| Field | Value |
|---|
| Source spec | vulnerabilities/openapi/v1.json |
| OpenAPI version | 3.1.1 |
| API version | 1.0.0 |
| Operations | 52 |
| Path filter | All paths |
Consensus issues for one vulnerability id
| Property | Value |
|---|
| Operation ID | GetAdvisoryIssues |
| Tags | StellaOps.Vulnerabilities.WebService |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|
vulnerabilityId | path | yes | |
Responses:
| Status | Description | Content types |
|---|
200 | OK | - |
Upstream affected symbols backed by current OSV fact provenance
| Property | Value |
|---|
| Operation ID | GetAdvisoryAffectedSymbols |
| Tags | StellaOps.Vulnerabilities.WebService |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|
vulnerabilityId | path | yes | |
Responses:
| Status | Description | Content types |
|---|
200 | OK | application/json |
503 | Service Unavailable | application/problem+json |
| Property | Value |
|---|
| Operation ID | ExportBinaryBuildIdIndex |
| Tags | Binary artifacts |
| Auth | Not declared |
| Request body | - |
Responses:
| Status | Description | Content types |
|---|
200 | OK | - |
503 | Service Unavailable | application/problem+json |
Live facts for one build-id (prefixed or bare; the artifact’s normalization applies)
| Property | Value |
|---|
| Operation ID | ResolveBuildId |
| Tags | StellaOps.Vulnerabilities.WebService |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|
buildId | path | yes | |
Responses:
| Status | Description | Content types |
|---|
200 | OK | application/json |
Live facts for one function fingerprint / delta signature (ADR-022)
| Property | Value |
|---|
| Operation ID | ResolveFingerprint |
| Tags | StellaOps.Vulnerabilities.WebService |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|
fingerprintId | path | yes | |
Responses:
| Status | Description | Content types |
|---|
200 | OK | application/json |
Patch-aware fix state for a distro source package — the backport signal a range cannot express
| Property | Value |
|---|
| Operation ID | GetBinaryFixStatus |
| Tags | StellaOps.Vulnerabilities.WebService |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|
distro | path | yes | |
release | path | yes | |
sourcePackage | path | yes | |
Responses:
| Status | Description | Content types |
|---|
200 | OK | application/json |
| Property | Value |
|---|
| Operation ID | GetBinaryOpsConfiguration |
| Tags | Binary operations |
| Auth | Not declared |
| Request body | - |
Responses:
| Status | Description | Content types |
|---|
200 | OK | application/json |
503 | Service Unavailable | application/problem+json |
| Property | Value |
|---|
| Operation ID | GetBinaryOpsHealth |
| Tags | Binary operations |
| Auth | Not declared |
| Request body | - |
Responses:
| Status | Description | Content types |
|---|
200 | OK | application/json |
503 | Service Unavailable | application/problem+json |
Delta-signature corpus coverage per vulnerability — how completely the corpus can tell patched from vulnerable
| Property | Value |
|---|
| Operation ID | GetBinaryPatchCoverage |
| Tags | StellaOps.Vulnerabilities.WebService |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|
component | query | no | |
limit | query | no | |
offset | query | no | |
vulnerability | query | no | |
Responses:
| Status | Description | Content types |
|---|
200 | OK | - |
Per-symbol delta-signature coverage for one vulnerability
| Property | Value |
|---|
| Operation ID | GetBinaryPatchCoverageDetails |
| Tags | StellaOps.Vulnerabilities.WebService |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|
vulnerabilityId | path | yes | |
Responses:
| Status | Description | Content types |
|---|
200 | OK | - |
Sectioned corpus stream (NDJSON, deterministic order): matcher-rows (default), consensus-inputs, or exploit-evidence
| Property | Value |
|---|
| Operation ID | ExportCorpus |
| Tags | StellaOps.Vulnerabilities.WebService |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|
section | query | no | |
Responses:
| Status | Description | Content types |
|---|
200 | OK | - |
Current retained corpus publication + the published artifact-retention window (VULN-B8 b) for bootstrap below the event retention horizon
| Property | Value |
|---|
| Operation ID | GetCurrentCorpusPublication |
| Tags | StellaOps.Vulnerabilities.WebService |
| Auth | Not declared |
| Request body | - |
Responses:
| Status | Description | Content types |
|---|
200 | OK | - |
Content-addressed corpus manifest with ETag and byte-range resume
| Property | Value |
|---|
| Operation ID | GetCorpusPublicationManifest |
