Findings API Reference
| Field | Value |
|---|---|
| Source spec | findings/openapi/v1.json |
| OpenAPI version | 3.1.1 |
| API version | 1.0.0 |
| Operations | 146 |
| Path filter | All paths |
Operations
GET /api/findings/v1/alerts
| Property | Value |
|---|---|
| Operation ID | ListAlerts.consolidated |
| Tags | StellaOps.Findings.WebService |
| Auth | Not declared |
| Request body | - |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
400 | Bad Request | application/problem+json |
GET /api/findings/v1/alerts/audit
| Property | Value |
|---|---|
| Operation ID | GetAlertAuditByQuery.consolidated |
| Tags | StellaOps.Findings.WebService |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
alert_id | query | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
400 | Bad Request | application/problem+json |
404 | Not Found | - |
GET /api/findings/v1/alerts/bundle
| Property | Value |
|---|---|
| Operation ID | DownloadAlertBundleByQuery.consolidated |
| Tags | StellaOps.Findings.WebService |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
alert_id | query | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | application/gzip |
400 | Bad Request | application/problem+json |
404 | Not Found | - |
POST /api/findings/v1/alerts/bundle/verify
| Property | Value |
|---|---|
| Operation ID | VerifyAlertBundleByQuery.consolidated |
| Tags | StellaOps.Findings.WebService |
| Auth | Not declared |
| Request body | application/json |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
alert_id | query | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
400 | Bad Request | application/problem+json |
404 | Not Found | - |
POST /api/findings/v1/alerts/decisions
| Property | Value |
|---|---|
| Operation ID | RecordDecisionByQuery.consolidated |
| Tags | StellaOps.Findings.WebService |
| Auth | Not declared |
| Request body | application/json |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
alert_id | query | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
201 | Created | - |
400 | Bad Request | application/problem+json |
404 | Not Found | - |
GET /api/findings/v1/alerts/summary
| Property | Value |
|---|---|
| Operation ID | GetAlertByQuery.consolidated |
| Tags | StellaOps.Findings.WebService |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
alert_id | query | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
400 | Bad Request | application/problem+json |
404 | Not Found | - |
GET /api/findings/v1/alerts/{alertId}
| Property | Value |
|---|---|
| Operation ID | GetAlert.consolidated |
| Tags | StellaOps.Findings.WebService |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
alertId | path | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
400 | Bad Request | application/problem+json |
404 | Not Found | - |
GET /api/findings/v1/alerts/{alertId}/audit
| Property | Value |
|---|---|
| Operation ID | GetAlertAudit.consolidated |
| Tags | StellaOps.Findings.WebService |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
alertId | path | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
400 | Bad Request | application/problem+json |
404 | Not Found | - |
GET /api/findings/v1/alerts/{alertId}/bundle
| Property | Value |
|---|---|
| Operation ID | DownloadAlertBundle.consolidated |
| Tags | StellaOps.Findings.WebService |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
alertId | path | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | application/gzip |
400 | Bad Request | application/problem+json |
404 | Not Found | - |
POST /api/findings/v1/alerts/{alertId}/bundle/verify
| Property | Value |
|---|---|
| Operation ID | VerifyAlertBundle.consolidated |
| Tags | StellaOps.Findings.WebService |
| Auth | Not declared |
| Request body | application/json |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
alertId | path | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
400 | Bad Request | application/problem+json |
404 | Not Found | - |
POST /api/findings/v1/alerts/{alertId}/decisions
| Property | Value |
|---|---|
| Operation ID | RecordDecision.consolidated |
| Tags | StellaOps.Findings.WebService |
| Auth | Not declared |
| Request body | application/json |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
alertId | path | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
201 | Created | - |
400 | Bad Request | application/problem+json |
404 | Not Found | - |
GET /api/findings/v1/capabilities/runtime
Get runtime instrumentation capability + tenant-scoped ingest stats
Returns whether runtime instrumentation is enabled at the platform level and, when enabled, the tenant-scoped last-ingest timestamp and ingested-trace count. Lets clients distinguish ‘feature disabled’ from ‘feature enabled but no data yet’ — both of which surface as 404 NotFound on the runtime read endpoints. Tenant scoping is enforced by the standard tenant accessor; data NEVER crosses tenants. Requires findings:read scope.
| Property | Value |
|---|---|
| Operation ID | GetRuntimeCapabilities.consolidated |
| Tags | Capabilities |
| Auth | Not declared |
| Request body | - |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | application/json |
401 | Unauthorized | - |
403 | Forbidden | - |
GET /api/findings/v1/evidence-subgraph/{vulnId}
| Property | Value |
|---|---|
| Operation ID | VulnExplorer_GetEvidenceSubgraph.consolidated |
| Tags | VulnExplorer |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
vulnId | path | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
POST /api/findings/v1/ledger/dispositions/consumers/{consumerId}
Register or report a finding-disposition consumer cursor
Registers/resets a remote consumer or reports its exact durable tenant cursor for the Findings-owned retention floor.
| Property | Value |
|---|---|
| Operation ID | findings.ledger.dispositions.consumer |
| Tags | FindingDisposition |
| Auth | Not declared |
| Request body | application/json |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
consumerId | path | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | application/json |
400 | Bad Request | application/json |
409 | Conflict | application/json |
GET /api/findings/v1/ledger/dispositions/events
Retained finding.disposition.changed event feed
Returns the authenticated tenant’s ordered P6 findings.dispositions envelopes after a durable tenant cursor with explicit epoch, head, retention-horizon and bootstrap signals.
| Property | Value |
|---|---|
| Operation ID | findings.ledger.dispositions.stream |
| Tags | FindingDisposition |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
afterSeq | query | no | |
limit | query | no | |
maxBytes | query | no | |
streamEpoch | query | no |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | application/json |
400 | Bad Request | application/json |
GET /api/findings/v1/ledger/dispositions/latest
List a tenant’s enforced-cap finding dispositions (cold-start reconcile)
Returns the tenant’s currently ENFORCED-CAP dispositions — the findings whose disposition differs from the matcher default because a trusted VEX consensus was Applied. Uncapped/advisory-only findings are omitted (Platform reconstructs those from the matcher). Each item carries the agnostic FindingDisposition fields plus the correlationKey (cve|packageName) the read-model joins on. Paginated by ?limit and ?cursor; the next cursor (when more remain) is returned in the X-Next-Cursor response header so the reconciler can loop. Used by Platform’s cold-start reconcile.
| Property | Value |
|---|---|
| Operation ID | GetLatestFindingDispositions.consolidated |
| Tags | FindingDisposition |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
cursor | query | no | |
limit | query | no |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | application/json |
400 | Bad Request | application/json |
POST /api/findings/v1/ledger/events
| Property | Value |
|---|---|
| Operation ID | LedgerEventAppend.consolidated |
| Tags | LedgerEventIngestEndpoints |
| Auth | Not declared |
| Request body | application/json |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
201 | Created | - |
400 | Bad Request | application/problem+json |
409 | Conflict | application/problem+json |
500 | Internal Server Error | application/problem+json |
GET /api/findings/v1/ledger/ledger
List ledger events for a tenant by runId (replay determinism) or actorRef (SAR).
