Zum Hauptinhalt springen

GraphQL-API

Das Gateway stellt die ganze Plattform über einen GraphQL-Endpunkt bereit. Sende ein Bearer-Token in Authorization und die Workspace-ID in X-Tenant.

Endpunkt
https://vulnara-gw.rso.dev/graphql
sh
curl https://vulnara-gw.rso.dev/graphql \
  -H "Authorization: Bearer $VULNARA_TOKEN" \
  -H "X-Tenant: $VULNARA_TENANT" \
  -H "Content-Type: application/json" \
  -d '{"query":"{ myUser { id } }"}'

acceptInvitationMutation

Argumente

NameTypBeschreibung
idID!

Rückgabe Boolean!

Beispiel
mutation AcceptInvitation($id: ID!) {
  acceptInvitation(id: $id)
}

associateGitTokenWithGitEntityMutation

Argumente

NameTypBeschreibung
inputGitTokenAssociationInput!

Rückgabe GitToken!

Beispiel
mutation AssociateGitTokenWithGitEntity($input: GitTokenAssociationInput!) {
  associateGitTokenWithGitEntity(input: $input) {
    id
    name
    value
    expiresAt
    flags
    status
    scopes
    createdAt
  }
}

Auch verfügbar als: CLI-Befehl vulnara associate_git_token_with_git_entity

cancelTaskMutation

Argumente

NameTypBeschreibung
idID!

Rückgabe Boolean!

Beispiel
mutation CancelTask($id: ID!) {
  cancelTask(id: $id)
}

Auch verfügbar als: CLI-Befehl vulnara cancel_task

checkGitTokenQuery

Probe the token against its provider, returning validity, the provider's error (when rejected) and the reported expiry. Used by the add-token form to surface why a token was rejected. When a workspace name is supplied and the token is valid, also returns how many repositories the token can see for it (public + private).

Argumente

NameTypBeschreibung
valueString!
gitTypeGitType!
nameString

Rückgabe GitTokenCheck!

Beispiel
query CheckGitToken($value: String!, $gitType: GitType!, $name: String) {
  checkGitToken(value: $value, gitType: $gitType, name: $name) {
    valid
    statusCode
    error
    expiresAt
    publicRepositoryCount
    privateRepositoryCount
  }
}

clearFindingTriageMutation

Argumente

NameTypBeschreibung
repositoryIdID!
matchKeyString!

Rückgabe Boolean!

Beispiel
mutation ClearFindingTriage($repositoryId: ID!, $matchKey: String!) {
  clearFindingTriage(repositoryId: $repositoryId, matchKey: $matchKey)
}

commitScansQuery

Argumente

NameTypBeschreibung
listList

Rückgabe CommitScanListResult!

Beispiel
query CommitScans($list: List) {
  commitScans(list: $list) {
    total
    items {
      id
      scanResultId
      commitHash
      createdAt
      updatedAt
    }
  }
}

Auch verfügbar als: MCP-Tool commit_scans

confirmEmptyOrderMutation

Argumente

NameTypBeschreibung
idID!

Rückgabe Boolean!

Beispiel
mutation ConfirmEmptyOrder($id: ID!) {
  confirmEmptyOrder(id: $id)
}

createEmptyOrderMutation

Rückgabe RevolutOrder!

Beispiel
mutation CreateEmptyOrder {
  createEmptyOrder {
    id
  }
}

createGitEntityMutation

Argumente

NameTypBeschreibung
inputCreateGitEntityInput!

Rückgabe GitEntity!

Beispiel
mutation CreateGitEntity($input: CreateGitEntityInput!) {
  createGitEntity(input: $input) {
    __typename
    ... on Organization {
      id
      name
      gitType
      externalId
      webUrl
      htmlUrl
      avatarUrl
      color
    }
    ... on GitUser {
      id
      name
      gitType
      externalId
      webUrl
      htmlUrl
      avatarUrl
      color
    }
  }
}

Auch verfügbar als: CLI-Befehl vulnara create_git_entity

createGitTokenMutation

Argumente

NameTypBeschreibung
inputCreateGitTokenInput!

Rückgabe GitToken!

Beispiel
mutation CreateGitToken($input: CreateGitTokenInput!) {
  createGitToken(input: $input) {
    id
    name
    value
    expiresAt
    flags
    status
    scopes
    createdAt
  }
}

Auch verfügbar als: CLI-Befehl vulnara create_git_token

createInvoiceDownloadUrlMutation

Argumente

NameTypBeschreibung
invoiceIdID!

Rückgabe InvoiceDownload!

Beispiel
mutation CreateInvoiceDownloadUrl($invoiceId: ID!) {
  createInvoiceDownloadUrl(invoiceId: $invoiceId) {
    url
    filename
    tenant
    contentType
  }
}

createNetworkMutation

Argumente

NameTypBeschreibung
inputCreateNetworkInput!

Rückgabe Network!

Beispiel
mutation CreateNetwork($input: CreateNetworkInput!) {
  createNetwork(input: $input) {
    id
    name
    network
    networkType
    tenant
    securityScore
    createdAt
    updatedAt
  }
}

Auch verfügbar als: CLI-Befehl vulnara create_network

createNotificationScopeMutation

Argumente

NameTypBeschreibung
inputCreateNotificationScopeInput!

Rückgabe NotificationScope!

Beispiel
mutation CreateNotificationScope($input: CreateNotificationScopeInput!) {
  createNotificationScope(input: $input) {
    id
    channelIds
    channelType
    scopes
    isActive
    status
    headers {
      name
      value
    }
    template
  }
}

Auch verfügbar als: CLI-Befehl vulnara create_notification_scope

createRepositoryMutation

Argumente

NameTypBeschreibung
inputCreateRepositoryInput!

Rückgabe Repository!

Beispiel
mutation CreateRepository($input: CreateRepositoryInput!) {
  createRepository(input: $input) {
    id
    gitEntityId
    repositoryName
    private
    securityScore
    programmingLanguage
    repositorySize
    numberOfBranches
  }
}

Auch verfügbar als: CLI-Befehl vulnara create_repository

createScanScheduleMutation

Argumente

NameTypBeschreibung
inputCreateScanScheduleInput!

Rückgabe ScanSchedule!

Beispiel
mutation CreateScanSchedule($input: CreateScanScheduleInput!) {
  createScanSchedule(input: $input) {
    id
    action
    repositoryId
    gitEntityId
    branch
    dockerScanToolId
    frequency
    hourUtc
  }
}

createServiceAccountMutation

Argumente

NameTypBeschreibung
inputCreateServiceAccountInput!

Rückgabe CreateServiceAccountPayload!

Beispiel
mutation CreateServiceAccount($input: CreateServiceAccountInput!) {
  createServiceAccount(input: $input) {
    serviceAccount {
      id
      name
      isActive
      expiresAt
    }
  }
}

Auch verfügbar als: CLI-Befehl vulnara create_service_account

createTenantMutation

Argumente

NameTypBeschreibung
inputCreateTenantInput!

Rückgabe Tenant!

Beispiel
mutation CreateTenant($input: CreateTenantInput!) {
  createTenant(input: $input) {
    id
    isPaying
    members {
      id
      roles
    }
  }
}

Auch verfügbar als: CLI-Befehl vulnara create_tenant

dashboardAnalyticsQuery

Argumente

NameTypBeschreibung
daysInt

Rückgabe DashboardAnalytics!

Beispiel
query DashboardAnalytics($days: Int) {
  dashboardAnalytics(days: $days) {
    days
    generatedAt
    lastScanAt
    averageSecurityScore
    previousAverageSecurityScore
    severityCounts {
      severity
      count
    }
    previousSeverityCounts {
      severity
      count
    }
    exposure {
      total
      previousTotal
      newFindings
      resolvedFindings
      codeFindings
      dependencyFindings
      corroboratedFindings
      falsePositives
    }
  }
}

Auch verfügbar als: MCP-Tool dashboard_analytics

declineInvitationMutation

Argumente

NameTypBeschreibung
idID!

Rückgabe Boolean!

Beispiel
mutation DeclineInvitation($id: ID!) {
  declineInvitation(id: $id)
}

deleteGitEntityMutation

Argumente

NameTypBeschreibung
idID!

Rückgabe Boolean!

Beispiel
mutation DeleteGitEntity($id: ID!) {
  deleteGitEntity(id: $id)
}

Auch verfügbar als: CLI-Befehl vulnara delete_git_entity

deleteGitTokenMutation

Argumente

NameTypBeschreibung
idID!

Rückgabe Boolean!

Beispiel
mutation DeleteGitToken($id: ID!) {
  deleteGitToken(id: $id)
}

Auch verfügbar als: CLI-Befehl vulnara delete_git_token

deleteInvitationMutation

Argumente

NameTypBeschreibung
idID!

Rückgabe Boolean!

Beispiel
mutation DeleteInvitation($id: ID!) {
  deleteInvitation(id: $id)
}

deleteNetworkMutation

Argumente

NameTypBeschreibung
idID!

Rückgabe Boolean!

Beispiel
mutation DeleteNetwork($id: ID!) {
  deleteNetwork(id: $id)
}

Auch verfügbar als: CLI-Befehl vulnara delete_network

deleteNetworkScanResultMutation

Argumente

NameTypBeschreibung
idID!

Rückgabe Boolean!

Beispiel
mutation DeleteNetworkScanResult($id: ID!) {
  deleteNetworkScanResult(id: $id)
}

Auch verfügbar als: CLI-Befehl vulnara delete_network_scan_result

deleteNotificationScopeMutation

Argumente

NameTypBeschreibung
idID!

Rückgabe Boolean!

