GraphQL API
The gateway exposes the whole platform at one GraphQL endpoint. Send a bearer token in Authorization and the workspace id in X-Tenant.
https://vulnara-gw.rso.dev/graphqlcurl https://vulnara-gw.rso.dev/graphql \
-H "Authorization: Bearer $VULNARA_TOKEN" \
-H "X-Tenant: $VULNARA_TENANT" \
-H "Content-Type: application/json" \
-d '{"query":"{ myUser { id } }"}'acceptInvitationMutation
Arguments
| Name | Type | Description |
|---|---|---|
| id | ID! |
Returns Boolean!
mutation AcceptInvitation($id: ID!) {
acceptInvitation(id: $id)
}associateGitTokenWithGitEntityMutation
Arguments
| Name | Type | Description |
|---|---|---|
| input | GitTokenAssociationInput! |
Returns GitToken!
mutation AssociateGitTokenWithGitEntity($input: GitTokenAssociationInput!) {
associateGitTokenWithGitEntity(input: $input) {
id
name
value
expiresAt
flags
status
scopes
createdAt
}
}Also available as: CLI command vulnara associate_git_token_with_git_entity
cancelTaskMutation
Arguments
| Name | Type | Description |
|---|---|---|
| id | ID! |
Returns Boolean!
mutation CancelTask($id: ID!) {
cancelTask(id: $id)
}Also available as: CLI command vulnara cancel_task
checkGitTokenQuery
Probe the token against its provider, returning validity, the provider's error (when rejected) and the reported expiry. Used by the add-token form to surface why a token was rejected. When a workspace name is supplied and the token is valid, also returns how many repositories the token can see for it (public + private).
Arguments
| Name | Type | Description |
|---|---|---|
| value | String! | |
| gitType | GitType! | |
| name | String |
Returns GitTokenCheck!
query CheckGitToken($value: String!, $gitType: GitType!, $name: String) {
checkGitToken(value: $value, gitType: $gitType, name: $name) {
valid
statusCode
error
expiresAt
publicRepositoryCount
privateRepositoryCount
}
}clearFindingTriageMutation
Arguments
| Name | Type | Description |
|---|---|---|
| repositoryId | ID! | |
| matchKey | String! |
Returns Boolean!
mutation ClearFindingTriage($repositoryId: ID!, $matchKey: String!) {
clearFindingTriage(repositoryId: $repositoryId, matchKey: $matchKey)
}commitScansQuery
Arguments
| Name | Type | Description |
|---|---|---|
| list | List |
Returns CommitScanListResult!
query CommitScans($list: List) {
commitScans(list: $list) {
total
items {
id
scanResultId
commitHash
createdAt
updatedAt
}
}
}Also available as: MCP tool commit_scans
confirmEmptyOrderMutation
Arguments
| Name | Type | Description |
|---|---|---|
| id | ID! |
Returns Boolean!
mutation ConfirmEmptyOrder($id: ID!) {
confirmEmptyOrder(id: $id)
}createEmptyOrderMutation
Returns RevolutOrder!
mutation CreateEmptyOrder {
createEmptyOrder {
id
}
}createGitEntityMutation
Arguments
| Name | Type | Description |
|---|---|---|
| input | CreateGitEntityInput! |
Returns GitEntity!
mutation CreateGitEntity($input: CreateGitEntityInput!) {
createGitEntity(input: $input) {
__typename
... on Organization {
id
name
gitType
externalId
webUrl
htmlUrl
avatarUrl
color
}
... on GitUser {
id
name
gitType
externalId
webUrl
htmlUrl
avatarUrl
color
}
}
}Also available as: CLI command vulnara create_git_entity
createGitTokenMutation
Arguments
| Name | Type | Description |
|---|---|---|
| input | CreateGitTokenInput! |
Returns GitToken!
mutation CreateGitToken($input: CreateGitTokenInput!) {
createGitToken(input: $input) {
id
name
value
expiresAt
flags
status
scopes
createdAt
}
}Also available as: CLI command vulnara create_git_token
createInvoiceDownloadUrlMutation
Arguments
| Name | Type | Description |
|---|---|---|
| invoiceId | ID! |
Returns InvoiceDownload!
mutation CreateInvoiceDownloadUrl($invoiceId: ID!) {
createInvoiceDownloadUrl(invoiceId: $invoiceId) {
url
filename
tenant
contentType
}
}createNetworkMutation
Arguments
| Name | Type | Description |
|---|---|---|
| input | CreateNetworkInput! |
Returns Network!
mutation CreateNetwork($input: CreateNetworkInput!) {
createNetwork(input: $input) {
id
name
network
networkType
tenant
securityScore
createdAt
updatedAt
}
}Also available as: CLI command vulnara create_network
createNotificationScopeMutation
Arguments
| Name | Type | Description |
|---|---|---|
| input | CreateNotificationScopeInput! |
Returns NotificationScope!
mutation CreateNotificationScope($input: CreateNotificationScopeInput!) {
createNotificationScope(input: $input) {
id
channelIds
channelType
scopes
isActive
status
headers {
name
value
}
template
}
}Also available as: CLI command vulnara create_notification_scope
createRepositoryMutation
Arguments
| Name | Type | Description |
|---|---|---|
| input | CreateRepositoryInput! |
Returns Repository!
mutation CreateRepository($input: CreateRepositoryInput!) {
createRepository(input: $input) {
id
gitEntityId
repositoryName
private
securityScore
programmingLanguage
repositorySize
numberOfBranches
}
}Also available as: CLI command vulnara create_repository
createScanScheduleMutation
Arguments
| Name | Type | Description |
|---|---|---|
| input | CreateScanScheduleInput! |
Returns ScanSchedule!
mutation CreateScanSchedule($input: CreateScanScheduleInput!) {
createScanSchedule(input: $input) {
id
action
repositoryId
gitEntityId
branch
dockerScanToolId
frequency
hourUtc
}
}createServiceAccountMutation
Arguments
| Name | Type | Description |
|---|---|---|
| input | CreateServiceAccountInput! |
Returns CreateServiceAccountPayload!
mutation CreateServiceAccount($input: CreateServiceAccountInput!) {
createServiceAccount(input: $input) {
serviceAccount {
id
name
isActive
expiresAt
}
}
}Also available as: CLI command vulnara create_service_account
createTenantMutation
Arguments
| Name | Type | Description |
|---|---|---|
| input | CreateTenantInput! |
Returns Tenant!
mutation CreateTenant($input: CreateTenantInput!) {
createTenant(input: $input) {
id
isPaying
members {
id
roles
}
}
}Also available as: CLI command vulnara create_tenant
dashboardAnalyticsQuery
Arguments
| Name | Type | Description |
|---|---|---|
| days | Int |
Returns DashboardAnalytics!
query DashboardAnalytics($days: Int) {
dashboardAnalytics(days: $days) {
days
generatedAt
lastScanAt
averageSecurityScore
previousAverageSecurityScore
severityCounts {
severity
count
}
previousSeverityCounts {
severity
count
}
exposure {
total
previousTotal
newFindings
resolvedFindings
codeFindings
dependencyFindings
corroboratedFindings
falsePositives
}
}
}Also available as: MCP tool dashboard_analytics
declineInvitationMutation
Arguments
| Name | Type | Description |
|---|---|---|
| id | ID! |
Returns Boolean!
mutation DeclineInvitation($id: ID!) {
declineInvitation(id: $id)
}deleteGitEntityMutation
Arguments
| Name | Type | Description |
|---|---|---|
| id | ID! |
Returns Boolean!
mutation DeleteGitEntity($id: ID!) {
deleteGitEntity(id: $id)
}Also available as: CLI command vulnara delete_git_entity
deleteGitTokenMutation
Arguments
| Name | Type | Description |
|---|---|---|
| id | ID! |
Returns Boolean!
mutation DeleteGitToken($id: ID!) {
deleteGitToken(id: $id)
}Also available as: CLI command vulnara delete_git_token
deleteInvitationMutation
Arguments
| Name | Type | Description |
|---|---|---|
| id | ID! |
Returns Boolean!
mutation DeleteInvitation($id: ID!) {
deleteInvitation(id: $id)
}deleteNetworkMutation
Arguments
| Name | Type | Description |
|---|---|---|
| id | ID! |
Returns Boolean!
mutation DeleteNetwork($id: ID!) {
deleteNetwork(id: $id)
}Also available as: CLI command vulnara delete_network
deleteNetworkScanResultMutation
Arguments
| Name | Type | Description |
|---|---|---|
| id | ID! |
Returns Boolean!
mutation DeleteNetworkScanResult($id: ID!) {
deleteNetworkScanResult(id: $id)
}Also available as: CLI command vulnara delete_network_scan_result
deleteNotificationScopeMutation
Arguments
| Name | Type | Description |
|---|---|---|
| id | ID! |
Returns Boolean!
mutation DeleteNotificationScope($id: ID!) {
deleteNotificationScope(id: $id)
}Also available as: CLI command vulnara delete_notification_scope
deletePaymentMethodMutation
Arguments
| Name | Type | Description |
|---|---|---|
| id | ID! |
Returns Boolean!
mutation DeletePaymentMethod($id: ID!) {
deletePaymentMethod(id: $id)
}deleteRepositoryMutation
Arguments
| Name | Type | Description |
|---|---|---|
| id | ID! |
Returns Boolean!
mutation DeleteRepository($id: ID!) {
deleteRepository(id: $id)
}Also available as: CLI command vulnara delete_repository
deleteScanResultMutation
Arguments
| Name | Type | Description |
|---|---|---|
| id | ID! |
Returns Boolean!
mutation DeleteScanResult($id: ID!) {
deleteScanResult(id: $id)
}Also available as: CLI command vulnara delete_scan_result
deleteScanScheduleMutation
Arguments
| Name | Type | Description |
|---|---|---|
| id | ID! |
Returns Boolean!
mutation DeleteScanSchedule($id: ID!) {
deleteScanSchedule(id: $id)
}deleteServiceAccountMutation
Arguments
| Name | Type | Description |
|---|---|---|
| id | ID! |
Returns Boolean!