| Property | Value |
|---|---|
| Operation ID | FindingsLedgerList.consolidated |
| Tags | Findings / Ledger |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
actorRef | query | no | |
runId | query | no |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | application/json |
400 | Bad Request | application/problem+json |
404 | Not Found | application/problem+json |
POST /api/findings/v1/ledger/ledger/advanced-assurance/append
Append the advanced-assurance-golden fixture seed to the Findings ledger.
| Property | Value |
|---|---|
| Operation ID | AdvancedAssuranceLedgerAppend.consolidated |
| Tags | Findings / Ledger / Advanced Assurance |
| Auth | Not declared |
| Request body | - |
Responses:
| Status | Description | Content types |
|---|---|---|
202 | Accepted | application/json |
400 | Bad Request | application/problem+json |
401 | Unauthorized | application/problem+json |
403 | Forbidden | application/problem+json |
409 | Conflict | application/problem+json |
500 | Internal Server Error | application/problem+json |
GET /api/findings/v1/ledger/ledger/{ledgerId}/chain-verify
| Property | Value |
|---|---|
| Operation ID | FindingsLedgerChainVerify.consolidated |
| Tags | LedgerChainVerifyEndpoints |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
ledgerId | path | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | application/json |
400 | Bad Request | application/problem+json |
POST /api/findings/v1/ledger/scores
Calculate evidence-weighted scores for multiple findings
Computes evidence-weighted scores for up to 100 findings in a single request. Each finding is scored independently; partial results are returned if some findings are missing evidence. Batch size exceeding 100 returns 400.
| Property | Value |
|---|---|
| Operation ID | CalculateFindingScoresBatch.consolidated |
| Tags | Scoring |
| Auth | Not declared |
| Request body | application/json |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | application/json |
400 | Bad Request | application/json |
429 | Too Many Requests | - |
GET /api/findings/v1/ledger/summaries
Get paginated list of finding summaries
Returns a paginated list of finding summaries with optional filtering by status, severity, and minimum confidence score. Results are sortable by any summary field and support both ascending and descending direction.
| Property | Value |
|---|---|
| Operation ID | GetFindingSummaries.consolidated |
| Tags | Findings |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
minConfidence | query | no | |
page | query | no | |
pageSize | query | no | |
severity | query | no | |
sortBy | query | no | |
sortDirection | query | no | |
status | query | no |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | application/json |
GET /api/findings/v1/ledger/vex-trust-overrides
Lists the tenant’s per-case VEX-consensus trust overrides in deterministic order.
| Property | Value |
|---|---|
| Operation ID | ListVexTrustOverrides.consolidated |
| Tags | VexTrustOverrides |
| Auth | Not declared |
| Request body | - |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
POST /api/findings/v1/ledger/vex-trust-overrides
Creates a per-case VEX-consensus trust override (an explicit row UNTRUSTS a (vuln, product[, source])).
| Property | Value |
|---|---|
| Operation ID | CreateVexTrustOverride.consolidated |
| Tags | VexTrustOverrides |
| Auth | Not declared |
| Request body | application/json |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
GET /api/findings/v1/ledger/vex-trust-overrides/{id}
Returns a single per-case VEX-consensus trust override.
| Property | Value |
|---|---|
| Operation ID | GetVexTrustOverride.consolidated |
| Tags | VexTrustOverrides |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
id | path | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
PUT /api/findings/v1/ledger/vex-trust-overrides/{id}
Replaces an existing per-case VEX-consensus trust override.
| Property | Value |
|---|---|
| Operation ID | UpdateVexTrustOverride.consolidated |
| Tags | VexTrustOverrides |
| Auth | Not declared |
| Request body | application/json |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
id | path | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
DELETE /api/findings/v1/ledger/vex-trust-overrides/{id}
Deletes a per-case VEX-consensus trust override.
| Property | Value |
|---|---|
| Operation ID | DeleteVexTrustOverride.consolidated |
| Tags | VexTrustOverrides |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
id | path | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
GET /api/findings/v1/ledger/{findingId}/backport
Get backport verification evidence for a finding
Returns backport verification evidence for a specific finding, detailing whether upstream patches have been ported to the affected package version and the confidence level of the backport determination.
| Property | Value |
|---|---|
| Operation ID | GetBackportEvidence.consolidated |
| Tags | Backport Evidence |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
findingId | path | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | application/json |
404 | Not Found | - |
GET /api/findings/v1/ledger/{findingId}/disposition
Get a finding’s enforced, domain-agnostic disposition
Returns the finding’s ENFORCED disposition as the agnostic FindingDisposition contract (disposition/reason/sourceModel/confidence/updatedAt/provenanceRef). Mirrors the finding.disposition.changed event payload; used by Platform for cold-start reconcile. Returns 404 when the finding has no computed score/evidence.
| Property | Value |
|---|---|
| Operation ID | GetFindingDisposition.consolidated |
| Tags | FindingDisposition |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
findingId | path | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | application/json |
400 | Bad Request | application/json |
404 | Not Found | - |
GET /api/findings/v1/ledger/{findingId}/evidence-graph
Get evidence graph for finding visualization
Returns the evidence graph for a finding as a set of typed nodes (scanner events, attestations, runtime observations, SBOM matches) and directed edges representing causal and corroborating relationships, suitable for interactive graph visualization in the UI.
| Property | Value |
|---|---|
| Operation ID | GetEvidenceGraph.consolidated |
| Tags | Evidence Graph |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
findingId | path | yes | |
includeContent | query | no |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | application/json |
404 | Not Found | - |
GET /api/findings/v1/ledger/{findingId}/evidence/{nodeId}
Get raw content for an evidence node
Returns the raw content payload of a specific evidence node within a finding’s evidence graph. Content format varies by node type (JSON for scanner events, JWS for signed attestations, plain text for trace logs).
| Property | Value |
|---|---|
| Operation ID | GetEvidenceNodeContent.consolidated |
| Tags | Evidence Graph |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
findingId | path | yes | |
nodeId | path | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | application/json |
404 | Not Found | - |
GET /api/findings/v1/ledger/{findingId}/patches
Get patch signatures for a finding
Returns the set of patch signatures associated with a finding, including cryptographic commit references and verification status used to confirm whether a given patch has been applied to the affected artifact.
| Property | Value |
|---|---|
| Operation ID | GetPatches.consolidated |
| Tags | Backport Evidence |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
findingId | path | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | application/json |
404 | Not Found | - |
GET /api/findings/v1/ledger/{findingId}/reachability-map
Get condensed reachability visualization
Returns a condensed reachability mini-map for a finding, showing the call graph paths from entry points to the affected vulnerable function. Limits the number of displayed paths via the maxPaths parameter to keep the visualization manageable.
| Property | Value |
|---|---|
| Operation ID | GetReachabilityMiniMap.consolidated |
| Tags | Reachability |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
findingId | path | yes | |
maxPaths | query | no |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | application/json |
404 | Not Found | - |
GET /api/findings/v1/ledger/{findingId}/runtime-timeline
Get runtime corroboration timeline
Returns chronologically-ordered runtime timeline events for a finding within a [from, to] window. 404 NotFound when no events match. Defaults: from = now - 24h, to = now, bucketHours = 1.
