Required scope: read:security
apiKeyAuthorizationBearer <token>Send the key as Authorization: Bearer plk_live_.... No other header is accepted.
limit?integerPage size.
1 <= value <= 10050cursor?stringThe next_cursor from the previous page. Reuse the same since and until.
since?stringOldest creation time to include (ISO 8601). Values older than your plan's data retention are moved forward, and meta.retention_clamped is true.
date-timeuntil?stringNewest creation time to include (ISO 8601). Defaults to now.
date-timestatus?stringOnly alerts with this status.
severity?stringOnly alerts with this severity.
A page of security alerts.
application/jsondata*array<>next_cursor*string|nullmeta*curl -X GET "https://api.prodgator.io/v1/security/alerts" \ -H "Authorization: Bearer plk_live_YOUR_KEY"{ "data": [ { "id": "string", "org_id": "string", "repository": "string", "type": "string", "severity": "string", "title": "string", "description": "string", "package_name": "string", "vulnerable_versions": "string", "patched_version": "string", "cve_id": "string", "status": "string", "detected_at": "2019-08-24T14:15:22Z", "fixed_at": "2019-08-24T14:15:22Z", "dismissed_by": "string", "dismiss_reason": "string", "dismiss_comment": "string", "dismissed_at": "2019-08-24T14:15:22Z", "dismissed_by_name": "string", "dismissal_source": "prodgator", "github_alert_url": "string", "ghsa_id": "string", "advisory_url": "string", "references": [ "string" ], "location": { "path": "string", "start_line": 0, "end_line": 0 }, "commit_sha": "string", "git_ref": "string", "provider": "github", "rule_id": "string", "tool_name": "string", "secret_type": "string", "created_at": "2019-08-24T14:15:22Z", "updated_at": "2019-08-24T14:15:22Z", "issue_id": "string", "grouping_code": "string", "grouping_detail": "string" } ], "next_cursor": "string", "meta": { "since": "2019-08-24T14:15:22Z", "until": "2019-08-24T14:15:22Z", "retention_clamped": true }}Required scope: read:security
apiKeyAuthorizationBearer <token>Send the key as Authorization: Bearer plk_live_.... No other header is accepted.
id*string^[A-Za-z0-9._:-]{1,128}$The alert.
application/jsondata*curl -X GET "https://api.prodgator.io/v1/security/alerts/string" \ -H "Authorization: Bearer plk_live_YOUR_KEY"{ "data": { "id": "string", "org_id": "string", "repository": "string", "type": "string", "severity": "string", "title": "string", "description": "string", "package_name": "string", "vulnerable_versions": "string", "patched_version": "string", "cve_id": "string", "status": "string", "detected_at": "2019-08-24T14:15:22Z", "fixed_at": "2019-08-24T14:15:22Z", "dismissed_by": "string", "dismiss_reason": "string", "dismiss_comment": "string", "dismissed_at": "2019-08-24T14:15:22Z", "dismissed_by_name": "string", "dismissal_source": "prodgator", "github_alert_url": "string", "ghsa_id": "string", "advisory_url": "string", "references": [ "string" ], "location": { "path": "string", "start_line": 0, "end_line": 0 }, "commit_sha": "string", "git_ref": "string", "provider": "github", "rule_id": "string", "tool_name": "string", "secret_type": "string", "created_at": "2019-08-24T14:15:22Z", "updated_at": "2019-08-24T14:15:22Z", "issue_id": "string", "grouping_code": "string", "grouping_detail": "string" }}Create the upload, PUT the file to put.url with put.headers and its Content-Length within 15 minutes, then call complete. Uploading the same file for the same repository, category and ref again returns the existing upload and put: null, and does not count against your limits. Each upload counts against your plan's per-run limit: uploads from the Prodgator report action count per pipeline run, other uploads count per repository and commit (send commitSha).
Required scope: write:security-findings
apiKeyAuthorizationBearer <token>Send the key as Authorization: Bearer plk_live_.... No other header is accepted.
application/jsonfilename*stringThe report file name (path components are dropped).
length <= 200size*integerFile size in bytes, checked against your plan limit.
1 <= valuesha256*stringSHA-256 of the file, lowercase hex.
^[0-9a-f]{64}$format?stringThe report format (SARIF 2.1.0, CycloneDX JSON or SPDX JSON). auto detects it from the file's contents. Scanner-specific JSON such as Grype or Trivy JSON is refused; run the scanner with SARIF output.
"auto""auto""sarif""cyclonedx""spdx"repository*string'owner/name'.
provider?|Where the repository is. Needed when the name is on more than one of your providers (the upload fails with 400 REPOSITORY_AMBIGUOUS otherwise). Findings are kept per provider and repository id, so same-named repositories on different providers never share findings or issues.
