GraphQL-API
Das Gateway stellt die ganze Plattform über einen GraphQL-Endpunkt bereit. Sende ein Bearer-Token in Authorization und die Workspace-ID in X-Tenant.
https://vulnara-gw.rso.dev/graphqlcurl https://vulnara-gw.rso.dev/graphql \
-H "Authorization: Bearer $VULNARA_TOKEN" \
-H "X-Tenant: $VULNARA_TENANT" \
-H "Content-Type: application/json" \
-d '{"query":"{ myUser { id } }"}'acceptInvitationMutation
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! |
Rückgabe Boolean!
mutation AcceptInvitation($id: ID!) {
acceptInvitation(id: $id)
}associateGitTokenWithGitEntityMutation
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| input | GitTokenAssociationInput! |
Rückgabe GitToken!
mutation AssociateGitTokenWithGitEntity($input: GitTokenAssociationInput!) {
associateGitTokenWithGitEntity(input: $input) {
id
name
value
expiresAt
flags
status
scopes
createdAt
}
}Auch verfügbar als: CLI-Befehl vulnara associate_git_token_with_git_entity
cancelTaskMutation
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! |
Rückgabe Boolean!
mutation CancelTask($id: ID!) {
cancelTask(id: $id)
}Auch verfügbar als: CLI-Befehl vulnara cancel_task
checkGitTokenQuery
Probe the token against its provider, returning validity, the provider's error (when rejected) and the reported expiry. Used by the add-token form to surface why a token was rejected. When a workspace name is supplied and the token is valid, also returns how many repositories the token can see for it (public + private).
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| value | String! | |
| gitType | GitType! | |
| name | String |
Rückgabe GitTokenCheck!
query CheckGitToken($value: String!, $gitType: GitType!, $name: String) {
checkGitToken(value: $value, gitType: $gitType, name: $name) {
valid
statusCode
error
expiresAt
publicRepositoryCount
privateRepositoryCount
}
}clearFindingTriageMutation
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| repositoryId | ID! | |
| matchKey | String! |
Rückgabe Boolean!
mutation ClearFindingTriage($repositoryId: ID!, $matchKey: String!) {
clearFindingTriage(repositoryId: $repositoryId, matchKey: $matchKey)
}commitScansQuery
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| list | List |
Rückgabe CommitScanListResult!
query CommitScans($list: List) {
commitScans(list: $list) {
total
items {
id
scanResultId
commitHash
createdAt
updatedAt
}
}
}Auch verfügbar als: MCP-Tool commit_scans
confirmEmptyOrderMutation
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! |
Rückgabe Boolean!
mutation ConfirmEmptyOrder($id: ID!) {
confirmEmptyOrder(id: $id)
}createEmptyOrderMutation
Rückgabe RevolutOrder!
mutation CreateEmptyOrder {
createEmptyOrder {
id
}
}createGitEntityMutation
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| input | CreateGitEntityInput! |
Rückgabe GitEntity!
mutation CreateGitEntity($input: CreateGitEntityInput!) {
createGitEntity(input: $input) {
__typename
... on Organization {
id
name
gitType
externalId
webUrl
htmlUrl
avatarUrl
color
}
... on GitUser {
id
name
gitType
externalId
webUrl
htmlUrl
avatarUrl
color
}
}
}Auch verfügbar als: CLI-Befehl vulnara create_git_entity
createGitTokenMutation
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| input | CreateGitTokenInput! |
Rückgabe GitToken!
mutation CreateGitToken($input: CreateGitTokenInput!) {
createGitToken(input: $input) {
id
name
value
expiresAt
flags
status
scopes
createdAt
}
}Auch verfügbar als: CLI-Befehl vulnara create_git_token
createInvoiceDownloadUrlMutation
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| invoiceId | ID! |
Rückgabe InvoiceDownload!
mutation CreateInvoiceDownloadUrl($invoiceId: ID!) {
createInvoiceDownloadUrl(invoiceId: $invoiceId) {
url
filename
tenant
contentType
}
}createNetworkMutation
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| input | CreateNetworkInput! |
Rückgabe Network!
mutation CreateNetwork($input: CreateNetworkInput!) {
createNetwork(input: $input) {
id
name
network
networkType
tenant
securityScore
createdAt
updatedAt
}
}Auch verfügbar als: CLI-Befehl vulnara create_network
createNotificationScopeMutation
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| input | CreateNotificationScopeInput! |
Rückgabe NotificationScope!
mutation CreateNotificationScope($input: CreateNotificationScopeInput!) {
createNotificationScope(input: $input) {
id
channelIds
channelType
scopes
isActive
status
headers {
name
value
}
template
}
}Auch verfügbar als: CLI-Befehl vulnara create_notification_scope
createRepositoryMutation
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| input | CreateRepositoryInput! |
Rückgabe Repository!
mutation CreateRepository($input: CreateRepositoryInput!) {
createRepository(input: $input) {
id
gitEntityId
repositoryName
private
securityScore
programmingLanguage
repositorySize
numberOfBranches
}
}Auch verfügbar als: CLI-Befehl vulnara create_repository
createScanScheduleMutation
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| input | CreateScanScheduleInput! |
Rückgabe ScanSchedule!
mutation CreateScanSchedule($input: CreateScanScheduleInput!) {
createScanSchedule(input: $input) {
id
action
repositoryId
gitEntityId
branch
dockerScanToolId
frequency
hourUtc
}
}createServiceAccountMutation
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| input | CreateServiceAccountInput! |
Rückgabe CreateServiceAccountPayload!
mutation CreateServiceAccount($input: CreateServiceAccountInput!) {
createServiceAccount(input: $input) {
serviceAccount {
id
name
isActive
expiresAt
}
}
}Auch verfügbar als: CLI-Befehl vulnara create_service_account
createTenantMutation
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| input | CreateTenantInput! |
Rückgabe Tenant!
mutation CreateTenant($input: CreateTenantInput!) {
createTenant(input: $input) {
id
isPaying
members {
id
roles
}
}
}Auch verfügbar als: CLI-Befehl vulnara create_tenant
dashboardAnalyticsQuery
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| days | Int |
Rückgabe DashboardAnalytics!
query DashboardAnalytics($days: Int) {
dashboardAnalytics(days: $days) {
days
generatedAt
lastScanAt
averageSecurityScore
previousAverageSecurityScore
severityCounts {
severity
count
}
previousSeverityCounts {
severity
count
}
exposure {
total
previousTotal
newFindings
resolvedFindings
codeFindings
dependencyFindings
corroboratedFindings
falsePositives
}
}
}Auch verfügbar als: MCP-Tool dashboard_analytics
declineInvitationMutation
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! |
Rückgabe Boolean!
mutation DeclineInvitation($id: ID!) {
declineInvitation(id: $id)
}deleteGitEntityMutation
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! |
Rückgabe Boolean!
mutation DeleteGitEntity($id: ID!) {
deleteGitEntity(id: $id)
}Auch verfügbar als: CLI-Befehl vulnara delete_git_entity
deleteGitTokenMutation
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! |
Rückgabe Boolean!
mutation DeleteGitToken($id: ID!) {
deleteGitToken(id: $id)
}Auch verfügbar als: CLI-Befehl vulnara delete_git_token
deleteInvitationMutation
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! |
Rückgabe Boolean!
mutation DeleteInvitation($id: ID!) {
deleteInvitation(id: $id)
}deleteNetworkMutation
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! |
Rückgabe Boolean!
mutation DeleteNetwork($id: ID!) {
deleteNetwork(id: $id)
}Auch verfügbar als: CLI-Befehl vulnara delete_network
deleteNetworkScanResultMutation
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! |
Rückgabe Boolean!
mutation DeleteNetworkScanResult($id: ID!) {
deleteNetworkScanResult(id: $id)
}Auch verfügbar als: CLI-Befehl vulnara delete_network_scan_result
deleteNotificationScopeMutation
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! |
Rückgabe Boolean!
mutation DeleteNotificationScope($id: ID!) {
deleteNotificationScope(id: $id)
}Auch verfügbar als: CLI-Befehl vulnara delete_notification_scope
deletePaymentMethodMutation
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! |
Rückgabe Boolean!
mutation DeletePaymentMethod($id: ID!) {
deletePaymentMethod(id: $id)
}deleteRepositoryMutation
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! |
Rückgabe Boolean!
mutation DeleteRepository($id: ID!) {
deleteRepository(id: $id)
}Auch verfügbar als: CLI-Befehl vulnara delete_repository
deleteScanResultMutation
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! |
Rückgabe Boolean!
mutation DeleteScanResult($id: ID!) {
deleteScanResult(id: $id)
}Auch verfügbar als: CLI-Befehl vulnara delete_scan_result
deleteScanScheduleMutation
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! |
Rückgabe Boolean!
mutation DeleteScanSchedule($id: ID!) {
deleteScanSchedule(id: $id)
}deleteServiceAccountMutation
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! |
Rückgabe Boolean!
mutation DeleteServiceAccount($id: ID!) {
deleteServiceAccount(id: $id)
}Auch verfügbar als: CLI-Befehl vulnara delete_service_account
deleteTenantMemberMutation
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! |
Rückgabe Boolean!
mutation DeleteTenantMember($id: ID!) {
deleteTenantMember(id: $id)
}dismissTaskMutation
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! |
Rückgabe Boolean!
mutation DismissTask($id: ID!) {
dismissTask(id: $id)
}dissociateGitTokenWithGitEntityMutation
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| input | GitTokenAssociationInput! |
Rückgabe Boolean!
mutation DissociateGitTokenWithGitEntity($input: GitTokenAssociationInput!) {
dissociateGitTokenWithGitEntity(input: $input)
}Auch verfügbar als: CLI-Befehl vulnara dissociate_git_token_with_git_entity
dockerScanToolQuery
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! |
Rückgabe DockerScanTool!
query DockerScanTool($id: ID!) {
dockerScanTool(id: $id) {
id
name
}
}Auch verfügbar als: MCP-Tool docker_scan_tool
dockerScanToolsQuery
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| list | List |
Rückgabe DockerScanToolListResult!
query DockerScanTools($list: List) {
dockerScanTools(list: $list) {
total
items {
id
name
}
}
}Auch verfügbar als: MCP-Tool docker_scan_tools
downgradeToFreeMutation
Rückgabe Boolean!
mutation DowngradeToFree {
downgradeToFree
}fetchRepositoriesMutation
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| input | FetchRepositoriesInput! |
Rückgabe Boolean!
mutation FetchRepositories($input: FetchRepositoriesInput!) {
fetchRepositories(input: $input)
}Auch verfügbar als: CLI-Befehl vulnara fetch_repositories
findingCorroborationQuery
Cross-tool agreement for every secret found in a repository.