| Property | Value |
|---|---|
| Operation ID | GetRuntimeTimeline.consolidated |
| Tags | Runtime |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
findingId | path | yes | |
bucketHours | query | no | |
from | query | no | |
to | query | no |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | application/json |
404 | Not Found | - |
GET /api/findings/v1/ledger/{findingId}/runtime/score
Get runtime trustworthiness score for a finding
Returns the runtime trustworthiness score (0-100) and per-component contributions. 404 NotFound when no score has been derived yet.
| Property | Value |
|---|---|
| Operation ID | GetRtsScore.consolidated |
| Tags | Runtime Evidence |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
findingId | path | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | application/json |
404 | Not Found | - |
GET /api/findings/v1/ledger/{findingId}/runtime/traces
Get runtime function traces for a finding
Returns the aggregated runtime function traces recorded for a finding, sorted by hit count or recency. Returns 404 NotFound when no aggregates exist for the (tenant, finding) — clients MUST distinguish 404 from 200 + empty array.
| Property | Value |
|---|---|
| Operation ID | GetRuntimeTraces.consolidated |
| Tags | Runtime Evidence |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
findingId | path | yes | |
limit | query | no | |
sortBy | query | no |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | application/json |
404 | Not Found | - |
POST /api/findings/v1/ledger/{findingId}/runtime/traces
Ingest runtime trace observation for a finding
Accepts a runtime trace observation from an eBPF or APM agent, applies privacy redaction, persists the raw trace, upserts the per-finding aggregate, and recomputes the runtime score in-line. Returns 202 Accepted with the assigned trace identifier.
| Property | Value |
|---|---|
| Operation ID | IngestRuntimeTrace.consolidated |
| Tags | Runtime Evidence |
| Auth | Not declared |
| Request body | application/json |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
findingId | path | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
202 | Accepted | application/json |
400 | Bad Request | application/problem+json |
GET /api/findings/v1/ledger/{findingId}/score
Get cached evidence-weighted score for a finding
Returns the most recently computed evidence-weighted score for a finding without triggering a recalculation. Returns 404 if no score has been computed yet; callers should use POST /score to trigger an initial computation.
| Property | Value |
|---|---|
| Operation ID | GetFindingScore.consolidated |
| Tags | Scoring |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
findingId | path | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | application/json |
404 | Not Found | - |
POST /api/findings/v1/ledger/{findingId}/score
Calculate evidence-weighted score for a finding
Computes and persists an evidence-weighted severity score for a finding by aggregating all available evidence signals (scanner severity, reachability, runtime corroboration, backport status). The result replaces any previously cached score. Returns 404 if the finding does not exist or has no evidence.
| Property | Value |
|---|---|
| Operation ID | CalculateFindingScore.consolidated |
| Tags | Scoring |
| Auth | Not declared |
| Request body | application/json |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
findingId | path | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | application/json |
400 | Bad Request | application/json |
404 | Not Found | application/json |
429 | Too Many Requests | - |
GET /api/findings/v1/ledger/{findingId}/score-history
Get score history for a finding
Returns a paginated history of evidence-weighted score computations for a finding, optionally filtered by time range. Each entry records the score value, contributing evidence weights, and the policy version used for that computation.
| Property | Value |
|---|---|
| Operation ID | GetFindingScoreHistory.consolidated |
| Tags | Scoring |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
findingId | path | yes | |
cursor | query | no | |
from | query | no | |
limit | query | no | |
to | query | no |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | application/json |
404 | Not Found | - |
PATCH /api/findings/v1/ledger/{findingId}/state
| Property | Value |
|---|---|
| Operation ID | TransitionFindingState.consolidated |
| Tags | FindingStateEndpoints |
| Auth | Not declared |
| Request body | application/json |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
findingId | path | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
400 | Bad Request | application/problem+json |
404 | Not Found | - |
409 | Conflict | application/problem+json |
GET /api/findings/v1/ledger/{findingId}/summary
Get condensed finding summary for vulnerability-first UX
Returns a condensed summary of a finding optimized for the vulnerability-first UI view, including severity, status, confidence, affected component, and evidence highlights. The findingId must be a valid GUID.
| Property | Value |
|---|---|
| Operation ID | GetFindingSummary.consolidated |
| Tags | Findings |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
findingId | path | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | application/json |
400 | Bad Request | application/problem+json |
404 | Not Found | - |
GET /api/findings/v1/risk/aggregated-status
Aggregated risk status for the Security dashboard (derived from real findings)
| Property | Value |
|---|---|
| Operation ID | GetAggregatedRiskStatus.consolidated |
| Tags | Risk |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
Artifact | query | no | |
Digest | query | no | |
Environment | query | no | |
Region | query | no |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
GET /api/findings/v1/scoring/policy
Get the active scoring policy configuration
Returns the currently active evidence-weighted scoring policy, including the version identifier, evidence type weights, severity multipliers, and effective date. The active policy is used for all new score computations.
| Property | Value |
|---|---|
| Operation ID | GetActiveScoringPolicy.consolidated |
| Tags | Scoring |
| Auth | Not declared |
| Request body | - |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | application/json |
GET /api/findings/v1/scoring/policy/versions
List all available scoring policy versions
Returns a list of all scoring policy versions available in the system, including version identifiers, effective dates, and which version is currently active. Used for audit log cross-referencing and policy governance.
| Property | Value |
|---|---|
| Operation ID | ListScoringPolicyVersions.consolidated |
| Tags | Scoring |
| Auth | Not declared |
| Request body | - |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | application/json |
GET /api/findings/v1/scoring/policy/{version}
Get a specific scoring policy version
Returns the scoring policy configuration for a specific version identifier. Useful for auditing historical score computations by confirming which weights and multipliers were in effect at the time a score was recorded.
| Property | Value |
|---|---|
| Operation ID | GetScoringPolicyVersion.consolidated |
| Tags | Scoring |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
version | path | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | application/json |
404 | Not Found | - |
GET /api/findings/v1/scoring/webhooks
List all registered webhooks
Returns all currently registered score change webhooks with their configuration, including URL, filter patterns, minimum score change threshold, and creation timestamp. Secrets are not returned in responses.
| Property | Value |
|---|---|
| Operation ID | ListScoringWebhooks.consolidated |
| Tags | Webhooks |
| Auth | Not declared |
| Request body | - |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | application/json |
POST /api/findings/v1/scoring/webhooks
Register a webhook for score change notifications
Registers an HTTPS callback URL to receive score change notifications. Supports optional HMAC-SHA256 signing via a shared secret, finding pattern filters, minimum score change threshold, and bucket transition triggers. The webhook is activated immediately upon registration.
| Property | Value |
|---|---|
| Operation ID | RegisterScoringWebhook.consolidated |
| Tags | Webhooks |
| Auth | Not declared |
| Request body | application/json |
Responses:
| Status | Description | Content types |
|---|---|---|
201 | Created | application/json |
400 | Bad Request | application/problem+json |
GET /api/findings/v1/scoring/webhooks/{id}
Get a specific webhook by ID
Returns the configuration of a specific webhook by its UUID. Inactive webhooks (soft-deleted) return 404. Secrets are not included in the response body.
| Property | Value |
|---|---|
| Operation ID | GetScoringWebhook.consolidated |
| Tags | Webhooks |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
id | path | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | application/json |
404 | Not Found | - |
PUT /api/findings/v1/scoring/webhooks/{id}
Update a webhook configuration
Replaces the full configuration of an existing webhook. All fields in the request body are applied as-is; partial updates are not supported. To update a secret, supply the new secret value; omitting the secret field retains the existing secret.
