getIssues
Retrieves all security issues detected during a scan. In addition to listing the identified issues, it provides detailed information about each one, in order to assess and address security risks effectively.
With this API you can:
Retrieve a comprehensive list of security issues.
Access in-depth details for each issue, including severity, affected components, remediation steps, and more.
Sort and filter issues based on custom criteria to prioritize and manage security risks efficiently.
Examples
query GetIssues($getIssuesInput: IssuesInput) {
getIssues(getIssuesInput: $getIssuesInput) {
issues {
importantSeverityBreakdown
overrideSeverityReason
highestOXCVESeverity
latestCommit {
date
commitLink
match
snippet
snippetLineNumber
}
additionalTabs {
type
aggItems {
callBranch
linkToExternalProduct
stars
forks
downloads
vulBySeverity
nameAndVer
sourceRepoName
sourceRepoLink
sourceCreationDate
sourceLastModifyDate
destinationRepoName
destinationRepoLink
destinationCreationDate
destinationLastModifyDate
destinationRepoVisibility
reasons
_id
url
additionalToolData
events
allEvents
pushType
sha
title
link
mergedBy
date
fileCount
diffInDays
reviewers
user
userLink
userAvatar
devOperation
devOperationDate
adminOperation
adminOperationDate
reviewOperation
reviewOperationDate
orgRole
earliestActivityDate
repoPermissions
adminLocation
email
pullRequestsCount
diffFromNowToCreatedAtInDays
username
accessLevel
createdAt
lastAccess
fileName
fileUri
startLine
endLine
match
snippet
commitLink
commitBy
region
eduVideoLink
resource
service
accountName
cloudEnv
secret
image
imageCreatedAt
pkgCount
dockerVer
os
binariesCount
tag
reputation
sha256
size
pushedAt
source
ruleId
realMatch
excludedByAlert
filePath
lockfile
accountId
snippetLineNumber
language
daysOpen
isFixAvailable
aggId
pkgName
installedVersion
fixedVersion
triggerPkgName
triggerPkgVersion
triggerPkgUpgradeVersion
dependencyType
branch
hashAggId
repo
repoCreator
lastCodeDate
lastAdminOperation
exclusionId
numberOfReposDomainAppear
layer
baseImage
imageLink
registryName
project
resourceGroup
location
parameter
test
cvss
evidence
dastUrl
method
parameterType
value
cluster
type
cloudType
k8sType
consoleLink
name
subscriptionId
stringifiedClusters
aggStatus
falsePositive {
isFalsePositive
comment
reportedBy
reportedAt
isCanceled
cancelComment
canceledBy
canceledAt
commentWhenCanceled
}
}
}
issueDetailsHeaders {
id
label
featureFlag
}
compliance {
standard
standardLink
control
category
description
categoryLink
controlLink
}
sbom {
id
references {
triggerPackage
location
locationLink
dependencyType
dependencyLevel
commit {
commitedAt
committerName
committerEmail
}
fileName
}
language
libraryName
libraryVersion
license
appName
location
dependencyType
source
appId
locationLink
appLink
pkgName
copyWriteInfo
copyWriteInfoLink
libLink
vulnerabilityCounts {
appox
critical
high
medium
low
info
}
triggerPackage
vulnerabilities {
issueId
oxSeverity
severityNumberFromTool
severityFromTool
cve
cveLink
cvsVer
cvssVersion
epss
percentile
libName
dependencyChain
libVersion
chainDepth
exploitInTheWild
exploitInTheWildLink
description
dateDiscovered
minorVerWithFix
majorVerWithFix
exploitRequirement
exploitCode
originalSeverity
}
latestVersion
latestVersionDate
stars
forks
openIssues
packageManager
packageManagerLink
maintainers
contributors
downloads
sourceLink
notPopular
licenseIssue
malicious
malwareType
osVname
notMaintained
isDeprecated
notImported
notUpdated
dependencyLevel
requestId
licenseLink
artifactInSbomLibs {
image
imageLink
imageCreatedAt
sha
os
osVersion
baseImage
baseImageVersion
tag
layer
registryName
source
}
sha
maintainersList {
name
email
}
}
dependencyGraph {
nodes {
id
name
width
height
vulnerable
}
allNodes {
id
name
width
height
vulnerable
}
edges {
v
w
}
allEdges {
v
w
}
}
groupId
name
mainTitle
secondTitle
scanId
sla {
daysPastSLA
status