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| repositoryId | ID! |
Rückgabe FindingCorroborationListResult!
query FindingCorroboration($repositoryId: ID!) {
findingCorroboration(repositoryId: $repositoryId) {
total
items {
id
matchHash
toolCount
severity
}
}
}Auch verfügbar als: MCP-Tool finding_corroboration
findingTriageQuery
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| repositoryId | ID! |
Rückgabe [FindingTriage!]!
query FindingTriage($repositoryId: ID!) {
findingTriage(repositoryId: $repositoryId) {
id
repositoryId
matchKey
findingType
state
justification
response
priority
}
}Auch verfügbar als: MCP-Tool finding_triage
findingTriageHistoryQuery
Every decision ever taken on this repository's findings, newest first.
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| repositoryId | ID! | |
| matchKey | String |
Rückgabe [FindingTriageEvent!]!
query FindingTriageHistory($repositoryId: ID!, $matchKey: String) {
findingTriageHistory(repositoryId: $repositoryId, matchKey: $matchKey) {
id
repositoryId
matchKey
action
state
justification
response
priority
}
}Auch verfügbar als: MCP-Tool finding_triage_history
gitEntitiesQuery
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| list | List |
Rückgabe GitEntityListResult!
query GitEntities($list: List) {
gitEntities(list: $list) {
total
}
}Auch verfügbar als: CLI-Befehl vulnara git_entities · MCP-Tool git_entities
gitEntityQuery
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! |
Rückgabe GitEntity!
query GitEntity($id: ID!) {
gitEntity(id: $id) {
__typename
... on Organization {
id
name
gitType
externalId
webUrl
htmlUrl
avatarUrl
color
}
... on GitUser {
id
name
gitType
externalId
webUrl
htmlUrl
avatarUrl
color
}
}
}Auch verfügbar als: CLI-Befehl vulnara get_git_entity · MCP-Tool git_entity
gitEntityProvidersQuery
Providers on which a bare handle resolves to an org/user/group. Lets the add-workspace form infer the provider automatically and only ask the user to choose when the same handle exists on more than one provider.
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| name | String! |
Rückgabe [GitType!]!
query GitEntityProviders($name: String!) {
gitEntityProviders(name: $name)
}gitEntityRepositoryCountQuery
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| name | String! | |
| gitType | GitType! |
Rückgabe Int
query GitEntityRepositoryCount($name: String!, $gitType: GitType!) {
gitEntityRepositoryCount(name: $name, gitType: $gitType)
}gitTokenQuery
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! |
Rückgabe GitToken!
query GitToken($id: ID!) {
gitToken(id: $id) {
id
name
value
expiresAt
flags
status
scopes
createdAt
}
}Auch verfügbar als: CLI-Befehl vulnara get_git_token
gitTokenExpirationQuery
The token's own expiry as reported by the provider (GitHub's token-expiration header / GitLab's PAT self endpoint), or null if the provider doesn't expose one or the token couldn't be checked. Lets the UI hide the manual "expires at" field when the token reports it itself.
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| value | String! | |
| gitType | GitType! |
Rückgabe DateTime
query GitTokenExpiration($value: String!, $gitType: GitType!) {
gitTokenExpiration(value: $value, gitType: $gitType)
}gitTokensQuery
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| list | List |
Rückgabe GitTokenListResult!
query GitTokens($list: List) {
gitTokens(list: $list) {
total
items {
id
name
value
expiresAt
flags
status
scopes
createdAt
}
}
}Auch verfügbar als: CLI-Befehl vulnara git_tokens
gitUserQuery
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! |
Rückgabe GitEntity!
query GitUser($id: ID!) {
gitUser(id: $id) {
__typename
... on Organization {
id
name
gitType
externalId
webUrl
htmlUrl
avatarUrl
color
}
... on GitUser {
id
name
gitType
externalId
webUrl
htmlUrl
avatarUrl
color
}
}
}Auch verfügbar als: MCP-Tool git_user
gitUsersQuery
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| list | List |
Rückgabe GitEntityListResult!
query GitUsers($list: List) {
gitUsers(list: $list) {
total
}
}Auch verfügbar als: MCP-Tool git_users
invitationQuery
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! |
Rückgabe Invitation
query Invitation($id: ID!) {
invitation(id: $id) {
id
email
tenantName
}
}invitationsQuery
Rückgabe [Invitation!]!
query Invitations {
invitations {
id
email
tenantName
}
}inviteTenantMemberMutation
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| input | InviteTeamMemberInput! |
Rückgabe Boolean!
mutation InviteTenantMember($input: InviteTeamMemberInput!) {
inviteTenantMember(input: $input)
}invoiceQuery
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! |
Rückgabe Invoice!
query Invoice($id: ID!) {
invoice(id: $id) {
id
invoiceNumber
date
dueDate
status
total
currency
}
}invoicesQuery
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| list | List |
Rückgabe InvoiceListResult!
query Invoices($list: List) {
invoices(list: $list) {
total
items {
id
invoiceNumber
date
dueDate
status
total
currency
}
}
}markAllNotificationsReadMutation
Rückgabe Boolean!
mutation MarkAllNotificationsRead {
markAllNotificationsRead
}markNotificationDeliveredMutation
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! |
Rückgabe Boolean!
mutation MarkNotificationDelivered($id: ID!) {
markNotificationDelivered(id: $id)
}markNotificationsReadMutation
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| ids | [ID!]! |
Rückgabe Boolean!
mutation MarkNotificationsRead($ids: [ID!]!) {
markNotificationsRead(ids: $ids)
}myUserQuery
Rückgabe MyUser
query MyUser {
myUser {
id
email
name
username
tenants {
id
isPaying
}
preferences {
theme
dateTimeFormat
repositoriesView
}
}
}Auch verfügbar als: MCP-Tool my_user
networkQuery
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! |
Rückgabe Network!
query Network($id: ID!) {
network(id: $id) {
id
name
network
networkType
tenant
securityScore
createdAt
updatedAt
}
}Auch verfügbar als: CLI-Befehl vulnara get_network · MCP-Tool network
networksQuery
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| list | List |
Rückgabe NetworkListResult!
query Networks($list: List) {
networks(list: $list) {
total
items {
id
name
network
networkType
tenant
securityScore
createdAt
updatedAt
}
}
}Auch verfügbar als: CLI-Befehl vulnara networks · MCP-Tool networks
networkScanFindingQuery
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! |
Rückgabe NetworkScanFinding!
query NetworkScanFinding($id: ID!) {
networkScanFinding(id: $id) {
id
scanResultId
host
hostname
hostnameType
protocol
port
serviceName
}
}Auch verfügbar als: MCP-Tool network_scan_finding
networkScanFindingsQuery
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| list | List |
Rückgabe NetworkScanFindingListResult!
query NetworkScanFindings($list: List) {
networkScanFindings(list: $list) {
total
items {
id
scanResultId
host
hostname
hostnameType
protocol
port
serviceName
}
}
}Auch verfügbar als: CLI-Befehl vulnara network_scan_findings · MCP-Tool network_scan_findings
networkScanResultQuery
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! |
Rückgabe NetworkScanResult!
query NetworkScanResult($id: ID!) {
networkScanResult(id: $id) {
id
networkId
status
createdAt
updatedAt
scanTime
network {
id
name
network
networkType
tenant
securityScore
createdAt
updatedAt
}
}
}Auch verfügbar als: CLI-Befehl vulnara get_network_scan_result · MCP-Tool network_scan_result
networkScanResultsQuery
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| list | List |
Rückgabe NetworkScanResultListResult!
query NetworkScanResults($list: List) {
networkScanResults(list: $list) {
total
items {
id
networkId
status
createdAt
updatedAt
scanTime
}
}
}Auch verfügbar als: CLI-Befehl vulnara network_scan_results · MCP-Tool network_scan_results
notificationsQuery
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| list | List |
Rückgabe NotificationList!
query Notifications($list: List) {
notifications(list: $list) {
items {
id
type
eventType
data
read
createdAt
}
total
}
}Auch verfügbar als: MCP-Tool notifications
notificationsSubscription
Rückgabe Notification!
subscription Notifications {
notifications {
id
type
eventType
data
read
createdAt
}
}notificationScopeQuery
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! |
Rückgabe NotificationScope!
query NotificationScope($id: ID!) {
notificationScope(id: $id) {
id
channelIds
channelType
scopes
isActive
status
headers {
name
value
}
template
}
}Auch verfügbar als: CLI-Befehl vulnara get_notification_scope · MCP-Tool notification_scope
notificationScopesQuery
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| list | List |
Rückgabe NotificationScopeListResult!