Beispiel
mutation DeleteNotificationScope($id: ID!) {
  deleteNotificationScope(id: $id)
}

Auch verfügbar als: CLI-Befehl vulnara delete_notification_scope

deletePaymentMethodMutation

Argumente

NameTypBeschreibung
idID!

Rückgabe Boolean!

Beispiel
mutation DeletePaymentMethod($id: ID!) {
  deletePaymentMethod(id: $id)
}

deleteRepositoryMutation

Argumente

NameTypBeschreibung
idID!

Rückgabe Boolean!

Beispiel
mutation DeleteRepository($id: ID!) {
  deleteRepository(id: $id)
}

Auch verfügbar als: CLI-Befehl vulnara delete_repository

deleteScanResultMutation

Argumente

NameTypBeschreibung
idID!

Rückgabe Boolean!

Beispiel
mutation DeleteScanResult($id: ID!) {
  deleteScanResult(id: $id)
}

Auch verfügbar als: CLI-Befehl vulnara delete_scan_result

deleteScanScheduleMutation

Argumente

NameTypBeschreibung
idID!

Rückgabe Boolean!

Beispiel
mutation DeleteScanSchedule($id: ID!) {
  deleteScanSchedule(id: $id)
}

deleteServiceAccountMutation

Argumente

NameTypBeschreibung
idID!

Rückgabe Boolean!

Beispiel
mutation DeleteServiceAccount($id: ID!) {
  deleteServiceAccount(id: $id)
}

Auch verfügbar als: CLI-Befehl vulnara delete_service_account

deleteTenantMemberMutation

Argumente

NameTypBeschreibung
idID!

Rückgabe Boolean!

Beispiel
mutation DeleteTenantMember($id: ID!) {
  deleteTenantMember(id: $id)
}

dismissTaskMutation

Argumente

NameTypBeschreibung
idID!

Rückgabe Boolean!

Beispiel
mutation DismissTask($id: ID!) {
  dismissTask(id: $id)
}

dissociateGitTokenWithGitEntityMutation

Argumente

NameTypBeschreibung
inputGitTokenAssociationInput!

Rückgabe Boolean!

Beispiel
mutation DissociateGitTokenWithGitEntity($input: GitTokenAssociationInput!) {
  dissociateGitTokenWithGitEntity(input: $input)
}

Auch verfügbar als: CLI-Befehl vulnara dissociate_git_token_with_git_entity

dockerScanToolQuery

Argumente

NameTypBeschreibung
idID!

Rückgabe DockerScanTool!

Beispiel
query DockerScanTool($id: ID!) {
  dockerScanTool(id: $id) {
    id
    name
  }
}

Auch verfügbar als: MCP-Tool docker_scan_tool

dockerScanToolsQuery

Argumente

NameTypBeschreibung
listList

Rückgabe DockerScanToolListResult!

Beispiel
query DockerScanTools($list: List) {
  dockerScanTools(list: $list) {
    total
    items {
      id
      name
    }
  }
}

Auch verfügbar als: MCP-Tool docker_scan_tools

downgradeToFreeMutation

Rückgabe Boolean!

Beispiel
mutation DowngradeToFree {
  downgradeToFree
}

fetchRepositoriesMutation

Argumente

NameTypBeschreibung
inputFetchRepositoriesInput!

Rückgabe Boolean!

Beispiel
mutation FetchRepositories($input: FetchRepositoriesInput!) {
  fetchRepositories(input: $input)
}

Auch verfügbar als: CLI-Befehl vulnara fetch_repositories

findingCorroborationQuery

Cross-tool agreement for every secret found in a repository.

Argumente

NameTypBeschreibung
repositoryIdID!

Rückgabe FindingCorroborationListResult!

Beispiel
query FindingCorroboration($repositoryId: ID!) {
  findingCorroboration(repositoryId: $repositoryId) {
    total
    items {
      id
      matchHash
      toolCount
      severity
    }
  }
}

Auch verfügbar als: MCP-Tool finding_corroboration

findingTriageQuery

Argumente

NameTypBeschreibung
repositoryIdID!

Rückgabe [FindingTriage!]!

Beispiel
query FindingTriage($repositoryId: ID!) {
  findingTriage(repositoryId: $repositoryId) {
    id
    repositoryId
    matchKey
    findingType
    state
    justification
    response
    priority
  }
}

Auch verfügbar als: MCP-Tool finding_triage

findingTriageHistoryQuery

Every decision ever taken on this repository's findings, newest first.

Argumente

NameTypBeschreibung
repositoryIdID!
matchKeyString

Rückgabe [FindingTriageEvent!]!

Beispiel
query FindingTriageHistory($repositoryId: ID!, $matchKey: String) {
  findingTriageHistory(repositoryId: $repositoryId, matchKey: $matchKey) {
    id
    repositoryId
    matchKey
    action
    state
    justification
    response
    priority
  }
}

Auch verfügbar als: MCP-Tool finding_triage_history

gitEntitiesQuery

Argumente

NameTypBeschreibung
listList

Rückgabe GitEntityListResult!

Beispiel
query GitEntities($list: List) {
  gitEntities(list: $list) {
    total
  }
}

Auch verfügbar als: CLI-Befehl vulnara git_entities · MCP-Tool git_entities

gitEntityQuery

Argumente

NameTypBeschreibung
idID!

Rückgabe GitEntity!

Beispiel
query GitEntity($id: ID!) {
  gitEntity(id: $id) {
    __typename
    ... on Organization {
      id
      name
      gitType
      externalId
      webUrl
      htmlUrl
      avatarUrl
      color
    }
    ... on GitUser {
      id
      name
      gitType
      externalId
      webUrl
      htmlUrl
      avatarUrl
      color
    }
  }
}

Auch verfügbar als: CLI-Befehl vulnara get_git_entity · MCP-Tool git_entity

gitEntityProvidersQuery

Providers on which a bare handle resolves to an org/user/group. Lets the add-workspace form infer the provider automatically and only ask the user to choose when the same handle exists on more than one provider.

Argumente

NameTypBeschreibung
nameString!

Rückgabe [GitType!]!

Beispiel
query GitEntityProviders($name: String!) {
  gitEntityProviders(name: $name)
}

gitEntityRepositoryCountQuery

Argumente

NameTypBeschreibung
nameString!
gitTypeGitType!

Rückgabe Int

Beispiel
query GitEntityRepositoryCount($name: String!, $gitType: GitType!) {
  gitEntityRepositoryCount(name: $name, gitType: $gitType)
}

gitTokenQuery

Argumente

NameTypBeschreibung
idID!

Rückgabe GitToken!

Beispiel
query GitToken($id: ID!) {
  gitToken(id: $id) {
    id
    name
    value
    expiresAt
    flags
    status
    scopes
    createdAt
  }
}

Auch verfügbar als: CLI-Befehl vulnara get_git_token

gitTokenExpirationQuery

The token's own expiry as reported by the provider (GitHub's token-expiration header / GitLab's PAT self endpoint), or null if the provider doesn't expose one or the token couldn't be checked. Lets the UI hide the manual "expires at" field when the token reports it itself.

Argumente

NameTypBeschreibung
valueString!
gitTypeGitType!

Rückgabe DateTime

Beispiel
query GitTokenExpiration($value: String!, $gitType: GitType!) {
  gitTokenExpiration(value: $value, gitType: $gitType)
}

gitTokensQuery

Argumente

NameTypBeschreibung
listList

Rückgabe GitTokenListResult!

Beispiel
query GitTokens($list: List) {
  gitTokens(list: $list) {
    total
    items {
      id
      name
      value
      expiresAt
      flags
      status
      scopes
      createdAt
    }
  }
}

Auch verfügbar als: CLI-Befehl vulnara git_tokens

gitUserQuery

Argumente

NameTypBeschreibung
idID!

Rückgabe GitEntity!

Beispiel
query GitUser($id: ID!) {
  gitUser(id: $id) {
    __typename
    ... on Organization {
      id
      name
      gitType
      externalId
      webUrl
      htmlUrl
      avatarUrl
      color
    }
    ... on GitUser {
      id
      name
      gitType
      externalId
      webUrl
      htmlUrl
      avatarUrl
      color
    }
  }
}

Auch verfügbar als: MCP-Tool git_user

gitUsersQuery

Argumente

NameTypBeschreibung
listList

Rückgabe GitEntityListResult!

Beispiel
query GitUsers($list: List) {
  gitUsers(list: $list) {
    total
  }
}

Auch verfügbar als: MCP-Tool git_users

invitationQuery

Argumente

NameTypBeschreibung
idID!

Rückgabe Invitation

Beispiel
query Invitation($id: ID!) {
  invitation(id: $id) {
    id
    email
    tenantName
  }
}

invitationsQuery

Rückgabe [Invitation!]!

Beispiel
query Invitations {
  invitations {
    id
    email
    tenantName
  }
}

inviteTenantMemberMutation

Argumente

NameTypBeschreibung
inputInviteTeamMemberInput!

Rückgabe Boolean!

Beispiel
mutation InviteTenantMember($input: InviteTeamMemberInput!) {
  inviteTenantMember(input: $input)
}

invoiceQuery

Argumente

NameTypBeschreibung
idID!

Rückgabe Invoice!

Beispiel
query Invoice($id: ID!) {
  invoice(id: $id) {
    id
    invoiceNumber
    date
    dueDate
    status
    total
    currency
  }
}

invoicesQuery

Argumente

NameTypBeschreibung
listList

Rückgabe InvoiceListResult!

Beispiel
query Invoices($list: List) {
  invoices(list: $list) {
    total
    items {
      id
      invoiceNumber
      date
      dueDate
      status
      total
      currency
    }
  }
}

markAllNotificationsReadMutation

Rückgabe Boolean!

