Palo Alto Networks Coderepos Ci API

The Coderepos-Ci API from Palo Alto Networks — 2 operation(s) for coderepos-ci.

OpenAPI Specification

palo-alto-networks-coderepos-ci-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Palo Alto Networks Coderepos Ci API
  version: '1.0'
  description: 'Operations tagged Coderepos-Ci across 4 of this provider''s published API definitions: palo-alto-compute-34-03-openapi-34-03-138-sh-openapi.json, palo-alto-compute-openapi-34-04-145-sh-openapi.json, palo-alto-cwpp-34-03-openapi-34-03-138-saas-openapi.json, palo-alto-cwpp-openapi-34-04-145-saas-openapi.json. Each path carries the servers of the definition it was published in.'
servers:
- url: PATH_TO_CONSOLE
tags:
- name: Coderepos-Ci
paths:
  /api/v34.03/coderepos-ci/evaluate:
    post:
      description: 'Resolve Code Repos. POST /api/v34.03/coderepos-ci/evaluate on the Coderepos-Ci API. Takes an optional request body. Documented responses: 200.'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/coderepos.ScanResult'
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/coderepos.ScanResult'
          description: ScanResult holds a specific repository data
        default:
          description: ''
      tags:
      - Coderepos-Ci
      x-prisma-cloud-target-env:
        permission: monitorCI
      operationId: post-coderepos-ci-evaluate
      summary: Resolve Code Repos
      x-description-source: desc/coderepos-ci/post_resolve.md
  /api/v34.04/coderepos-ci/evaluate:
    post:
      description: 'Resolve Code Repos. POST /api/v34.04/coderepos-ci/evaluate on the Coderepos-Ci API. Takes an optional request body. Documented responses: 200.'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/coderepos.ScanResult'
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/coderepos.ScanResult'
          description: ScanResult holds a specific repository data
        default:
          description: ''
      tags:
      - Coderepos-Ci
      x-prisma-cloud-target-env:
        permission: monitorCI
      operationId: post-coderepos-ci-evaluate
      summary: Resolve Code Repos
      x-description-source: desc/coderepos-ci/post_resolve.md
components:
  schemas:
    vuln.Application:
      description: Application represents a detected application
      properties:
        installedFromPackage:
          description: 'Indicates that the app was installed as an OS package.

            '
          type: boolean
        knownVulnerabilities:
          description: 'Total number of vulnerabilities for this application.

            '
          type: integer
        layerTime:
          description: 'Image layer to which the application belongs - layer creation time.

            '
          format: int64
          type: integer
        md5:
          description: 'MD5 is the md5sum of the app.

            '
          type: string
        name:
          description: 'Name of the application.

            '
          type: string
        originPackageName:
          description: 'OriginPackageName is the name of the app origin package.

            '
          type: string
        path:
          description: 'Path of the detected application.

            '
          type: string
        rpmModule:
          description: 'RPMModule represents the RPM module in which this application is included.

            '
          type: string
        service:
          description: 'Service indicates whether the application is installed as a service.

            '
          type: boolean
        version:
          description: 'Version of the application.