query NotificationScopes($list: List) {
notificationScopes(list: $list) {
total
items {
id
channelIds
channelType
scopes
isActive
status
template
}
}
}Auch verfügbar als: CLI-Befehl vulnara notification_scopes · MCP-Tool notification_scopes
organizationQuery
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! |
Rückgabe GitEntity!
query Organization($id: ID!) {
organization(id: $id) {
__typename
... on Organization {
id
name
gitType
externalId
webUrl
htmlUrl
avatarUrl
color
}
... on GitUser {
id
name
gitType
externalId
webUrl
htmlUrl
avatarUrl
color
}
}
}Auch verfügbar als: MCP-Tool organization
organizationsQuery
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| list | List |
Rückgabe GitEntityListResult!
query Organizations($list: List) {
organizations(list: $list) {
total
}
}Auch verfügbar als: MCP-Tool organizations
paymentMethodQuery
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! |
Rückgabe PaymentMethod!
query PaymentMethod($id: ID!) {
paymentMethod(id: $id) {
id
default
lastFour
brand
expiryMonth
expiryYear
cardholderName
expired
}
}paymentMethodsQuery
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| list | List |
Rückgabe PaymentMethodListResult!
query PaymentMethods($list: List) {
paymentMethods(list: $list) {
total
items {
id
default
lastFour
brand
expiryMonth
expiryYear
cardholderName
expired
}
}
}plansQuery
Rückgabe [Plan!]!
query Plans {
plans {
id
availableGitScanMinutes
availableNetworkScanMinutes
maxRepositories
maxNetworks
maxEmails
pricePerGitScanMinute
pricePerNetworkScanMinute
}
}programmingLanguagesQuery
Rückgabe [String!]
query ProgrammingLanguages {
programmingLanguages
}Auch verfügbar als: CLI-Befehl vulnara programming_languages · MCP-Tool programming_languages
promoGrantsQuery
Every grant this tenant holds, including ones that have run out.
Rückgabe [PromoGrant!]!
query PromoGrants {
promoGrants {
id
code
startsAt
endsAt
gitScanMinutes
networkScanMinutes
maxRepositories
maxNetworks
}
}Auch verfügbar als: MCP-Tool promo_grants
redeemPromoCodeMutation
Redeem a code for this tenant. ADMIN because redeeming changes what the tenant may spend, which is the same authority as changing the plan. A refusal arrives as PROMO_CODE_UNKNOWN, PROMO_CODE_INACTIVE, PROMO_CODE_EXPIRED, PROMO_CODE_FULLY_CLAIMED or PROMO_CODE_ALREADY_REDEEMED. They are distinct because each tells the person typing the code something different about what to do next.
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| code | String! |
Rückgabe PromoGrant!
mutation RedeemPromoCode($code: String!) {
redeemPromoCode(code: $code) {
id
code
startsAt
endsAt
gitScanMinutes
networkScanMinutes
maxRepositories
maxNetworks
}
}registerPushSubscriptionMutation
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| input | PushSubscriptionInput! |
Rückgabe Boolean!
mutation RegisterPushSubscription($input: PushSubscriptionInput!) {
registerPushSubscription(input: $input)
}remediationTemplateQuery
Rückgabe RemediationTemplate!
query RemediationTemplate {
remediationTemplate {
codeIssueBody
dependencyIssueBody
pullRequestBody
}
}Auch verfügbar als: MCP-Tool remediation_template
repositoriesQuery
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| list | List |
Rückgabe RepositoryListResult!
query Repositories($list: List) {
repositories(list: $list) {
total
items {
id
gitEntityId
repositoryName
private
securityScore
programmingLanguage
repositorySize
numberOfBranches
}
}
}Auch verfügbar als: CLI-Befehl vulnara repositories · MCP-Tool repositories
repositoryQuery
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! |
Rückgabe Repository!
query Repository($id: ID!) {
repository(id: $id) {
id
gitEntityId
repositoryName
private
securityScore
programmingLanguage
repositorySize
numberOfBranches
}
}Auch verfügbar als: CLI-Befehl vulnara get_repository · MCP-Tool repository
repositoryBranchesQuery
Branch names for a repository, read from its git provider, so the scan form can offer real branches instead of free-text input.
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| repositoryId | ID! |
Rückgabe [String!]!
query RepositoryBranches($repositoryId: ID!) {
repositoryBranches(repositoryId: $repositoryId)
}Auch verfügbar als: MCP-Tool repository_branches
repositoryDependencyScanFindingGroupsQuery
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| list | List |
Rückgabe RepositoryDependencyScanFindingGroupListResult!
query RepositoryDependencyScanFindingGroups($list: List) {
repositoryDependencyScanFindingGroups(list: $list) {
total
items {
id
dependency
repositoryId
severity
installedVersion
occurrences
issueUrl
issueStatus
}
}
}Auch verfügbar als: MCP-Tool repository_dependency_scan_finding_groups
repositoryDependencyScanFindingsQuery
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| list | List |
Rückgabe RepositoryDependencyScanFindingListResult!
query RepositoryDependencyScanFindings($list: List) {
repositoryDependencyScanFindings(list: $list) {
total
items {
id
commitScanId
createdAt
updatedAt
severity
vulnerability
dependency
installedVersion
}
}
}Auch verfügbar als: CLI-Befehl vulnara repository_dependency_scan_findings · MCP-Tool repository_dependency_scan_findings
requestNSFConsultationMutation
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| input | NSFConsultation! |
Rückgabe Boolean!
mutation RequestNSFConsultation($input: NSFConsultation!) {
requestNSFConsultation(input: $input)
}Auch verfügbar als: CLI-Befehl vulnara request_nsf_consultation
requestRSFConsultationMutation
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| input | RSFConsultation! |
Rückgabe Boolean!
mutation RequestRSFConsultation($input: RSFConsultation!) {
requestRSFConsultation(input: $input)
}Auch verfügbar als: CLI-Befehl vulnara request_rsf_consultation
retryPaymentMutation
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| invoiceId | ID! | |
| paymentMethodId | ID! |
Rückgabe Invoice!
mutation RetryPayment($invoiceId: ID!, $paymentMethodId: ID!) {
retryPayment(invoiceId: $invoiceId, paymentMethodId: $paymentMethodId) {
id
invoiceNumber
date
dueDate
status
total
currency
}
}revealScanFindingMatchMutation
The audited path to the raw secret behind a masked ScanFinding/ScanFindingGroup/ ScanFindingMatchGroup.match. Every call is logged with the caller, repository and match hash.
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| repositoryId | ID! | |
| matchHash | String! |
Rückgabe String!
mutation RevealScanFindingMatch($repositoryId: ID!, $matchHash: String!) {
revealScanFindingMatch(repositoryId: $repositoryId, matchHash: $matchHash)
}scanFindingGroupsQuery
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| list | List |
Rückgabe ScanFindingGroupListResult!
query ScanFindingGroups($list: List) {
scanFindingGroups(list: $list) {
total
items {
id
fingerprint
matchHash
matchedByToolCount
file
severity
confidence
match
}
}
}Auch verfügbar als: MCP-Tool scan_finding_groups
scanFindingMatchGroupsQuery
Findings grouped by cross-tool identity, one row per real secret.
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| list | List |
Rückgabe ScanFindingMatchGroupListResult!
query ScanFindingMatchGroups($list: List) {
scanFindingMatchGroups(list: $list) {
total
items {
id
matchHash
file
line
severity
confidence
match
occurrences
}
}
}Auch verfügbar als: MCP-Tool scan_finding_match_groups
scanFindingsQuery
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| list | List |
Rückgabe ScanFindingListResult!
query ScanFindings($list: List) {
scanFindings(list: $list) {
total
items {
id
commitScanId
createdAt
updatedAt
line
file
severity
confidence
}
}
}Auch verfügbar als: CLI-Befehl vulnara scan_findings · MCP-Tool scan_findings
scanResultQuery
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! |
Rückgabe ScanResult!
query ScanResult($id: ID!) {
scanResult(id: $id) {
id
repositoryId
scanType
scanner
dockerScanToolId
status
createdAt
updatedAt
}
}Auch verfügbar als: CLI-Befehl vulnara get_scan_result · MCP-Tool scan_result
scanResultsQuery
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| list | List |
Rückgabe ScanResultListResult!
query ScanResults($list: List) {
scanResults(list: $list) {
total
items {
id
repositoryId
scanType
scanner
dockerScanToolId
status
createdAt
updatedAt
}
}
}Auch verfügbar als: CLI-Befehl vulnara scan_results · MCP-Tool scan_results
scanScheduleQuery
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! |
Rückgabe ScanSchedule!
query ScanSchedule($id: ID!) {
scanSchedule(id: $id) {
id
action
repositoryId
gitEntityId
branch
dockerScanToolId
frequency
hourUtc
}
}Auch verfügbar als: MCP-Tool scan_schedule
scanSchedulesQuery
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| list | List |
Rückgabe ScanScheduleListResult!
query ScanSchedules($list: List) {
scanSchedules(list: $list) {
total
items {
id
action
repositoryId
gitEntityId
branch
dockerScanToolId
frequency
hourUtc
}
}
}Auch verfügbar als: MCP-Tool scan_schedules
serviceAccountsQuery
Rückgabe [ServiceAccount!]!
query ServiceAccounts {
serviceAccounts {
id
name
isActive
expiresAt
createdBy {
id
email
username
name
}
}
}Auch verfügbar als: CLI-Befehl vulnara service_accounts
setDefaultPaymentMethodMutation
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! |
Rückgabe Boolean!