}
issueUpdatedAt
scanDate
description
impact
severity
owners
ownerEmails
occurrences
score {
value
comments
}
orgConScore
connector
learnMore
extraInfo {
key
val
value
}
resource {
id
type
}
app {
id
name
businessPriority
riskScore
secPosture
type
typeComments
applicationFlows {
artifacts {
type
name
hashType
system
subType
hash
size
date
location {
runBy
foundBy
foundIn
link
}
linkName
k8sType
cluster
region
}
cloudDeployments {
type
subType
name
hash
hashType
link
location {
runBy
foundBy
foundIn
link
}
k8sType
imageName
date
cluster
region
}
cicdInfo {
type
system
latestDate
lastMonthJobCount
location {
runBy
foundBy
foundIn
link
}
}
orchestrators {
type
name
hashType
system
hash
size
date
location {
runBy
foundBy
foundIn
link
}
}
kubernetes {
type
name
hashType
system
hash
subType
size
date
location {
runBy
foundBy
foundIn
link
}
}
repository {
type
system
date
location {
runBy
foundBy
foundIn
link
}
}
}
fakeApp
originBranchName
repoId
organization
repoName
owners {
name
email
roles
}
credentialsId
}
policy {
id
name
detailedDescription
}
issueId
category {
name
categoryId
subCategoryName
subCategoryComment
}
aggregations {
type
summary {
summary
comment
}
columns {
columns {
header
key
tooltip
href
type
}
comment
}
items {
callBranch
linkToExternalProduct
stars
forks
downloads
vulBySeverity
nameAndVer
sourceRepoName
sourceRepoLink
sourceCreationDate
sourceLastModifyDate
destinationRepoName
destinationRepoLink
destinationCreationDate
destinationLastModifyDate
destinationRepoVisibility
reasons
_id
url
additionalToolData
events
allEvents
pushType
sha
title
link
mergedBy
date
fileCount
diffInDays
reviewers
user
userLink
userAvatar
devOperation
devOperationDate
adminOperation
adminOperationDate
reviewOperation
reviewOperationDate
orgRole
earliestActivityDate
repoPermissions
adminLocation
email
pullRequestsCount
diffFromNowToCreatedAtInDays
username
accessLevel
createdAt
lastAccess
fileName
fileUri
startLine
endLine
match
snippet
commitLink
commitBy
region
eduVideoLink
resource
service
accountName
cloudEnv
secret
image
imageCreatedAt
pkgCount
dockerVer
os
binariesCount
tag
reputation
sha256
size
pushedAt
source
ruleId
realMatch
excludedByAlert
filePath
lockfile
accountId
snippetLineNumber
language
daysOpen
isFixAvailable
aggId
pkgName
installedVersion
fixedVersion
triggerPkgName
triggerPkgVersion
triggerPkgUpgradeVersion
dependencyType
branch
hashAggId
repo
repoCreator
lastCodeDate
lastAdminOperation
exclusionId
numberOfReposDomainAppear
layer
baseImage
imageLink
registryName
project
resourceGroup
location
parameter
test
cvss
evidence
dastUrl
method
parameterType
value
cluster
type
cloudType
k8sType
consoleLink
name
subscriptionId
stringifiedClusters
aggStatus
falsePositive {
isFalsePositive
comment
reportedBy
reportedAt
isCanceled
cancelComment
canceledBy
canceledAt
commentWhenCanceled
}
}
}
recommendation
violationInfoTitle
sourceTools
ruleId
fixes {
settingType
tooltip
description
warning
confirmation
inputs {
type
name
options {
name
selected
metadata
info
displayName
isDisabled
}
multiSelect
maxSelect
minSelect
displayName
}
}
fixAppliedDeatils {
appliedBy
appliedDate
}
cwe
fixLink
cweList {
name
description
url
}
dependencyChain
publicExploitLink
createdAt
tickets {
provider
ticketId
createdBy
issueId
issueName
appName
appId
category
assignee
reporter
link
project
issueType
key
}
slackNotification {
channelName
timestamp
}
messages {
messagingVendor
recipients {
name
id
type
}
createdAt
}
fixIssue {
fixType
fixTitle
fixDescription
isFixApplied
fixAppliedBy
sourceControlType
fixDate
}
requestContent
responseContent
autoFix {
fixType
fixTitle
fixDescription
isFixApplied
fixAppliedBy
sourceControlType
fixDate
}
lowerSeverityReason
severityChange
originalToolSeverity
scaVulnerabilities {
issueId
oxSeverity
severityNumberFromTool
severityFromTool
cve
cveLink
cvsVer
cvssVersion
epss
percentile