Beispiel
mutation MarkAllNotificationsRead {
  markAllNotificationsRead
}

markNotificationDeliveredMutation

Argumente

NameTypBeschreibung
idID!

Rückgabe Boolean!

Beispiel
mutation MarkNotificationDelivered($id: ID!) {
  markNotificationDelivered(id: $id)
}

markNotificationsReadMutation

Argumente

NameTypBeschreibung
ids[ID!]!

Rückgabe Boolean!

Beispiel
mutation MarkNotificationsRead($ids: [ID!]!) {
  markNotificationsRead(ids: $ids)
}

myUserQuery

Rückgabe MyUser

Beispiel
query MyUser {
  myUser {
    id
    email
    name
    username
    tenants {
      id
      isPaying
    }
    preferences {
      theme
      dateTimeFormat
      repositoriesView
    }
  }
}

Auch verfügbar als: MCP-Tool my_user

networkQuery

Argumente

NameTypBeschreibung
idID!

Rückgabe Network!

Beispiel
query Network($id: ID!) {
  network(id: $id) {
    id
    name
    network
    networkType
    tenant
    securityScore
    createdAt
    updatedAt
  }
}

Auch verfügbar als: CLI-Befehl vulnara get_network · MCP-Tool network

networksQuery

Argumente

NameTypBeschreibung
listList

Rückgabe NetworkListResult!

Beispiel
query Networks($list: List) {
  networks(list: $list) {
    total
    items {
      id
      name
      network
      networkType
      tenant
      securityScore
      createdAt
      updatedAt
    }
  }
}

Auch verfügbar als: CLI-Befehl vulnara networks · MCP-Tool networks

networkScanFindingQuery

Argumente

NameTypBeschreibung
idID!

Rückgabe NetworkScanFinding!

Beispiel
query NetworkScanFinding($id: ID!) {
  networkScanFinding(id: $id) {
    id
    scanResultId
    host
    hostname
    hostnameType
    protocol
    port
    serviceName
  }
}

Auch verfügbar als: MCP-Tool network_scan_finding

networkScanFindingsQuery

Argumente

NameTypBeschreibung
listList

Rückgabe NetworkScanFindingListResult!

Beispiel
query NetworkScanFindings($list: List) {
  networkScanFindings(list: $list) {
    total
    items {
      id
      scanResultId
      host
      hostname
      hostnameType
      protocol
      port
      serviceName
    }
  }
}

Auch verfügbar als: CLI-Befehl vulnara network_scan_findings · MCP-Tool network_scan_findings

networkScanResultQuery

Argumente

NameTypBeschreibung
idID!

Rückgabe NetworkScanResult!

Beispiel
query NetworkScanResult($id: ID!) {
  networkScanResult(id: $id) {
    id
    networkId
    status
    createdAt
    updatedAt
    scanTime
    network {
      id
      name
      network
      networkType
      tenant
      securityScore
      createdAt
      updatedAt
    }
  }
}

Auch verfügbar als: CLI-Befehl vulnara get_network_scan_result · MCP-Tool network_scan_result

networkScanResultsQuery

Argumente

NameTypBeschreibung
listList

Rückgabe NetworkScanResultListResult!

Beispiel
query NetworkScanResults($list: List) {
  networkScanResults(list: $list) {
    total
    items {
      id
      networkId
      status
      createdAt
      updatedAt
      scanTime
    }
  }
}

Auch verfügbar als: CLI-Befehl vulnara network_scan_results · MCP-Tool network_scan_results

notificationsQuery

Argumente

NameTypBeschreibung
listList

Rückgabe NotificationList!

Beispiel
query Notifications($list: List) {
  notifications(list: $list) {
    items {
      id
      type
      eventType
      data
      read
      createdAt
    }
    total
  }
}

Auch verfügbar als: MCP-Tool notifications

notificationsSubscription

Rückgabe Notification!

Beispiel
subscription Notifications {
  notifications {
    id
    type
    eventType
    data
    read
    createdAt
  }
}

notificationScopeQuery

Argumente

NameTypBeschreibung
idID!

Rückgabe NotificationScope!

Beispiel
query NotificationScope($id: ID!) {
  notificationScope(id: $id) {
    id
    channelIds
    channelType
    scopes
    isActive
    status
    headers {
      name
      value
    }
    template
  }
}

Auch verfügbar als: CLI-Befehl vulnara get_notification_scope · MCP-Tool notification_scope

notificationScopesQuery

Argumente

NameTypBeschreibung
listList

Rückgabe NotificationScopeListResult!

Beispiel
query NotificationScopes($list: List) {
  notificationScopes(list: $list) {
    total
    items {
      id
      channelIds
      channelType
      scopes
      isActive
      status
      template
    }
  }
}

Auch verfügbar als: CLI-Befehl vulnara notification_scopes · MCP-Tool notification_scopes

organizationQuery

Argumente

NameTypBeschreibung
idID!

Rückgabe GitEntity!

Beispiel
query Organization($id: ID!) {
  organization(id: $id) {
    __typename
    ... on Organization {
      id
      name
      gitType
      externalId
      webUrl
      htmlUrl
      avatarUrl
      color
    }
    ... on GitUser {
      id
      name
      gitType
      externalId
      webUrl
      htmlUrl
      avatarUrl
      color
    }
  }
}

Auch verfügbar als: MCP-Tool organization

organizationsQuery

Argumente

NameTypBeschreibung
listList

Rückgabe GitEntityListResult!

Beispiel
query Organizations($list: List) {
  organizations(list: $list) {
    total
  }
}

Auch verfügbar als: MCP-Tool organizations

paymentMethodQuery

Argumente

NameTypBeschreibung
idID!

Rückgabe PaymentMethod!

Beispiel
query PaymentMethod($id: ID!) {
  paymentMethod(id: $id) {
    id
    default
    lastFour
    brand
    expiryMonth
    expiryYear
    cardholderName
    expired
  }
}

paymentMethodsQuery

Argumente

NameTypBeschreibung
listList

Rückgabe PaymentMethodListResult!

Beispiel
query PaymentMethods($list: List) {
  paymentMethods(list: $list) {
    total
    items {
      id
      default
      lastFour
      brand
      expiryMonth
      expiryYear
      cardholderName
      expired
    }
  }
}

plansQuery

Rückgabe [Plan!]!

Beispiel
query Plans {
  plans {
    id
    availableGitScanMinutes
    availableNetworkScanMinutes
    maxRepositories
    maxNetworks
    maxEmails
    pricePerGitScanMinute
    pricePerNetworkScanMinute
  }
}

programmingLanguagesQuery

Rückgabe [String!]

Beispiel
query ProgrammingLanguages {
  programmingLanguages
}

Auch verfügbar als: CLI-Befehl vulnara programming_languages · MCP-Tool programming_languages

promoGrantsQuery

Every grant this tenant holds, including ones that have run out.

Rückgabe [PromoGrant!]!

Beispiel
query PromoGrants {
  promoGrants {
    id
    code
    startsAt
    endsAt
    gitScanMinutes
    networkScanMinutes
    maxRepositories
    maxNetworks
  }
}

Auch verfügbar als: MCP-Tool promo_grants

redeemPromoCodeMutation

Redeem a code for this tenant. ADMIN because redeeming changes what the tenant may spend, which is the same authority as changing the plan. A refusal arrives as PROMO_CODE_UNKNOWN, PROMO_CODE_INACTIVE, PROMO_CODE_EXPIRED, PROMO_CODE_FULLY_CLAIMED or PROMO_CODE_ALREADY_REDEEMED. They are distinct because each tells the person typing the code something different about what to do next.

Argumente

NameTypBeschreibung
codeString!

Rückgabe PromoGrant!

Beispiel
mutation RedeemPromoCode($code: String!) {
  redeemPromoCode(code: $code) {
    id
    code
    startsAt
    endsAt
    gitScanMinutes
    networkScanMinutes
    maxRepositories
    maxNetworks
  }
}

registerPushSubscriptionMutation

Argumente

NameTypBeschreibung
inputPushSubscriptionInput!

Rückgabe Boolean!

Beispiel
mutation RegisterPushSubscription($input: PushSubscriptionInput!) {
  registerPushSubscription(input: $input)
}

remediationTemplateQuery

Rückgabe RemediationTemplate!

Beispiel
query RemediationTemplate {
  remediationTemplate {
    codeIssueBody
    dependencyIssueBody
    pullRequestBody
  }
}

Auch verfügbar als: MCP-Tool remediation_template

repositoriesQuery

Argumente

NameTypBeschreibung
listList

Rückgabe RepositoryListResult!

Beispiel
query Repositories($list: List) {
  repositories(list: $list) {
    total
    items {
      id
      gitEntityId
      repositoryName
      private
      securityScore
      programmingLanguage
      repositorySize
      numberOfBranches
    }
  }
}

Auch verfügbar als: CLI-Befehl vulnara repositories · MCP-Tool repositories

repositoryQuery

Argumente

NameTypBeschreibung
idID!

Rückgabe Repository!

Beispiel
query Repository($id: ID!) {
  repository(id: $id) {
    id
    gitEntityId
    repositoryName
    private
    securityScore
    programmingLanguage
    repositorySize
    numberOfBranches
  }
}

Auch verfügbar als: CLI-Befehl vulnara get_repository · MCP-Tool repository

repositoryBranchesQuery

Branch names for a repository, read from its git provider, so the scan form can offer real branches instead of free-text input.

Argumente

NameTypBeschreibung
repositoryIdID!

Rückgabe [String!]!

Beispiel
query RepositoryBranches($repositoryId: ID!) {
  repositoryBranches(repositoryId: $repositoryId)
}

Auch verfügbar als: MCP-Tool repository_branches

repositoryDependencyScanFindingGroupsQuery

Argumente

NameTypBeschreibung
listList

Rückgabe RepositoryDependencyScanFindingGroupListResult!