mutation SetDefaultPaymentMethod($id: ID!) {
setDefaultPaymentMethod(id: $id)
}setFindingTriageMutation
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| input | SetFindingTriageInput! |
Rückgabe FindingTriage!
mutation SetFindingTriage($input: SetFindingTriageInput!) {
setFindingTriage(input: $input) {
id
repositoryId
matchKey
findingType
state
justification
response
priority
}
}setGitEntityIgnorePathsMutation
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| input | SetGitEntityIgnorePathsInput! |
Rückgabe GitEntity!
mutation SetGitEntityIgnorePaths($input: SetGitEntityIgnorePathsInput!) {
setGitEntityIgnorePaths(input: $input) {
__typename
... on Organization {
id
name
gitType
externalId
webUrl
htmlUrl
avatarUrl
color
}
... on GitUser {
id
name
gitType
externalId
webUrl
htmlUrl
avatarUrl
color
}
}
}setRemediationTemplateMutation
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| input | RemediationTemplateInput! |
Rückgabe RemediationTemplate!
mutation SetRemediationTemplate($input: RemediationTemplateInput!) {
setRemediationTemplate(input: $input) {
codeIssueBody
dependencyIssueBody
pullRequestBody
}
}setRepositoryEnabledMutation
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| input | SetRepositoryEnabledInput! |
Rückgabe Boolean!
mutation SetRepositoryEnabled($input: SetRepositoryEnabledInput!) {
setRepositoryEnabled(input: $input)
}setRepositoryIgnorePathsMutation
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| input | SetRepositoryIgnorePathsInput! |
Rückgabe Repository!
mutation SetRepositoryIgnorePaths($input: SetRepositoryIgnorePathsInput!) {
setRepositoryIgnorePaths(input: $input) {
id
gitEntityId
repositoryName
private
securityScore
programmingLanguage
repositorySize
numberOfBranches
}
}setServiceAccountActiveMutation
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| input | SetServiceAccountActiveInput! |
Rückgabe ServiceAccount!
mutation SetServiceAccountActive($input: SetServiceAccountActiveInput!) {
setServiceAccountActive(input: $input) {
id
name
isActive
expiresAt
createdBy {
id
email
username
name
}
}
}Auch verfügbar als: CLI-Befehl vulnara set_service_account_active
startNetworkScanMutation
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| input | StartNetworkScanInput! |
Rückgabe Boolean!
mutation StartNetworkScan($input: StartNetworkScanInput!) {
startNetworkScan(input: $input)
}Auch verfügbar als: CLI-Befehl vulnara start_network_scan
startRepositoryScanMutation
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| input | StartRepositoryScanInput! |
Rückgabe RepositoryScanTask!
mutation StartRepositoryScan($input: StartRepositoryScanInput!) {
startRepositoryScan(input: $input) {
id
objectId
status
state {
totalCommits
scheduled
scanned
failed
parsed
}
createdAt
scanResult {
id
repositoryId
scanType
scanner
dockerScanToolId
status
createdAt
updatedAt
}
}
}Auch verfügbar als: CLI-Befehl vulnara start_repository_scan
statisticsQuery
Rückgabe TenantStatistics!
query Statistics {
statistics {
tenant
totalUsers
totalGitEntities
totalRepositories
totalNetworks
}
}Auch verfügbar als: MCP-Tool statistics
taskQuery
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! |
Rückgabe Task!
query Task($id: ID!) {
task(id: $id) {
__typename
... on RepositoryScanTask {
id
objectId
status
createdAt
}
... on NetworkScanTask {
id
objectId
status
createdAt
}
}
}Auch verfügbar als: MCP-Tool task
taskEventsSubscription
Rückgabe TaskEvent!
subscription TaskEvents {
taskEvents {
type
taskId
}
}tasksQuery
Rückgabe [Task!]!
query Tasks {
tasks {
__typename
... on RepositoryScanTask {
id
objectId
status
createdAt
}
... on NetworkScanTask {
id
objectId
status
createdAt
}
}
}Auch verfügbar als: CLI-Befehl vulnara tasks · MCP-Tool tasks
testNotificationScopeMutation
Send a test notification to the rule's channel and record its reachability as the channel status.
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! |
Rückgabe NotificationScope!
mutation TestNotificationScope($id: ID!) {
testNotificationScope(id: $id) {
id
channelIds
channelType
scopes
isActive
status
headers {
name
value
}
template
}
}transferGitEntityMutation
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| input | TransferGitEntityInput! |
Rückgabe Boolean!
mutation TransferGitEntity($input: TransferGitEntityInput!) {
transferGitEntity(input: $input)
}Auch verfügbar als: CLI-Befehl vulnara transfer_git_entity
transferNetworkMutation
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| input | TransferNetworkInput! |
Rückgabe Boolean!
mutation TransferNetwork($input: TransferNetworkInput!) {
transferNetwork(input: $input)
}Auch verfügbar als: CLI-Befehl vulnara transfer_network
unreadNotificationCountQuery
Rückgabe Int!
query UnreadNotificationCount {
unreadNotificationCount
}Auch verfügbar als: MCP-Tool unread_notification_count
unregisterPushSubscriptionMutation
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| endpoint | String! |
Rückgabe Boolean!
mutation UnregisterPushSubscription($endpoint: String!) {
unregisterPushSubscription(endpoint: $endpoint)
}updateGitEntityMutation
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| input | UpdateGitEntityInput! |
Rückgabe GitEntity!
mutation UpdateGitEntity($input: UpdateGitEntityInput!) {
updateGitEntity(input: $input) {
__typename
... on Organization {
id
name
gitType
externalId
webUrl
htmlUrl
avatarUrl
color
}
... on GitUser {
id
name
gitType
externalId
webUrl
htmlUrl
avatarUrl
color
}
}
}updateGitTokenMutation
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| input | UpdateGitTokenInput! |
Rückgabe GitToken!
mutation UpdateGitToken($input: UpdateGitTokenInput!) {
updateGitToken(input: $input) {
id
name
value
expiresAt
flags
status
scopes
createdAt
}
}Auch verfügbar als: CLI-Befehl vulnara update_git_token
updateMyUserPreferencesMutation
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| input | UpdateUserPreferencesInput! |
Rückgabe UserPreferences!
mutation UpdateMyUserPreferences($input: UpdateUserPreferencesInput!) {
updateMyUserPreferences(input: $input) {
theme
dateTimeFormat
repositoriesView
}
}updateNotificationScopeMutation
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| input | UpdateNotificationScopeInput! |
Rückgabe NotificationScope!
mutation UpdateNotificationScope($input: UpdateNotificationScopeInput!) {
updateNotificationScope(input: $input) {
id
channelIds
channelType
scopes
isActive
status
headers {
name
value
}
template
}
}Auch verfügbar als: CLI-Befehl vulnara update_notification_scope
updateScanScheduleMutation
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| input | UpdateScanScheduleInput! |
Rückgabe ScanSchedule!
mutation UpdateScanSchedule($input: UpdateScanScheduleInput!) {
updateScanSchedule(input: $input) {
id
action
repositoryId
gitEntityId
branch
dockerScanToolId
frequency
hourUtc
}
}updateUserRolesMutation
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| input | UpdateUserRolesInput! |
Rückgabe TenantUser!
mutation UpdateUserRoles($input: UpdateUserRolesInput!) {
updateUserRoles(input: $input) {
id
roles
user {
id
email
username
name
}
}
}upgradeToPayingMutation
Rückgabe Boolean!
mutation UpgradeToPaying {
upgradeToPaying
}usageQuery
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| startDate | DateTime! | |
| endDate | DateTime! |
Rückgabe Usage!
query Usage($startDate: DateTime!, $endDate: DateTime!) {
usage(startDate: $startDate, endDate: $endDate) {
accountTier
usedGitScanTimeMinutes
repositoryScanLimited
usedNetworkScanTimeMinutes
networkScanLimited
parallelScans
availableGitScanMinutes
availableNetworkScanMinutes
}
}workspaceOverviewQuery
Argumente
| Name | Typ | Beschreibung |
|---|---|---|
| gitEntityId | ID! |
Rückgabe WorkspaceOverview!
query WorkspaceOverview($gitEntityId: ID!) {
workspaceOverview(gitEntityId: $gitEntityId) {
severityCounts {
severity
count
}
totalFindings
totalRepositories
scanned
unscanned
}
}Auch verfügbar als: MCP-Tool workspace_overview
Typen
AgingBucket object
| Name | Typ | Beschreibung |
|---|---|---|
| bucket | String! | Age range in days, such as 8-30 or 91+. |
| count | Int! |
ChannelStatus enum
| Name | Beschreibung |
|---|---|
| operational | |
| degraded | |
| unknown | |
| error |
ChannelType enum
| Name | Beschreibung |
|---|---|
| slack | |
| webhook | |
| telegram | |
| discord |
CommitScan object
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! | |
| scanResultId | ID! | |
| commitHash | String! | |
| createdAt | DateTime | |
| updatedAt | DateTime | |
| scanResult | ScanResult! |
CommitScanListResult object
| Name | Typ | Beschreibung |
|---|---|---|
| total | Int! | |
| items | [CommitScan!]! |
CorroboratedFinding object
One finding that more than one scanner reported. Carries no matched value on purpose: a corroborated finding is very often a leaked secret, and the dashboard is the most widely viewed screen in the product. The repository and file identify it, and the view behind the link masks what it shows.
