PUT/v1/analysis

Record an analysis decision

Records an analysis decision for a vulnerability affecting a component. Supply component and vulnerability, and add analysis state, justification, response, or comments as needed. The authenticated user needs the VULNERABILITY_ANALYSIS or VULNERABILITY_ANALYSIS_UPDATE permission.

10 body fields

Analysis decision details for a component and vulnerability. component and vulnerability are required.

analysisDetailsstringoptional
Free-form details of the analysis decision.
analysisJustificationstringoptional
The reason for the analysis decision: CODE_NOT_PRESENT, CODE_NOT_REACHABLE, REQUIRES_CONFIGURATION, REQUIRES_DEPENDENCY, REQUIRES_ENVIRONMENT, PROTECTED_BY_COMPILER, PROTECTED_AT_RUNTIME, PROTECTED_AT_PERIMETER, PROTECTED_BY_MITIGATING_CONTROL, or NOT_SET.
Allowed:CODE_NOT_PRESENTCODE_NOT_REACHABLEREQUIRES_CONFIGURATIONREQUIRES_DEPENDENCYREQUIRES_ENVIRONMENTPROTECTED_BY_COMPILERPROTECTED_AT_RUNTIMEPROTECTED_AT_PERIMETERPROTECTED_BY_MITIGATING_CONTROLNOT_SET
analysisResponsestringoptional
The response to the vulnerability: CAN_NOT_FIX, WILL_NOT_FIX, UPDATE, ROLLBACK, WORKAROUND_AVAILABLE, or NOT_SET.
Allowed:CAN_NOT_FIXWILL_NOT_FIXUPDATEROLLBACKWORKAROUND_AVAILABLENOT_SET
analysisStatestringoptional
The analysis state: EXPLOITABLE, IN_TRIAGE, FALSE_POSITIVE, NOT_AFFECTED, RESOLVED, or NOT_SET.
Allowed:EXPLOITABLEIN_TRIAGEFALSE_POSITIVENOT_AFFECTEDRESOLVEDNOT_SET
commentstringoptional
A comment for the analysis decision.
componentstringrequired
The UUID of the affected component.
isSuppressedbooleanoptional
Set whether to suppress the finding.
projectstringoptional
The UUID of the project associated with the analysis.
suppressedbooleanoptional
Whether the finding is suppressed.
vulnerabilitystringrequired
The UUID of the vulnerability being analyzed.

4 status codes
200Returns the created analysis, including its analysis comments, state, suppression status, decision details, scores, vectors, and severity where available.
analysisCommentsarray<object>required
Audit trail of analysis comments
analysisDetailsstringoptional
Free-form details of the analysis decision
analysisJustificationstringoptional
The justification of the analysis decision
Allowed:CODE_NOT_PRESENTCODE_NOT_REACHABLEREQUIRES_CONFIGURATIONREQUIRES_DEPENDENCYREQUIRES_ENVIRONMENTPROTECTED_BY_COMPILERPROTECTED_AT_RUNTIMEPROTECTED_AT_PERIMETERPROTECTED_BY_MITIGATING_CONTROLNOT_SET
analysisResponsestringoptional
The vendor response to the vulnerability
Allowed:CAN_NOT_FIXWILL_NOT_FIXUPDATEROLLBACKWORKAROUND_AVAILABLENOT_SET
analysisStatestringrequired
The state of the analysis decision
Allowed:EXPLOITABLEIN_TRIAGEFALSE_POSITIVENOT_AFFECTEDRESOLVEDNOT_SET
cvssV2Scorenumberoptional
CVSS v2 score assigned by the analysis
cvssV2Vectorstringoptional
CVSS v2 vector assigned by the analysis
cvssV3Scorenumberoptional
CVSS v3 score assigned by the analysis
cvssV3Vectorstringoptional
CVSS v3 vector assigned by the analysis
cvssV4Scorenumberoptional
CVSS v4 score assigned by the analysis
cvssV4Vectorstringoptional
CVSS v4 vector assigned by the analysis
isSuppressedbooleanrequired
Whether the finding is suppressed
owaspScorenumberoptional
OWASP Risk Rating score assigned by the analysis
owaspVectorstringoptional
OWASP Risk Rating vector assigned by the analysis
severitystringoptional
Severity assigned by the analysis
Allowed:CRITICALHIGHMEDIUMLOWINFOUNASSIGNED
401Returned when the request is unauthorized.
403Returned when access to the requested project is forbidden.
detailstringrequired
Human-readable explanation specific to this occurrence of the problem
instancestringoptional
Reference URI that identifies the specific occurrence of the problem
statusintegerrequired
HTTP status code generated by the origin server for this occurrence of the problem
titlestringrequired
Short, human-readable summary of the problem type
typestringoptional
A URI reference that identifies the problem type
404Returned when the project, component, or vulnerability could not be found.

Error handling

A 401 is returned when the request is unauthorized. A 403 is returned when access to the project is forbidden. A 404 is returned when the project, component, or vulnerability cannot be found. component and vulnerability are required UUIDs. analysisJustification, analysisResponse, and analysisState must each use one of the values defined for that field.