| Property | Value |
|---|---|
| Operation ID | UpdateScoringWebhook.consolidated |
| Tags | Webhooks |
| Auth | Not declared |
| Request body | application/json |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
id | path | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | application/json |
400 | Bad Request | application/problem+json |
404 | Not Found | - |
DELETE /api/findings/v1/scoring/webhooks/{id}
Delete a webhook
Permanently removes a webhook registration by its UUID. No further score change notifications will be delivered to the associated URL after deletion. Returns 204 on success, 404 if the webhook does not exist.
| Property | Value |
|---|---|
| Operation ID | DeleteScoringWebhook.consolidated |
| Tags | Webhooks |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
id | path | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
204 | No Content | - |
404 | Not Found | - |
POST /api/findings/v1/security/advisory-generations/recovery/hold
| Property | Value |
|---|---|
| Operation ID | findings.recovery.hold |
| Tags | FindingsRecovery |
| Auth | Not declared |
| Request body | application/json |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
POST /api/findings/v1/security/advisory-generations/recovery/restore
| Property | Value |
|---|---|
| Operation ID | findings.recovery.restore |
| Tags | FindingsRecovery |
| Auth | Not declared |
| Request body | application/json |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
POST /api/findings/v1/security/advisory-generations/recovery/resume
| Property | Value |
|---|---|
| Operation ID | findings.recovery.resume |
| Tags | FindingsRecovery |
| Auth | Not declared |
| Request body | application/json |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
POST /api/findings/v1/security/advisory-generations/recovery/rollback
| Property | Value |
|---|---|
| Operation ID | findings.recovery.rollback |
| Tags | FindingsRecovery |
| Auth | Not declared |
| Request body | application/json |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
GET /api/findings/v1/security/artifact-triage
List tenant-scoped artifact triage facts keyed by immutable digest
| Property | Value |
|---|---|
| Operation ID | ListSecurityArtifactTriageV2.consolidated |
| Tags | Security V2 |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
cursor | query | no | |
limit | query | no | |
offset | query | no |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
GET /api/findings/v1/security/artifact-triage/detail
Get one artifact through the shared artifact-triage projector
| Property | Value |
|---|---|
| Operation ID | GetSecurityArtifactTriageDetailV2.consolidated |
| Tags | Security V2 |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
digest | query | no |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
GET /api/findings/v1/security/disposition
List consolidated security disposition projection (VEX + exceptions read-join)
| Property | Value |
|---|---|
| Operation ID | ListSecurityDispositionV2.consolidated |
| Tags | Security V2 |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
Environment | query | no | |
Limit | query | no | |
Offset | query | no | |
Region | query | no | |
Status | query | no |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
GET /api/findings/v1/security/disposition/{findingId}
Get consolidated security disposition by finding id
| Property | Value |
|---|---|
| Operation ID | GetSecurityDispositionV2.consolidated |
| Tags | Security V2 |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
findingId | path | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
GET /api/findings/v1/security/findings
List consolidated security findings with pivot/facet schema
| Property | Value |
|---|---|
| Operation ID | ListSecurityFindingsV2.consolidated |
| Tags | Security V2 |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
Actionable | query | no | |
Artifact | query | no | |
Cursor | query | no | |
Digest | query | no | |
Disposition | query | no | |
DrillDownFilter | query | no | |
DrillDownValue | query | no | |
Environment | query | no | |
Limit | query | no | |
Offset | query | no | |
Pivot | query | no | |
Region | query | no | |
Search | query | no | |
Severity | query | no | |
Sort | query | no |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
GET /api/findings/v1/security/findings/summary
Get shell-safe critical findings triage count from the materialized projection
| Property | Value |
|---|---|
| Operation ID | GetSecurityFindingsSummaryV2.consolidated |
| Tags | Security V2 |
| Auth | Not declared |
| Request body | - |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
GET /api/findings/v1/security/findings/vulnerability-exposure
Answer whether one exact vulnerability identifier is exposed in the tenant-scoped findings projection
Returns exposed, not_exposed, or unknown. Empty, not-observed, computing, and mixed evidence remain unknown; only all-not-present exact matches prove not_exposed.
| Property | Value |
|---|---|
| Operation ID | GetSecurityVulnerabilityExposureV2.consolidated |
| Tags | Security V2 |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
Artifact | query | no | |
Environment | query | no | |
Limit | query | no | |
Region | query | no | |
VulnerabilityId | query | no |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
GET /api/findings/v1/security/freshness
Get tenant-scoped disposition and scanner freshness state
| Property | Value |
|---|---|
| Operation ID | GetSecurityFreshnessV2.consolidated |
| Tags | Security V2 |
| Auth | Not declared |
| Request body | - |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
GET /api/findings/v1/security/image-context
Get per-image artifact context (reference, SBOM stats, timestamps) for a digest
| Property | Value |
|---|---|
| Operation ID | GetSecurityImageContextV2.consolidated |
| Tags | Security V2 |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
digest | query | no |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
GET /api/findings/v1/security/image-related-releases
List releases whose components pin a single image digest
| Property | Value |
|---|---|
| Operation ID | ListSecurityImageRelatedReleasesV2.consolidated |
| Tags | Security V2 |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
digest | query | no |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
GET /api/findings/v1/security/image-sbom
List the real SBOM component inventory for a single image digest
| Property | Value |
|---|---|
| Operation ID | ListSecurityImageSbomV2.consolidated |
| Tags | Security V2 |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
digest | query | no |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
GET /api/findings/v1/security/sbom-explorer
Get consolidated SBOM explorer projection (table/graph/diff)
| Property | Value |
|---|---|
| Operation ID | GetSecuritySbomExplorerV2.consolidated |
| Tags | Security V2 |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
Environment | query | no | |
LeftReleaseId | query | no | |
Limit | query | no | |
Mode | query | no | |
Offset | query | no | |
Region | query | no | |
RightReleaseId | query | no |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
GET /api/findings/v1/security/vulnerabilities/{vulnerabilityId}
Get the per-vulnerability detail read-model (advisory metadata + affected findings)
Joins canonical advisory metadata (description, severity, authoritative CVSS, EPSS, KEV, fixed/affected versions, CWE) with a bounded tenant-scoped affected-findings sample and explicit scope/currency metadata. Accepts any identifier scheme the advisory corpus carries (CVE, GHSA, MAL, UBUNTU, USN, RUSTSEC, GO, PYSEC and others). 404 when the identifier has neither an advisory row nor any affected finding.