| Name | Typ | Beschreibung |
|---|---|---|
| kind | String! | Either code or dependency. |
| repositoryId | ID! | |
| repositoryName | String! | |
| label | String | The file for a code finding, the library for a dependency finding. |
| severity | String! | |
| scanners | [String!]! | The scanners that agreed, by name. |
| toolCount | Int! | |
| findingKey | String! | The identity the vulnerabilities explorer addresses this finding by, usable directly as its matchHash filter. |
CreateGitEntityInput input
| Name | Typ | Beschreibung |
|---|---|---|
| name | String! | |
| gitType | GitType! | |
| externalId | Float | |
| webUrl | String | |
| ignorePaths | [String!] | Gitignore-style glob patterns applied to every repo under this entity. |
| ownershipConsent | Boolean! | Attests that the caller's tenant owns this organisation/user, or is authorized to scan it. No default: the client must decide explicitly. Rejected unless true; the actor and statement version are added server-side, not taken from client input. |
CreateGitTokenInput input
| Name | Typ | Beschreibung |
|---|---|---|
| name | String! | |
| value | String! | |
| flags | [GitTokenFlag!]! | |
| gitTokenType | GitType! | |
| expiresAt | DateTime |
CreateNetworkInput input
| Name | Typ | Beschreibung |
|---|---|---|
| name | String! | |
| network | String! | |
| networkType | NetworkType! | |
| ownershipConsent | Boolean! |
CreateNotificationScopeInput input
| Name | Typ | Beschreibung |
|---|---|---|
| channelIds | [String!]! | |
| channelType | ChannelType! | |
| scopes | [String!]! | |
| isActive | Boolean! | |
| headers | [HttpHeaderInput!] | |
| templates | [NotificationTemplateInput!] |
CreateRepositoryInput input
| Name | Typ | Beschreibung |
|---|---|---|
| gitEntityId | ID! | |
| repositoryName | String! | |
| cloneUrl | String | |
| ignorePaths | [String!] | Gitignore-style glob patterns to exclude from scans. |
CreateScanScheduleInput input
| Name | Typ | Beschreibung |
|---|---|---|
| action | ScanScheduleAction | Defaults to SCAN. SYNC requires gitEntityId. |
| repositoryId | ID | Supply exactly one of repositoryId or gitEntityId. |
| gitEntityId | ID | |
| branch | String | |
| dockerScanToolId | ID | |
| frequency | ScanScheduleFrequency! | |
| hourUtc | Int! | |
| minuteUtc | Int | Defaults to 0 upstream, which is the minute every schedule fired at before this field existed. |
| dayOfWeek | Int | |
| isActive | Boolean | |
| recipients | [String!] | Required for a REPORT, refused for anything else. The address shape is checked here because this is the trust boundary; vulnara-api forwards it and vulnara-notification-api refuses a malformed one at the far end. |
CreateServiceAccountInput input
| Name | Typ | Beschreibung |
|---|---|---|
| name | String! | |
| expiresAt | DateTime! |
CreateServiceAccountPayload object
| Name | Typ | Beschreibung |
|---|---|---|
| serviceAccount | ServiceAccount! | |
| token | String! |
CreateTenantInput input
| Name | Typ | Beschreibung |
|---|---|---|
| name | String! |
Currency enum
| Name | Beschreibung |
|---|---|
| USD | |
| EUR | |
| BGN |
DashboardAnalytics object
| Name | Typ | Beschreibung |
|---|---|---|
| days | Int! | The window the deltas and activity are measured over. |
| generatedAt | DateTime! | |
| lastScanAt | DateTime | |
| averageSecurityScore | Float! | |
| previousAverageSecurityScore | Float! | The same score as it stood at the start of the period. |
| severityCounts | [SeverityCount!]! | |
| previousSeverityCounts | [SeverityCount!]! | |
| exposure | Exposure! | |
| scanActivity | [ScanActivityPoint!]! | |
| scoreTrend | [ScoreTrendPoint!]! | |
| topRiskRepositories | [RepositoryRisk!]! | |
| remediation | RemediationFunnel! | |
| dependencyFixes | DependencyFixes! | |
| aging | [AgingBucket!]! | |
| oldestFindingDays | Int | |
| oldestCriticalDays | Int | |
| coverage | ScanCoverage! | |
| scanHealth | ScanHealth! | |
| staleWorkspaces | [StaleWorkspace!]! |
DependencyFixes object
| Name | Typ | Beschreibung |
|---|---|---|
| total | Int! | |
| fixable | Int! | Dependency findings whose advisory names a fixed version. |
DockerScanTool object
A scanner, named. The image, tag and arguments are deliberately not exposed: they identify our scanners and their private registry paths, and every screen in the product only ever needs to label a scan with the tool that produced it. Managed in vulnara-backoffice, not through this API.
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! | |
| name | String! |
DockerScanToolListResult object
| Name | Typ | Beschreibung |
|---|---|---|
| total | Int! | |
| items | [DockerScanTool!]! |
Exposure object
Findings currently exposed, and how that moved over the period. Deduplicated by match hash within a repository and read from the latest scan per tool, so this is what is open now - not every row ever written.
| Name | Typ | Beschreibung |
|---|---|---|
| total | Int! | |
| previousTotal | Int! | |
| newFindings | Int! | |
| resolvedFindings | Int! | |
| codeFindings | Int! | |
| dependencyFindings | Int! | |
| corroboratedFindings | Int! | Findings more than one scanner reported - the least likely to be noise. |
| corroborated | [CorroboratedFinding!]! | The findings behind corroboratedFindings, worst first. They come from the same query as the count, so the two cannot disagree - which is why this is here rather than the client deep-linking into the explorer, whose finding list is a different population (every scan, code only, triaged included). Capped, while the count stays exact: a tenant over the cap reads as "some of many" rather than seeing a list that looks complete. |
| falsePositives | Int! | Held back by a decision rather than by a fix. Reported beside the open total, never folded into it - a number that shrinks when somebody dismisses something is what this endpoint exists to avoid. |
| notAffected | Int! | |
| hiddenButScored | Int! | Real findings a decision keeps out of the working list - deferred, or will-not-fix. They still count against the score, so they are named here rather than being quietly absent from both numbers. |
| resolvedFindingsTriaged | Int! | Everything a decision took out of the score entirely. |
FetchGitEntityTask object
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! | |
| objectId | ID! | |
| status | TaskStatus! | |
| state | FetchGitEntityTaskState! | |
| createdAt | Int! | |
| gitEntity | GitEntity! |
FetchGitEntityTaskState object
| Name | Typ | Beschreibung |
|---|---|---|
| processed | Int! | |
| total | Int! |
FetchRepositoriesInput input
| Name | Typ | Beschreibung |
|---|---|---|
| gitEntityId | ID! | |
| gitTokenId | ID |
Filter input
| Name | Typ | Beschreibung |
|---|---|---|
| field | String! | |
| min | Float | |
| max | Float | |
| stringEquals | String | |
| idEquals | ID |
FindingCorroboration object
One real-world issue and how many independent scanners found it. toolCount > 1 is the "confirmed by N tools" signal.
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! | |
| matchHash | String! | |
| toolCount | Int! | |
| severity | Severity | Reconciled across the tools that reported it (highest severity wins). |
FindingCorroborationListResult object
| Name | Typ | Beschreibung |
|---|---|---|
| total | Int! | |
| items | [FindingCorroboration!]! |
FindingTriage object
A decision taken about a finding. Keyed on the finding's identity rather than its row, so it survives rescans and applies to every scanner that reported the same thing. The three axes are separate on purpose. state decides whether the finding still counts against the security score - only states asserting no live risk take it out. response and a defer priority clear it from the working list while leaving the score alone, because deciding not to act on something does not make it safe.
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! | |
| repositoryId | ID! | |
| matchKey | String! | |
| findingType | String! | |
| state | TriageState! | |
| justification | TriageJustification | |
| response | TriageResponse | |
| priority | TriagePriority | |
| reason | String! | |
| createdBy | String | |
| createdAt | DateTime! | |
| expiresAt | DateTime | Required whenever the decision hides a finding that is still exposed. |
FindingTriageEvent object
One entry in a finding's decision history. Append-only.
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! | |
| repositoryId | ID! | |
| matchKey | String! | |
| action | String! | set or reopen. |
| state | TriageState | |
| justification | TriageJustification | |
| response | TriageResponse | |
| priority | TriagePriority | |
| reason | String | |
| expiresAt | DateTime | |
| actor | String | |
| createdAt | DateTime! |
GitEntity union
Eines von: Organization, GitUser
GitEntityListResult object
| Name | Typ | Beschreibung |
|---|---|---|
| total | Int! | |
| items | [GitEntity!]! |
GitEntityType enum
| Name | Beschreibung |
|---|---|
| organization | |
| user |
GitToken object
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! | |
| name | String | |
| value | String! | |
| expiresAt | DateTime | |
| flags | [GitTokenFlag!]! | |
| status | GitTokenStatus! | |
| scopes | [String!]! | |
| createdAt | DateTime | |
| updatedAt | DateTime | |
| gitTokenType | GitType! | |
| tenant | String! | |
| gitEntities | GitEntityListResult! |
GitTokenAssociationInput input
| Name | Typ | Beschreibung |
|---|---|---|
| gitEntityId | ID! | |
| gitTokenId | ID! |
GitTokenCheck object
Result of probing a git token against its provider so the UI can pre-fill the expiry and explain what's wrong when the token is rejected.