| Tags | StellaOps.Vulnerabilities.WebService |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|
artifactRef | path | yes | |
Responses:
| Status | Description | Content types |
|---|
200 | OK | - |
Named retained corpus section with digest ETag and byte-range resume
| Property | Value |
|---|
| Operation ID | GetCorpusPublicationSection |
| Tags | StellaOps.Vulnerabilities.WebService |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|
artifactRef | path | yes | |
sectionName | path | yes | |
Responses:
| Status | Description | Content types |
|---|
200 | OK | - |
| Property | Value |
|---|
| Operation ID | GetEpssCurrentBatch |
| Tags | StellaOps.Vulnerabilities.WebService |
| Auth | Not declared |
| Request body | application/json |
Responses:
| Status | Description | Content types |
|---|
200 | OK | - |
| Property | Value |
|---|
| Operation ID | GetEpssLatestModelDate |
| Tags | StellaOps.Vulnerabilities.WebService |
| Auth | Not declared |
| Request body | - |
Responses:
| Status | Description | Content types |
|---|
200 | OK | - |
| Property | Value |
|---|
| Operation ID | GetEpssChangeWindow |
| Tags | StellaOps.Vulnerabilities.WebService |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|
cveId | path | yes | |
Responses:
| Status | Description | Content types |
|---|
200 | OK | - |
Ordered catch-up over a hub event stream (DC-07 pull; transport push is an optimization)
| Property | Value |
|---|
| Operation ID | ReadHubEvents |
| Tags | StellaOps.Vulnerabilities.WebService |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|
stream | path | yes | |
afterSeq | query | no | |
limit | query | no | |
Responses:
| Status | Description | Content types |
|---|
200 | OK | - |
Registered cross-database consumers holding a hub stream’s retention floor
| Property | Value |
|---|
| Operation ID | ListHubStreamConsumers |
| Tags | StellaOps.Vulnerabilities.WebService |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|
stream | path | yes | |
Responses:
| Status | Description | Content types |
|---|
200 | OK | - |
Register a cross-database consumer, or report its durable position, against a hub stream
| Property | Value |
|---|
| Operation ID | RegisterHubStreamConsumer |
| Tags | StellaOps.Vulnerabilities.WebService |
| Auth | Not declared |
| Request body | application/json |
Parameters:
| Name | In | Required | Description |
|---|
consumerId | path | yes | |
stream | path | yes | |
Responses:
| Status | Description | Content types |
|---|
200 | OK | - |
Release a consumer’s hold on a hub stream’s retention floor (reclaims without waiting out the lease)
| Property | Value |
|---|
| Operation ID | UnregisterHubStreamConsumer |
| Tags | StellaOps.Vulnerabilities.WebService |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|
consumerId | path | yes | |
stream | path | yes | |
Responses:
| Status | Description | Content types |
|---|
200 | OK | - |
Exploit evidence for one CVE: curated + available attributes, EPSS probability beside them
| Property | Value |
|---|
| Operation ID | GetExploitEvidence |
| Tags | StellaOps.Vulnerabilities.WebService |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|
vulnerabilityId | path | yes | |
Responses:
| Status | Description | Content types |
|---|
200 | OK | - |
Evidence drill-down: provenance origins resolved to their raw documents
| Property | Value |
|---|
| Operation ID | GetFactEvidence |
| Tags | StellaOps.Vulnerabilities.WebService |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|
factId | path | yes | |
Responses:
| Status | Description | Content types |
|---|
200 | OK | - |
| Property | Value |
|---|
| Operation ID | SubmitIssuerVex |
| Tags | StellaOps.Vulnerabilities.WebService |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|
issuerId | path | yes | |
Responses:
| Status | Description | Content types |
|---|
200 | OK | - |
Consensus drill-down: the live facts behind one issue
| Property | Value |
|---|
| Operation ID | GetIssueFacts |
| Tags | StellaOps.Vulnerabilities.WebService |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|
productKey | path | yes | |
vulnerabilityId | path | yes | |
Responses:
| Status | Description | Content types |
|---|
200 | OK | - |
Run one bounded maintenance pass over the hub’s OWN database (retention prune + ANALYZE)
| Property | Value |
|---|
| Operation ID | RunHubDatabaseMaintenance |
| Tags | StellaOps.Vulnerabilities.WebService |
| Auth | Not declared |
| Request body | application/json |
Responses:
| Status | Description | Content types |
|---|
200 | OK | - |
Validate a declared digest and replay the complete seed through owner ingestion.