libName
dependencyChain
libVersion
chainDepth
exploitInTheWild
exploitInTheWildLink
description
dateDiscovered
minorVerWithFix
majorVerWithFix
exploitRequirement
exploitCode
originalSeverity
}
dependencyGraphNodes {
id
name
width
height
vulnerable
}
dependencyGraphEdges {
v
w
}
scaTriggerPkg
scaTriggerPkgs {
scaTriggerPkg
fileName
}
pkgSemanticVersion
severityChangeReason
severityChangedReason {
changeNumber
withoutAutoNumbering
evidenceLabel
reason
shortName
changeCategory
extraInfo {
key
value
link
snippet {
snippetLineNumber
language
text
fileName
}
iconLink
callBranch
}
extraInfoContainer {
layerSha
layerNum
artifactName
sha
registryName
}
}
resolvedIssueDate
isPRAvailable
cicdFields {
issueStatus
sourceBranch
targetBranch
jobId
jobTriggeredAt
jobTriggeredAtDate
jobTriggeredBy
jobTriggeredReason
jobUrl
pullRequestId
pullRequestUrl
enforcement
excludedByAlert
cicdEventType
}
comment
excludedByAlert
excludedByPolicy
excludedByApp
countRule
exclusionId
languageInfo {
name
version
}
isMonoRepoChild
monoRepoParent
isFixAvailable
isFixApplied
isGPTFixAvailable
oscarData {
name
description
url
id
}
gptInfo {
gptResponse
user
createdAt
}
prDeatils {
sourceControlType
issueId
appId
repo
prId
prURL
prBranchName
commitMessage
commiter
comment
date
prTitle
prBody
prStatus
prApprover
prReviewer
prMergeTime
}
tags {
tagId
name
email
displayName
tagType
createdBy
purpose
deploymentModel
}
originalSeverity
overrideSeverity
isFalsePositive
falsePositiveComment
isCanceledFalsePositive
cancelFalsePositiveComment
falsePositiveDetails {
isAggregationsMixed
canceledBy
reportedBy
commentWhenCanceled
aggregationsStatus
}
issueStatus
scanIssueStatus
resolvedReason
resolvedDetails
resolvedReasonDetails {
description
}
disappearedReason
disappearedDetails
disappearedReasonDetails {
description
}
disappearedDate
correlatedIssueId
correlatedRegistry
scaFixType
previousSeverity {
severity
severityChangedDate
}
version
severityFactorsDiff {
shortName
change
status
}
exposedByApiItems {
apiId
codeLocations {
link
callBranch
}
}
originBranchName
exclusionComment
exclusionExpiredAt
problematicPkg
serverlessDeploymentOperation {
userIdentity {
type
principalId
arn
accountId
accessKeyId
sessionContext {
sessionIssuer {
type
principalId
arn
accountId
userName
}
attributes {
creationDate
mfaAuthenticated
}
}
}
deploymentTime
sourceIPAddress
userAgent
connectedFromConsole
location
linkToCode
functionName
functionArn
internalFunctionName
cloudRegion
version
revisionId
codeSha256
entryPoint
codeSize
memorySize
timeout
runtime
runtimeVersionConfig {
runtimeVersionArn
}
architectures
role
recipientAccountId
description
}
}
totalIssues
totalFilteredIssues
totalResolvedIssues
offset
totalActiveIssues
selectedPosition
topOffset
}
}
Variables
This is an example input showing all available input fields. Only fields marked as required in the schema are mandatory.
{
"getIssuesInput": {
"scanID": "",
"limit": 100,
"page": 1,
"search": [
{
"fieldName": "example",
"value": ["example"]
}
],
"offset": 0,
"sort": {
"fields": ["Category"],
"order": ["ASC"]
},
"owners": ["example"],
"tagIds": ["example"],
"inventoryFilters": ["New"],
"dateRange": {
"from": 1749000000000,
"to": 1749900000000
},
"limitAggItems": 42,
"offsetAggItems": 42,
"ignoreEnvCheck": true,
"exportsOptions": {
"flattenAgg": true,
"isDemoEnabled": true,
"columns": [
{
"key": "Severity",
"name": "SomeName"
}
],
"rowsLimit": 42
},
"issueId": "30966426-oxPolicy_securityCloudScan_100-example",
"topOffset": 42,
"topLevelSearch": "example",
"scrollDirection": "example",
"openItems": ["digest"],
"conditionalFilters": [
{
"condition": "AND",
"fieldName": "digest",
"values": ["example"],
"greaterThan": 13.37,
"lessThan": 13.37
}
],
"getLatestStableData": true,
"isCloudResourcesTabEnabled": true
}
}
Arguments
You can use the following argument(s) to customize your getIssues
query.
