers running this image. ' items: $ref: '#/components/schemas/common.ExternalLabel' type: array files: description: 'Files in the container. ' items: $ref: '#/components/schemas/shared.FileDetails' type: array firstScanTime: description: 'Specifies the time of the scan for the first version of the image. This time is preserved even after the version update. ' format: date-time type: string foundSecrets: description: 'FoundSecrets are secrets with metadata that were found in the secrets'' scan. Requires json tag for reporting secrets from image scan. ' items: $ref: '#/components/schemas/vuln.Secret' type: array history: description: 'Docker image history. ' items: $ref: '#/components/schemas/shared.ImageHistory' type: array hostDevices: description: 'Map from host network device name to IP address. ' items: $ref: '#/components/schemas/common.NetworkDeviceIP' type: array id: description: 'Image ID. ' type: string image: $ref: '#/components/schemas/shared.Image' installedProducts: $ref: '#/components/schemas/shared.InstalledProducts_3' isARM64: description: 'IsARM64 indicates if the architecture of the image is aarch64. ' type: boolean k8sClusterAddr: description: 'Endpoint of the Kubernetes API server. ' type: string labels: description: 'Image labels. ' items: $ref: '#/components/schemas/string' type: array layers: description: 'Image''s filesystem layers. Each layer is a SHA256 digest of the filesystem diff See: https://windsock.io/explaining-docker-image-ids/. ' items: $ref: '#/components/schemas/string' type: array missingDistroVulnCoverage: description: 'Indicates if the image OS is covered in the IS (true) or not (false). ' type: boolean namespaces: description: 'k8s namespaces of all the containers running this image. ' items: $ref: '#/components/schemas/string' type: array osDistro: description: 'Name of the OS distribution. ' type: string osDistroRelease: description: 'OS distribution release. ' type: string osDistroVersion: description: 'OS distribution version. ' type: string packageManager: description: 'Indicates if the package manager is installed for the OS. ' type: boolean packages: description: 'Packages which exist in the image. ' items: $ref: '#/components/schemas/shared.Packages' type: array pushTime: description: 'PushTime is the image push time to the registry. ' format: date-time type: string redHatNonRPMImage: description: 'RedHatNonRPMImage indicates whether the image is a Red Hat image with non-RPM content. ' type: boolean registryNamespace: description: 'IBM cloud namespace to which the image belongs. ' type: string registryTags: description: 'RegistryTags are the tags of the registry this image is stored. ' items: $ref: '#/components/schemas/string' type: array registryType: description: 'RegistryType indicates the registry type where the image is stored. ' type: string repoDigests: description: 'Digests of the image. Used for content trust (notary). Has one digest per tag. ' items: $ref: '#/components/schemas/string' type: array repoTag: $ref: '#/components/schemas/shared.ImageTag' rhelRepos: description: 'RhelRepositories are the (RPM) repositories IDs from which the packages in this image were installed Used for matching vulnerabilities by Red Hat CPEs. ' items: $ref: '#/components/schemas/string' type: array rhelReposRelativeURLs: description: 'RhelRepositoriesRelativeURLs are the relative URLs of the repositories from which the packages in this image were installed Used for matching vulnerabilities by Red Hat CPEs when the repository IDs are not available in the repository-to-cpe mapping file. ' items: $ref: '#/components/schemas/string' type: array riskFactors: $ref: '#/components/schemas/vulnerability.RiskFactors' scanBuildDate: description: 'Scanner build date that published the image. ' type: string scanVersion: description: 'Scanner version that published the image. ' type: string secretScanMetrics: $ref: '#/components/schemas/secrets.SecretScanMetrics' startupBinaries: description: 'Binaries which are expected to run when the container is created from this image. ' items: $ref: '#/components/schemas/shared.Binary' type: array tags: description: 'Tags associated with the given image. ' items: $ref: '#/components/schemas/shared.ImageTag' type: array topLayer: description: 'SHA256 of the image''s last layer that is the last element of the Layers field. ' type: string twistlockImage: description: 'Indicates if the image is a Twistlock image (true) or not (false). ' type: boolean underlyingDistro: description: 'UnderlyingDistro is used in cases OS an OS is built on top of another, and we need to know both. ' type: string underlyingDistroRelease: description: 'UnderlyingDistroRelease is used in cases OS an OS is built on top of another, and we need to know both. ' type: string vulnerabilities: description: 'CVE vulnerabilities of the image. ' items: $ref: '#/components/schemas/vuln.Vulnerability_3' type: array vulnerabilitiesCount: description: 'Total number of vulnerabilities. ' type: integer vulnerabilityDistribution: $ref: '#/components/schemas/vuln.Distribution' vulnerabilityRiskScore: description: 'Image''s CVE risk score. ' format: float type: number type: object x-refined-from: - palo-alto-compute-34-03-openapi-34-03-138-sh-openapi.json - palo-alto-compute-openapi-34-04-145-sh-openapi.json - palo-alto-cwpp-34-03-openapi-34-03-138-saas-openapi.json - palo-alto-cwpp-openapi-34-04-145-saas-openapi.json