"github""gitlab""bitbucket"nullrepositoryId?|The provider's repository id (GitHub repository id, GitLab project id, Bitbucket repository UUID). Needs provider. Without it, Prodgator looks the id up by name.
category?|Distinguishes multiple reports for the same repository and ref (an image name, a scan target).
length <= 100gitRef?|Branch or tag the report was taken from.
length <= 255commitSha?|Commit the report was taken at. Send it so a direct upload counts against its commit rather than the whole day.
^[0-9a-f]{7,40}$tracked?|Overrides whether this report joins issues, instead of Prodgator deciding from gitRef and the repository's tracked branch.
The upload already exists (the same file, repository, category and ref were sent before); no PUT is needed.
application/jsondata*curl -X POST "https://api.prodgator.io/v1/security/uploads" \ -H "Authorization: Bearer plk_live_YOUR_KEY" \ -H "Content-Type: application/json" \ -d '{ "filename": "string", "size": 1, "sha256": "string", "repository": "string" }'{ "data": { "upload": { "id": "string", "origin": "ui", "status": "pending", "format": "sarif", "filename": "string", "size": 0, "repository": "string", "provider": "string", "repository_id": "string", "category": "string", "git_ref": "string", "commit_sha": "string", "tracked": true, "counts": { "findings": 0, "created": 0, "updated": 0, "resolved": 0, "components": 0, "openBySeverity": { "critical": 0, "high": 0, "medium": 0, "low": 0 }, "newIssues": 0, "newCritical": 0, "newHigh": 0 }, "truncated": true, "warnings": [ "string" ], "error": "string", "created_at": "2019-08-24T14:15:22Z", "updated_at": "2019-08-24T14:15:22Z" }, "put": null }}Call once the file has been PUT to put.url. Prodgator verifies the object's size and checksum, then queues the report for parsing.
Required scope: write:security-findings
apiKeyAuthorizationBearer <token>Send the key as Authorization: Bearer plk_live_.... No other header is accepted.
uploadId*string^[0-9a-f]{32}$The upload was queued for parsing (or was already past pending).
application/jsondata*curl -X POST "https://api.prodgator.io/v1/security/uploads/string/complete" \ -H "Authorization: Bearer plk_live_YOUR_KEY"{ "data": { "upload": { "id": "string", "origin": "ui", "status": "pending", "format": "sarif", "filename": "string", "size": 0, "repository": "string", "provider": "string", "repository_id": "string", "category": "string", "git_ref": "string", "commit_sha": "string", "tracked": true, "counts": { "findings": 0, "created": 0, "updated": 0, "resolved": 0, "components": 0, "openBySeverity": { "critical": 0, "high": 0, "medium": 0, "low": 0 }, "newIssues": 0, "newCritical": 0, "newHigh": 0 }, "truncated": true, "warnings": [ "string" ], "error": "string", "created_at": "2019-08-24T14:15:22Z", "updated_at": "2019-08-24T14:15:22Z" } }}Required scope: write:security-findings
apiKeyAuthorizationBearer <token>Send the key as Authorization: Bearer plk_live_.... No other header is accepted.
uploadId*string^[0-9a-f]{32}$The upload.
application/jsondata*curl -X GET "https://api.prodgator.io/v1/security/uploads/string" \ -H "Authorization: Bearer plk_live_YOUR_KEY"{ "data": { "id": "string", "origin": "ui", "status": "pending", "format": "sarif", "filename": "string", "size": 0, "repository": "string", "provider": "string", "repository_id": "string", "category": "string", "git_ref": "string", "commit_sha": "string", "tracked": true, "counts": { "findings": 0, "created": 0, "updated": 0, "resolved": 0, "components": 0, "openBySeverity": { "critical": 0, "high": 0, "medium": 0, "low": 0 }, "newIssues": 0, "newCritical": 0, "newHigh": 0 }, "truncated": true, "warnings": [ "string" ], "error": "string", "created_at": "2019-08-24T14:15:22Z", "updated_at": "2019-08-24T14:15:22Z" }}Every raw finding from every source, including branch, fixed and dismissed findings. Each one names its issue (issue_id) and why it was grouped.
Required scope: read:security
apiKeyAuthorizationBearer <token>Send the key as Authorization: Bearer plk_live_.... No other header is accepted.
limit?integerPage size.
1 <= value <= 1000100cursor?stringThe next_cursor from the previous page. Reuse the same since and until.
repository?stringOnly findings on this repository ('owner/name'). A name that more than one of your providers has (for example the same repository on GitHub and GitLab) needs provider, or the request fails with 400 REPOSITORY_AMBIGUOUS.
provider?stringThe provider of repository. Findings of a same-named repository on another provider are never returned.