Beispiel
query RepositoryDependencyScanFindingGroups($list: List) {
  repositoryDependencyScanFindingGroups(list: $list) {
    total
    items {
      id
      dependency
      repositoryId
      severity
      installedVersion
      occurrences
      issueUrl
      issueStatus
    }
  }
}

Auch verfügbar als: MCP-Tool repository_dependency_scan_finding_groups

repositoryDependencyScanFindingsQuery

Argumente

NameTypBeschreibung
listList

Rückgabe RepositoryDependencyScanFindingListResult!

Beispiel
query RepositoryDependencyScanFindings($list: List) {
  repositoryDependencyScanFindings(list: $list) {
    total
    items {
      id
      commitScanId
      createdAt
      updatedAt
      severity
      vulnerability
      dependency
      installedVersion
    }
  }
}

Auch verfügbar als: CLI-Befehl vulnara repository_dependency_scan_findings · MCP-Tool repository_dependency_scan_findings

requestNSFConsultationMutation

Argumente

NameTypBeschreibung
inputNSFConsultation!

Rückgabe Boolean!

Beispiel
mutation RequestNSFConsultation($input: NSFConsultation!) {
  requestNSFConsultation(input: $input)
}

Auch verfügbar als: CLI-Befehl vulnara request_nsf_consultation

requestRSFConsultationMutation

Argumente

NameTypBeschreibung
inputRSFConsultation!

Rückgabe Boolean!

Beispiel
mutation RequestRSFConsultation($input: RSFConsultation!) {
  requestRSFConsultation(input: $input)
}

Auch verfügbar als: CLI-Befehl vulnara request_rsf_consultation

retryPaymentMutation

Argumente

NameTypBeschreibung
invoiceIdID!
paymentMethodIdID!

Rückgabe Invoice!

Beispiel
mutation RetryPayment($invoiceId: ID!, $paymentMethodId: ID!) {
  retryPayment(invoiceId: $invoiceId, paymentMethodId: $paymentMethodId) {
    id
    invoiceNumber
    date
    dueDate
    status
    total
    currency
  }
}

revealScanFindingMatchMutation

The audited path to the raw secret behind a masked ScanFinding/ScanFindingGroup/ ScanFindingMatchGroup.match. Every call is logged with the caller, repository and match hash.

Argumente

NameTypBeschreibung
repositoryIdID!
matchHashString!

Rückgabe String!

Beispiel
mutation RevealScanFindingMatch($repositoryId: ID!, $matchHash: String!) {
  revealScanFindingMatch(repositoryId: $repositoryId, matchHash: $matchHash)
}

scanFindingGroupsQuery

Argumente

NameTypBeschreibung
listList

Rückgabe ScanFindingGroupListResult!

Beispiel
query ScanFindingGroups($list: List) {
  scanFindingGroups(list: $list) {
    total
    items {
      id
      fingerprint
      matchHash
      matchedByToolCount
      file
      severity
      confidence
      match
    }
  }
}

Auch verfügbar als: MCP-Tool scan_finding_groups

scanFindingMatchGroupsQuery

Findings grouped by cross-tool identity, one row per real secret.

Argumente

NameTypBeschreibung
listList

Rückgabe ScanFindingMatchGroupListResult!

Beispiel
query ScanFindingMatchGroups($list: List) {
  scanFindingMatchGroups(list: $list) {
    total
    items {
      id
      matchHash
      file
      line
      severity
      confidence
      match
      occurrences
    }
  }
}

Auch verfügbar als: MCP-Tool scan_finding_match_groups

scanFindingsQuery

Argumente

NameTypBeschreibung
listList

Rückgabe ScanFindingListResult!

Beispiel
query ScanFindings($list: List) {
  scanFindings(list: $list) {
    total
    items {
      id
      commitScanId
      createdAt
      updatedAt
      line
      file
      severity
      confidence
    }
  }
}

Auch verfügbar als: CLI-Befehl vulnara scan_findings · MCP-Tool scan_findings

scanResultQuery

Argumente

NameTypBeschreibung
idID!

Rückgabe ScanResult!

Beispiel
query ScanResult($id: ID!) {
  scanResult(id: $id) {
    id
    repositoryId
    scanType
    scanner
    dockerScanToolId
    status
    createdAt
    updatedAt
  }
}

Auch verfügbar als: CLI-Befehl vulnara get_scan_result · MCP-Tool scan_result

scanResultsQuery

Argumente

NameTypBeschreibung
listList

Rückgabe ScanResultListResult!

Beispiel
query ScanResults($list: List) {
  scanResults(list: $list) {
    total
    items {
      id
      repositoryId
      scanType
      scanner
      dockerScanToolId
      status
      createdAt
      updatedAt
    }
  }
}

Auch verfügbar als: CLI-Befehl vulnara scan_results · MCP-Tool scan_results

scanScheduleQuery

Argumente

NameTypBeschreibung
idID!

Rückgabe ScanSchedule!

Beispiel
query ScanSchedule($id: ID!) {
  scanSchedule(id: $id) {
    id
    action
    repositoryId
    gitEntityId
    branch
    dockerScanToolId
    frequency
    hourUtc
  }
}

Auch verfügbar als: MCP-Tool scan_schedule

scanSchedulesQuery

Argumente

NameTypBeschreibung
listList

Rückgabe ScanScheduleListResult!

Beispiel
query ScanSchedules($list: List) {
  scanSchedules(list: $list) {
    total
    items {
      id
      action
      repositoryId
      gitEntityId
      branch
      dockerScanToolId
      frequency
      hourUtc
    }
  }
}

Auch verfügbar als: MCP-Tool scan_schedules

serviceAccountsQuery

Rückgabe [ServiceAccount!]!

Beispiel
query ServiceAccounts {
  serviceAccounts {
    id
    name
    isActive
    expiresAt
    createdBy {
      id
      email
      username
      name
    }
  }
}

Auch verfügbar als: CLI-Befehl vulnara service_accounts

setDefaultPaymentMethodMutation

Argumente

NameTypBeschreibung
idID!

Rückgabe Boolean!

Beispiel
mutation SetDefaultPaymentMethod($id: ID!) {
  setDefaultPaymentMethod(id: $id)
}

setFindingTriageMutation

Argumente

NameTypBeschreibung
inputSetFindingTriageInput!

Rückgabe FindingTriage!

Beispiel
mutation SetFindingTriage($input: SetFindingTriageInput!) {
  setFindingTriage(input: $input) {
    id
    repositoryId
    matchKey
    findingType
    state
    justification
    response
    priority
  }
}

setGitEntityIgnorePathsMutation

Argumente

NameTypBeschreibung
inputSetGitEntityIgnorePathsInput!

Rückgabe GitEntity!

Beispiel
mutation SetGitEntityIgnorePaths($input: SetGitEntityIgnorePathsInput!) {
  setGitEntityIgnorePaths(input: $input) {
    __typename
    ... on Organization {
      id
      name
      gitType
      externalId
      webUrl
      htmlUrl
      avatarUrl
      color
    }
    ... on GitUser {
      id
      name
      gitType
      externalId
      webUrl
      htmlUrl
      avatarUrl
      color
    }
  }
}

setRemediationTemplateMutation

Argumente

NameTypBeschreibung
inputRemediationTemplateInput!

Rückgabe RemediationTemplate!

Beispiel
mutation SetRemediationTemplate($input: RemediationTemplateInput!) {
  setRemediationTemplate(input: $input) {
    codeIssueBody
    dependencyIssueBody
    pullRequestBody
  }
}

setRepositoryEnabledMutation

Argumente

NameTypBeschreibung
inputSetRepositoryEnabledInput!

Rückgabe Boolean!

Beispiel
mutation SetRepositoryEnabled($input: SetRepositoryEnabledInput!) {
  setRepositoryEnabled(input: $input)
}

setRepositoryIgnorePathsMutation

Argumente

NameTypBeschreibung
inputSetRepositoryIgnorePathsInput!

Rückgabe Repository!

Beispiel
mutation SetRepositoryIgnorePaths($input: SetRepositoryIgnorePathsInput!) {
  setRepositoryIgnorePaths(input: $input) {
    id
    gitEntityId
    repositoryName
    private
    securityScore
    programmingLanguage
    repositorySize
    numberOfBranches
  }
}

setServiceAccountActiveMutation

Argumente

NameTypBeschreibung
inputSetServiceAccountActiveInput!

Rückgabe ServiceAccount!

Beispiel
mutation SetServiceAccountActive($input: SetServiceAccountActiveInput!) {
  setServiceAccountActive(input: $input) {
    id
    name
    isActive
    expiresAt
    createdBy {
      id
      email
      username
      name
    }
  }
}

Auch verfügbar als: CLI-Befehl vulnara set_service_account_active

startNetworkScanMutation

Argumente

NameTypBeschreibung
inputStartNetworkScanInput!

Rückgabe Boolean!

Beispiel
mutation StartNetworkScan($input: StartNetworkScanInput!) {
  startNetworkScan(input: $input)
}

Auch verfügbar als: CLI-Befehl vulnara start_network_scan

startRepositoryScanMutation

Argumente

NameTypBeschreibung
inputStartRepositoryScanInput!

Rückgabe RepositoryScanTask!

Beispiel
mutation StartRepositoryScan($input: StartRepositoryScanInput!) {
  startRepositoryScan(input: $input) {
    id
    objectId
    status
    state {
      totalCommits
      scheduled
      scanned
      failed
      parsed
    }
    createdAt
    scanResult {
      id
      repositoryId
      scanType
      scanner
      dockerScanToolId
      status
      createdAt
      updatedAt
    }
  }
}

Auch verfügbar als: CLI-Befehl vulnara start_repository_scan

statisticsQuery

Rückgabe TenantStatistics!