mutation DeleteServiceAccount($id: ID!) {
deleteServiceAccount(id: $id)
}Also available as: CLI command vulnara delete_service_account
deleteTenantMemberMutation
Arguments
| Name | Type | Description |
|---|---|---|
| id | ID! |
Returns Boolean!
mutation DeleteTenantMember($id: ID!) {
deleteTenantMember(id: $id)
}dismissTaskMutation
Arguments
| Name | Type | Description |
|---|---|---|
| id | ID! |
Returns Boolean!
mutation DismissTask($id: ID!) {
dismissTask(id: $id)
}dissociateGitTokenWithGitEntityMutation
Arguments
| Name | Type | Description |
|---|---|---|
| input | GitTokenAssociationInput! |
Returns Boolean!
mutation DissociateGitTokenWithGitEntity($input: GitTokenAssociationInput!) {
dissociateGitTokenWithGitEntity(input: $input)
}Also available as: CLI command vulnara dissociate_git_token_with_git_entity
dockerScanToolQuery
Arguments
| Name | Type | Description |
|---|---|---|
| id | ID! |
Returns DockerScanTool!
query DockerScanTool($id: ID!) {
dockerScanTool(id: $id) {
id
name
}
}Also available as: MCP tool docker_scan_tool
dockerScanToolsQuery
Arguments
| Name | Type | Description |
|---|---|---|
| list | List |
Returns DockerScanToolListResult!
query DockerScanTools($list: List) {
dockerScanTools(list: $list) {
total
items {
id
name
}
}
}Also available as: MCP tool docker_scan_tools
downgradeToFreeMutation
Returns Boolean!
mutation DowngradeToFree {
downgradeToFree
}fetchRepositoriesMutation
Arguments
| Name | Type | Description |
|---|---|---|
| input | FetchRepositoriesInput! |
Returns Boolean!
mutation FetchRepositories($input: FetchRepositoriesInput!) {
fetchRepositories(input: $input)
}Also available as: CLI command vulnara fetch_repositories
findingCorroborationQuery
Cross-tool agreement for every secret found in a repository.
Arguments
| Name | Type | Description |
|---|---|---|
| repositoryId | ID! |
Returns FindingCorroborationListResult!
query FindingCorroboration($repositoryId: ID!) {
findingCorroboration(repositoryId: $repositoryId) {
total
items {
id
matchHash
toolCount
severity
}
}
}Also available as: MCP tool finding_corroboration
findingTriageQuery
Arguments
| Name | Type | Description |
|---|---|---|
| repositoryId | ID! |
Returns [FindingTriage!]!
query FindingTriage($repositoryId: ID!) {
findingTriage(repositoryId: $repositoryId) {
id
repositoryId
matchKey
findingType
state
justification
response
priority
}
}Also available as: MCP tool finding_triage
findingTriageHistoryQuery
Every decision ever taken on this repository's findings, newest first.
Arguments
| Name | Type | Description |
|---|---|---|
| repositoryId | ID! | |
| matchKey | String |
Returns [FindingTriageEvent!]!
query FindingTriageHistory($repositoryId: ID!, $matchKey: String) {
findingTriageHistory(repositoryId: $repositoryId, matchKey: $matchKey) {
id
repositoryId
matchKey
action
state
justification
response
priority
}
}Also available as: MCP tool finding_triage_history
gitEntitiesQuery
Arguments
| Name | Type | Description |
|---|---|---|
| list | List |
Returns GitEntityListResult!
query GitEntities($list: List) {
gitEntities(list: $list) {
total
}
}Also available as: CLI command vulnara git_entities · MCP tool git_entities
gitEntityQuery
Arguments
| Name | Type | Description |
|---|---|---|
| id | ID! |
Returns GitEntity!
query GitEntity($id: ID!) {
gitEntity(id: $id) {
__typename
... on Organization {
id
name
gitType
externalId
webUrl
htmlUrl
avatarUrl
color
}
... on GitUser {
id
name
gitType
externalId
webUrl
htmlUrl
avatarUrl
color
}
}
}Also available as: CLI command vulnara get_git_entity · MCP tool git_entity
gitEntityProvidersQuery
Providers on which a bare handle resolves to an org/user/group. Lets the add-workspace form infer the provider automatically and only ask the user to choose when the same handle exists on more than one provider.
Arguments
| Name | Type | Description |
|---|---|---|
| name | String! |
Returns [GitType!]!
query GitEntityProviders($name: String!) {
gitEntityProviders(name: $name)
}gitEntityRepositoryCountQuery
Arguments
| Name | Type | Description |
|---|---|---|
| name | String! | |
| gitType | GitType! |
Returns Int
query GitEntityRepositoryCount($name: String!, $gitType: GitType!) {
gitEntityRepositoryCount(name: $name, gitType: $gitType)
}gitTokenQuery
Arguments
| Name | Type | Description |
|---|---|---|
| id | ID! |
Returns GitToken!
query GitToken($id: ID!) {
gitToken(id: $id) {
id
name
value
expiresAt
flags
status
scopes
createdAt
}
}Also available as: CLI command vulnara get_git_token
gitTokenExpirationQuery
The token's own expiry as reported by the provider (GitHub's token-expiration header / GitLab's PAT self endpoint), or null if the provider doesn't expose one or the token couldn't be checked. Lets the UI hide the manual "expires at" field when the token reports it itself.
Arguments
| Name | Type | Description |
|---|---|---|
| value | String! | |
| gitType | GitType! |
Returns DateTime
query GitTokenExpiration($value: String!, $gitType: GitType!) {
gitTokenExpiration(value: $value, gitType: $gitType)
}gitTokensQuery
Arguments
| Name | Type | Description |
|---|---|---|
| list | List |
Returns GitTokenListResult!
query GitTokens($list: List) {
gitTokens(list: $list) {
total
items {
id
name
value
expiresAt
flags
status
scopes
createdAt
}
}
}Also available as: CLI command vulnara git_tokens
gitUserQuery
Arguments
| Name | Type | Description |
|---|---|---|
| id | ID! |
Returns GitEntity!
query GitUser($id: ID!) {
gitUser(id: $id) {
__typename
... on Organization {
id
name
gitType
externalId
webUrl
htmlUrl
avatarUrl
color
}
... on GitUser {
id
name
gitType
externalId
webUrl
htmlUrl
avatarUrl
color
}
}
}Also available as: MCP tool git_user
gitUsersQuery
Arguments
| Name | Type | Description |
|---|---|---|
| list | List |
Returns GitEntityListResult!
query GitUsers($list: List) {
gitUsers(list: $list) {
total
}
}Also available as: MCP tool git_users
invitationQuery
Arguments
| Name | Type | Description |
|---|---|---|
| id | ID! |
Returns Invitation
query Invitation($id: ID!) {
invitation(id: $id) {
id
email
tenantName
}
}invitationsQuery
Returns [Invitation!]!
query Invitations {
invitations {
id
email
tenantName
}
}inviteTenantMemberMutation
Arguments
| Name | Type | Description |
|---|---|---|
| input | InviteTeamMemberInput! |
Returns Boolean!
mutation InviteTenantMember($input: InviteTeamMemberInput!) {
inviteTenantMember(input: $input)
}invoiceQuery
Arguments
| Name | Type | Description |
|---|---|---|
| id | ID! |
Returns Invoice!
query Invoice($id: ID!) {
invoice(id: $id) {
id
invoiceNumber
date
dueDate
status
total
currency
}
}invoicesQuery
Arguments
| Name | Type | Description |
|---|---|---|
| list | List |
Returns InvoiceListResult!
query Invoices($list: List) {
invoices(list: $list) {
total
items {
id
invoiceNumber
date
dueDate
status
total
currency
}
}
}markAllNotificationsReadMutation
Returns Boolean!
mutation MarkAllNotificationsRead {
markAllNotificationsRead
}markNotificationDeliveredMutation
Arguments
| Name | Type | Description |
|---|---|---|
| id | ID! |
Returns Boolean!
mutation MarkNotificationDelivered($id: ID!) {
markNotificationDelivered(id: $id)
}markNotificationsReadMutation
Arguments
| Name | Type | Description |
|---|---|---|
| ids | [ID!]! |
Returns Boolean!
mutation MarkNotificationsRead($ids: [ID!]!) {
markNotificationsRead(ids: $ids)
}myUserQuery
Returns MyUser
query MyUser {
myUser {
id
email
name
username
tenants {
id
isPaying
}
preferences {
theme
dateTimeFormat
repositoriesView
}
}
}Also available as: MCP tool my_user
networkQuery
Arguments
| Name | Type | Description |
|---|---|---|
| id | ID! |
Returns Network!
query Network($id: ID!) {
network(id: $id) {
id
name
network
networkType
tenant
securityScore
createdAt
updatedAt
}
}Also available as: CLI command vulnara get_network · MCP tool network
networksQuery
Arguments
| Name | Type | Description |
|---|---|---|
| list | List |
Returns NetworkListResult!
query Networks($list: List) {
networks(list: $list) {
total
items {
id
name
network
networkType
tenant
securityScore
createdAt
updatedAt
}
}
}Also available as: CLI command vulnara networks · MCP tool networks
networkScanFindingQuery
Arguments
| Name | Type | Description |
|---|---|---|
| id | ID! |
Returns NetworkScanFinding!
query NetworkScanFinding($id: ID!) {
networkScanFinding(id: $id) {
id
scanResultId
host
hostname
hostnameType
protocol
port
serviceName
}
}Also available as: MCP tool network_scan_finding
networkScanFindingsQuery
Arguments
| Name | Type | Description |
|---|---|---|
| list | List |
Returns NetworkScanFindingListResult!
query NetworkScanFindings($list: List) {
networkScanFindings(list: $list) {
total
items {
id
scanResultId
host
hostname
hostnameType
protocol
port
serviceName
}
}
}Also available as: CLI command vulnara network_scan_findings · MCP tool network_scan_findings
networkScanResultQuery
Arguments
| Name | Type | Description |
|---|---|---|
| id | ID! |
Returns NetworkScanResult!
query NetworkScanResult($id: ID!) {
networkScanResult(id: $id) {
id
networkId
status
createdAt
updatedAt
scanTime
network {
id
name
network
networkType
tenant
securityScore
createdAt
updatedAt
}
}
}Also available as: CLI command vulnara get_network_scan_result · MCP tool network_scan_result
networkScanResultsQuery
Arguments
| Name | Type | Description |
|---|---|---|
| list | List |
Returns NetworkScanResultListResult!