| Property | Value |
|---|---|
| Operation ID | GetSecurityVulnerabilityDetailV2.consolidated |
| Tags | Security V2 |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
vulnerabilityId | path | yes | |
Artifact | query | no | |
Environment | query | no | |
Region | query | no |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
GET /api/findings/v1/vex-decisions
| Property | Value |
|---|---|
| Operation ID | VulnExplorer_ListVexDecisions.consolidated |
| Tags | VulnExplorer |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
continuationToken | query | no | |
limit | query | no | |
pageSize | query | no | |
pageToken | query | no | |
status | query | no | |
subject | query | no | |
subjectName | query | no | |
vulnerabilityId | query | no |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
POST /api/findings/v1/vex-decisions
| Property | Value |
|---|---|
| Operation ID | VulnExplorer_CreateVexDecision.consolidated |
| Tags | VulnExplorer |
| Auth | Not declared |
| Request body | application/json |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
x-stella-user-id | header | no | |
x-stella-user-name | header | no |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
GET /api/findings/v1/vex-decisions/{id}
| Property | Value |
|---|---|
| Operation ID | VulnExplorer_GetVexDecision.consolidated |
| Tags | VulnExplorer |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
id | path | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
PATCH /api/findings/v1/vex-decisions/{id}
| Property | Value |
|---|---|
| Operation ID | VulnExplorer_UpdateVexDecision.consolidated |
| Tags | VulnExplorer |
| Auth | Not declared |
| Request body | application/json |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
id | path | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
GET /api/risk/aggregated-status
Aggregated risk status for the Security dashboard (derived from real findings)
| Property | Value |
|---|---|
| Operation ID | GetAggregatedRiskStatus |
| Tags | Risk |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
Artifact | query | no | |
Digest | query | no | |
Environment | query | no | |
Region | query | no |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
GET /api/v1/buildinfo
API alias for /buildinfo.json (same payload).
| Property | Value |
|---|---|
| Operation ID | StellaOpsBuildInfoApi |
| Tags | StellaOps.Findings.WebService |
| Auth | Not declared |
| Request body | - |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
GET /api/v1/capabilities/runtime
Get runtime instrumentation capability + tenant-scoped ingest stats
Returns whether runtime instrumentation is enabled at the platform level and, when enabled, the tenant-scoped last-ingest timestamp and ingested-trace count. Lets clients distinguish ‘feature disabled’ from ‘feature enabled but no data yet’ — both of which surface as 404 NotFound on the runtime read endpoints. Tenant scoping is enforced by the standard tenant accessor; data NEVER crosses tenants. Requires findings:read scope.
| Property | Value |
|---|---|
| Operation ID | GetRuntimeCapabilities |
| Tags | Capabilities |
| Auth | Not declared |
| Request body | - |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | application/json |
401 | Unauthorized | - |
403 | Forbidden | - |
GET /api/v1/findings/dispositions/latest
List a tenant’s enforced-cap finding dispositions (cold-start reconcile)
Returns the tenant’s currently ENFORCED-CAP dispositions — the findings whose disposition differs from the matcher default because a trusted VEX consensus was Applied. Uncapped/advisory-only findings are omitted (Platform reconstructs those from the matcher). Each item carries the agnostic FindingDisposition fields plus the correlationKey (cve|packageName) the read-model joins on. Paginated by ?limit and ?cursor; the next cursor (when more remain) is returned in the X-Next-Cursor response header so the reconciler can loop. Used by Platform’s cold-start reconcile.
| Property | Value |
|---|---|
| Operation ID | GetLatestFindingDispositions |
| Tags | FindingDisposition |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
cursor | query | no | |
limit | query | no |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | application/json |
400 | Bad Request | application/json |
GET /api/v1/findings/ledger
List ledger events for a tenant by runId (replay determinism) or actorRef (SAR).
| Property | Value |
|---|---|
| Operation ID | FindingsLedgerList |
| Tags | Findings / Ledger |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
actorRef | query | no | |
runId | query | no |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | application/json |
400 | Bad Request | application/problem+json |
404 | Not Found | application/problem+json |
POST /api/v1/findings/ledger/advanced-assurance/append
Append the advanced-assurance-golden fixture seed to the Findings ledger.
| Property | Value |
|---|---|
| Operation ID | AdvancedAssuranceLedgerAppend |
| Tags | Findings / Ledger / Advanced Assurance |
| Auth | Not declared |
| Request body | - |
Responses:
| Status | Description | Content types |
|---|---|---|
202 | Accepted | application/json |
400 | Bad Request | application/problem+json |
401 | Unauthorized | application/problem+json |
403 | Forbidden | application/problem+json |
409 | Conflict | application/problem+json |
500 | Internal Server Error | application/problem+json |
GET /api/v1/findings/ledger/{ledgerId}/chain-verify
| Property | Value |
|---|---|
| Operation ID | FindingsLedgerChainVerify |
| Tags | LedgerChainVerifyEndpoints |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
ledgerId | path | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | application/json |
400 | Bad Request | application/problem+json |
POST /api/v1/findings/scores
Calculate evidence-weighted scores for multiple findings
Computes evidence-weighted scores for up to 100 findings in a single request. Each finding is scored independently; partial results are returned if some findings are missing evidence. Batch size exceeding 100 returns 400.
| Property | Value |
|---|---|
| Operation ID | CalculateFindingScoresBatch |
| Tags | Scoring |
| Auth | Not declared |
| Request body | application/json |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | application/json |
400 | Bad Request | application/json |
429 | Too Many Requests | - |
GET /api/v1/findings/summaries
Get paginated list of finding summaries
Returns a paginated list of finding summaries with optional filtering by status, severity, and minimum confidence score. Results are sortable by any summary field and support both ascending and descending direction.
| Property | Value |
|---|---|
| Operation ID | GetFindingSummaries |
| Tags | Findings |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
minConfidence | query | no | |
page | query | no | |
pageSize | query | no | |
severity | query | no | |
sortBy | query | no | |
sortDirection | query | no | |
status | query | no |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | application/json |
GET /api/v1/findings/vex-trust-overrides
Lists the tenant’s per-case VEX-consensus trust overrides in deterministic order.
| Property | Value |
|---|---|
| Operation ID | ListVexTrustOverrides |
| Tags | VexTrustOverrides |
| Auth | Not declared |
| Request body | - |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
POST /api/v1/findings/vex-trust-overrides
Creates a per-case VEX-consensus trust override (an explicit row UNTRUSTS a (vuln, product[, source])).
| Property | Value |
|---|---|
| Operation ID | CreateVexTrustOverride |
| Tags | VexTrustOverrides |
| Auth | Not declared |
| Request body | application/json |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
GET /api/v1/findings/vex-trust-overrides/{id}
Returns a single per-case VEX-consensus trust override.
| Property | Value |
|---|---|
| Operation ID | GetVexTrustOverride |
| Tags | VexTrustOverrides |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
id | path | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
PUT /api/v1/findings/vex-trust-overrides/{id}
Replaces an existing per-case VEX-consensus trust override.
| Property | Value |
|---|---|
| Operation ID | UpdateVexTrustOverride |
| Tags | VexTrustOverrides |
| Auth | Not declared |
| Request body | application/json |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
id | path | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
DELETE /api/v1/findings/vex-trust-overrides/{id}
Deletes a per-case VEX-consensus trust override.
| Property | Value |
|---|---|
| Operation ID | DeleteVexTrustOverride |
| Tags | VexTrustOverrides |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
id | path | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
GET /api/v1/findings/{findingId}/backport
Get backport verification evidence for a finding
Returns backport verification evidence for a specific finding, detailing whether upstream patches have been ported to the affected package version and the confidence level of the backport determination.