Beispiel
query Statistics {
  statistics {
    tenant
    totalUsers
    totalGitEntities
    totalRepositories
    totalNetworks
  }
}

Auch verfügbar als: MCP-Tool statistics

taskQuery

Argumente

NameTypBeschreibung
idID!

Rückgabe Task!

Beispiel
query Task($id: ID!) {
  task(id: $id) {
    __typename
    ... on RepositoryScanTask {
      id
      objectId
      status
      createdAt
    }
    ... on NetworkScanTask {
      id
      objectId
      status
      createdAt
    }
  }
}

Auch verfügbar als: MCP-Tool task

taskEventsSubscription

Rückgabe TaskEvent!

Beispiel
subscription TaskEvents {
  taskEvents {
    type
    taskId
  }
}

tasksQuery

Rückgabe [Task!]!

Beispiel
query Tasks {
  tasks {
    __typename
    ... on RepositoryScanTask {
      id
      objectId
      status
      createdAt
    }
    ... on NetworkScanTask {
      id
      objectId
      status
      createdAt
    }
  }
}

Auch verfügbar als: CLI-Befehl vulnara tasks · MCP-Tool tasks

testNotificationScopeMutation

Send a test notification to the rule's channel and record its reachability as the channel status.

Argumente

NameTypBeschreibung
idID!

Rückgabe NotificationScope!

Beispiel
mutation TestNotificationScope($id: ID!) {
  testNotificationScope(id: $id) {
    id
    channelIds
    channelType
    scopes
    isActive
    status
    headers {
      name
      value
    }
    template
  }
}

transferGitEntityMutation

Argumente

NameTypBeschreibung
inputTransferGitEntityInput!

Rückgabe Boolean!

Beispiel
mutation TransferGitEntity($input: TransferGitEntityInput!) {
  transferGitEntity(input: $input)
}

Auch verfügbar als: CLI-Befehl vulnara transfer_git_entity

transferNetworkMutation

Argumente

NameTypBeschreibung
inputTransferNetworkInput!

Rückgabe Boolean!

Beispiel
mutation TransferNetwork($input: TransferNetworkInput!) {
  transferNetwork(input: $input)
}

Auch verfügbar als: CLI-Befehl vulnara transfer_network

unreadNotificationCountQuery

Rückgabe Int!

Beispiel
query UnreadNotificationCount {
  unreadNotificationCount
}

Auch verfügbar als: MCP-Tool unread_notification_count

unregisterPushSubscriptionMutation

Argumente

NameTypBeschreibung
endpointString!

Rückgabe Boolean!

Beispiel
mutation UnregisterPushSubscription($endpoint: String!) {
  unregisterPushSubscription(endpoint: $endpoint)
}

updateGitEntityMutation

Argumente

NameTypBeschreibung
inputUpdateGitEntityInput!

Rückgabe GitEntity!

Beispiel
mutation UpdateGitEntity($input: UpdateGitEntityInput!) {
  updateGitEntity(input: $input) {
    __typename
    ... on Organization {
      id
      name
      gitType
      externalId
      webUrl
      htmlUrl
      avatarUrl
      color
    }
    ... on GitUser {
      id
      name
      gitType
      externalId
      webUrl
      htmlUrl
      avatarUrl
      color
    }
  }
}

updateGitTokenMutation

Argumente

NameTypBeschreibung
inputUpdateGitTokenInput!

Rückgabe GitToken!

Beispiel
mutation UpdateGitToken($input: UpdateGitTokenInput!) {
  updateGitToken(input: $input) {
    id
    name
    value
    expiresAt
    flags
    status
    scopes
    createdAt
  }
}

Auch verfügbar als: CLI-Befehl vulnara update_git_token

updateMyUserPreferencesMutation

Argumente

NameTypBeschreibung
inputUpdateUserPreferencesInput!

Rückgabe UserPreferences!

Beispiel
mutation UpdateMyUserPreferences($input: UpdateUserPreferencesInput!) {
  updateMyUserPreferences(input: $input) {
    theme
    dateTimeFormat
    repositoriesView
  }
}

updateNotificationScopeMutation

Argumente

NameTypBeschreibung
inputUpdateNotificationScopeInput!

Rückgabe NotificationScope!

Beispiel
mutation UpdateNotificationScope($input: UpdateNotificationScopeInput!) {
  updateNotificationScope(input: $input) {
    id
    channelIds
    channelType
    scopes
    isActive
    status
    headers {
      name
      value
    }
    template
  }
}

Auch verfügbar als: CLI-Befehl vulnara update_notification_scope

updateScanScheduleMutation

Argumente

NameTypBeschreibung
inputUpdateScanScheduleInput!

Rückgabe ScanSchedule!

Beispiel
mutation UpdateScanSchedule($input: UpdateScanScheduleInput!) {
  updateScanSchedule(input: $input) {
    id
    action
    repositoryId
    gitEntityId
    branch
    dockerScanToolId
    frequency
    hourUtc
  }
}

updateUserRolesMutation

Argumente

NameTypBeschreibung
inputUpdateUserRolesInput!

Rückgabe TenantUser!

Beispiel
mutation UpdateUserRoles($input: UpdateUserRolesInput!) {
  updateUserRoles(input: $input) {
    id
    roles
    user {
      id
      email
      username
      name
    }
  }
}

upgradeToPayingMutation

Rückgabe Boolean!

Beispiel
mutation UpgradeToPaying {
  upgradeToPaying
}

usageQuery

Argumente

NameTypBeschreibung
startDateDateTime!
endDateDateTime!

Rückgabe Usage!

Beispiel
query Usage($startDate: DateTime!, $endDate: DateTime!) {
  usage(startDate: $startDate, endDate: $endDate) {
    accountTier
    usedGitScanTimeMinutes
    repositoryScanLimited
    usedNetworkScanTimeMinutes
    networkScanLimited
    parallelScans
    availableGitScanMinutes
    availableNetworkScanMinutes
  }
}

workspaceOverviewQuery

Argumente

NameTypBeschreibung
gitEntityIdID!

Rückgabe WorkspaceOverview!

Beispiel
query WorkspaceOverview($gitEntityId: ID!) {
  workspaceOverview(gitEntityId: $gitEntityId) {
    severityCounts {
      severity
      count
    }
    totalFindings
    totalRepositories
    scanned
    unscanned
  }
}

Auch verfügbar als: MCP-Tool workspace_overview

Typen

AgingBucket object
NameTypBeschreibung
bucketString!Age range in days, such as 8-30 or 91+.
countInt!
ChannelStatus enum
NameBeschreibung
operational
degraded
unknown
error
ChannelType enum
NameBeschreibung
email
slack
webhook
telegram
discord
CommitScan object
NameTypBeschreibung
idID!
scanResultIdID!
commitHashString!
createdAtDateTime
updatedAtDateTime
scanResultScanResult!
CommitScanListResult object
NameTypBeschreibung
totalInt!
items[CommitScan!]!
CorroboratedFinding object

One finding that more than one scanner reported. Carries no matched value on purpose: a corroborated finding is very often a leaked secret, and the dashboard is the most widely viewed screen in the product. The repository and file identify it, and the view behind the link masks what it shows.

NameTypBeschreibung
kindString!Either code or dependency.
repositoryIdID!
repositoryNameString!
labelStringThe file for a code finding, the library for a dependency finding.
severityString!
scanners[String!]!The scanners that agreed, by name.
toolCountInt!
findingKeyString!The identity the vulnerabilities explorer addresses this finding by, usable directly as its matchHash filter.
CreateGitEntityInput input
NameTypBeschreibung
nameString!
gitTypeGitType!
externalIdFloat
webUrlString
ignorePaths[String!]Gitignore-style glob patterns applied to every repo under this entity.
ownershipConsentBoolean!Attests that the caller's tenant owns this organisation/user, or is authorized to scan it. No default: the client must decide explicitly. Rejected unless true; the actor and statement version are added server-side, not taken from client input.
CreateGitTokenInput input
NameTypBeschreibung
nameString!
valueString!
flags[GitTokenFlag!]!
gitTokenTypeGitType!
expiresAtDateTime
CreateNetworkInput input
NameTypBeschreibung
nameString!
networkString!
networkTypeNetworkType!
ownershipConsentBoolean!
CreateNotificationScopeInput input
NameTypBeschreibung
channelIds[String!]!
channelTypeChannelType!
scopes[String!]!
isActiveBoolean!
headers[HttpHeaderInput!]
templates[NotificationTemplateInput!]
CreateRepositoryInput input
NameTypBeschreibung
gitEntityIdID!
repositoryNameString!
cloneUrlString
ignorePaths[String!]Gitignore-style glob patterns to exclude from scans.
CreateScanScheduleInput input
NameTypBeschreibung
actionScanScheduleActionDefaults to SCAN. SYNC requires gitEntityId.
repositoryIdIDSupply exactly one of repositoryId or gitEntityId.
gitEntityIdID
branchString
dockerScanToolIdID
frequencyScanScheduleFrequency!
hourUtcInt!
minuteUtcIntDefaults to 0 upstream, which is the minute every schedule fired at before this field existed.
dayOfWeekInt
isActiveBoolean
recipients[String!]Required for a REPORT, refused for anything else. The address shape is checked here because this is the trust boundary; vulnara-api forwards it and vulnara-notification-api refuses a malformed one at the far end.
CreateServiceAccountInput input
NameTypBeschreibung
nameString!
expiresAtDateTime!
CreateServiceAccountPayload object
NameTypBeschreibung
serviceAccountServiceAccount!
tokenString!
CreateTenantInput input
NameTypBeschreibung
nameString!
Currency enum
NameBeschreibung
USD
EUR
BGN
DashboardAnalytics object
NameTypBeschreibung
daysInt!The window the deltas and activity are measured over.
generatedAtDateTime!
lastScanAtDateTime
averageSecurityScoreFloat!
previousAverageSecurityScoreFloat!The same score as it stood at the start of the period.
severityCounts[SeverityCount!]!
previousSeverityCounts[SeverityCount!]!
exposureExposure!
scanActivity[ScanActivityPoint!]!
scoreTrend[ScoreTrendPoint!]!
topRiskRepositories[RepositoryRisk!]!
remediationRemediationFunnel!
dependencyFixesDependencyFixes!
aging[AgingBucket!]!
oldestFindingDaysInt
oldestCriticalDaysInt
coverageScanCoverage!
scanHealthScanHealth!
staleWorkspaces[StaleWorkspace!]!
DependencyFixes object
NameTypBeschreibung
totalInt!
fixableInt!Dependency findings whose advisory names a fixed version.
DockerScanTool object

A scanner, named. The image, tag and arguments are deliberately not exposed: they identify our scanners and their private registry paths, and every screen in the product only ever needs to label a scan with the tool that produced it. Managed in vulnara-backoffice, not through this API.