query NetworkScanResults($list: List) {
networkScanResults(list: $list) {
total
items {
id
networkId
status
createdAt
updatedAt
scanTime
}
}
}Also available as: CLI command vulnara network_scan_results · MCP tool network_scan_results
notificationsQuery
Arguments
| Name | Type | Description |
|---|---|---|
| list | List |
Returns NotificationList!
query Notifications($list: List) {
notifications(list: $list) {
items {
id
type
eventType
data
read
createdAt
}
total
}
}Also available as: MCP tool notifications
notificationsSubscription
Returns Notification!
subscription Notifications {
notifications {
id
type
eventType
data
read
createdAt
}
}notificationScopeQuery
Arguments
| Name | Type | Description |
|---|---|---|
| id | ID! |
Returns NotificationScope!
query NotificationScope($id: ID!) {
notificationScope(id: $id) {
id
channelIds
channelType
scopes
isActive
status
headers {
name
value
}
template
}
}Also available as: CLI command vulnara get_notification_scope · MCP tool notification_scope
notificationScopesQuery
Arguments
| Name | Type | Description |
|---|---|---|
| list | List |
Returns NotificationScopeListResult!
query NotificationScopes($list: List) {
notificationScopes(list: $list) {
total
items {
id
channelIds
channelType
scopes
isActive
status
template
}
}
}Also available as: CLI command vulnara notification_scopes · MCP tool notification_scopes
organizationQuery
Arguments
| Name | Type | Description |
|---|---|---|
| id | ID! |
Returns GitEntity!
query Organization($id: ID!) {
organization(id: $id) {
__typename
... on Organization {
id
name
gitType
externalId
webUrl
htmlUrl
avatarUrl
color
}
... on GitUser {
id
name
gitType
externalId
webUrl
htmlUrl
avatarUrl
color
}
}
}Also available as: MCP tool organization
organizationsQuery
Arguments
| Name | Type | Description |
|---|---|---|
| list | List |
Returns GitEntityListResult!
query Organizations($list: List) {
organizations(list: $list) {
total
}
}Also available as: MCP tool organizations
paymentMethodQuery
Arguments
| Name | Type | Description |
|---|---|---|
| id | ID! |
Returns PaymentMethod!
query PaymentMethod($id: ID!) {
paymentMethod(id: $id) {
id
default
lastFour
brand
expiryMonth
expiryYear
cardholderName
expired
}
}paymentMethodsQuery
Arguments
| Name | Type | Description |
|---|---|---|
| list | List |
Returns PaymentMethodListResult!
query PaymentMethods($list: List) {
paymentMethods(list: $list) {
total
items {
id
default
lastFour
brand
expiryMonth
expiryYear
cardholderName
expired
}
}
}plansQuery
Returns [Plan!]!
query Plans {
plans {
id
availableGitScanMinutes
availableNetworkScanMinutes
maxRepositories
maxNetworks
maxEmails
pricePerGitScanMinute
pricePerNetworkScanMinute
}
}programmingLanguagesQuery
Returns [String!]
query ProgrammingLanguages {
programmingLanguages
}Also available as: CLI command vulnara programming_languages · MCP tool programming_languages
promoGrantsQuery
Every grant this tenant holds, including ones that have run out.
Returns [PromoGrant!]!
query PromoGrants {
promoGrants {
id
code
startsAt
endsAt
gitScanMinutes
networkScanMinutes
maxRepositories
maxNetworks
}
}Also available as: MCP tool promo_grants
redeemPromoCodeMutation
Redeem a code for this tenant. ADMIN because redeeming changes what the tenant may spend, which is the same authority as changing the plan. A refusal arrives as PROMO_CODE_UNKNOWN, PROMO_CODE_INACTIVE, PROMO_CODE_EXPIRED, PROMO_CODE_FULLY_CLAIMED or PROMO_CODE_ALREADY_REDEEMED. They are distinct because each tells the person typing the code something different about what to do next.
Arguments
| Name | Type | Description |
|---|---|---|
| code | String! |
Returns PromoGrant!
mutation RedeemPromoCode($code: String!) {
redeemPromoCode(code: $code) {
id
code
startsAt
endsAt
gitScanMinutes
networkScanMinutes
maxRepositories
maxNetworks
}
}registerPushSubscriptionMutation
Arguments
| Name | Type | Description |
|---|---|---|
| input | PushSubscriptionInput! |
Returns Boolean!
mutation RegisterPushSubscription($input: PushSubscriptionInput!) {
registerPushSubscription(input: $input)
}remediationTemplateQuery
Returns RemediationTemplate!
query RemediationTemplate {
remediationTemplate {
codeIssueBody
dependencyIssueBody
pullRequestBody
}
}Also available as: MCP tool remediation_template
repositoriesQuery
Arguments
| Name | Type | Description |
|---|---|---|
| list | List |
Returns RepositoryListResult!
query Repositories($list: List) {
repositories(list: $list) {
total
items {
id
gitEntityId
repositoryName
private
securityScore
programmingLanguage
repositorySize
numberOfBranches
}
}
}Also available as: CLI command vulnara repositories · MCP tool repositories
repositoryQuery
Arguments
| Name | Type | Description |
|---|---|---|
| id | ID! |
Returns Repository!
query Repository($id: ID!) {
repository(id: $id) {
id
gitEntityId
repositoryName
private
securityScore
programmingLanguage
repositorySize
numberOfBranches
}
}Also available as: CLI command vulnara get_repository · MCP tool repository
repositoryBranchesQuery
Branch names for a repository, read from its git provider, so the scan form can offer real branches instead of free-text input.
Arguments
| Name | Type | Description |
|---|---|---|
| repositoryId | ID! |
Returns [String!]!
query RepositoryBranches($repositoryId: ID!) {
repositoryBranches(repositoryId: $repositoryId)
}Also available as: MCP tool repository_branches
repositoryDependencyScanFindingGroupsQuery
Arguments
| Name | Type | Description |
|---|---|---|
| list | List |
Returns RepositoryDependencyScanFindingGroupListResult!
query RepositoryDependencyScanFindingGroups($list: List) {
repositoryDependencyScanFindingGroups(list: $list) {
total
items {
id
dependency
repositoryId
severity
installedVersion
occurrences
issueUrl
issueStatus
}
}
}Also available as: MCP tool repository_dependency_scan_finding_groups
repositoryDependencyScanFindingsQuery
Arguments
| Name | Type | Description |
|---|---|---|
| list | List |
Returns RepositoryDependencyScanFindingListResult!
query RepositoryDependencyScanFindings($list: List) {
repositoryDependencyScanFindings(list: $list) {
total
items {
id
commitScanId
createdAt
updatedAt
severity
vulnerability
dependency
installedVersion
}
}
}Also available as: CLI command vulnara repository_dependency_scan_findings · MCP tool repository_dependency_scan_findings
requestNSFConsultationMutation
Arguments
| Name | Type | Description |
|---|---|---|
| input | NSFConsultation! |
Returns Boolean!
mutation RequestNSFConsultation($input: NSFConsultation!) {
requestNSFConsultation(input: $input)
}Also available as: CLI command vulnara request_nsf_consultation
requestRSFConsultationMutation
Arguments
| Name | Type | Description |
|---|---|---|
| input | RSFConsultation! |
Returns Boolean!
mutation RequestRSFConsultation($input: RSFConsultation!) {
requestRSFConsultation(input: $input)
}Also available as: CLI command vulnara request_rsf_consultation
retryPaymentMutation
Arguments
| Name | Type | Description |
|---|---|---|
| invoiceId | ID! | |
| paymentMethodId | ID! |
Returns Invoice!
mutation RetryPayment($invoiceId: ID!, $paymentMethodId: ID!) {
retryPayment(invoiceId: $invoiceId, paymentMethodId: $paymentMethodId) {
id
invoiceNumber
date
dueDate
status
total
currency
}
}revealScanFindingMatchMutation
The audited path to the raw secret behind a masked ScanFinding/ScanFindingGroup/ ScanFindingMatchGroup.match. Every call is logged with the caller, repository and match hash.
Arguments
| Name | Type | Description |
|---|---|---|
| repositoryId | ID! | |
| matchHash | String! |
Returns String!
mutation RevealScanFindingMatch($repositoryId: ID!, $matchHash: String!) {
revealScanFindingMatch(repositoryId: $repositoryId, matchHash: $matchHash)
}scanFindingGroupsQuery
Arguments
| Name | Type | Description |
|---|---|---|
| list | List |
Returns ScanFindingGroupListResult!
query ScanFindingGroups($list: List) {
scanFindingGroups(list: $list) {
total
items {
id
fingerprint
matchHash
matchedByToolCount
file
severity
confidence
match
}
}
}Also available as: MCP tool scan_finding_groups
scanFindingMatchGroupsQuery
Findings grouped by cross-tool identity, one row per real secret.