| Name | Typ | Beschreibung |
|---|---|---|
| valid | Boolean! | Whether the provider accepted the token. |
| statusCode | Int | HTTP status the provider returned (e.g. 401 for bad credentials), if any. |
| error | String | Provider error message/code (e.g. "Bad credentials"), if the check failed. |
| expiresAt | DateTime | The token's own expiry as reported by the provider, if it exposes one. |
| publicRepositoryCount | Int | Public repositories the token can see for the given workspace name, or null when no name was supplied, the token is invalid, or the provider couldn't be reached. |
| privateRepositoryCount | Int | Private repositories the token can see for the given workspace name, or null when no name was supplied, the token is invalid, or the provider couldn't be reached. |
GitTokenFlag enum
| Name | Beschreibung |
|---|---|
| default |
GitTokenListResult object
| Name | Typ | Beschreibung |
|---|---|---|
| total | Int! | |
| items | [GitToken!]! |
GitTokenStatus enum
| Name | Beschreibung |
|---|---|
| valid | |
| invalid | |
| unknown | |
| error |
GitType enum
| Name | Beschreibung |
|---|---|
| github | |
| gitlab |
GitUser object
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! | |
| name | String! | |
| gitType | GitType! | |
| externalId | Float | |
| webUrl | String | |
| htmlUrl | String | |
| avatarUrl | String | Presigned URL of the entity's avatar (re-hosted from the provider), null if none. |
| color | String | Representative, always-vivid colour (hex) derived from the avatar or seeded from the name. |
| averageSecurityScore | Float! | |
| lastImportDate | DateTime | |
| repositoryCount | Int | |
| type | GitEntityType! | |
| createdAt | DateTime! | |
| updatedAt | DateTime | |
| ignorePaths | [String!] | |
| tags | [Tag!]! |
HttpHeader object
| Name | Typ | Beschreibung |
|---|---|---|
| name | String! | |
| value | String! |
HttpHeaderInput input
| Name | Typ | Beschreibung |
|---|---|---|
| name | String! | |
| value | String! |
Invitation object
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! | |
| String! | ||
| tenantName | String! |
InviteTeamMemberInput input
| Name | Typ | Beschreibung |
|---|---|---|
| String! | ||
| language | String |
Invoice object
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! | |
| invoiceNumber | String | |
| date | DateTime! | |
| dueDate | DateTime! | |
| status | String! | |
| total | Float! | |
| currency | Currency! |
InvoiceDownload object
| Name | Typ | Beschreibung |
|---|---|---|
| url | String! | |
| filename | String! | |
| tenant | String! | |
| contentType | String! |
InvoiceListResult object
| Name | Typ | Beschreibung |
|---|---|---|
| total | Int! | |
| items | [Invoice!]! |
IssueStatus enum
Normalized issue state across providers (GitHub open/closed, GitLab opened/closed).
| Name | Beschreibung |
|---|---|
| open | |
| closed |
MyUser object
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! | |
| String! | ||
| name | String! | |
| username | String! | |
| tenants | [Tenant!]! | |
| preferences | UserPreferences! |
Network object
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! | |
| name | String! | |
| network | String! | |
| networkType | NetworkType! | |
| tenant | String! | |
| securityScore | Float! | |
| createdAt | DateTime! | |
| updatedAt | DateTime | |
| tags | [Tag!]! |
NetworkListResult object
| Name | Typ | Beschreibung |
|---|---|---|
| total | Int! | |
| items | [Network!]! |
NetworkScanFinding object
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! | |
| scanResultId | ID! | |
| host | String! | |
| hostname | String! | |
| hostnameType | String | |
| protocol | String! | |
| port | Int! | |
| serviceName | String! | |
| state | String! | |
| product | String! | |
| version | String! | |
| extraInfo | String! | |
| reason | String! | |
| confidence | Int! | |
| cpe | String! | |
| tags | [Tag!]! | |
| createdAt | DateTime! | |
| updatedAt | DateTime | |
| networkScanResult | NetworkScanResult! |
NetworkScanFindingListResult object
| Name | Typ | Beschreibung |
|---|---|---|
| total | Int! | |
| items | [NetworkScanFinding!]! |
NetworkScanResult object
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! | |
| networkId | ID! | |
| status | ScanStatus! | |
| createdAt | DateTime! | |
| updatedAt | DateTime | |
| scanTime | Int | |
| network | Network! |
NetworkScanResultListResult object
| Name | Typ | Beschreibung |
|---|---|---|
| total | Int! | |
| items | [NetworkScanResult!]! |
NetworkScanTask object
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! | |
| objectId | ID! | |
| status | TaskStatus! | |
| state | NetworkScanTaskState! | |
| createdAt | Int! | |
| scanResult | NetworkScanResult! |
NetworkScanTaskState object
| Name | Typ | Beschreibung |
|---|---|---|
| totalHosts | Int! | |
| processedHosts | Int! | |
| currentHost | String |
NetworkType enum
| Name | Beschreibung |
|---|---|
| public | |
| private | |
| vpn | |
| internal | |
| external | |
| dmz | |
| unknown |
Notification object
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! | |
| type | NotificationType! | |
| eventType | String! | |
| data | JSON | |
| read | Boolean! | |
| createdAt | DateTime! |
NotificationList object
| Name | Typ | Beschreibung |
|---|---|---|
| items | [Notification!]! | |
| total | Int! |
NotificationScope object
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! | |
| channelIds | [String!]! | |
| channelType | ChannelType! | |
| scopes | [String!]! | |
| isActive | Boolean! | |
| status | ChannelStatus! | |
| headers | [HttpHeader!] | Custom HTTP headers sent with webhook deliveries (webhook channel only). |
| template | String | Deprecated: superseded by templates. |
| templates | [NotificationTemplate!] | Per-event message templates (eventType '*' is the default for all events). |
NotificationScopeListResult object
| Name | Typ | Beschreibung |
|---|---|---|
| total | Int! | |
| items | [NotificationScope!]! |
NotificationTemplate object
A message template for one event type ('*' = every event).
| Name | Typ | Beschreibung |
|---|---|---|
| eventType | String! | |
| template | String! |
NotificationTemplateInput input
| Name | Typ | Beschreibung |
|---|---|---|
| eventType | String! | |
| template | String! |
NotificationType enum
| Name | Beschreibung |
|---|---|
| SCAN_FINISHED | |
| REPOSITORY_FETCH_FINISHED |
NSFConsultation input
| Name | Typ | Beschreibung |
|---|---|---|
| findingId | ID! |
Order enum
| Name | Beschreibung |
|---|---|
| ASC | |
| DESC |
Organization object
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! | |
| name | String! | |
| gitType | GitType! | |
| externalId | Float | |
| webUrl | String | |
| htmlUrl | String | |
| avatarUrl | String | Presigned URL of the entity's avatar (re-hosted from the provider), null if none. |
| color | String | Representative, always-vivid colour (hex) derived from the avatar or seeded from the name. |
| averageSecurityScore | Float! | |
| lastImportDate | DateTime | |
| repositoryCount | Int | |
| type | GitEntityType! | |
| createdAt | DateTime! | |
| updatedAt | DateTime | |
| ignorePaths | [String!] | |
| tags | [Tag!]! |
PaymentMethod object
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! | |
| default | Boolean! | |
| lastFour | String! | |
| brand | String! | |
| expiryMonth | Int! | |
| expiryYear | Int! | |
| cardholderName | String! | |
| expired | Boolean! |
PaymentMethodListResult object
| Name | Typ | Beschreibung |
|---|---|---|
| total | Int! | |
| items | [PaymentMethod!]! |
Plan object
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! | |
| availableGitScanMinutes | Int | |
| availableNetworkScanMinutes | Int | |
| maxRepositories | Int | |
| maxNetworks | Int | |
| maxEmails | Int | |
| pricePerGitScanMinute | Float | |
| pricePerNetworkScanMinute | Float | |
| currency | Currency |
PreferredDateTimeFormat enum
| Name | Beschreibung |
|---|---|
| localized | |
| iso | |
| us | |
| eu |
PreferredRepositoriesView enum
| Name | Beschreibung |
|---|---|
| board | |
| table |
PreferredTheme enum
| Name | Beschreibung |
|---|---|
| Light | |
| Dark | |
| System |
PromoGrant object
A promotion a tenant holds. The limits are the ones granted when the code was redeemed, not the ones the code names today: vulnara-api copies them at redemption so that editing a code cannot change a grant already made.