| Property | Value |
|---|
| Operation ID | ImportMirrorSeed |
| Tags | StellaOps.Vulnerabilities.WebService |
| Auth | Not declared |
| Request body | application/vnd.stellaops.mirror-seed+ndjson |
Parameters:
| Name | In | Required | Description |
|---|
X-StellaOps-Content-Digest | header | yes | |
X-StellaOps-Mirror-Base-Digest | header | no | |
X-StellaOps-Mirror-Scope | header | no | |
X-StellaOps-Mirror-State-Digest | header | yes | |
replaceExisting | query | no | |
validateOnly | query | no | |
Responses:
| Status | Description | Content types |
|---|
200 | OK | application/json |
400 | Bad Request | application/problem+json |
409 | Conflict | application/problem+json |
415 | Unsupported Media Type | application/problem+json |
503 | Service Unavailable | application/problem+json |
Exploit evidence for every CVE with a LIVE fact against the product
| Property | Value |
|---|
| Operation ID | GetExploitEvidenceByProduct |
| Tags | StellaOps.Vulnerabilities.WebService |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|
productKey | path | yes | |
Responses:
| Status | Description | Content types |
|---|
200 | OK | - |
Consensus issues affecting one canonical product key (purl without version)
| Property | Value |
|---|
| Operation ID | GetProductIssues |
| Tags | StellaOps.Vulnerabilities.WebService |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|
productKey | path | yes | |
Responses:
| Status | Description | Content types |
|---|
200 | OK | application/json |
| Property | Value |
|---|
| Operation ID | GetCorpusReadiness |
| Tags | StellaOps.Vulnerabilities.WebService |
| Auth | Not declared |
| Request body | - |
Responses:
| Status | Description | Content types |
|---|
200 | OK | - |
| Property | Value |
|---|
| Operation ID | GetSourceGenerations |
| Tags | StellaOps.Vulnerabilities.WebService |
| Auth | Not declared |
| Request body | - |
Responses:
| Status | Description | Content types |
|---|
200 | OK | - |
Object-store address for a symbol blob (P16 — the catalog holds no payload)
| Property | Value |
|---|
| Operation ID | ResolveSymbolBlob |
| Tags | StellaOps.Vulnerabilities.WebService |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|
contentHash | path | yes | |
Responses:
| Status | Description | Content types |
|---|
200 | OK | - |
| Property | Value |
|---|
| Operation ID | HubQuerySymbolManifests |
| Tags | Global symbol manifests |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|
binaryName | query | no | |
codeId | query | no | |
createdAfter | query | no | |
createdBefore | query | no | |
debugId | query | no | |
format | query | no | |
hasDsse | query | no | |
limit | query | no | |
offset | query | no | |
platform | query | no | |
Responses:
| Status | Description | Content types |
|---|
200 | OK | application/json |
400 | Bad Request | application/problem+json |
401 | Unauthorized | - |
403 | Forbidden | - |
503 | Service Unavailable | application/problem+json |
| Property | Value |
|---|
| Operation ID | HubUploadSymbolManifest |
| Tags | Global symbol manifests |
| Auth | Not declared |
| Request body | application/json |
Responses:
| Status | Description | Content types |
|---|
201 | Created | application/json |
400 | Bad Request | application/problem+json |
401 | Unauthorized | - |
403 | Forbidden | - |
409 | Conflict | application/problem+json |
503 | Service Unavailable | application/problem+json |
| Property | Value |
|---|
| Operation ID | HubReadSymbolManifest |
| Tags | Global symbol manifests |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|
manifestId | path | yes | |
Responses:
| Status | Description | Content types |
|---|