Arguments
| Name | Type | Description |
|---|---|---|
| list | List |
Returns ScanFindingMatchGroupListResult!
query ScanFindingMatchGroups($list: List) {
scanFindingMatchGroups(list: $list) {
total
items {
id
matchHash
file
line
severity
confidence
match
occurrences
}
}
}Also available as: MCP tool scan_finding_match_groups
scanFindingsQuery
Arguments
| Name | Type | Description |
|---|---|---|
| list | List |
Returns ScanFindingListResult!
query ScanFindings($list: List) {
scanFindings(list: $list) {
total
items {
id
commitScanId
createdAt
updatedAt
line
file
severity
confidence
}
}
}Also available as: CLI command vulnara scan_findings · MCP tool scan_findings
scanResultQuery
Arguments
| Name | Type | Description |
|---|---|---|
| id | ID! |
Returns ScanResult!
query ScanResult($id: ID!) {
scanResult(id: $id) {
id
repositoryId
scanType
scanner
dockerScanToolId
status
createdAt
updatedAt
}
}Also available as: CLI command vulnara get_scan_result · MCP tool scan_result
scanResultsQuery
Arguments
| Name | Type | Description |
|---|---|---|
| list | List |
Returns ScanResultListResult!
query ScanResults($list: List) {
scanResults(list: $list) {
total
items {
id
repositoryId
scanType
scanner
dockerScanToolId
status
createdAt
updatedAt
}
}
}Also available as: CLI command vulnara scan_results · MCP tool scan_results
scanScheduleQuery
Arguments
| Name | Type | Description |
|---|---|---|
| id | ID! |
Returns ScanSchedule!
query ScanSchedule($id: ID!) {
scanSchedule(id: $id) {
id
action
repositoryId
gitEntityId
branch
dockerScanToolId
frequency
hourUtc
}
}Also available as: MCP tool scan_schedule
scanSchedulesQuery
Arguments
| Name | Type | Description |
|---|---|---|
| list | List |
Returns ScanScheduleListResult!
query ScanSchedules($list: List) {
scanSchedules(list: $list) {
total
items {
id
action
repositoryId
gitEntityId
branch
dockerScanToolId
frequency
hourUtc
}
}
}Also available as: MCP tool scan_schedules
serviceAccountsQuery
Returns [ServiceAccount!]!
query ServiceAccounts {
serviceAccounts {
id
name
isActive
expiresAt
createdBy {
id
email
username
name
}
}
}Also available as: CLI command vulnara service_accounts
setDefaultPaymentMethodMutation
Arguments
| Name | Type | Description |
|---|---|---|
| id | ID! |
Returns Boolean!
mutation SetDefaultPaymentMethod($id: ID!) {
setDefaultPaymentMethod(id: $id)
}setFindingTriageMutation
Arguments
| Name | Type | Description |
|---|---|---|
| input | SetFindingTriageInput! |
Returns FindingTriage!
mutation SetFindingTriage($input: SetFindingTriageInput!) {
setFindingTriage(input: $input) {
id
repositoryId
matchKey
findingType
state
justification
response
priority
}
}setGitEntityIgnorePathsMutation
Arguments
| Name | Type | Description |
|---|---|---|
| input | SetGitEntityIgnorePathsInput! |
Returns GitEntity!
mutation SetGitEntityIgnorePaths($input: SetGitEntityIgnorePathsInput!) {
setGitEntityIgnorePaths(input: $input) {
__typename
... on Organization {
id
name
gitType
externalId
webUrl
htmlUrl
avatarUrl
color
}
... on GitUser {
id
name
gitType
externalId
webUrl
htmlUrl
avatarUrl
color
}
}
}setRemediationTemplateMutation
Arguments
| Name | Type | Description |
|---|---|---|
| input | RemediationTemplateInput! |
Returns RemediationTemplate!
mutation SetRemediationTemplate($input: RemediationTemplateInput!) {
setRemediationTemplate(input: $input) {
codeIssueBody
dependencyIssueBody
pullRequestBody
}
}setRepositoryEnabledMutation
Arguments
| Name | Type | Description |
|---|---|---|
| input | SetRepositoryEnabledInput! |
Returns Boolean!
mutation SetRepositoryEnabled($input: SetRepositoryEnabledInput!) {
setRepositoryEnabled(input: $input)
}setRepositoryIgnorePathsMutation
Arguments
| Name | Type | Description |
|---|---|---|
| input | SetRepositoryIgnorePathsInput! |
Returns Repository!
mutation SetRepositoryIgnorePaths($input: SetRepositoryIgnorePathsInput!) {
setRepositoryIgnorePaths(input: $input) {
id
gitEntityId
repositoryName
private
securityScore
programmingLanguage
repositorySize
numberOfBranches
}
}setServiceAccountActiveMutation
Arguments
| Name | Type | Description |
|---|---|---|
| input | SetServiceAccountActiveInput! |
Returns ServiceAccount!
mutation SetServiceAccountActive($input: SetServiceAccountActiveInput!) {
setServiceAccountActive(input: $input) {
id
name
isActive
expiresAt
createdBy {
id
email
username
name
}
}
}Also available as: CLI command vulnara set_service_account_active
startNetworkScanMutation
Arguments
| Name | Type | Description |
|---|---|---|
| input | StartNetworkScanInput! |
Returns Boolean!
mutation StartNetworkScan($input: StartNetworkScanInput!) {
startNetworkScan(input: $input)
}Also available as: CLI command vulnara start_network_scan
startRepositoryScanMutation
Arguments
| Name | Type | Description |
|---|---|---|
| input | StartRepositoryScanInput! |
Returns RepositoryScanTask!
mutation StartRepositoryScan($input: StartRepositoryScanInput!) {
startRepositoryScan(input: $input) {
id
objectId
status
state {
totalCommits
scheduled
scanned
failed
parsed
}
createdAt
scanResult {
id
repositoryId
scanType
scanner
dockerScanToolId
status
createdAt
updatedAt
}
}
}Also available as: CLI command vulnara start_repository_scan
statisticsQuery
Returns TenantStatistics!
query Statistics {
statistics {
tenant
totalUsers
totalGitEntities
totalRepositories
totalNetworks
}
}Also available as: MCP tool statistics
taskQuery
Arguments
| Name | Type | Description |
|---|---|---|
| id | ID! |
Returns Task!
query Task($id: ID!) {
task(id: $id) {
__typename
... on RepositoryScanTask {
id
objectId
status
createdAt
}
... on NetworkScanTask {
id
objectId
status
createdAt
}
}
}Also available as: MCP tool task
taskEventsSubscription
Returns TaskEvent!
subscription TaskEvents {
taskEvents {
type
taskId
}
}tasksQuery
Returns [Task!]!
query Tasks {
tasks {
__typename
... on RepositoryScanTask {
id
objectId
status
createdAt
}
... on NetworkScanTask {
id
objectId
status
createdAt
}
}
}Also available as: CLI command vulnara tasks · MCP tool tasks
testNotificationScopeMutation
Send a test notification to the rule's channel and record its reachability as the channel status.
Arguments
| Name | Type | Description |
|---|---|---|
| id | ID! |
Returns NotificationScope!
mutation TestNotificationScope($id: ID!) {
testNotificationScope(id: $id) {
id
channelIds
channelType
scopes
isActive
status
headers {
name
value
}
template
}
}transferGitEntityMutation
Arguments
| Name | Type | Description |
|---|---|---|
| input | TransferGitEntityInput! |
Returns Boolean!
mutation TransferGitEntity($input: TransferGitEntityInput!) {
transferGitEntity(input: $input)
}Also available as: CLI command vulnara transfer_git_entity
transferNetworkMutation
Arguments
| Name | Type | Description |
|---|---|---|
| input | TransferNetworkInput! |
Returns Boolean!
mutation TransferNetwork($input: TransferNetworkInput!) {
transferNetwork(input: $input)
}Also available as: CLI command vulnara transfer_network
unreadNotificationCountQuery
Returns Int!
query UnreadNotificationCount {
unreadNotificationCount
}Also available as: MCP tool unread_notification_count
unregisterPushSubscriptionMutation
Arguments
| Name | Type | Description |
|---|---|---|
| endpoint | String! |
Returns Boolean!
mutation UnregisterPushSubscription($endpoint: String!) {
unregisterPushSubscription(endpoint: $endpoint)
}updateGitEntityMutation
Arguments
| Name | Type | Description |
|---|---|---|
| input | UpdateGitEntityInput! |
Returns GitEntity!
mutation UpdateGitEntity($input: UpdateGitEntityInput!) {
updateGitEntity(input: $input) {
__typename
... on Organization {
id
name
gitType
externalId
webUrl
htmlUrl
avatarUrl
color
}
... on GitUser {
id
name
gitType
externalId
webUrl
htmlUrl
avatarUrl
color
}
}
}updateGitTokenMutation
Arguments
| Name | Type | Description |
|---|---|---|
| input | UpdateGitTokenInput! |
Returns GitToken!
mutation UpdateGitToken($input: UpdateGitTokenInput!) {
updateGitToken(input: $input) {
id
name
value
expiresAt
flags
status
scopes
createdAt
}
}Also available as: CLI command vulnara update_git_token
updateMyUserPreferencesMutation
Arguments
| Name | Type | Description |
|---|---|---|
| input | UpdateUserPreferencesInput! |
Returns UserPreferences!
mutation UpdateMyUserPreferences($input: UpdateUserPreferencesInput!) {
updateMyUserPreferences(input: $input) {
theme
dateTimeFormat
repositoriesView
}
}updateNotificationScopeMutation
Arguments
| Name | Type | Description |
|---|---|---|
| input | UpdateNotificationScopeInput! |
Returns NotificationScope!
mutation UpdateNotificationScope($input: UpdateNotificationScopeInput!) {
updateNotificationScope(input: $input) {
id
channelIds
channelType
scopes
isActive
status
headers {
name
value
}
template
}
}Also available as: CLI command vulnara update_notification_scope
updateScanScheduleMutation
Arguments
| Name | Type | Description |
|---|---|---|
| input | UpdateScanScheduleInput! |
Returns ScanSchedule!
mutation UpdateScanSchedule($input: UpdateScanScheduleInput!) {
updateScanSchedule(input: $input) {
id
action
repositoryId
gitEntityId
branch
dockerScanToolId
frequency
hourUtc
}
}updateUserRolesMutation
Arguments
| Name | Type | Description |
|---|---|---|
| input | UpdateUserRolesInput! |
Returns TenantUser!
mutation UpdateUserRoles($input: UpdateUserRolesInput!) {
updateUserRoles(input: $input) {
id
roles
user {
id
email
username
name
}
}
}upgradeToPayingMutation
Returns Boolean!
mutation UpgradeToPaying {
upgradeToPaying
}usageQuery
Arguments
| Name | Type | Description |
|---|---|---|
| startDate | DateTime! | |
| endDate | DateTime! |
Returns Usage!
query Usage($startDate: DateTime!, $endDate: DateTime!) {
usage(startDate: $startDate, endDate: $endDate) {
accountTier
usedGitScanTimeMinutes
repositoryScanLimited
usedNetworkScanTimeMinutes
networkScanLimited
parallelScans
availableGitScanMinutes
availableNetworkScanMinutes
}
}workspaceOverviewQuery
Arguments
| Name | Type | Description |
|---|---|---|
| gitEntityId | ID! |
Returns WorkspaceOverview!
