GET
/v1/finding/project/{uuid}List project findings or export them as SARIF
Lists findings for a specific project, or returns a SARIF document when you request application/sarif+json. Use searchText, source and analysis filters, or either pagination pair to narrow the results. You need the VIEW_VULNERABILITY permission to access the project.
uuidstringrequired
UUID of the project whose findings you want to retrieve.
searchTextstringoptional
Case-insensitive substring filter for component name, component group, and vulnerability ID; also matches component UUID, vulnerability UUID, and the exact `componentUuid:vulnerabilityUuid` pair.
pageNumberstringoptional
Page number to return, used with `pageSize`. Defaults to 1 when omitted.
pageSizestringoptional
Number of findings per page, used with `pageNumber`. Defaults to 100 when omitted.
offsetstringoptional
Index of the first finding to return, used with `limit`.
limitstringoptional
Maximum number of findings to return, used with `offset`.
sortNamestringoptional
Name of the finding field to sort by.
sortOrderstringoptional
Sort direction for `sortName`; the documented enum value is `asc, desc`.
suppressedbooleanoptional
Set to include suppressed findings.
sourcestringoptional
Limit findings to a vulnerability intelligence source: NVD, GITHUB, VULNDB, OSSINDEX, INTERNAL, OSV, SNYK, CX, JVN, or UNKNOWN.
hasAnalysisbooleanoptional
Set to include only findings for projects with existing analysis.
epssFromnumberoptional
Inclusive lower bound for filtering findings by EPSS score.
epssTonumberoptional
Inclusive upper bound for filtering findings by EPSS score.
isKevbooleanoptional
Filter by known exploited vulnerability status: omit for any status, true for KEVs only, or false to exclude KEVs.
totalCountstringoptional
Controls the `X-Total-Count` response header: EXACT or BOUNDED. Defaults to EXACT when omitted; BOUNDED may return a lower-bound count, with `X-Total-Count-Type` identifying the count type.
acceptstringoptional
Set the response media type; use `application/sarif+json` to request a SARIF document instead of JSON.
200Returns either an array of finding objects containing analysis, attribution, component, matrix, and vulnerability data, or a SARIF document when requested with `application/sarif+json`. SARIF responses do not include count headers.
analysisobjectoptional
attributionobjectoptional
componentobjectoptional
matrixstringoptional
vulnerabilityobjectoptional
400Returned when a query parameter is invalid.
detailstringrequired
Human-readable explanation specific to this occurrence of the problem
instancestringoptional
Reference URI that identifies the specific occurrence of the problem
statusintegerrequired
HTTP status code generated by the origin server for this occurrence of the problem
titlestringrequired
Short, human-readable summary of the problem type
typestringoptional
A URI reference that identifies the problem type
401Returned when the request is unauthorized.
403Returned when access to the requested project is forbidden.
detailstringrequired
Human-readable explanation specific to this occurrence of the problem
instancestringoptional
Reference URI that identifies the specific occurrence of the problem
statusintegerrequired
HTTP status code generated by the origin server for this occurrence of the problem
titlestringrequired
Short, human-readable summary of the problem type
typestringoptional
A URI reference that identifies the problem type
404Returned when the project cannot be found.
Error handling
A 400 is returned when a query parameter is invalid, a 401 when the request is unauthorized, a 403 when access to the project is forbidden, and a 404 when the project cannot be found. The uuid path parameter must be a UUID; sortOrder must match its documented enum value, asc, desc, and source must be one of NVD, GITHUB, VULNDB, OSSINDEX, INTERNAL, OSV, SNYK, CX, JVN, or UNKNOWN. totalCount must be EXACT or BOUNDED when supplied.