200 | OK | application/json |
400 | Bad Request | application/problem+json |
401 | Unauthorized | - |
403 | Forbidden | - |
404 | Not Found | application/problem+json |
409 | Conflict | application/problem+json |
503 | Service Unavailable | application/problem+json |
| Property | Value |
|---|
| Operation ID | HubListSymbolCatalog |
| Tags | Symbol catalog |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|
limit | query | no | |
offset | query | no | |
search | query | no | |
sourceKey | query | no | |
Responses:
| Status | Description | Content types |
|---|
200 | OK | application/json |
400 | Bad Request | application/problem+json |
401 | Unauthorized | - |
403 | Forbidden | - |
503 | Service Unavailable | application/problem+json |
| Property | Value |
|---|
| Operation ID | HubRegisterSymbolPack |
| Tags | Symbol catalog |
| Auth | Not declared |
| Request body | application/json |
Responses:
| Status | Description | Content types |
|---|
201 | Created | application/json |
400 | Bad Request | application/problem+json |
401 | Unauthorized | - |
403 | Forbidden | - |
404 | Not Found | application/problem+json |
409 | Conflict | application/problem+json |
503 | Service Unavailable | application/problem+json |
| Property | Value |
|---|
| Operation ID | HubInstalledSymbolPacks |
| Tags | Symbol catalog |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|
limit | query | no | |
offset | query | no | |
Responses:
| Status | Description | Content types |
|---|
200 | OK | application/json |
401 | Unauthorized | - |
403 | Forbidden | - |
503 | Service Unavailable | application/problem+json |
| Property | Value |
|---|
| Operation ID | HubSymbolPackDetail |
| Tags | Symbol catalog |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|
packId | path | yes | |
sourceKey | path | yes | |
Responses:
| Status | Description | Content types |
|---|
200 | OK | application/json |
401 | Unauthorized | - |
403 | Forbidden | - |
404 | Not Found | application/problem+json |
503 | Service Unavailable | application/problem+json |
| Property | Value |
|---|
| Operation ID | HubActivateSymbolPack |
| Tags | Symbol catalog |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|
packId | path | yes | |
sourceKey | path | yes | |
Responses:
| Status | Description | Content types |
|---|
200 | OK | application/json |
401 | Unauthorized | - |
403 | Forbidden | - |
404 | Not Found | application/problem+json |
409 | Conflict | application/problem+json |
503 | Service Unavailable | application/problem+json |
| Property | Value |
|---|
| Operation ID | HubDeactivateSymbolPack |
| Tags | Symbol catalog |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|
packId | path | yes | |
sourceKey | path | yes | |
Responses:
| Status | Description | Content types |
|---|
200 | OK | application/json |
401 | Unauthorized | - |
403 | Forbidden | - |
404 | Not Found | application/problem+json |
503 | Service Unavailable | application/problem+json |
| Property | Value |
|---|
| Operation ID | HubResolveSymbolAddresses |
| Tags | Global symbol manifests |
| Auth | Not declared |
| Request body | application/json |
Responses:
| Status | Description | Content types |
|---|
200 | OK | application/json |
400 | Bad Request | application/problem+json |
401 | Unauthorized | - |
403 | Forbidden | - |
409 | Conflict | application/problem+json |
503 | Service Unavailable | application/problem+json |
| Property | Value |
|---|
| Operation ID | HubListSymbolSources |
| Tags | Symbol sources |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|
includeDisabled | query | no | |
Responses:
| Status | Description | Content types |
|---|