query WorkspaceOverview($gitEntityId: ID!) {
workspaceOverview(gitEntityId: $gitEntityId) {
severityCounts {
severity
count
}
totalFindings
totalRepositories
scanned
unscanned
}
}Also available as: MCP tool workspace_overview
Types
AgingBucket object
| Name | Type | Description |
|---|---|---|
| bucket | String! | Age range in days, such as 8-30 or 91+. |
| count | Int! |
ChannelStatus enum
| Name | Description |
|---|---|
| operational | |
| degraded | |
| unknown | |
| error |
ChannelType enum
| Name | Description |
|---|---|
| slack | |
| webhook | |
| telegram | |
| discord |
CommitScan object
| Name | Type | Description |
|---|---|---|
| id | ID! | |
| scanResultId | ID! | |
| commitHash | String! | |
| createdAt | DateTime | |
| updatedAt | DateTime | |
| scanResult | ScanResult! |
CommitScanListResult object
| Name | Type | Description |
|---|---|---|
| total | Int! | |
| items | [CommitScan!]! |
CorroboratedFinding object
One finding that more than one scanner reported. Carries no matched value on purpose: a corroborated finding is very often a leaked secret, and the dashboard is the most widely viewed screen in the product. The repository and file identify it, and the view behind the link masks what it shows.
| Name | Type | Description |
|---|---|---|
| kind | String! | Either code or dependency. |
| repositoryId | ID! | |
| repositoryName | String! | |
| label | String | The file for a code finding, the library for a dependency finding. |
| severity | String! | |
| scanners | [String!]! | The scanners that agreed, by name. |
| toolCount | Int! | |
| findingKey | String! | The identity the vulnerabilities explorer addresses this finding by, usable directly as its matchHash filter. |
CreateGitEntityInput input
| Name | Type | Description |
|---|---|---|
| name | String! | |
| gitType | GitType! | |
| externalId | Float | |
| webUrl | String | |
| ignorePaths | [String!] | Gitignore-style glob patterns applied to every repo under this entity. |
| ownershipConsent | Boolean! | Attests that the caller's tenant owns this organisation/user, or is authorized to scan it. No default: the client must decide explicitly. Rejected unless true; the actor and statement version are added server-side, not taken from client input. |
CreateGitTokenInput input
| Name | Type | Description |
|---|---|---|
| name | String! | |
| value | String! | |
| flags | [GitTokenFlag!]! | |
| gitTokenType | GitType! | |
| expiresAt | DateTime |
CreateNetworkInput input
| Name | Type | Description |
|---|---|---|
| name | String! | |
| network | String! | |
| networkType | NetworkType! | |
| ownershipConsent | Boolean! |
CreateNotificationScopeInput input
| Name | Type | Description |
|---|---|---|
| channelIds | [String!]! | |
| channelType | ChannelType! | |
| scopes | [String!]! | |
| isActive | Boolean! | |
| headers | [HttpHeaderInput!] | |
| templates | [NotificationTemplateInput!] |
CreateRepositoryInput input
| Name | Type | Description |
|---|---|---|
| gitEntityId | ID! | |
| repositoryName | String! | |
| cloneUrl | String | |
| ignorePaths | [String!] | Gitignore-style glob patterns to exclude from scans. |
CreateScanScheduleInput input
| Name | Type | Description |
|---|---|---|
| action | ScanScheduleAction | Defaults to SCAN. SYNC requires gitEntityId. |
| repositoryId | ID | Supply exactly one of repositoryId or gitEntityId. |
| gitEntityId | ID | |
| branch | String | |
| dockerScanToolId | ID | |
| frequency | ScanScheduleFrequency! | |
| hourUtc | Int! | |
| minuteUtc | Int | Defaults to 0 upstream, which is the minute every schedule fired at before this field existed. |
| dayOfWeek | Int | |
| isActive | Boolean | |
| recipients | [String!] | Required for a REPORT, refused for anything else. The address shape is checked here because this is the trust boundary; vulnara-api forwards it and vulnara-notification-api refuses a malformed one at the far end. |
CreateServiceAccountInput input
| Name | Type | Description |
|---|---|---|
| name | String! | |
| expiresAt | DateTime! |
CreateServiceAccountPayload object
| Name | Type | Description |
|---|---|---|
| serviceAccount | ServiceAccount! | |
| token | String! |
CreateTenantInput input
| Name | Type | Description |
|---|---|---|
| name | String! |
Currency enum
| Name | Description |
|---|---|
| USD | |
| EUR | |
| BGN |
DashboardAnalytics object
| Name | Type | Description |
|---|---|---|
| days | Int! | The window the deltas and activity are measured over. |
| generatedAt | DateTime! | |
| lastScanAt | DateTime | |
| averageSecurityScore | Float! | |
| previousAverageSecurityScore | Float! | The same score as it stood at the start of the period. |
| severityCounts | [SeverityCount!]! | |
| previousSeverityCounts | [SeverityCount!]! | |
| exposure | Exposure! | |
| scanActivity | [ScanActivityPoint!]! | |
| scoreTrend | [ScoreTrendPoint!]! | |
| topRiskRepositories | [RepositoryRisk!]! | |
| remediation | RemediationFunnel! | |
| dependencyFixes | DependencyFixes! | |
| aging | [AgingBucket!]! | |
| oldestFindingDays | Int | |
| oldestCriticalDays | Int | |
| coverage | ScanCoverage! | |
| scanHealth | ScanHealth! | |
| staleWorkspaces | [StaleWorkspace!]! |
DependencyFixes object
| Name | Type | Description |
|---|---|---|
| total | Int! | |
| fixable | Int! | Dependency findings whose advisory names a fixed version. |
DockerScanTool object
A scanner, named. The image, tag and arguments are deliberately not exposed: they identify our scanners and their private registry paths, and every screen in the product only ever needs to label a scan with the tool that produced it. Managed in vulnara-backoffice, not through this API.
| Name | Type | Description |
|---|---|---|
| id | ID! | |
| name | String! |
DockerScanToolListResult object
| Name | Type | Description |
|---|---|---|
| total | Int! | |
| items | [DockerScanTool!]! |
Exposure object
Findings currently exposed, and how that moved over the period. Deduplicated by match hash within a repository and read from the latest scan per tool, so this is what is open now - not every row ever written.
| Name | Type | Description |
|---|---|---|
| total | Int! | |
| previousTotal | Int! | |
| newFindings | Int! | |
| resolvedFindings | Int! | |
| codeFindings | Int! | |
| dependencyFindings | Int! | |
| corroboratedFindings | Int! | Findings more than one scanner reported - the least likely to be noise. |
| corroborated | [CorroboratedFinding!]! | The findings behind corroboratedFindings, worst first. They come from the same query as the count, so the two cannot disagree - which is why this is here rather than the client deep-linking into the explorer, whose finding list is a different population (every scan, code only, triaged included). Capped, while the count stays exact: a tenant over the cap reads as "some of many" rather than seeing a list that looks complete. |
| falsePositives | Int! | Held back by a decision rather than by a fix. Reported beside the open total, never folded into it - a number that shrinks when somebody dismisses something is what this endpoint exists to avoid. |
| notAffected | Int! | |
| hiddenButScored | Int! | Real findings a decision keeps out of the working list - deferred, or will-not-fix. They still count against the score, so they are named here rather than being quietly absent from both numbers. |
| resolvedFindingsTriaged | Int! | Everything a decision took out of the score entirely. |
FetchGitEntityTask object
| Name | Type | Description |
|---|---|---|
| id | ID! | |
| objectId | ID! | |
| status | TaskStatus! | |
| state | FetchGitEntityTaskState! | |
| createdAt | Int! | |
| gitEntity | GitEntity! |
FetchGitEntityTaskState object
| Name | Type | Description |
|---|---|---|
| processed | Int! | |
| total | Int! |
FetchRepositoriesInput input
| Name | Type | Description |
|---|---|---|
| gitEntityId | ID! | |
| gitTokenId | ID |
Filter input
| Name | Type | Description |
|---|---|---|
| field | String! | |
| min | Float | |
| max | Float | |
| stringEquals | String | |
| idEquals | ID |
FindingCorroboration object
One real-world issue and how many independent scanners found it. toolCount > 1 is the "confirmed by N tools" signal.
| Name | Type | Description |
|---|---|---|
| id | ID! | |
| matchHash | String! | |
| toolCount | Int! | |
| severity | Severity | Reconciled across the tools that reported it (highest severity wins). |
FindingCorroborationListResult object
| Name | Type | Description |
|---|---|---|
| total | Int! | |
| items | [FindingCorroboration!]! |
FindingTriage object
A decision taken about a finding. Keyed on the finding's identity rather than its row, so it survives rescans and applies to every scanner that reported the same thing. The three axes are separate on purpose. state decides whether the finding still counts against the security score - only states asserting no live risk take it out. response and a defer priority clear it from the working list while leaving the score alone, because deciding not to act on something does not make it safe.
| Name | Type | Description |
|---|---|---|
| id | ID! | |
| repositoryId | ID! | |
| matchKey | String! | |
| findingType | String! | |
| state | TriageState! | |
| justification | TriageJustification | |
| response | TriageResponse | |
| priority | TriagePriority | |
| reason | String! | |
| createdBy | String | |
| createdAt | DateTime! | |
| expiresAt | DateTime | Required whenever the decision hides a finding that is still exposed. |
FindingTriageEvent object
One entry in a finding's decision history. Append-only.
| Name | Type | Description |
|---|---|---|
| id | ID! | |
| repositoryId | ID! | |
| matchKey | String! | |
| action | String! | set or reopen. |
| state | TriageState | |
| justification | TriageJustification | |
| response | TriageResponse | |
| priority | TriagePriority | |
| reason | String | |
| expiresAt | DateTime | |
| actor | String | |
| createdAt | DateTime! |
GitEntity union
One of: Organization, GitUser
GitEntityListResult object
| Name | Type | Description |
|---|---|---|
| total | Int! | |
| items | [GitEntity!]! |
GitEntityType enum
| Name | Description |
|---|---|
| organization | |
| user |
GitToken object
| Name | Type | Description |
|---|---|---|
| id | ID! | |
| name | String | |
| value | String! | |
| expiresAt | DateTime | |
| flags | [GitTokenFlag!]! | |
| status | GitTokenStatus! | |
| scopes | [String!]! | |
| createdAt | DateTime | |
| updatedAt | DateTime | |
| gitTokenType | GitType! | |
| tenant | String! | |
| gitEntities | GitEntityListResult! |
GitTokenAssociationInput input
| Name | Type | Description |
|---|---|---|
| gitEntityId | ID! | |
| gitTokenId | ID! |
GitTokenCheck object
Result of probing a git token against its provider so the UI can pre-fill the expiry and explain what's wrong when the token is rejected.