| Property | Value |
|---|---|
| Operation ID | GetBackportEvidence |
| Tags | Backport Evidence |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
findingId | path | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | application/json |
404 | Not Found | - |
GET /api/v1/findings/{findingId}/disposition
Get a finding’s enforced, domain-agnostic disposition
Returns the finding’s ENFORCED disposition as the agnostic FindingDisposition contract (disposition/reason/sourceModel/confidence/updatedAt/provenanceRef). Mirrors the finding.disposition.changed event payload; used by Platform for cold-start reconcile. Returns 404 when the finding has no computed score/evidence.
| Property | Value |
|---|---|
| Operation ID | GetFindingDisposition |
| Tags | FindingDisposition |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
findingId | path | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | application/json |
400 | Bad Request | application/json |
404 | Not Found | - |
GET /api/v1/findings/{findingId}/evidence-graph
Get evidence graph for finding visualization
Returns the evidence graph for a finding as a set of typed nodes (scanner events, attestations, runtime observations, SBOM matches) and directed edges representing causal and corroborating relationships, suitable for interactive graph visualization in the UI.
| Property | Value |
|---|---|
| Operation ID | GetEvidenceGraph |
| Tags | Evidence Graph |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
findingId | path | yes | |
includeContent | query | no |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | application/json |
404 | Not Found | - |
GET /api/v1/findings/{findingId}/evidence/{nodeId}
Get raw content for an evidence node
Returns the raw content payload of a specific evidence node within a finding’s evidence graph. Content format varies by node type (JSON for scanner events, JWS for signed attestations, plain text for trace logs).
| Property | Value |
|---|---|
| Operation ID | GetEvidenceNodeContent |
| Tags | Evidence Graph |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
findingId | path | yes | |
nodeId | path | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | application/json |
404 | Not Found | - |
GET /api/v1/findings/{findingId}/patches
Get patch signatures for a finding
Returns the set of patch signatures associated with a finding, including cryptographic commit references and verification status used to confirm whether a given patch has been applied to the affected artifact.
| Property | Value |
|---|---|
| Operation ID | GetPatches |
| Tags | Backport Evidence |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
findingId | path | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | application/json |
404 | Not Found | - |
GET /api/v1/findings/{findingId}/reachability-map
Get condensed reachability visualization
Returns a condensed reachability mini-map for a finding, showing the call graph paths from entry points to the affected vulnerable function. Limits the number of displayed paths via the maxPaths parameter to keep the visualization manageable.
| Property | Value |
|---|---|
| Operation ID | GetReachabilityMiniMap |
| Tags | Reachability |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
findingId | path | yes | |
maxPaths | query | no |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | application/json |
404 | Not Found | - |
GET /api/v1/findings/{findingId}/runtime-timeline
Get runtime corroboration timeline
Returns chronologically-ordered runtime timeline events for a finding within a [from, to] window. 404 NotFound when no events match. Defaults: from = now - 24h, to = now, bucketHours = 1.
| Property | Value |
|---|---|
| Operation ID | GetRuntimeTimeline |
| Tags | Runtime |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
findingId | path | yes | |
bucketHours | query | no | |
from | query | no | |
to | query | no |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | application/json |
404 | Not Found | - |
GET /api/v1/findings/{findingId}/runtime/score
Get runtime trustworthiness score for a finding
Returns the runtime trustworthiness score (0-100) and per-component contributions. 404 NotFound when no score has been derived yet.
| Property | Value |
|---|---|
| Operation ID | GetRtsScore |
| Tags | Runtime Evidence |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
findingId | path | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | application/json |
404 | Not Found | - |
GET /api/v1/findings/{findingId}/runtime/traces
Get runtime function traces for a finding
Returns the aggregated runtime function traces recorded for a finding, sorted by hit count or recency. Returns 404 NotFound when no aggregates exist for the (tenant, finding) — clients MUST distinguish 404 from 200 + empty array.
| Property | Value |
|---|---|
| Operation ID | GetRuntimeTraces |
| Tags | Runtime Evidence |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
findingId | path | yes | |
limit | query | no | |
sortBy | query | no |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | application/json |
404 | Not Found | - |
POST /api/v1/findings/{findingId}/runtime/traces
Ingest runtime trace observation for a finding
Accepts a runtime trace observation from an eBPF or APM agent, applies privacy redaction, persists the raw trace, upserts the per-finding aggregate, and recomputes the runtime score in-line. Returns 202 Accepted with the assigned trace identifier.
| Property | Value |
|---|---|
| Operation ID | IngestRuntimeTrace |
| Tags | Runtime Evidence |
| Auth | Not declared |
| Request body | application/json |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
findingId | path | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
202 | Accepted | application/json |
400 | Bad Request | application/problem+json |
GET /api/v1/findings/{findingId}/score
Get cached evidence-weighted score for a finding
Returns the most recently computed evidence-weighted score for a finding without triggering a recalculation. Returns 404 if no score has been computed yet; callers should use POST /score to trigger an initial computation.
| Property | Value |
|---|---|
| Operation ID | GetFindingScore |
| Tags | Scoring |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
findingId | path | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | application/json |
404 | Not Found | - |
POST /api/v1/findings/{findingId}/score
Calculate evidence-weighted score for a finding
Computes and persists an evidence-weighted severity score for a finding by aggregating all available evidence signals (scanner severity, reachability, runtime corroboration, backport status). The result replaces any previously cached score. Returns 404 if the finding does not exist or has no evidence.
| Property | Value |
|---|---|
| Operation ID | CalculateFindingScore |
| Tags | Scoring |
| Auth | Not declared |
| Request body | application/json |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
findingId | path | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | application/json |
400 | Bad Request | application/json |
404 | Not Found | application/json |
429 | Too Many Requests | - |
GET /api/v1/findings/{findingId}/score-history
Get score history for a finding
Returns a paginated history of evidence-weighted score computations for a finding, optionally filtered by time range. Each entry records the score value, contributing evidence weights, and the policy version used for that computation.
| Property | Value |
|---|---|
| Operation ID | GetFindingScoreHistory |
| Tags | Scoring |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
findingId | path | yes | |
cursor | query | no | |
from | query | no | |
limit | query | no | |
to | query | no |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | application/json |
404 | Not Found | - |
PATCH /api/v1/findings/{findingId}/state
| Property | Value |
|---|---|
| Operation ID | TransitionFindingState |
| Tags | FindingStateEndpoints |
| Auth | Not declared |
| Request body | application/json |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
findingId | path | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
400 | Bad Request | application/problem+json |
404 | Not Found | - |
409 | Conflict | application/problem+json |
GET /api/v1/findings/{findingId}/summary
Get condensed finding summary for vulnerability-first UX
Returns a condensed summary of a finding optimized for the vulnerability-first UI view, including severity, status, confidence, affected component, and evidence highlights. The findingId must be a valid GUID.
| Property | Value |
|---|---|
| Operation ID | GetFindingSummary |
| Tags | Findings |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
findingId | path | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | application/json |
400 | Bad Request | application/problem+json |
404 | Not Found | - |
GET /api/v1/scoring/policy
Get the active scoring policy configuration
Returns the currently active evidence-weighted scoring policy, including the version identifier, evidence type weights, severity multipliers, and effective date. The active policy is used for all new score computations.
| Property | Value |
|---|---|
| Operation ID | GetActiveScoringPolicy |
| Tags | Scoring |
| Auth | Not declared |
| Request body | - |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | application/json |
GET /api/v1/scoring/policy/versions
List all available scoring policy versions
Returns a list of all scoring policy versions available in the system, including version identifiers, effective dates, and which version is currently active. Used for audit log cross-referencing and policy governance.