NameTypBeschreibung
idID!
nameString!
DockerScanToolListResult object
NameTypBeschreibung
totalInt!
items[DockerScanTool!]!
Exposure object

Findings currently exposed, and how that moved over the period. Deduplicated by match hash within a repository and read from the latest scan per tool, so this is what is open now - not every row ever written.

NameTypBeschreibung
totalInt!
previousTotalInt!
newFindingsInt!
resolvedFindingsInt!
codeFindingsInt!
dependencyFindingsInt!
corroboratedFindingsInt!Findings more than one scanner reported - the least likely to be noise.
corroborated[CorroboratedFinding!]!The findings behind corroboratedFindings, worst first. They come from the same query as the count, so the two cannot disagree - which is why this is here rather than the client deep-linking into the explorer, whose finding list is a different population (every scan, code only, triaged included). Capped, while the count stays exact: a tenant over the cap reads as "some of many" rather than seeing a list that looks complete.
falsePositivesInt!Held back by a decision rather than by a fix. Reported beside the open total, never folded into it - a number that shrinks when somebody dismisses something is what this endpoint exists to avoid.
notAffectedInt!
hiddenButScoredInt!Real findings a decision keeps out of the working list - deferred, or will-not-fix. They still count against the score, so they are named here rather than being quietly absent from both numbers.
resolvedFindingsTriagedInt!Everything a decision took out of the score entirely.
FetchGitEntityTask object
NameTypBeschreibung
idID!
objectIdID!
statusTaskStatus!
stateFetchGitEntityTaskState!
createdAtInt!
gitEntityGitEntity!
FetchGitEntityTaskState object
NameTypBeschreibung
processedInt!
totalInt!
FetchRepositoriesInput input
NameTypBeschreibung
gitEntityIdID!
gitTokenIdID
Filter input
NameTypBeschreibung
fieldString!
minFloat
maxFloat
stringEqualsString
idEqualsID
FindingCorroboration object

One real-world issue and how many independent scanners found it. toolCount > 1 is the "confirmed by N tools" signal.

NameTypBeschreibung
idID!
matchHashString!
toolCountInt!
severitySeverityReconciled across the tools that reported it (highest severity wins).
FindingCorroborationListResult object
NameTypBeschreibung
totalInt!
items[FindingCorroboration!]!
FindingTriage object

A decision taken about a finding. Keyed on the finding's identity rather than its row, so it survives rescans and applies to every scanner that reported the same thing. The three axes are separate on purpose. state decides whether the finding still counts against the security score - only states asserting no live risk take it out. response and a defer priority clear it from the working list while leaving the score alone, because deciding not to act on something does not make it safe.

NameTypBeschreibung
idID!
repositoryIdID!
matchKeyString!
findingTypeString!
stateTriageState!
justificationTriageJustification
responseTriageResponse
priorityTriagePriority
reasonString!
createdByString
createdAtDateTime!
expiresAtDateTimeRequired whenever the decision hides a finding that is still exposed.
FindingTriageEvent object

One entry in a finding's decision history. Append-only.

NameTypBeschreibung
idID!
repositoryIdID!
matchKeyString!
actionString!set or reopen.
stateTriageState
justificationTriageJustification
responseTriageResponse
priorityTriagePriority
reasonString
expiresAtDateTime
actorString
createdAtDateTime!
GitEntity union

Eines von: Organization, GitUser

GitEntityListResult object
NameTypBeschreibung
totalInt!
items[GitEntity!]!
GitEntityType enum
NameBeschreibung
organization
user
GitToken object
NameTypBeschreibung
idID!
nameString
valueString!
expiresAtDateTime
flags[GitTokenFlag!]!
statusGitTokenStatus!
scopes[String!]!
createdAtDateTime
updatedAtDateTime
gitTokenTypeGitType!
tenantString!
gitEntitiesGitEntityListResult!
GitTokenAssociationInput input
NameTypBeschreibung
gitEntityIdID!
gitTokenIdID!
GitTokenCheck object

Result of probing a git token against its provider so the UI can pre-fill the expiry and explain what's wrong when the token is rejected.

NameTypBeschreibung
validBoolean!Whether the provider accepted the token.
statusCodeIntHTTP status the provider returned (e.g. 401 for bad credentials), if any.
errorStringProvider error message/code (e.g. "Bad credentials"), if the check failed.
expiresAtDateTimeThe token's own expiry as reported by the provider, if it exposes one.
publicRepositoryCountIntPublic repositories the token can see for the given workspace name, or null when no name was supplied, the token is invalid, or the provider couldn't be reached.
privateRepositoryCountIntPrivate repositories the token can see for the given workspace name, or null when no name was supplied, the token is invalid, or the provider couldn't be reached.
GitTokenFlag enum
NameBeschreibung
default
GitTokenListResult object
NameTypBeschreibung
totalInt!
items[GitToken!]!
GitTokenStatus enum
NameBeschreibung
valid
invalid
unknown
error
GitType enum
NameBeschreibung
github
gitlab
GitUser object
NameTypBeschreibung
idID!
nameString!
gitTypeGitType!
externalIdFloat
webUrlString
htmlUrlString
avatarUrlStringPresigned URL of the entity's avatar (re-hosted from the provider), null if none.
colorStringRepresentative, always-vivid colour (hex) derived from the avatar or seeded from the name.
averageSecurityScoreFloat!
lastImportDateDateTime
repositoryCountInt
typeGitEntityType!
createdAtDateTime!
updatedAtDateTime
ignorePaths[String!]
tags[Tag!]!
HttpHeader object
NameTypBeschreibung
nameString!
valueString!
HttpHeaderInput input
NameTypBeschreibung
nameString!
valueString!
Invitation object
NameTypBeschreibung
idID!
emailString!
tenantNameString!
InviteTeamMemberInput input
NameTypBeschreibung
emailString!
languageString
Invoice object
NameTypBeschreibung
idID!
invoiceNumberString
dateDateTime!
dueDateDateTime!
statusString!
totalFloat!
currencyCurrency!
InvoiceDownload object
NameTypBeschreibung
urlString!
filenameString!
tenantString!
contentTypeString!
InvoiceListResult object
NameTypBeschreibung
totalInt!
items[Invoice!]!
IssueStatus enum

Normalized issue state across providers (GitHub open/closed, GitLab opened/closed).

NameBeschreibung
open
closed
List input
NameTypBeschreibung
limitInt
skipInt
filters[Filter!]
sortString
orderOrder
searchString
MyUser object
NameTypBeschreibung
idID!
emailString!
nameString!
usernameString!
tenants[Tenant!]!
preferencesUserPreferences!
Network object
NameTypBeschreibung
idID!
nameString!
networkString!
networkTypeNetworkType!
tenantString!
securityScoreFloat!
createdAtDateTime!
updatedAtDateTime
tags[Tag!]!
NetworkListResult object
NameTypBeschreibung
totalInt!
items[Network!]!
NetworkScanFinding object
NameTypBeschreibung
idID!
scanResultIdID!
hostString!
hostnameString!
hostnameTypeString
protocolString!
portInt!
serviceNameString!
stateString!
productString!
versionString!
extraInfoString!
reasonString!
confidenceInt!
cpeString!
tags[Tag!]!
createdAtDateTime!
updatedAtDateTime
networkScanResultNetworkScanResult!
NetworkScanFindingListResult object
NameTypBeschreibung
totalInt!
items[NetworkScanFinding!]!
NetworkScanResult object
NameTypBeschreibung
idID!
networkIdID!
statusScanStatus!
createdAtDateTime!
updatedAtDateTime
scanTimeInt
networkNetwork!
NetworkScanResultListResult object
NameTypBeschreibung
totalInt!
items[NetworkScanResult!]!
NetworkScanTask object
NameTypBeschreibung
idID!
objectIdID!
statusTaskStatus!
stateNetworkScanTaskState!
createdAtInt!
scanResultNetworkScanResult!
NetworkScanTaskState object
NameTypBeschreibung
totalHostsInt!
processedHostsInt!
currentHostString
NetworkType enum
NameBeschreibung
public
private
vpn
internal
external
dmz
unknown
Notification object
NameTypBeschreibung
idID!
typeNotificationType!
eventTypeString!
dataJSON
readBoolean!
createdAtDateTime!
NotificationList object
NameTypBeschreibung
items[Notification!]!
totalInt!
NotificationScope object
NameTypBeschreibung
idID!
channelIds[String!]!
channelTypeChannelType!
scopes[String!]!
isActiveBoolean!
statusChannelStatus!
headers[HttpHeader!]Custom HTTP headers sent with webhook deliveries (webhook channel only).
templateStringDeprecated: superseded by templates.
templates[NotificationTemplate!]Per-event message templates (eventType '*' is the default for all events).
NotificationScopeListResult object
NameTypBeschreibung
totalInt!
items[NotificationScope!]!
NotificationTemplate object

A message template for one event type ('*' = every event).