| Name | Type | Description |
|---|---|---|
| valid | Boolean! | Whether the provider accepted the token. |
| statusCode | Int | HTTP status the provider returned (e.g. 401 for bad credentials), if any. |
| error | String | Provider error message/code (e.g. "Bad credentials"), if the check failed. |
| expiresAt | DateTime | The token's own expiry as reported by the provider, if it exposes one. |
| publicRepositoryCount | Int | Public repositories the token can see for the given workspace name, or null when no name was supplied, the token is invalid, or the provider couldn't be reached. |
| privateRepositoryCount | Int | Private repositories the token can see for the given workspace name, or null when no name was supplied, the token is invalid, or the provider couldn't be reached. |
GitTokenFlag enum
| Name | Description |
|---|---|
| default |
GitTokenListResult object
| Name | Type | Description |
|---|---|---|
| total | Int! | |
| items | [GitToken!]! |
GitTokenStatus enum
| Name | Description |
|---|---|
| valid | |
| invalid | |
| unknown | |
| error |
GitType enum
| Name | Description |
|---|---|
| github | |
| gitlab |
GitUser object
| Name | Type | Description |
|---|---|---|
| id | ID! | |
| name | String! | |
| gitType | GitType! | |
| externalId | Float | |
| webUrl | String | |
| htmlUrl | String | |
| avatarUrl | String | Presigned URL of the entity's avatar (re-hosted from the provider), null if none. |
| color | String | Representative, always-vivid colour (hex) derived from the avatar or seeded from the name. |
| averageSecurityScore | Float! | |
| lastImportDate | DateTime | |
| repositoryCount | Int | |
| type | GitEntityType! | |
| createdAt | DateTime! | |
| updatedAt | DateTime | |
| ignorePaths | [String!] | |
| tags | [Tag!]! |
HttpHeader object
| Name | Type | Description |
|---|---|---|
| name | String! | |
| value | String! |
HttpHeaderInput input
| Name | Type | Description |
|---|---|---|
| name | String! | |
| value | String! |
Invitation object
| Name | Type | Description |
|---|---|---|
| id | ID! | |
| String! | ||
| tenantName | String! |
InviteTeamMemberInput input
| Name | Type | Description |
|---|---|---|
| String! | ||
| language | String |
Invoice object
| Name | Type | Description |
|---|---|---|
| id | ID! | |
| invoiceNumber | String | |
| date | DateTime! | |
| dueDate | DateTime! | |
| status | String! | |
| total | Float! | |
| currency | Currency! |
InvoiceDownload object
| Name | Type | Description |
|---|---|---|
| url | String! | |
| filename | String! | |
| tenant | String! | |
| contentType | String! |
InvoiceListResult object
| Name | Type | Description |
|---|---|---|
| total | Int! | |
| items | [Invoice!]! |
IssueStatus enum
Normalized issue state across providers (GitHub open/closed, GitLab opened/closed).
| Name | Description |
|---|---|
| open | |
| closed |
MyUser object
| Name | Type | Description |
|---|---|---|
| id | ID! | |
| String! | ||
| name | String! | |
| username | String! | |
| tenants | [Tenant!]! | |
| preferences | UserPreferences! |
Network object
| Name | Type | Description |
|---|---|---|
| id | ID! | |
| name | String! | |
| network | String! | |
| networkType | NetworkType! | |
| tenant | String! | |
| securityScore | Float! | |
| createdAt | DateTime! | |
| updatedAt | DateTime | |
| tags | [Tag!]! |
NetworkListResult object
| Name | Type | Description |
|---|---|---|
| total | Int! | |
| items | [Network!]! |
NetworkScanFinding object
| Name | Type | Description |
|---|---|---|
| id | ID! | |
| scanResultId | ID! | |
| host | String! | |
| hostname | String! | |
| hostnameType | String | |
| protocol | String! | |
| port | Int! | |
| serviceName | String! | |
| state | String! | |
| product | String! | |
| version | String! | |
| extraInfo | String! | |
| reason | String! | |
| confidence | Int! | |
| cpe | String! | |
| tags | [Tag!]! | |
| createdAt | DateTime! | |
| updatedAt | DateTime | |
| networkScanResult | NetworkScanResult! |
NetworkScanFindingListResult object
| Name | Type | Description |
|---|---|---|
| total | Int! | |
| items | [NetworkScanFinding!]! |
NetworkScanResult object
| Name | Type | Description |
|---|---|---|
| id | ID! | |
| networkId | ID! | |
| status | ScanStatus! | |
| createdAt | DateTime! | |
| updatedAt | DateTime | |
| scanTime | Int | |
| network | Network! |
NetworkScanResultListResult object
| Name | Type | Description |
|---|---|---|
| total | Int! | |
| items | [NetworkScanResult!]! |
NetworkScanTask object
| Name | Type | Description |
|---|---|---|
| id | ID! | |
| objectId | ID! | |
| status | TaskStatus! | |
| state | NetworkScanTaskState! | |
| createdAt | Int! | |
| scanResult | NetworkScanResult! |
NetworkScanTaskState object
| Name | Type | Description |
|---|---|---|
| totalHosts | Int! | |
| processedHosts | Int! | |
| currentHost | String |
NetworkType enum
| Name | Description |
|---|---|
| public | |
| private | |
| vpn | |
| internal | |
| external | |
| dmz | |
| unknown |
Notification object
| Name | Type | Description |
|---|---|---|
| id | ID! | |
| type | NotificationType! | |
| eventType | String! | |
| data | JSON | |
| read | Boolean! | |
| createdAt | DateTime! |
NotificationList object
| Name | Type | Description |
|---|---|---|
| items | [Notification!]! | |
| total | Int! |
NotificationScope object
| Name | Type | Description |
|---|---|---|
| id | ID! | |
| channelIds | [String!]! | |
| channelType | ChannelType! | |
| scopes | [String!]! | |
| isActive | Boolean! | |
| status | ChannelStatus! | |
| headers | [HttpHeader!] | Custom HTTP headers sent with webhook deliveries (webhook channel only). |
| template | String | Deprecated: superseded by templates. |
| templates | [NotificationTemplate!] | Per-event message templates (eventType '*' is the default for all events). |
NotificationScopeListResult object
| Name | Type | Description |
|---|---|---|
| total | Int! | |
| items | [NotificationScope!]! |
NotificationTemplate object
A message template for one event type ('*' = every event).
| Name | Type | Description |
|---|---|---|
| eventType | String! | |
| template | String! |
NotificationTemplateInput input
| Name | Type | Description |
|---|---|---|
| eventType | String! | |
| template | String! |
NotificationType enum
| Name | Description |
|---|---|
| SCAN_FINISHED | |
| REPOSITORY_FETCH_FINISHED |
NSFConsultation input
| Name | Type | Description |
|---|---|---|
| findingId | ID! |
Order enum
| Name | Description |
|---|---|
| ASC | |
| DESC |
Organization object
| Name | Type | Description |
|---|---|---|
| id | ID! | |
| name | String! | |
| gitType | GitType! | |
| externalId | Float | |
| webUrl | String | |
| htmlUrl | String | |
| avatarUrl | String | Presigned URL of the entity's avatar (re-hosted from the provider), null if none. |
| color | String | Representative, always-vivid colour (hex) derived from the avatar or seeded from the name. |
| averageSecurityScore | Float! | |
| lastImportDate | DateTime | |
| repositoryCount | Int | |
| type | GitEntityType! | |
| createdAt | DateTime! | |
| updatedAt | DateTime | |
| ignorePaths | [String!] | |
| tags | [Tag!]! |
PaymentMethod object
| Name | Type | Description |
|---|---|---|
| id | ID! | |
| default | Boolean! | |
| lastFour | String! | |
| brand | String! | |
| expiryMonth | Int! | |
| expiryYear | Int! | |
| cardholderName | String! | |
| expired | Boolean! |
PaymentMethodListResult object
| Name | Type | Description |
|---|---|---|
| total | Int! | |
| items | [PaymentMethod!]! |
Plan object
| Name | Type | Description |
|---|---|---|
| id | ID! | |
| availableGitScanMinutes | Int | |
| availableNetworkScanMinutes | Int | |
| maxRepositories | Int | |
| maxNetworks | Int | |
| maxEmails | Int | |
| pricePerGitScanMinute | Float | |
| pricePerNetworkScanMinute | Float | |
| currency | Currency |
PreferredDateTimeFormat enum
| Name | Description |
|---|---|
| localized | |
| iso | |
| us | |
| eu |
PreferredRepositoriesView enum
| Name | Description |
|---|---|
| board | |
| table |
PreferredTheme enum
| Name | Description |
|---|---|
| Light | |
| Dark | |
| System |
PromoGrant object
A promotion a tenant holds. The limits are the ones granted when the code was redeemed, not the ones the code names today: vulnara-api copies them at redemption so that editing a code cannot change a grant already made.
| Name | Type | Description |
|---|---|---|
| id | ID! | |
| code | String! | |
| startsAt | DateTime! | |
| endsAt | DateTime! | |
| gitScanMinutes | Int | |
| networkScanMinutes | Int | |
| maxRepositories | Int | |
| maxNetworks | Int | |
| maxEmails | Int |
PrStatus enum
Normalized remediation pull/merge request state.
| Name | Description |
|---|---|
| open | |
| merged | |
| closed |
PushSubscriptionInput input
| Name | Type | Description |
|---|---|---|
| endpoint | String! | |
| p256dh | String! | |
| auth | String! |
RemediationFunnel object
Findings to opened issues to merged remediation PRs.