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! | |
| code | String! | |
| startsAt | DateTime! | |
| endsAt | DateTime! | |
| gitScanMinutes | Int | |
| networkScanMinutes | Int | |
| maxRepositories | Int | |
| maxNetworks | Int | |
| maxEmails | Int |
PrStatus enum
Normalized remediation pull/merge request state.
| Name | Beschreibung |
|---|---|
| open | |
| merged | |
| closed |
PushSubscriptionInput input
| Name | Typ | Beschreibung |
|---|---|---|
| endpoint | String! | |
| p256dh | String! | |
| auth | String! |
RemediationFunnel object
Findings to opened issues to merged remediation PRs.
| Name | Typ | Beschreibung |
|---|---|---|
| findings | Int! | |
| issuesOpened | Int! | |
| issuesClosed | Int! | |
| prsOpened | Int! | |
| prsMerged | Int! |
RemediationTemplate object
| Name | Typ | Beschreibung |
|---|---|---|
| codeIssueBody | String | |
| dependencyIssueBody | String | |
| pullRequestBody | String |
RemediationTemplateInput input
| Name | Typ | Beschreibung |
|---|---|---|
| codeIssueBody | String | |
| dependencyIssueBody | String | |
| pullRequestBody | String |
Repository object
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! | |
| gitEntityId | ID! | |
| repositoryName | String! | |
| private | Boolean | |
| securityScore | Float | |
| programmingLanguage | [String!] | |
| repositorySize | Float | Repository size in bytes. Float, not Int, so large repos (>2GB) don't overflow GraphQL's 32-bit Int. |
| numberOfBranches | Int | |
| cloneUrl | String | |
| createdAt | DateTime! | |
| updatedAt | DateTime | |
| isBlacklisted | Boolean | |
| enabled | Boolean | |
| isStandalone | Boolean | |
| avatarUrl | String | Presigned URL of the repo's own avatar (GitLab project image or GitHub custom social-preview image); null otherwise - fall back to gitEntity.avatarUrl. |
| color | String | Vivid colour derived from the repo's avatar; null when it has no colourful image - fall back to a hash of the id. |
| ignorePaths | [String!] | |
| tags | [Tag!]! | |
| gitEntity | GitEntity! | |
| severityCounts | [SeverityCount!] | |
| latestScan | RepositoryScan | Most recent scan's status and time (null if never scanned). |
| scoreHistory | [Float!] | Recent security scores oldest→newest, for the list trend sparkline. |
RepositoryDependencyScanFinding object
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! | |
| commitScanId | ID! | |
| createdAt | DateTime! | |
| updatedAt | DateTime | |
| severity | Severity | |
| vulnerability | String | |
| dependency | String | |
| installedVersion | String | |
| fixedVersion | String | |
| purl | String | Package URL, e.g. pkg:npm/[email protected]. |
| vulnerabilityAliases | [String!] | Other identifiers for the same advisory (GHSA, vendor ids). |
| matchHash | String | Cross-tool identity: two scanners reporting the same vulnerable package share this value, even when one leads with a CVE and the other a GHSA. |
| issueUrl | String | URL of the GitHub/GitLab issue opened for this dependency, if any. |
| issueStatus | IssueStatus | |
| prUrl | String | URL of the remediation PR opened for this dependency, if any. |
| prStatus | PrStatus | |
| commitScan | CommitScan! | |
| tags | [Tag!]! |
RepositoryDependencyScanFindingGroup object
One vulnerable library, aggregating all its advisories (CVEs). Queried with a scanResultId filter it covers that scan; without one it covers the tenant, one row per repository the library is vulnerable in.
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! | |
| dependency | String! | |
| repositoryId | ID | Which repository the library is vulnerable in. Null within a single scan result, where the caller already named the repository. |
| severity | Severity | |
| installedVersion | String | |
| occurrences | Int! | |
| issueUrl | String | |
| issueStatus | IssueStatus | |
| prUrl | String | |
| prStatus | PrStatus |
RepositoryDependencyScanFindingGroupListResult object
| Name | Typ | Beschreibung |
|---|---|---|
| total | Int! | |
| items | [RepositoryDependencyScanFindingGroup!]! |
RepositoryDependencyScanFindingListResult object
| Name | Typ | Beschreibung |
|---|---|---|
| total | Int! | |
| items | [RepositoryDependencyScanFinding!]! |
RepositoryListResult object
| Name | Typ | Beschreibung |
|---|---|---|
| total | Int! | |
| items | [Repository!]! |
RepositoryRisk object
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! | |
| name | String! | |
| securityScore | Float! | |
| criticalCount | Int! | |
| highCount | Int! | |
| findingCount | Int! |
RepositoryScan object
| Name | Typ | Beschreibung |
|---|---|---|
| status | ScanStatus | |
| scannedAt | DateTime |
RepositoryScanTask object
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! | |
| objectId | ID! | |
| status | TaskStatus! | |
| state | RepositoryScanTaskState! | |
| createdAt | Int! | |
| scanResult | ScanResult! |
RepositoryScanTaskState object
| Name | Typ | Beschreibung |
|---|---|---|
| totalCommits | Int! | |
| scheduled | Int! | |
| scanned | Int! | |
| failed | Int! | |
| parsed | Int! |
RevolutOrder object
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! | |
| token | String! |
RSFConsultation input
| Name | Typ | Beschreibung |
|---|---|---|
| findingId | ID! |
ScanActivityPoint object
| Name | Typ | Beschreibung |
|---|---|---|
| date | String! | |
| count | Int! | Every scan started that day, failed ones included. |
| succeeded | Int! | |
| failed | Int! | Failed and cancelled scans - activity that produced no coverage. |
ScanCoverage object
| Name | Typ | Beschreibung |
|---|---|---|
| totalRepositories | Int! | |
| scanned | Int! | |
| unscanned | Int! | Repositories never scanned - unknown risk, and excluded from the score. |
ScanFinding object
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! | |
| commitScanId | ID! | |
| createdAt | DateTime! | |
| updatedAt | DateTime | |
| line | Int | |
| file | String | |
| severity | Severity | |
| confidence | String | |
| match | String | Masked (first/last few characters only) - see revealScanFindingMatch for the raw value. |
| fingerprint | String | |
| matchHash | String | Cross-tool identity: two different scanners that found the same secret share this value. Null when the secret could not be resolved (older scans). Distinct from fingerprint, which is per-tool. |
| matchedByToolCount | Int | How many distinct scanners reported this finding. Greater than 1 means two tools independently agreed, which is the strongest cheap signal that it is not a false positive. Null when the finding has no cross-tool identity. |
| issueUrl | String | URL of the GitHub/GitLab issue opened for this finding, if any. |
| issueStatus | IssueStatus | |
| prUrl | String | URL of the remediation PR opened for this finding, if any. |
| prStatus | PrStatus | |
| commitScan | CommitScan! | |
| tags | [Tag!]! |
ScanFindingGroup object
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! | |
| fingerprint | String! | |
| matchHash | String | Cross-tool identity of this group. |
| matchedByToolCount | Int | How many distinct scanners reported this finding. A fingerprint group is one tool's view; this says whether anyone else found the same thing. |
| file | String | |
| severity | Severity | |
| confidence | String | |
| match | String | Masked (first/last few characters only) - see revealScanFindingMatch for the raw value. |
| occurrences | Int! | |
| issueUrl | String | URL of the GitHub/GitLab issue opened for this finding, if any. |
| issueStatus | IssueStatus | |
| prUrl | String | URL of the remediation PR opened for this finding, if any. |
| prStatus | PrStatus |
ScanFindingGroupListResult object
| Name | Typ | Beschreibung |
|---|---|---|
| total | Int! | |
| items | [ScanFindingGroup!]! |
ScanFindingListResult object
| Name | Typ | Beschreibung |
|---|---|---|
| total | Int! | |
| items | [ScanFinding!]! |
ScanFindingMatchGroup object
One real secret, collapsed across every commit and tool that saw it. The explorer listed raw findings, so a token committed once appeared per commit per tool - 26 commits scanned by 2 tools meant 52 rows for one secret.
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! | |
| matchHash | String! | |
| file | String | |
| line | Int | |
| severity | Severity | |
| confidence | String | Highest confidence any contributing tool assigned. |
| match | String | Masked (first/last few characters only) - see revealScanFindingMatch for the raw value. |
| occurrences | Int! | How many raw findings collapsed into this group. |
| toolCount | Int! | How many distinct scanners agreed. Greater than 1 is the corroboration signal. |
| scanners | [String!]! | Which scanners reported it. toolCount answers "is this corroborated"; this answers "who says so", which is what you need to judge a finding you disagree with. |
| repositoryId | ID | |
| triageKey | String | The identity a triage decision is filed under - the match hash, or the fingerprint when there is none. Distinct from matchHash above, which falls back to the finding id: filing a decision under that key stored it somewhere nothing ever looks up. |
| triageState | TriageState | The decision in force, carried on the row so the explorer can show and filter it without a call per finding. Null when nothing has been decided. |
| triageResponse | TriageResponse | |
| triagePriority | TriagePriority |
ScanFindingMatchGroupListResult object
| Name | Typ | Beschreibung |
|---|---|---|
| total | Int! | |
| items | [ScanFindingMatchGroup!]! |
ScanHealth object
| Name | Typ | Beschreibung |
|---|---|---|
| totalScans | Int! | |
| succeededScans | Int! | |
| failedScans | Int! | |
| runningScans | Int! | |
| invalidTokens | Int! | Tokens the provider rejected; every scan under their workspaces is blocked. |
| expiringTokens | Int! |
ScanResult object
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! | |
| repositoryId | ID! | |
| scanType | String! | |
| scanner | String! | |
| dockerScanToolId | ID! | |
| status | ScanStatus! | |
| createdAt | DateTime! | |
| updatedAt | DateTime | |
| scanTime | Int | |
| securityScore | Float | |
| createIssue | Boolean! | |
| autoRemediate | Boolean! | |
| branches | [String!] | |
| repository | Repository! | |
| dockerScanTool | DockerScanTool! | |
| severityCounts | [SeverityCount!]! |
ScanResultListResult object
| Name | Typ | Beschreibung |
|---|---|---|
| total | Int! | |
| items | [ScanResult!]! |
ScanSchedule object
A standing instruction to run on a fixed cadence. Deliberately a frequency plus an hour rather than a cron expression: the whole space of valid values is enumerable, so it validates here and renders as two selects. Exactly one of repositoryId or gitEntityId is set. A workspace SCAN fans out over the repositories the workspace holds when it fires, so one imported after the schedule was made is included and one disabled since is not.