NameTypBeschreibung
eventTypeString!
templateString!
NotificationTemplateInput input
NameTypBeschreibung
eventTypeString!
templateString!
NotificationType enum
NameBeschreibung
SCAN_FINISHED
REPOSITORY_FETCH_FINISHED
NSFConsultation input
NameTypBeschreibung
findingIdID!
Order enum
NameBeschreibung
ASC
DESC
Organization object
NameTypBeschreibung
idID!
nameString!
gitTypeGitType!
externalIdFloat
webUrlString
htmlUrlString
avatarUrlStringPresigned URL of the entity's avatar (re-hosted from the provider), null if none.
colorStringRepresentative, always-vivid colour (hex) derived from the avatar or seeded from the name.
averageSecurityScoreFloat!
lastImportDateDateTime
repositoryCountInt
typeGitEntityType!
createdAtDateTime!
updatedAtDateTime
ignorePaths[String!]
tags[Tag!]!
PaymentMethod object
NameTypBeschreibung
idID!
defaultBoolean!
lastFourString!
brandString!
expiryMonthInt!
expiryYearInt!
cardholderNameString!
expiredBoolean!
PaymentMethodListResult object
NameTypBeschreibung
totalInt!
items[PaymentMethod!]!
Plan object
NameTypBeschreibung
idID!
availableGitScanMinutesInt
availableNetworkScanMinutesInt
maxRepositoriesInt
maxNetworksInt
maxEmailsInt
pricePerGitScanMinuteFloat
pricePerNetworkScanMinuteFloat
currencyCurrency
PreferredDateTimeFormat enum
NameBeschreibung
localized
iso
us
eu
PreferredRepositoriesView enum
NameBeschreibung
board
table
PreferredTheme enum
NameBeschreibung
Light
Dark
System
PromoGrant object

A promotion a tenant holds. The limits are the ones granted when the code was redeemed, not the ones the code names today: vulnara-api copies them at redemption so that editing a code cannot change a grant already made.

NameTypBeschreibung
idID!
codeString!
startsAtDateTime!
endsAtDateTime!
gitScanMinutesInt
networkScanMinutesInt
maxRepositoriesInt
maxNetworksInt
maxEmailsInt
PrStatus enum

Normalized remediation pull/merge request state.

NameBeschreibung
open
merged
closed
PushSubscriptionInput input
NameTypBeschreibung
endpointString!
p256dhString!
authString!
RemediationFunnel object

Findings to opened issues to merged remediation PRs.

NameTypBeschreibung
findingsInt!
issuesOpenedInt!
issuesClosedInt!
prsOpenedInt!
prsMergedInt!
RemediationTemplate object
NameTypBeschreibung
codeIssueBodyString
dependencyIssueBodyString
pullRequestBodyString
RemediationTemplateInput input
NameTypBeschreibung
codeIssueBodyString
dependencyIssueBodyString
pullRequestBodyString
Repository object
NameTypBeschreibung
idID!
gitEntityIdID!
repositoryNameString!
privateBoolean
securityScoreFloat
programmingLanguage[String!]
repositorySizeFloatRepository size in bytes. Float, not Int, so large repos (>2GB) don't overflow GraphQL's 32-bit Int.
numberOfBranchesInt
cloneUrlString
createdAtDateTime!
updatedAtDateTime
isBlacklistedBoolean
enabledBoolean
isStandaloneBoolean
avatarUrlStringPresigned URL of the repo's own avatar (GitLab project image or GitHub custom social-preview image); null otherwise - fall back to gitEntity.avatarUrl.
colorStringVivid colour derived from the repo's avatar; null when it has no colourful image - fall back to a hash of the id.
ignorePaths[String!]
tags[Tag!]!
gitEntityGitEntity!
severityCounts[SeverityCount!]
latestScanRepositoryScanMost recent scan's status and time (null if never scanned).
scoreHistory[Float!]Recent security scores oldest→newest, for the list trend sparkline.
RepositoryDependencyScanFinding object
NameTypBeschreibung
idID!
commitScanIdID!
createdAtDateTime!
updatedAtDateTime
severitySeverity
vulnerabilityString
dependencyString
installedVersionString
fixedVersionString
purlStringPackage URL, e.g. pkg:npm/[email protected].
vulnerabilityAliases[String!]Other identifiers for the same advisory (GHSA, vendor ids).
matchHashStringCross-tool identity: two scanners reporting the same vulnerable package share this value, even when one leads with a CVE and the other a GHSA.
issueUrlStringURL of the GitHub/GitLab issue opened for this dependency, if any.
issueStatusIssueStatus
prUrlStringURL of the remediation PR opened for this dependency, if any.
prStatusPrStatus
commitScanCommitScan!
tags[Tag!]!
RepositoryDependencyScanFindingGroup object

One vulnerable library, aggregating all its advisories (CVEs). Queried with a scanResultId filter it covers that scan; without one it covers the tenant, one row per repository the library is vulnerable in.

NameTypBeschreibung
idID!
dependencyString!
repositoryIdIDWhich repository the library is vulnerable in. Null within a single scan result, where the caller already named the repository.
severitySeverity
installedVersionString
occurrencesInt!
issueUrlString
issueStatusIssueStatus
prUrlString
prStatusPrStatus
RepositoryDependencyScanFindingGroupListResult object
NameTypBeschreibung
totalInt!
items[RepositoryDependencyScanFindingGroup!]!
RepositoryDependencyScanFindingListResult object
NameTypBeschreibung
totalInt!
items[RepositoryDependencyScanFinding!]!
RepositoryListResult object
NameTypBeschreibung
totalInt!
items[Repository!]!
RepositoryRisk object
NameTypBeschreibung
idID!
nameString!
securityScoreFloat!
criticalCountInt!
highCountInt!
findingCountInt!
RepositoryScan object
NameTypBeschreibung
statusScanStatus
scannedAtDateTime
RepositoryScanTask object
NameTypBeschreibung
idID!
objectIdID!
statusTaskStatus!
stateRepositoryScanTaskState!
createdAtInt!
scanResultScanResult!
RepositoryScanTaskState object
NameTypBeschreibung
totalCommitsInt!
scheduledInt!
scannedInt!
failedInt!
parsedInt!
RevolutOrder object
NameTypBeschreibung
idID!
tokenString!
RSFConsultation input
NameTypBeschreibung
findingIdID!
ScanActivityPoint object
NameTypBeschreibung
dateString!
countInt!Every scan started that day, failed ones included.
succeededInt!
failedInt!Failed and cancelled scans - activity that produced no coverage.
ScanCoverage object
NameTypBeschreibung
totalRepositoriesInt!
scannedInt!
unscannedInt!Repositories never scanned - unknown risk, and excluded from the score.
ScanFinding object
NameTypBeschreibung
idID!
commitScanIdID!
createdAtDateTime!
updatedAtDateTime
lineInt
fileString
severitySeverity
confidenceString
matchStringMasked (first/last few characters only) - see revealScanFindingMatch for the raw value.
fingerprintString
matchHashStringCross-tool identity: two different scanners that found the same secret share this value. Null when the secret could not be resolved (older scans). Distinct from fingerprint, which is per-tool.
matchedByToolCountIntHow many distinct scanners reported this finding. Greater than 1 means two tools independently agreed, which is the strongest cheap signal that it is not a false positive. Null when the finding has no cross-tool identity.
issueUrlStringURL of the GitHub/GitLab issue opened for this finding, if any.
issueStatusIssueStatus
prUrlStringURL of the remediation PR opened for this finding, if any.
prStatusPrStatus
commitScanCommitScan!
tags[Tag!]!
ScanFindingGroup object
NameTypBeschreibung
idID!
fingerprintString!
matchHashStringCross-tool identity of this group.
matchedByToolCountIntHow many distinct scanners reported this finding. A fingerprint group is one tool's view; this says whether anyone else found the same thing.
fileString
severitySeverity
confidenceString
matchStringMasked (first/last few characters only) - see revealScanFindingMatch for the raw value.
occurrencesInt!
issueUrlStringURL of the GitHub/GitLab issue opened for this finding, if any.
issueStatusIssueStatus
prUrlStringURL of the remediation PR opened for this finding, if any.
prStatusPrStatus
ScanFindingGroupListResult object
NameTypBeschreibung
totalInt!
items[ScanFindingGroup!]!
ScanFindingListResult object
NameTypBeschreibung
totalInt!
items[ScanFinding!]!
ScanFindingMatchGroup object

One real secret, collapsed across every commit and tool that saw it. The explorer listed raw findings, so a token committed once appeared per commit per tool - 26 commits scanned by 2 tools meant 52 rows for one secret.