| Name | Type | Description |
|---|---|---|
| findings | Int! | |
| issuesOpened | Int! | |
| issuesClosed | Int! | |
| prsOpened | Int! | |
| prsMerged | Int! |
RemediationTemplate object
| Name | Type | Description |
|---|---|---|
| codeIssueBody | String | |
| dependencyIssueBody | String | |
| pullRequestBody | String |
RemediationTemplateInput input
| Name | Type | Description |
|---|---|---|
| codeIssueBody | String | |
| dependencyIssueBody | String | |
| pullRequestBody | String |
Repository object
| Name | Type | Description |
|---|---|---|
| id | ID! | |
| gitEntityId | ID! | |
| repositoryName | String! | |
| private | Boolean | |
| securityScore | Float | |
| programmingLanguage | [String!] | |
| repositorySize | Float | Repository size in bytes. Float, not Int, so large repos (>2GB) don't overflow GraphQL's 32-bit Int. |
| numberOfBranches | Int | |
| cloneUrl | String | |
| createdAt | DateTime! | |
| updatedAt | DateTime | |
| isBlacklisted | Boolean | |
| enabled | Boolean | |
| isStandalone | Boolean | |
| avatarUrl | String | Presigned URL of the repo's own avatar (GitLab project image or GitHub custom social-preview image); null otherwise - fall back to gitEntity.avatarUrl. |
| color | String | Vivid colour derived from the repo's avatar; null when it has no colourful image - fall back to a hash of the id. |
| ignorePaths | [String!] | |
| tags | [Tag!]! | |
| gitEntity | GitEntity! | |
| severityCounts | [SeverityCount!] | |
| latestScan | RepositoryScan | Most recent scan's status and time (null if never scanned). |
| scoreHistory | [Float!] | Recent security scores oldest→newest, for the list trend sparkline. |
RepositoryDependencyScanFinding object
| Name | Type | Description |
|---|---|---|
| id | ID! | |
| commitScanId | ID! | |
| createdAt | DateTime! | |
| updatedAt | DateTime | |
| severity | Severity | |
| vulnerability | String | |
| dependency | String | |
| installedVersion | String | |
| fixedVersion | String | |
| purl | String | Package URL, e.g. pkg:npm/[email protected]. |
| vulnerabilityAliases | [String!] | Other identifiers for the same advisory (GHSA, vendor ids). |
| matchHash | String | Cross-tool identity: two scanners reporting the same vulnerable package share this value, even when one leads with a CVE and the other a GHSA. |
| issueUrl | String | URL of the GitHub/GitLab issue opened for this dependency, if any. |
| issueStatus | IssueStatus | |
| prUrl | String | URL of the remediation PR opened for this dependency, if any. |
| prStatus | PrStatus | |
| commitScan | CommitScan! | |
| tags | [Tag!]! |
RepositoryDependencyScanFindingGroup object
One vulnerable library, aggregating all its advisories (CVEs). Queried with a scanResultId filter it covers that scan; without one it covers the tenant, one row per repository the library is vulnerable in.
| Name | Type | Description |
|---|---|---|
| id | ID! | |
| dependency | String! | |
| repositoryId | ID | Which repository the library is vulnerable in. Null within a single scan result, where the caller already named the repository. |
| severity | Severity | |
| installedVersion | String | |
| occurrences | Int! | |
| issueUrl | String | |
| issueStatus | IssueStatus | |
| prUrl | String | |
| prStatus | PrStatus |
RepositoryDependencyScanFindingGroupListResult object
| Name | Type | Description |
|---|---|---|
| total | Int! | |
| items | [RepositoryDependencyScanFindingGroup!]! |
RepositoryDependencyScanFindingListResult object
| Name | Type | Description |
|---|---|---|
| total | Int! | |
| items | [RepositoryDependencyScanFinding!]! |
RepositoryListResult object
| Name | Type | Description |
|---|---|---|
| total | Int! | |
| items | [Repository!]! |
RepositoryRisk object
| Name | Type | Description |
|---|---|---|
| id | ID! | |
| name | String! | |
| securityScore | Float! | |
| criticalCount | Int! | |
| highCount | Int! | |
| findingCount | Int! |
RepositoryScan object
| Name | Type | Description |
|---|---|---|
| status | ScanStatus | |
| scannedAt | DateTime |
RepositoryScanTask object
| Name | Type | Description |
|---|---|---|
| id | ID! | |
| objectId | ID! | |
| status | TaskStatus! | |
| state | RepositoryScanTaskState! | |
| createdAt | Int! | |
| scanResult | ScanResult! |
RepositoryScanTaskState object
| Name | Type | Description |
|---|---|---|
| totalCommits | Int! | |
| scheduled | Int! | |
| scanned | Int! | |
| failed | Int! | |
| parsed | Int! |
RevolutOrder object
| Name | Type | Description |
|---|---|---|
| id | ID! | |
| token | String! |
RSFConsultation input
| Name | Type | Description |
|---|---|---|
| findingId | ID! |
ScanActivityPoint object
| Name | Type | Description |
|---|---|---|
| date | String! | |
| count | Int! | Every scan started that day, failed ones included. |
| succeeded | Int! | |
| failed | Int! | Failed and cancelled scans - activity that produced no coverage. |
ScanCoverage object
| Name | Type | Description |
|---|---|---|
| totalRepositories | Int! | |
| scanned | Int! | |
| unscanned | Int! | Repositories never scanned - unknown risk, and excluded from the score. |
ScanFinding object
| Name | Type | Description |
|---|---|---|
| id | ID! | |
| commitScanId | ID! | |
| createdAt | DateTime! | |
| updatedAt | DateTime | |
| line | Int | |
| file | String | |
| severity | Severity | |
| confidence | String | |
| match | String | Masked (first/last few characters only) - see revealScanFindingMatch for the raw value. |
| fingerprint | String | |
| matchHash | String | Cross-tool identity: two different scanners that found the same secret share this value. Null when the secret could not be resolved (older scans). Distinct from fingerprint, which is per-tool. |
| matchedByToolCount | Int | How many distinct scanners reported this finding. Greater than 1 means two tools independently agreed, which is the strongest cheap signal that it is not a false positive. Null when the finding has no cross-tool identity. |
| issueUrl | String | URL of the GitHub/GitLab issue opened for this finding, if any. |
| issueStatus | IssueStatus | |
| prUrl | String | URL of the remediation PR opened for this finding, if any. |
| prStatus | PrStatus | |
| commitScan | CommitScan! | |
| tags | [Tag!]! |
ScanFindingGroup object
| Name | Type | Description |
|---|---|---|
| id | ID! | |
| fingerprint | String! | |
| matchHash | String | Cross-tool identity of this group. |
| matchedByToolCount | Int | How many distinct scanners reported this finding. A fingerprint group is one tool's view; this says whether anyone else found the same thing. |
| file | String | |
| severity | Severity | |
| confidence | String | |
| match | String | Masked (first/last few characters only) - see revealScanFindingMatch for the raw value. |
| occurrences | Int! | |
| issueUrl | String | URL of the GitHub/GitLab issue opened for this finding, if any. |
| issueStatus | IssueStatus | |
| prUrl | String | URL of the remediation PR opened for this finding, if any. |
| prStatus | PrStatus |
ScanFindingGroupListResult object
| Name | Type | Description |
|---|---|---|
| total | Int! | |
| items | [ScanFindingGroup!]! |
ScanFindingListResult object
| Name | Type | Description |
|---|---|---|
| total | Int! | |
| items | [ScanFinding!]! |
ScanFindingMatchGroup object
One real secret, collapsed across every commit and tool that saw it. The explorer listed raw findings, so a token committed once appeared per commit per tool - 26 commits scanned by 2 tools meant 52 rows for one secret.
| Name | Type | Description |
|---|---|---|
| id | ID! | |
| matchHash | String! | |
| file | String | |
| line | Int | |
| severity | Severity | |
| confidence | String | Highest confidence any contributing tool assigned. |
| match | String | Masked (first/last few characters only) - see revealScanFindingMatch for the raw value. |
| occurrences | Int! | How many raw findings collapsed into this group. |
| toolCount | Int! | How many distinct scanners agreed. Greater than 1 is the corroboration signal. |
| scanners | [String!]! | Which scanners reported it. toolCount answers "is this corroborated"; this answers "who says so", which is what you need to judge a finding you disagree with. |
| repositoryId | ID | |
| triageKey | String | The identity a triage decision is filed under - the match hash, or the fingerprint when there is none. Distinct from matchHash above, which falls back to the finding id: filing a decision under that key stored it somewhere nothing ever looks up. |
| triageState | TriageState | The decision in force, carried on the row so the explorer can show and filter it without a call per finding. Null when nothing has been decided. |
| triageResponse | TriageResponse | |
| triagePriority | TriagePriority |
ScanFindingMatchGroupListResult object
| Name | Type | Description |
|---|---|---|
| total | Int! | |
| items | [ScanFindingMatchGroup!]! |
ScanHealth object
| Name | Type | Description |
|---|---|---|
| totalScans | Int! | |
| succeededScans | Int! | |
| failedScans | Int! | |
| runningScans | Int! | |
| invalidTokens | Int! | Tokens the provider rejected; every scan under their workspaces is blocked. |
| expiringTokens | Int! |
ScanResult object
| Name | Type | Description |
|---|---|---|
| id | ID! | |
| repositoryId | ID! | |
| scanType | String! | |
| scanner | String! | |
| dockerScanToolId | ID! | |
| status | ScanStatus! | |
| createdAt | DateTime! | |
| updatedAt | DateTime | |
| scanTime | Int | |
| securityScore | Float | |
| createIssue | Boolean! | |
| autoRemediate | Boolean! | |
| branches | [String!] | |
| repository | Repository! | |
| dockerScanTool | DockerScanTool! | |
| severityCounts | [SeverityCount!]! |
ScanResultListResult object
| Name | Type | Description |
|---|---|---|
| total | Int! | |
| items | [ScanResult!]! |
ScanSchedule object
A standing instruction to run on a fixed cadence. Deliberately a frequency plus an hour rather than a cron expression: the whole space of valid values is enumerable, so it validates here and renders as two selects. Exactly one of repositoryId or gitEntityId is set. A workspace SCAN fans out over the repositories the workspace holds when it fires, so one imported after the schedule was made is included and one disabled since is not.