"github""gitlab""bitbucket"repository_id?stringThe provider's repository id (GitHub repository id, GitLab project id, Bitbucket repository UUID). Needs provider.
A page of raw findings.
application/jsondata*array<>next_cursor*string|nullmeta*curl -X GET "https://api.prodgator.io/v1/security/findings" \ -H "Authorization: Bearer plk_live_YOUR_KEY"{ "data": [ { "intel": { "canonical_id": "string", "kev": { "cve_id": "string", "date_added": "string", "due_date": "string", "ransomware": true }, "epss": { "score": 0, "percentile": 0, "date": "string" }, "cvss": { "version": "string", "score": 0, "vector": "string" }, "advisory_severity": "string", "withdrawn": "string", "fix_available": true, "as_of": { "kev": "string", "epss": "string", "advisory": "string" } }, "intel_at_detection": { "at": "string", "severity": "string", "scanner_score": 0, "cvss": { "version": "string", "score": 0, "vector": "string" }, "epss": { "score": 0, "percentile": 0, "date": "string" }, "kev": { "date_added": "string" }, "fix_available": true, "backfilled": true }, "id": "string", "origin": "alert", "source": "string", "scanner": "string", "scanner_version": "string", "kind": "dependency", "type": "string", "severity": "string", "state": "open", "title": "string", "description": "string", "native_url": "string", "repository": "string", "provider": "string", "repository_id": "string", "commit_sha": "string", "git_ref": "string", "category": "string", "tracked": true, "location": { "path": "string", "start_line": 0, "end_line": 0 }, "package_name": "string", "package_version": "string", "fixed_version": "string", "purl": "string", "vuln_ids": [ "string" ], "cwes": [ "string" ], "rule_id": "string", "secret_type": "string", "resource_name": "string", "first_seen_at": "2019-08-24T14:15:22Z", "last_seen_at": "2019-08-24T14:15:22Z", "issue_id": "string", "grouping_reason": { "code": "string", "detail": "string", "at": "2019-08-24T14:15:22Z" }, "category_reason": "string", "dismiss_reason": "string", "dismiss_comment": "string", "dismissed_by_name": "string", "dismissed_at": "2019-08-24T14:15:22Z", "dismissal_source": "prodgator" } ], "next_cursor": "string", "meta": { "since": "2019-08-24T14:15:22Z", "until": "2019-08-24T14:15:22Z", "retention_clamped": true }}Unique issues. member_count is the number of raw findings grouped into the issue and source_count the number of sources; list them with GET /v1/security/findings.
Required scope: read:security
apiKeyAuthorizationBearer <token>Send the key as Authorization: Bearer plk_live_.... No other header is accepted.
limit?integerPage size.
1 <= value <= 1000100cursor?stringThe next_cursor from the previous page. Reuse the same since and until.
A page of unique issues.
application/jsondata*array<>next_cursor*string|nullmeta*curl -X GET "https://api.prodgator.io/v1/security/issues" \ -H "Authorization: Bearer plk_live_YOUR_KEY"{ "data": [ { "intel": { "canonical_id": "string", "kev": { "cve_id": "string", "date_added": "string", "due_date": "string", "ransomware": true }, "epss": { "score": 0, "percentile": 0, "date": "string" }, "cvss": { "version": "string", "score": 0, "vector": "string" }, "advisory_severity": "string", "withdrawn": "string", "fix_available": true, "as_of": { "kev": "string", "epss": "string", "advisory": "string" } }, "id": "string", "synthetic": true, "kind": "dependency", "type": "string", "title": "string", "description": "string", "severity": "string", "status": "open", "repository": "string", "provider": "string", "repository_id": "string", "package_name": "string", "package_version": "string", "purl": "string", "vuln_ids": [ "string" ], "cwes": [ "string" ], "location": { "path": "string", "start_line": 0, "end_line": 0 }, "resource_name": "string", "first_seen_at": "2019-08-24T14:15:22Z", "last_seen_at": "2019-08-24T14:15:22Z", "sources": [ { "source": "string", "scanner": "string", "count": 0, "open": 0 } ], "member_count": 0, "source_count": 0, "open_member_count": 0, "split_from": "string", "dismiss_reason": "string", "dismiss_comment": "string", "dismissed_by_name": "string", "dismissed_at": "2019-08-24T14:15:22Z", "updated_at": "2019-08-24T14:15:22Z" } ], "next_cursor": "string", "meta": { "since": "2019-08-24T14:15:22Z", "until": "2019-08-24T14:15:22Z", "retention_clamped": true }}