NameTypBeschreibung
idID!
matchHashString!
fileString
lineInt
severitySeverity
confidenceStringHighest confidence any contributing tool assigned.
matchStringMasked (first/last few characters only) - see revealScanFindingMatch for the raw value.
occurrencesInt!How many raw findings collapsed into this group.
toolCountInt!How many distinct scanners agreed. Greater than 1 is the corroboration signal.
scanners[String!]!Which scanners reported it. toolCount answers "is this corroborated"; this answers "who says so", which is what you need to judge a finding you disagree with.
repositoryIdID
triageKeyStringThe identity a triage decision is filed under - the match hash, or the fingerprint when there is none. Distinct from matchHash above, which falls back to the finding id: filing a decision under that key stored it somewhere nothing ever looks up.
triageStateTriageStateThe decision in force, carried on the row so the explorer can show and filter it without a call per finding. Null when nothing has been decided.
triageResponseTriageResponse
triagePriorityTriagePriority
ScanFindingMatchGroupListResult object
NameTypBeschreibung
totalInt!
items[ScanFindingMatchGroup!]!
ScanHealth object
NameTypBeschreibung
totalScansInt!
succeededScansInt!
failedScansInt!
runningScansInt!
invalidTokensInt!Tokens the provider rejected; every scan under their workspaces is blocked.
expiringTokensInt!
ScanResult object
NameTypBeschreibung
idID!
repositoryIdID!
scanTypeString!
scannerString!
dockerScanToolIdID!
statusScanStatus!
createdAtDateTime!
updatedAtDateTime
scanTimeInt
securityScoreFloat
createIssueBoolean!
autoRemediateBoolean!
branches[String!]
repositoryRepository!
dockerScanToolDockerScanTool!
severityCounts[SeverityCount!]!
ScanResultListResult object
NameTypBeschreibung
totalInt!
items[ScanResult!]!
ScanSchedule object

A standing instruction to run on a fixed cadence. Deliberately a frequency plus an hour rather than a cron expression: the whole space of valid values is enumerable, so it validates here and renders as two selects. Exactly one of repositoryId or gitEntityId is set. A workspace SCAN fans out over the repositories the workspace holds when it fires, so one imported after the schedule was made is included and one disabled since is not.

NameTypBeschreibung
idID!
actionScanScheduleAction!
repositoryIdIDSet when this schedule targets one repository. Null for a workspace schedule.
gitEntityIdIDSet when this schedule targets a whole workspace. Null for a repository schedule.
branchStringBranch to scan. Null means the default branch. Never set on a workspace schedule - a branch is a repository-level idea and a workspace's repositories do not share one - nor on a SYNC.
dockerScanToolIdIDScanner to run. Null means the tenant's default scanner.
frequencyScanScheduleFrequency!
hourUtcInt!Hour of day in UTC, 0-23. Clients render it in the viewer's own zone.
minuteUtcInt!Minute of the hour in UTC, 0-59. Zero for a schedule created before minutes existed.
dayOfWeekIntDay of week, 0-6, Monday is 0. Only read when frequency is WEEKLY.
isActiveBoolean!
nextRunAtDateTimeWhen the next run is due, in UTC. Computed by vulnara-api, never written by a client.
lastRunAtDateTimeWhen the schedule last dispatched a scan, in UTC. Read only.
recipients[String!]!Where a REPORT is mailed. Empty for a SCAN or a SYNC. Not restricted to tenant members, matching the destinations alert rules already accept.
createdByString
createdAtDateTime
updatedAtDateTime
repositoryRepositoryNull for a workspace schedule.
gitEntityGitEntityNull for a repository schedule.
dockerScanToolDockerScanTool
ScanScheduleAction enum

What a due schedule does. SCAN queues a scan; SYNC re-imports a workspace's repositories, the same job the workspace sync button runs. A SYNC only ever targets a workspace: there is nothing to re-import for a single repository.

NameBeschreibung
SCAN
SYNC
REPORT
ScanScheduleFrequency enum
NameBeschreibung
DAILY
WEEKLY
ScanScheduleListResult object
NameTypBeschreibung
totalInt!
items[ScanSchedule!]!
ScanStatus enum
NameBeschreibung
PENDING
SUCCESS
FAILED
CANCELLED
ScoreTrendPoint object
NameTypBeschreibung
dateString!
scoreFloat!
ServiceAccount object
NameTypBeschreibung
idID!
nameString!
isActiveBoolean!
expiresAtDateTime
createdByUser!
SetFindingTriageInput input
NameTypBeschreibung
repositoryIdID!
matchKeyString!The finding's matchHash, or its per-tool fallback when it has none.
findingTypeString!
stateTriageState!
justificationTriageJustification
responseTriageResponse
priorityTriagePriority
reasonString!
expiresAtDateTime
SetGitEntityIgnorePathsInput input
NameTypBeschreibung
gitEntityIdID!
ignorePaths[String!]!
SetRepositoryEnabledInput input
NameTypBeschreibung
repositoryIds[ID!]!
enabledBoolean!
SetRepositoryIgnorePathsInput input
NameTypBeschreibung
repositoryIdID!
ignorePaths[String!]!
SetServiceAccountActiveInput input
NameTypBeschreibung
idID!
isActiveBoolean!
Severity enum
NameBeschreibung
info
low
medium
high
critical
SeverityCount object
NameTypBeschreibung
severityString!
countInt!
StaleWorkspace object
NameTypBeschreibung
idID!
nameString!
lastImportDateDateTime
StartNetworkScanInput input
NameTypBeschreibung
networkIdID!
StartRepositoryScanInput input
NameTypBeschreibung
repositoryIdID!
dockerScanToolIdID!
branchString
gitTokenIdID
createIssueBoolean
autoRemediateBoolean
Tag object
NameTypBeschreibung
keyString!
valueString!
Task union

Eines von: RepositoryScanTask, NetworkScanTask, FetchGitEntityTask

TaskEvent object
NameTypBeschreibung
typeTaskEventType!
taskIdID!
taskTask
TaskEventType enum
NameBeschreibung
STATE_UPDATED
TASK_CANCELLED
TaskStatus enum
NameBeschreibung
QUEUED
STARTED
CANCELLED
PROCESSING
COMPLETED
FAILED
Tenant object
NameTypBeschreibung
idID!
isPayingBoolean!
members[TenantUser!]!
TenantStatistics object
NameTypBeschreibung
tenantString!
totalUsersInt!
totalGitEntitiesInt!
totalRepositoriesInt!
totalNetworksInt!
TenantUser object
NameTypBeschreibung
idID!
roles[TenantUserRole!]!
userUser!
TenantUserRole enum
NameBeschreibung
VIEWER
EDITOR
ADMIN
TransferGitEntityInput input
NameTypBeschreibung
gitEntityIdID!
newTenantString!
TransferNetworkInput input
NameTypBeschreibung
networkIdID!
newTenantString!
TriageJustification enum

CycloneDX VEX justification. Required when the state is not_affected.

NameBeschreibung
code_not_present
code_not_reachable
requires_configuration
requires_dependency
requires_environment
protected_by_compiler
protected_at_runtime
protected_at_perimeter
protected_by_mitigating_control
TriagePriority enum

SSVC decision outcome. Only defer hides the finding from the working list.

NameBeschreibung
defer
scheduled
out_of_cycle
immediate
TriageResponse enum

CycloneDX VEX analysis.response - what will be done about it.

NameBeschreibung
can_not_fix
rollback
update
will_not_fix
workaround_available
TriageState enum

CycloneDX VEX analysis.state - what is true about the finding.

NameBeschreibung
resolved
resolved_with_pedigree
exploitable
in_triage
false_positive
not_affected
UpdateGitEntityInput input
NameTypBeschreibung
gitEntityIdID!
nameString
gitTypeGitType
ignorePaths[String!]
UpdateGitTokenInput input
NameTypBeschreibung
idID!
nameString
valueString
UpdateNotificationScopeInput input
NameTypBeschreibung
idID!
channelIds[String!]
channelTypeChannelType
scopes[String!]
isActiveBoolean
headers[HttpHeaderInput!]
templates[NotificationTemplateInput!]
UpdateScanScheduleInput input
NameTypBeschreibung
idID!
branchString
dockerScanToolIdID
frequencyScanScheduleFrequency
hourUtcInt
minuteUtcInt
dayOfWeekInt
isActiveBoolean
recipients[String!]
UpdateUserPreferencesInput input
NameTypBeschreibung
themePreferredTheme
dateTimeFormatPreferredDateTimeFormat
repositoriesViewPreferredRepositoriesView
UpdateUserRolesInput input
NameTypBeschreibung
userIdID!
roles[TenantUserRole!]!
Usage object
NameTypBeschreibung
accountTierString!
usedGitScanTimeMinutesInt!
repositoryScanLimitedBoolean!
usedNetworkScanTimeMinutesInt!
networkScanLimitedBoolean!
parallelScansInt!
availableGitScanMinutesInt!
availableNetworkScanMinutesInt!
maxParallelScansInt!
usedRepositoriesInt!
maxRepositoriesInt!
repositoryLimitReachedBoolean!
usedNetworksInt!
maxNetworksInt!
networkLimitReachedBoolean!
usedEmailsInt!
maxEmailsInt!
emailLimitReachedBoolean!
User object
NameTypBeschreibung
idID!
emailStringNull unless the caller may read it: their own address, or any address in a tenant they hold EDITOR or ADMIN in. Nullable rather than guarded by @tenantRole because the directive throws, and a thrown error on a non-null field takes the whole myUser query down for every VIEWER instead of hiding one field.
usernameString!
nameString!
UserPreferences object
NameTypBeschreibung
themePreferredTheme
dateTimeFormatPreferredDateTimeFormat
repositoriesViewPreferredRepositoriesView
WorkspaceOverview object

Security aggregate for one workspace, counted on the server with the same latest-scan + deduplicated policy as the dashboard.

NameTypBeschreibung
severityCounts[SeverityCount!]!
totalFindingsInt!
totalRepositoriesInt!
scannedInt!
unscannedInt!

Verwalten Sie Ihre Cookie-Einstellungen

Wir verwenden Cookies, um Ihr Erlebnis zu verbessern. Sie können alle Cookies akzeptieren, nicht unbedingt erforderliche Cookies ablehnen oder unten Ihre Einstellungen verwalten. Datenschutzerklärung