| Name | Type | Description |
|---|---|---|
| id | ID! | |
| action | ScanScheduleAction! | |
| repositoryId | ID | Set when this schedule targets one repository. Null for a workspace schedule. |
| gitEntityId | ID | Set when this schedule targets a whole workspace. Null for a repository schedule. |
| branch | String | Branch to scan. Null means the default branch. Never set on a workspace schedule - a branch is a repository-level idea and a workspace's repositories do not share one - nor on a SYNC. |
| dockerScanToolId | ID | Scanner to run. Null means the tenant's default scanner. |
| frequency | ScanScheduleFrequency! | |
| hourUtc | Int! | Hour of day in UTC, 0-23. Clients render it in the viewer's own zone. |
| minuteUtc | Int! | Minute of the hour in UTC, 0-59. Zero for a schedule created before minutes existed. |
| dayOfWeek | Int | Day of week, 0-6, Monday is 0. Only read when frequency is WEEKLY. |
| isActive | Boolean! | |
| nextRunAt | DateTime | When the next run is due, in UTC. Computed by vulnara-api, never written by a client. |
| lastRunAt | DateTime | When the schedule last dispatched a scan, in UTC. Read only. |
| recipients | [String!]! | Where a REPORT is mailed. Empty for a SCAN or a SYNC. Not restricted to tenant members, matching the destinations alert rules already accept. |
| createdBy | String | |
| createdAt | DateTime | |
| updatedAt | DateTime | |
| repository | Repository | Null for a workspace schedule. |
| gitEntity | GitEntity | Null for a repository schedule. |
| dockerScanTool | DockerScanTool |
ScanScheduleAction enum
What a due schedule does. SCAN queues a scan; SYNC re-imports a workspace's repositories, the same job the workspace sync button runs. A SYNC only ever targets a workspace: there is nothing to re-import for a single repository.
| Name | Description |
|---|---|
| SCAN | |
| SYNC | |
| REPORT |
ScanScheduleFrequency enum
| Name | Description |
|---|---|
| DAILY | |
| WEEKLY |
ScanScheduleListResult object
| Name | Type | Description |
|---|---|---|
| total | Int! | |
| items | [ScanSchedule!]! |
ScanStatus enum
| Name | Description |
|---|---|
| PENDING | |
| SUCCESS | |
| FAILED | |
| CANCELLED |
ScoreTrendPoint object
| Name | Type | Description |
|---|---|---|
| date | String! | |
| score | Float! |
ServiceAccount object
| Name | Type | Description |
|---|---|---|
| id | ID! | |
| name | String! | |
| isActive | Boolean! | |
| expiresAt | DateTime | |
| createdBy | User! |
SetFindingTriageInput input
| Name | Type | Description |
|---|---|---|
| repositoryId | ID! | |
| matchKey | String! | The finding's matchHash, or its per-tool fallback when it has none. |
| findingType | String! | |
| state | TriageState! | |
| justification | TriageJustification | |
| response | TriageResponse | |
| priority | TriagePriority | |
| reason | String! | |
| expiresAt | DateTime |
SetGitEntityIgnorePathsInput input
| Name | Type | Description |
|---|---|---|
| gitEntityId | ID! | |
| ignorePaths | [String!]! |
SetRepositoryEnabledInput input
| Name | Type | Description |
|---|---|---|
| repositoryIds | [ID!]! | |
| enabled | Boolean! |
SetRepositoryIgnorePathsInput input
| Name | Type | Description |
|---|---|---|
| repositoryId | ID! | |
| ignorePaths | [String!]! |
SetServiceAccountActiveInput input
| Name | Type | Description |
|---|---|---|
| id | ID! | |
| isActive | Boolean! |
Severity enum
| Name | Description |
|---|---|
| info | |
| low | |
| medium | |
| high | |
| critical |
SeverityCount object
| Name | Type | Description |
|---|---|---|
| severity | String! | |
| count | Int! |
StaleWorkspace object
| Name | Type | Description |
|---|---|---|
| id | ID! | |
| name | String! | |
| lastImportDate | DateTime |
StartNetworkScanInput input
| Name | Type | Description |
|---|---|---|
| networkId | ID! |
StartRepositoryScanInput input
| Name | Type | Description |
|---|---|---|
| repositoryId | ID! | |
| dockerScanToolId | ID! | |
| branch | String | |
| gitTokenId | ID | |
| createIssue | Boolean | |
| autoRemediate | Boolean |
Tag object
| Name | Type | Description |
|---|---|---|
| key | String! | |
| value | String! |
Task union
One of: RepositoryScanTask, NetworkScanTask, FetchGitEntityTask
TaskEvent object
| Name | Type | Description |
|---|---|---|
| type | TaskEventType! | |
| taskId | ID! | |
| task | Task |
TaskEventType enum
| Name | Description |
|---|---|
| STATE_UPDATED | |
| TASK_CANCELLED |
TaskStatus enum
| Name | Description |
|---|---|
| QUEUED | |
| STARTED | |
| CANCELLED | |
| PROCESSING | |
| COMPLETED | |
| FAILED |
Tenant object
| Name | Type | Description |
|---|---|---|
| id | ID! | |
| isPaying | Boolean! | |
| members | [TenantUser!]! |
TenantStatistics object
| Name | Type | Description |
|---|---|---|
| tenant | String! | |
| totalUsers | Int! | |
| totalGitEntities | Int! | |
| totalRepositories | Int! | |
| totalNetworks | Int! |
TenantUser object
| Name | Type | Description |
|---|---|---|
| id | ID! | |
| roles | [TenantUserRole!]! | |
| user | User! |
TenantUserRole enum
| Name | Description |
|---|---|
| VIEWER | |
| EDITOR | |
| ADMIN |
TransferGitEntityInput input
| Name | Type | Description |
|---|---|---|
| gitEntityId | ID! | |
| newTenant | String! |
TransferNetworkInput input
| Name | Type | Description |
|---|---|---|
| networkId | ID! | |
| newTenant | String! |
TriageJustification enum
CycloneDX VEX justification. Required when the state is not_affected.
| Name | Description |
|---|---|
| code_not_present | |
| code_not_reachable | |
| requires_configuration | |
| requires_dependency | |
| requires_environment | |
| protected_by_compiler | |
| protected_at_runtime | |
| protected_at_perimeter | |
| protected_by_mitigating_control |
TriagePriority enum
SSVC decision outcome. Only defer hides the finding from the working list.
| Name | Description |
|---|---|
| defer | |
| scheduled | |
| out_of_cycle | |
| immediate |
TriageResponse enum
CycloneDX VEX analysis.response - what will be done about it.
| Name | Description |
|---|---|
| can_not_fix | |
| rollback | |
| update | |
| will_not_fix | |
| workaround_available |
TriageState enum
CycloneDX VEX analysis.state - what is true about the finding.
| Name | Description |
|---|---|
| resolved | |
| resolved_with_pedigree | |
| exploitable | |
| in_triage | |
| false_positive | |
| not_affected |
UpdateGitEntityInput input
| Name | Type | Description |
|---|---|---|
| gitEntityId | ID! | |
| name | String | |
| gitType | GitType | |
| ignorePaths | [String!] |
UpdateGitTokenInput input
| Name | Type | Description |
|---|---|---|
| id | ID! | |
| name | String | |
| value | String |
UpdateNotificationScopeInput input
| Name | Type | Description |
|---|---|---|
| id | ID! | |
| channelIds | [String!] | |
| channelType | ChannelType | |
| scopes | [String!] | |
| isActive | Boolean | |
| headers | [HttpHeaderInput!] | |
| templates | [NotificationTemplateInput!] |
UpdateScanScheduleInput input
| Name | Type | Description |
|---|---|---|
| id | ID! | |
| branch | String | |
| dockerScanToolId | ID | |
| frequency | ScanScheduleFrequency | |
| hourUtc | Int | |
| minuteUtc | Int | |
| dayOfWeek | Int | |
| isActive | Boolean | |
| recipients | [String!] |
UpdateUserPreferencesInput input
| Name | Type | Description |
|---|---|---|
| theme | PreferredTheme | |
| dateTimeFormat | PreferredDateTimeFormat | |
| repositoriesView | PreferredRepositoriesView |
UpdateUserRolesInput input
| Name | Type | Description |
|---|---|---|
| userId | ID! | |
| roles | [TenantUserRole!]! |
Usage object
| Name | Type | Description |
|---|---|---|
| accountTier | String! | |
| usedGitScanTimeMinutes | Int! | |
| repositoryScanLimited | Boolean! | |
| usedNetworkScanTimeMinutes | Int! | |
| networkScanLimited | Boolean! | |
| parallelScans | Int! | |
| availableGitScanMinutes | Int! | |
| availableNetworkScanMinutes | Int! | |
| maxParallelScans | Int! | |
| usedRepositories | Int! | |
| maxRepositories | Int! | |
| repositoryLimitReached | Boolean! | |
| usedNetworks | Int! | |
| maxNetworks | Int! | |
| networkLimitReached | Boolean! | |
| usedEmails | Int! | |
| maxEmails | Int! | |
| emailLimitReached | Boolean! |
User object
| Name | Type | Description |
|---|---|---|
| id | ID! | |
| String | Null unless the caller may read it: their own address, or any address in a tenant they hold EDITOR or ADMIN in. Nullable rather than guarded by @tenantRole because the directive throws, and a thrown error on a non-null field takes the whole myUser query down for every VIEWER instead of hiding one field. | |
| username | String! | |
| name | String! |
UserPreferences object
| Name | Type | Description |
|---|---|---|
| theme | PreferredTheme | |
| dateTimeFormat | PreferredDateTimeFormat | |
| repositoriesView | PreferredRepositoriesView |
WorkspaceOverview object
Security aggregate for one workspace, counted on the server with the same latest-scan + deduplicated policy as the dashboard.
| Name | Type | Description |
|---|---|---|
| severityCounts | [SeverityCount!]! | |
| totalFindings | Int! | |
| totalRepositories | Int! | |
| scanned | Int! | |
| unscanned | Int! |