| Property | Value |
|---|---|
| Operation ID | ListScoringPolicyVersions |
| Tags | Scoring |
| Auth | Not declared |
| Request body | - |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | application/json |
GET /api/v1/scoring/policy/{version}
Get a specific scoring policy version
Returns the scoring policy configuration for a specific version identifier. Useful for auditing historical score computations by confirming which weights and multipliers were in effect at the time a score was recorded.
| Property | Value |
|---|---|
| Operation ID | GetScoringPolicyVersion |
| Tags | Scoring |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
version | path | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | application/json |
404 | Not Found | - |
GET /api/v1/scoring/webhooks
List all registered webhooks
Returns all currently registered score change webhooks with their configuration, including URL, filter patterns, minimum score change threshold, and creation timestamp. Secrets are not returned in responses.
| Property | Value |
|---|---|
| Operation ID | ListScoringWebhooks |
| Tags | Webhooks |
| Auth | Not declared |
| Request body | - |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | application/json |
POST /api/v1/scoring/webhooks
Register a webhook for score change notifications
Registers an HTTPS callback URL to receive score change notifications. Supports optional HMAC-SHA256 signing via a shared secret, finding pattern filters, minimum score change threshold, and bucket transition triggers. The webhook is activated immediately upon registration.
| Property | Value |
|---|---|
| Operation ID | RegisterScoringWebhook |
| Tags | Webhooks |
| Auth | Not declared |
| Request body | application/json |
Responses:
| Status | Description | Content types |
|---|---|---|
201 | Created | application/json |
400 | Bad Request | application/problem+json |
GET /api/v1/scoring/webhooks/{id}
Get a specific webhook by ID
Returns the configuration of a specific webhook by its UUID. Inactive webhooks (soft-deleted) return 404. Secrets are not included in the response body.
| Property | Value |
|---|---|
| Operation ID | GetScoringWebhook |
| Tags | Webhooks |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
id | path | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | application/json |
404 | Not Found | - |
PUT /api/v1/scoring/webhooks/{id}
Update a webhook configuration
Replaces the full configuration of an existing webhook. All fields in the request body are applied as-is; partial updates are not supported. To update a secret, supply the new secret value; omitting the secret field retains the existing secret.
| Property | Value |
|---|---|
| Operation ID | UpdateScoringWebhook |
| Tags | Webhooks |
| Auth | Not declared |
| Request body | application/json |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
id | path | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | application/json |
400 | Bad Request | application/problem+json |
404 | Not Found | - |
DELETE /api/v1/scoring/webhooks/{id}
Delete a webhook
Permanently removes a webhook registration by its UUID. No further score change notifications will be delivered to the associated URL after deletion. Returns 204 on success, 404 if the webhook does not exist.
| Property | Value |
|---|---|
| Operation ID | DeleteScoringWebhook |
| Tags | Webhooks |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
id | path | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
204 | No Content | - |
404 | Not Found | - |
GET /api/v2/security/artifact-triage
List tenant-scoped artifact triage facts keyed by immutable digest
| Property | Value |
|---|---|
| Operation ID | ListSecurityArtifactTriageV2 |
| Tags | Security V2 |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
cursor | query | no | |
limit | query | no | |
offset | query | no |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
GET /api/v2/security/artifact-triage/detail
Get one artifact through the shared artifact-triage projector
| Property | Value |
|---|---|
| Operation ID | GetSecurityArtifactTriageDetailV2 |
| Tags | Security V2 |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
digest | query | no |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
GET /api/v2/security/disposition
List consolidated security disposition projection (VEX + exceptions read-join)
| Property | Value |
|---|---|
| Operation ID | ListSecurityDispositionV2 |
| Tags | Security V2 |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
Environment | query | no | |
Limit | query | no | |
Offset | query | no | |
Region | query | no | |
Status | query | no |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
GET /api/v2/security/disposition/{findingId}
Get consolidated security disposition by finding id
| Property | Value |
|---|---|
| Operation ID | GetSecurityDispositionV2 |
| Tags | Security V2 |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
findingId | path | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
GET /api/v2/security/findings
List consolidated security findings with pivot/facet schema
| Property | Value |
|---|---|
| Operation ID | ListSecurityFindingsV2 |
| Tags | Security V2 |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
Actionable | query | no | |
Artifact | query | no | |
Cursor | query | no | |
Digest | query | no | |
Disposition | query | no | |
DrillDownFilter | query | no | |
DrillDownValue | query | no | |
Environment | query | no | |
Limit | query | no | |
Offset | query | no | |
Pivot | query | no | |
Region | query | no | |
Search | query | no | |
Severity | query | no | |
Sort | query | no |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
GET /api/v2/security/findings/summary
Get shell-safe critical findings triage count from the materialized projection
| Property | Value |
|---|---|
| Operation ID | GetSecurityFindingsSummaryV2 |
| Tags | Security V2 |
| Auth | Not declared |
| Request body | - |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
GET /api/v2/security/findings/vulnerability-exposure
Answer whether one exact vulnerability identifier is exposed in the tenant-scoped findings projection
Returns exposed, not_exposed, or unknown. Empty, not-observed, computing, and mixed evidence remain unknown; only all-not-present exact matches prove not_exposed.
| Property | Value |
|---|---|
| Operation ID | GetSecurityVulnerabilityExposureV2 |
| Tags | Security V2 |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
Artifact | query | no | |
Environment | query | no | |
Limit | query | no | |
Region | query | no | |
VulnerabilityId | query | no |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
GET /api/v2/security/freshness
Get tenant-scoped disposition and scanner freshness state
| Property | Value |
|---|---|
| Operation ID | GetSecurityFreshnessV2 |
| Tags | Security V2 |
| Auth | Not declared |
| Request body | - |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
GET /api/v2/security/image-context
Get per-image artifact context (reference, SBOM stats, timestamps) for a digest
| Property | Value |
|---|---|
| Operation ID | GetSecurityImageContextV2 |
| Tags | Security V2 |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
digest | query | no |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
GET /api/v2/security/image-related-releases
List releases whose components pin a single image digest
| Property | Value |
|---|---|
| Operation ID | ListSecurityImageRelatedReleasesV2 |
| Tags | Security V2 |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
digest | query | no |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
GET /api/v2/security/image-sbom
List the real SBOM component inventory for a single image digest
| Property | Value |
|---|---|
| Operation ID | ListSecurityImageSbomV2 |
| Tags | Security V2 |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
digest | query | no |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
GET /api/v2/security/sbom-explorer
Get consolidated SBOM explorer projection (table/graph/diff)
| Property | Value |
|---|---|
| Operation ID | GetSecuritySbomExplorerV2 |
| Tags | Security V2 |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
Environment | query | no | |
LeftReleaseId | query | no | |
Limit | query | no | |
Mode | query | no | |
Offset | query | no | |
Region | query | no | |
RightReleaseId | query | no |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
GET /api/v2/security/vulnerabilities/{vulnerabilityId}
Get the per-vulnerability detail read-model (advisory metadata + affected findings)
Joins canonical advisory metadata (description, severity, authoritative CVSS, EPSS, KEV, fixed/affected versions, CWE) with a bounded tenant-scoped affected-findings sample and explicit scope/currency metadata. Accepts any identifier scheme the advisory corpus carries (CVE, GHSA, MAL, UBUNTU, USN, RUSTSEC, GO, PYSEC and others). 404 when the identifier has neither an advisory row nor any affected finding.