200 | OK | application/json |
401 | Unauthorized | - |
403 | Forbidden | - |
409 | Conflict | application/problem+json |
503 | Service Unavailable | application/problem+json |
| Property | Value |
|---|
| Operation ID | HubCreateSymbolSource |
| Tags | Symbol sources |
| Auth | Not declared |
| Request body | application/json |
Responses:
| Status | Description | Content types |
|---|
201 | Created | application/json |
400 | Bad Request | application/problem+json |
401 | Unauthorized | - |
403 | Forbidden | - |
409 | Conflict | application/problem+json |
503 | Service Unavailable | application/problem+json |
| Property | Value |
|---|
| Operation ID | HubSymbolSourceSummary |
| Tags | Symbol sources |
| Auth | Not declared |
| Request body | - |
Responses:
| Status | Description | Content types |
|---|
200 | OK | application/json |
401 | Unauthorized | - |
403 | Forbidden | - |
409 | Conflict | application/problem+json |
503 | Service Unavailable | application/problem+json |
| Property | Value |
|---|
| Operation ID | HubSymbolSourceDetail |
| Tags | Symbol sources |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|
sourceKey | path | yes | |
Responses:
| Status | Description | Content types |
|---|
200 | OK | application/json |
401 | Unauthorized | - |
403 | Forbidden | - |
404 | Not Found | application/problem+json |
503 | Service Unavailable | application/problem+json |
| Property | Value |
|---|
| Operation ID | HubUpdateSymbolSource |
| Tags | Symbol sources |
| Auth | Not declared |
| Request body | application/json |
Parameters:
| Name | In | Required | Description |
|---|
sourceKey | path | yes | |
Responses:
| Status | Description | Content types |
|---|
200 | OK | application/json |
400 | Bad Request | application/problem+json |
401 | Unauthorized | - |
403 | Forbidden | - |
404 | Not Found | application/problem+json |
503 | Service Unavailable | application/problem+json |
| Property | Value |
|---|
| Operation ID | HubDisableSymbolSource |
| Tags | Symbol sources |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|
sourceKey | path | yes | |
Responses:
| Status | Description | Content types |
|---|
204 | No Content | - |
401 | Unauthorized | - |
403 | Forbidden | - |
404 | Not Found | application/problem+json |
503 | Service Unavailable | application/problem+json |
| Property | Value |
|---|
| Operation ID | HubSymbolServiceStatus |
| Tags | Global symbol manifests |
| Auth | Not declared |
| Request body | - |
Responses:
| Status | Description | Content types |
|---|
200 | OK | application/json |
401 | Unauthorized | - |
403 | Forbidden | - |
503 | Service Unavailable | application/problem+json |
Resolved symbol manifest for one debug-id (tenant-free — a debug-id resolves identically for every estate)
| Property | Value |
|---|
| Operation ID | ResolveSymbolManifest |
| Tags | StellaOps.Vulnerabilities.WebService |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|
debugId | path | yes | |
Responses:
| Status | Description | Content types |
|---|
200 | OK | - |
VEX status view for one issue (rebuildable distribution statements)
| Property | Value |
|---|
| Operation ID | GetVexStatements |
| Tags | StellaOps.Vulnerabilities.WebService |
| Auth | Not declared |
| Request body | - |
Parameters:
| Name | In | Required | Description |
|---|
productKey | path | yes | |
vulnerabilityId | path | yes | |
Responses:
| Status | Description | Content types |
|---|
200 | OK | - |
| Property | Value |
|---|
| Operation ID | - |
| Tags | StellaOps.Vulnerabilities.WebService |
| Auth | Not declared |
| Request body | - |
Responses:
| Status | Description | Content types |
|---|
200 | OK | - |