getIssuesInput IssuesInput
Parameters for filtering, sorting, and paginating the issues list, including search criteria, severity filters, and display preferences
scanID String
limit Int!
page Int
search [AutoCompleteSearch]
offset Int!
filters IssueFilters
sort IssuesSort
owners [String]
tagIds [String]
inventoryFilters [InventoryTypes]
dateRange DateRange
limitAggItems Int
offsetAggItems Int
ignoreEnvCheck Boolean
exportsOptions IssuesExportOptions
issueId String
topOffset Int
topLevelSearch String
scrollDirection String
openItems [FilterTypes]
conditionalFilters [ConditionalFilters]
getLatestStableData Boolean
isCloudResourcesTabEnabled Boolean
Fields
Return type: IssuesResponse
You can use the following field(s) to specify what information your getIssues
query will return. Please note that some fields may have their own subfields.
issues [Issue]
List of issues or alerts associated with the query
importantSeverityBreakdown [String]
isCVERelated Boolean
overrideSeverityReason String
highestOXCVESeverity String
latestCommit LatestCommit
additionalTabs [AdditionalTab]
issueDetailsHeaders [IssueDetailsTabs]
compliance [ComplianceItem]
sbom SbomLib
dependencyGraph SbomDependencyGraphResponse
groupId String
name String
mainTitle String
secondTitle String
scanId String
created Float
sla SlaData
issueUpdatedAt Float
scanDate Float
description String
impact String
severity String
owners [String]
ownerEmails [String]
occurrences Int
score IssueScore
orgConScore Float
connector String
learnMore [String]
extraInfo [ExtraInfo]
resource IssueResource
app IAppsInfo
policy IPolicy
issueId String
category ICategory
aggregations IAggregations
recommendation String
violationInfoTitle String
sourceTools [String]
ruleId String
fixes PolicyFix
fixAppliedDeatils FixAppliedDeatils
cwe [String]
fixLink String
cweList [CweList]
dependencyChain [String]
publicExploitLink String
createdAt Float
tickets [Ticket]
slackNotification [SlackNotification]
messages [IssueMessage]
fixIssue FixIssue
requestContent String
responseContent String
autoFix FixIssue
lowerSeverityReason [String]
severityChange String
originalToolSeverity String
scaVulnerabilities [SCAVulnerability]
dependencyGraphNodes [DependencyNode]
dependencyGraphEdges [DependencyEdge]
scaTriggerPkg String
scaTriggerPkgs [TriggerPackage]
pkgSemanticVersion String
graphExist Boolean
indirectSupported Boolean
severityChangeReason [String]
severityChangedReason [SeverityChangedReason]
resolvedIssueDate Float
isPRAvailable Boolean
cicdFields CICDFields
comment String
excludedByAlert Boolean
excludedByPolicy Boolean
excludedByApp Boolean
countRule CountRule
exclusionId String
languageInfo LanguageInfo
isMonoRepoChild Boolean
monoRepoParent String
isFixAvailable Boolean
isFixApplied Boolean
isGPTFixAvailable Boolean
oscarData [OscarItem]
gptInfo GPTInfo
prDeatils PullRequest
tags [AppTag]
originalSeverity Int
overrideSeverity Boolean
isFalsePositive Boolean
falsePositiveComment String
isCanceledFalsePositive Boolean
cancelFalsePositiveComment String
falsePositiveDetails FalsePositiveDetails
issueStatus IssueStatus
scanIssueStatus IssueStatus
resolvedReason String
resolvedDetails String
resolvedReasonDetails ReasonDetails
disappearedReason String
disappearedDetails String
disappearedReasonDetails ReasonDetails
disappearedDate Float
correlatedIssueId String
correlatedRegistry String
scaFixType ScaFixType
previousSeverity PrevSeverity
version String
severityFactorsDiff [SeverityFactorsDiff]
exposedByApiItems [ExposedByApiItem]
originBranchName String
exclusionComment String
exclusionExpiredAt Date
problematicPkg String
serverlessDeploymentOperation ServerlessDeploymentOperation
totalIssues Int
Total count of issues without any filters applied
totalFilteredIssues Int
Total count of issues considering applied filters
totalResolvedIssues Int
Total count of resolved issues
offset Int
Offset value to skip records in paginated responses
totalActiveIssues Int
Total count of active issues
selectedPosition Int
Selected position in the issue list
topOffset Int
Offset value used for top-level pagination
Last updated