| Property | Value |
|---|---|
| Operation ID | GetSecurityVulnerabilityDetailV2 |
| Tags | Security V2 |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
vulnerabilityId | path | yes | |
Artifact | query | no | |
Environment | query | no | |
Region | query | no |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
GET /buildinfo.json
Image build provenance (module, gitSha, gitCommitTime, imageBuiltAt, branch) for drift detection.
| Property | Value |
|---|---|
| Operation ID | StellaOpsBuildInfoFile |
| Tags | StellaOps.Findings.WebService |
| Auth | Not declared |
| Request body | - |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
GET /doctor/findings-web/checks
| Property | Value |
|---|---|
| Operation ID | - |
| Tags | StellaOps.Findings.WebService |
| Auth | Not declared |
| Request body | - |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
GET /v1/alerts
| Property | Value |
|---|---|
| Operation ID | ListAlerts |
| Tags | StellaOps.Findings.WebService |
| Auth | Not declared |
| Request body | - |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
400 | Bad Request | application/problem+json |
GET /v1/alerts/audit
| Property | Value |
|---|---|
| Operation ID | GetAlertAuditByQuery |
| Tags | StellaOps.Findings.WebService |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
alert_id | query | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
400 | Bad Request | application/problem+json |
404 | Not Found | - |
GET /v1/alerts/bundle
| Property | Value |
|---|---|
| Operation ID | DownloadAlertBundleByQuery |
| Tags | StellaOps.Findings.WebService |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
alert_id | query | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | application/gzip |
400 | Bad Request | application/problem+json |
404 | Not Found | - |
POST /v1/alerts/bundle/verify
| Property | Value |
|---|---|
| Operation ID | VerifyAlertBundleByQuery |
| Tags | StellaOps.Findings.WebService |
| Auth | Not declared |
| Request body | application/json |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
alert_id | query | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
400 | Bad Request | application/problem+json |
404 | Not Found | - |
POST /v1/alerts/decisions
| Property | Value |
|---|---|
| Operation ID | RecordDecisionByQuery |
| Tags | StellaOps.Findings.WebService |
| Auth | Not declared |
| Request body | application/json |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
alert_id | query | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
201 | Created | - |
400 | Bad Request | application/problem+json |
404 | Not Found | - |
GET /v1/alerts/summary
| Property | Value |
|---|---|
| Operation ID | GetAlertByQuery |
| Tags | StellaOps.Findings.WebService |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
alert_id | query | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
400 | Bad Request | application/problem+json |
404 | Not Found | - |
GET /v1/alerts/{alertId}
| Property | Value |
|---|---|
| Operation ID | GetAlert |
| Tags | StellaOps.Findings.WebService |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
alertId | path | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
400 | Bad Request | application/problem+json |
404 | Not Found | - |
GET /v1/alerts/{alertId}/audit
| Property | Value |
|---|---|
| Operation ID | GetAlertAudit |
| Tags | StellaOps.Findings.WebService |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
alertId | path | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
400 | Bad Request | application/problem+json |
404 | Not Found | - |
GET /v1/alerts/{alertId}/bundle
| Property | Value |
|---|---|
| Operation ID | DownloadAlertBundle |
| Tags | StellaOps.Findings.WebService |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
alertId | path | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | application/gzip |
400 | Bad Request | application/problem+json |
404 | Not Found | - |
POST /v1/alerts/{alertId}/bundle/verify
| Property | Value |
|---|---|
| Operation ID | VerifyAlertBundle |
| Tags | StellaOps.Findings.WebService |
| Auth | Not declared |
| Request body | application/json |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
alertId | path | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
400 | Bad Request | application/problem+json |
404 | Not Found | - |
POST /v1/alerts/{alertId}/decisions
| Property | Value |
|---|---|
| Operation ID | RecordDecision |
| Tags | StellaOps.Findings.WebService |
| Auth | Not declared |
| Request body | application/json |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
alertId | path | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
201 | Created | - |
400 | Bad Request | application/problem+json |
404 | Not Found | - |
POST /v1/audit-bundles
| Property | Value |
|---|---|
| Operation ID | VulnExplorer_CreateAuditBundle |
| Tags | VulnExplorer |
| Auth | Not declared |
| Request body | application/json |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
GET /v1/evidence-subgraph/{vulnId}
| Property | Value |
|---|---|
| Operation ID | VulnExplorer_GetEvidenceSubgraph |
| Tags | VulnExplorer |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
vulnId | path | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
POST /v1/fix-verifications
| Property | Value |
|---|---|
| Operation ID | VulnExplorer_CreateFixVerification |
| Tags | VulnExplorer |
| Auth | Not declared |
| Request body | application/json |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
PATCH /v1/fix-verifications/{cveId}
| Property | Value |
|---|---|
| Operation ID | VulnExplorer_UpdateFixVerification |
| Tags | VulnExplorer |
| Auth | Not declared |
| Request body | application/json |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
cveId | path | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
GET /v1/vex-decisions
| Property | Value |
|---|---|
| Operation ID | VulnExplorer_ListVexDecisions |
| Tags | VulnExplorer |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
continuationToken | query | no | |
limit | query | no | |
pageSize | query | no | |
pageToken | query | no | |
status | query | no | |
subject | query | no | |
subjectName | query | no | |
vulnerabilityId | query | no |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
POST /v1/vex-decisions
| Property | Value |
|---|---|
| Operation ID | VulnExplorer_CreateVexDecision |
| Tags | VulnExplorer |
| Auth | Not declared |
| Request body | application/json |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
x-stella-user-id | header | no | |
x-stella-user-name | header | no |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
GET /v1/vex-decisions/{id}
| Property | Value |
|---|---|
| Operation ID | VulnExplorer_GetVexDecision |
| Tags | VulnExplorer |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
id | path | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
PATCH /v1/vex-decisions/{id}
| Property | Value |
|---|---|
| Operation ID | VulnExplorer_UpdateVexDecision |
| Tags | VulnExplorer |
| Auth | Not declared |
| Request body | application/json |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
id | path | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
GET /v1/vulns
| Property | Value |
|---|---|
| Operation ID | VulnExplorer_ListVulns |
| Tags | VulnExplorer |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
cve | query | no | |
exploitability | query | no | |
fixAvailable | query | no | |
pageSize | query | no | |
pageToken | query | no | |
policyVersion | query | no | |
purl | query | no | |
severity | query | no |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
GET /v1/vulns/{id}
| Property | Value |
|---|---|
| Operation ID | VulnExplorer_GetVuln |
| Tags | VulnExplorer |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|---|---|---|
id | path | yes |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
POST /vuln/ledger/events
| Property | Value |
|---|---|
| Operation ID | LedgerEventAppend |
| Tags | LedgerEventIngestEndpoints |
| Auth | Not declared |
| Request body | application/json |
Responses:
| Status | Description | Content types |
|---|---|---|
200 | OK | - |
201 | Created | - |
400 | Bad Request | application/problem+json |
409 | Conflict | application/problem+json |
500 | Internal Server Error | application/problem+json |