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! | |
| action | ScanScheduleAction! | |
| repositoryId | ID | Set when this schedule targets one repository. Null for a workspace schedule. |
| gitEntityId | ID | Set when this schedule targets a whole workspace. Null for a repository schedule. |
| branch | String | Branch to scan. Null means the default branch. Never set on a workspace schedule - a branch is a repository-level idea and a workspace's repositories do not share one - nor on a SYNC. |
| dockerScanToolId | ID | Scanner to run. Null means the tenant's default scanner. |
| frequency | ScanScheduleFrequency! | |
| hourUtc | Int! | Hour of day in UTC, 0-23. Clients render it in the viewer's own zone. |
| minuteUtc | Int! | Minute of the hour in UTC, 0-59. Zero for a schedule created before minutes existed. |
| dayOfWeek | Int | Day of week, 0-6, Monday is 0. Only read when frequency is WEEKLY. |
| isActive | Boolean! | |
| nextRunAt | DateTime | When the next run is due, in UTC. Computed by vulnara-api, never written by a client. |
| lastRunAt | DateTime | When the schedule last dispatched a scan, in UTC. Read only. |
| recipients | [String!]! | Where a REPORT is mailed. Empty for a SCAN or a SYNC. Not restricted to tenant members, matching the destinations alert rules already accept. |
| createdBy | String | |
| createdAt | DateTime | |
| updatedAt | DateTime | |
| repository | Repository | Null for a workspace schedule. |
| gitEntity | GitEntity | Null for a repository schedule. |
| dockerScanTool | DockerScanTool |
ScanScheduleAction enum
What a due schedule does. SCAN queues a scan; SYNC re-imports a workspace's repositories, the same job the workspace sync button runs. A SYNC only ever targets a workspace: there is nothing to re-import for a single repository.
| Name | Beschreibung |
|---|---|
| SCAN | |
| SYNC | |
| REPORT |
ScanScheduleFrequency enum
| Name | Beschreibung |
|---|---|
| DAILY | |
| WEEKLY |
ScanScheduleListResult object
| Name | Typ | Beschreibung |
|---|---|---|
| total | Int! | |
| items | [ScanSchedule!]! |
ScanStatus enum
| Name | Beschreibung |
|---|---|
| PENDING | |
| SUCCESS | |
| FAILED | |
| CANCELLED |
ScoreTrendPoint object
| Name | Typ | Beschreibung |
|---|---|---|
| date | String! | |
| score | Float! |
ServiceAccount object
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! | |
| name | String! | |
| isActive | Boolean! | |
| expiresAt | DateTime | |
| createdBy | User! |
SetFindingTriageInput input
| Name | Typ | Beschreibung |
|---|---|---|
| repositoryId | ID! | |
| matchKey | String! | The finding's matchHash, or its per-tool fallback when it has none. |
| findingType | String! | |
| state | TriageState! | |
| justification | TriageJustification | |
| response | TriageResponse | |
| priority | TriagePriority | |
| reason | String! | |
| expiresAt | DateTime |
SetGitEntityIgnorePathsInput input
| Name | Typ | Beschreibung |
|---|---|---|
| gitEntityId | ID! | |
| ignorePaths | [String!]! |
SetRepositoryEnabledInput input
| Name | Typ | Beschreibung |
|---|---|---|
| repositoryIds | [ID!]! | |
| enabled | Boolean! |
SetRepositoryIgnorePathsInput input
| Name | Typ | Beschreibung |
|---|---|---|
| repositoryId | ID! | |
| ignorePaths | [String!]! |
SetServiceAccountActiveInput input
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! | |
| isActive | Boolean! |
Severity enum
| Name | Beschreibung |
|---|---|
| info | |
| low | |
| medium | |
| high | |
| critical |
SeverityCount object
| Name | Typ | Beschreibung |
|---|---|---|
| severity | String! | |
| count | Int! |
StaleWorkspace object
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! | |
| name | String! | |
| lastImportDate | DateTime |
StartNetworkScanInput input
| Name | Typ | Beschreibung |
|---|---|---|
| networkId | ID! |
StartRepositoryScanInput input
| Name | Typ | Beschreibung |
|---|---|---|
| repositoryId | ID! | |
| dockerScanToolId | ID! | |
| branch | String | |
| gitTokenId | ID | |
| createIssue | Boolean | |
| autoRemediate | Boolean |
Tag object
| Name | Typ | Beschreibung |
|---|---|---|
| key | String! | |
| value | String! |
Task union
Eines von: RepositoryScanTask, NetworkScanTask, FetchGitEntityTask
TaskEvent object
| Name | Typ | Beschreibung |
|---|---|---|
| type | TaskEventType! | |
| taskId | ID! | |
| task | Task |
TaskEventType enum
| Name | Beschreibung |
|---|---|
| STATE_UPDATED | |
| TASK_CANCELLED |
TaskStatus enum
| Name | Beschreibung |
|---|---|
| QUEUED | |
| STARTED | |
| CANCELLED | |
| PROCESSING | |
| COMPLETED | |
| FAILED |
Tenant object
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! | |
| isPaying | Boolean! | |
| members | [TenantUser!]! |
TenantStatistics object
| Name | Typ | Beschreibung |
|---|---|---|
| tenant | String! | |
| totalUsers | Int! | |
| totalGitEntities | Int! | |
| totalRepositories | Int! | |
| totalNetworks | Int! |
TenantUser object
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! | |
| roles | [TenantUserRole!]! | |
| user | User! |
TenantUserRole enum
| Name | Beschreibung |
|---|---|
| VIEWER | |
| EDITOR | |
| ADMIN |
TransferGitEntityInput input
| Name | Typ | Beschreibung |
|---|---|---|
| gitEntityId | ID! | |
| newTenant | String! |
TransferNetworkInput input
| Name | Typ | Beschreibung |
|---|---|---|
| networkId | ID! | |
| newTenant | String! |
TriageJustification enum
CycloneDX VEX justification. Required when the state is not_affected.
| Name | Beschreibung |
|---|---|
| code_not_present | |
| code_not_reachable | |
| requires_configuration | |
| requires_dependency | |
| requires_environment | |
| protected_by_compiler | |
| protected_at_runtime | |
| protected_at_perimeter | |
| protected_by_mitigating_control |
TriagePriority enum
SSVC decision outcome. Only defer hides the finding from the working list.
| Name | Beschreibung |
|---|---|
| defer | |
| scheduled | |
| out_of_cycle | |
| immediate |
TriageResponse enum
CycloneDX VEX analysis.response - what will be done about it.
| Name | Beschreibung |
|---|---|
| can_not_fix | |
| rollback | |
| update | |
| will_not_fix | |
| workaround_available |
TriageState enum
CycloneDX VEX analysis.state - what is true about the finding.
| Name | Beschreibung |
|---|---|
| resolved | |
| resolved_with_pedigree | |
| exploitable | |
| in_triage | |
| false_positive | |
| not_affected |
UpdateGitEntityInput input
| Name | Typ | Beschreibung |
|---|---|---|
| gitEntityId | ID! | |
| name | String | |
| gitType | GitType | |
| ignorePaths | [String!] |
UpdateGitTokenInput input
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! | |
| name | String | |
| value | String |
UpdateNotificationScopeInput input
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! | |
| channelIds | [String!] | |
| channelType | ChannelType | |
| scopes | [String!] | |
| isActive | Boolean | |
| headers | [HttpHeaderInput!] | |
| templates | [NotificationTemplateInput!] |
UpdateScanScheduleInput input
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! | |
| branch | String | |
| dockerScanToolId | ID | |
| frequency | ScanScheduleFrequency | |
| hourUtc | Int | |
| minuteUtc | Int | |
| dayOfWeek | Int | |
| isActive | Boolean | |
| recipients | [String!] |
UpdateUserPreferencesInput input
| Name | Typ | Beschreibung |
|---|---|---|
| theme | PreferredTheme | |
| dateTimeFormat | PreferredDateTimeFormat | |
| repositoriesView | PreferredRepositoriesView |
UpdateUserRolesInput input
| Name | Typ | Beschreibung |
|---|---|---|
| userId | ID! | |
| roles | [TenantUserRole!]! |
Usage object
| Name | Typ | Beschreibung |
|---|---|---|
| accountTier | String! | |
| usedGitScanTimeMinutes | Int! | |
| repositoryScanLimited | Boolean! | |
| usedNetworkScanTimeMinutes | Int! | |
| networkScanLimited | Boolean! | |
| parallelScans | Int! | |
| availableGitScanMinutes | Int! | |
| availableNetworkScanMinutes | Int! | |
| maxParallelScans | Int! | |
| usedRepositories | Int! | |
| maxRepositories | Int! | |
| repositoryLimitReached | Boolean! | |
| usedNetworks | Int! | |
| maxNetworks | Int! | |
| networkLimitReached | Boolean! | |
| usedEmails | Int! | |
| maxEmails | Int! | |
| emailLimitReached | Boolean! |
User object
| Name | Typ | Beschreibung |
|---|---|---|
| id | ID! | |
| String | Null unless the caller may read it: their own address, or any address in a tenant they hold EDITOR or ADMIN in. Nullable rather than guarded by @tenantRole because the directive throws, and a thrown error on a non-null field takes the whole myUser query down for every VIEWER instead of hiding one field. | |
| username | String! | |
| name | String! |
UserPreferences object
| Name | Typ | Beschreibung |
|---|---|---|
| theme | PreferredTheme | |
| dateTimeFormat | PreferredDateTimeFormat | |
| repositoriesView | PreferredRepositoriesView |
WorkspaceOverview object
Security aggregate for one workspace, counted on the server with the same latest-scan + deduplicated policy as the dashboard.
| Name | Typ | Beschreibung |
|---|---|---|
| severityCounts | [SeverityCount!]! | |
| totalFindings | Int! | |
| totalRepositories | Int! | |
| scanned | Int! | |
| unscanned | Int! |