            '
          type: string
      type: object
    vulnerability.ExploitType:
      description: ExploitType represents the source of an exploit
      enum:
      - - ''
        - exploit-db
        - exploit-windows
        - cisa-kev
      type: string
    license.SPDXLicense:
      description: SPDXLicense represents a SPDX license ID
      enum:
      - - 0BSD
        - AAL
        - ADSL
        - AFL-1.1
        - AFL-1.2
        - AFL-2.0
        - AFL-2.1
        - AFL-3.0
        - AGPL-1.0
        - AGPL-1.0-only
        - AGPL-1.0-or-later
        - AGPL-3.0
        - AGPL-3.0-only
        - AGPL-3.0-or-later
        - AMDPLPA
        - AML
        - AMPAS
        - ANTLR-PD
        - ANTLR-PD-fallback
        - APAFML
        - APL-1.0
        - APSL-1.0
        - APSL-1.1
        - APSL-1.2
        - APSL-2.0
        - Abstyles
        - Adobe-2006
        - Adobe-Glyph
        - Afmparse
        - Aladdin
        - Apache-1.0
        - Apache-1.1
        - Apache-2.0
        - Artistic-1.0
        - Artistic-1.0-Perl
        - Artistic-1.0-cl8
        - Artistic-2.0
        - BSD-1-Clause
        - BSD-2-Clause
        - BSD-2-Clause-FreeBSD
        - BSD-2-Clause-NetBSD
        - BSD-2-Clause-Patent
        - BSD-2-Clause-Views
        - BSD-3-Clause
        - BSD-3-Clause-Attribution
        - BSD-3-Clause-Clear
        - BSD-3-Clause-LBNL
        - BSD-3-Clause-No-Nuclear-License
        - BSD-3-Clause-No-Nuclear-License-2014
        - BSD-3-Clause-No-Nuclear-Warranty
        - BSD-3-Clause-Open-MPI
        - BSD-4-Clause
        - BSD-4-Clause-UC
        - BSD-Protection
        - BSD-Source-Code
        - BSL-1.0
        - BUSL-1.1
        - Bahyph
        - Barr
        - Beerware
        - BitTorrent-1.0
        - BitTorrent-1.1
        - BlueOak-1.0.0
        - Borceux
        - CAL-1.0
        - CAL-1.0-Combined-Work-Exception
        - CATOSL-1.1
        - CC-BY-1.0
        - CC-BY-2.0
        - CC-BY-2.5
        - CC-BY-3.0
        - CC-BY-3.0-AT
        - CC-BY-3.0-US
        - CC-BY-4.0
        - CC-BY-NC-1.0
        - CC-BY-NC-2.0
        - CC-BY-NC-2.5
        - CC-BY-NC-3.0
        - CC-BY-NC-4.0
        - CC-BY-NC-ND-1.0
        - CC-BY-NC-ND-2.0
        - CC-BY-NC-ND-2.5
        - CC-BY-NC-ND-3.0
        - CC-BY-NC-ND-3.0-IGO
        - CC-BY-NC-ND-4.0
        - CC-BY-NC-SA-1.0
        - CC-BY-NC-SA-2.0
        - CC-BY-NC-SA-2.5
        - CC-BY-NC-SA-3.0
        - CC-BY-NC-SA-4.0
        - CC-BY-ND-1.0
        - CC-BY-ND-2.0
        - CC-BY-ND-2.5
        - CC-BY-ND-3.0
        - CC-BY-ND-4.0
        - CC-BY-SA-1.0
        - CC-BY-SA-2.0
        - CC-BY-SA-2.0-UK
        - CC-BY-SA-2.5
        - CC-BY-SA-3.0
        - CC-BY-SA-3.0-AT
        - CC-BY-SA-4.0
        - CC-PDDC
        - CC0-1.0
        - CDDL-1.0
        - CDDL-1.1
        - CDLA-Permissive-1.0
        - CDLA-Sharing-1.0
        - CECILL-1.0
        - CECILL-1.1
        - CECILL-2.0
        - CECILL-2.1
        - CECILL-B
        - CECILL-C
        - CERN-OHL-1.1
        - CERN-OHL-1.2
        - CERN-OHL-P-2.0
        - CERN-OHL-S-2.0
        - CERN-OHL-W-2.0
        - CNRI-Jython
        - CNRI-Python
        - CNRI-Python-GPL-Compatible
        - CPAL-1.0
        - CPL-1.0
        - CPOL-1.02
        - CUA-OPL-1.0
        - Caldera
        - ClArtistic
        - Condor-1.1
        - Crossword
        - CrystalStacker
        - Cube
        - D-FSL-1.0
        - DOC
        - DSDP
        - Dotseqn
        - ECL-1.0
        - ECL-2.0
        - EFL-1.0
        - EFL-2.0
        - EPICS
        - EPL-1.0
        - EPL-2.0
        - EUDatagrid
        - EUPL-1.0
        - EUPL-1.1
        - EUPL-1.2
        - Entessa
        - ErlPL-1.1
        - Eurosym
        - FSFAP
        - FSFUL
        - FSFULLR
        - FTL
        - Fair
        - Frameworx-1.0
        - FreeImage
        - GFDL-1.1
        - GFDL-1.1-invariants-only
        - GFDL-1.1-invariants-or-later
        - GFDL-1.1-no-invariants-only
        - GFDL-1.1-no-invariants-or-later
        - GFDL-1.1-only
        - GFDL-1.1-or-later
        - GFDL-1.2
        - GFDL-1.2-invariants-only
        - GFDL-1.2-invariants-or-later
        - GFDL-1.2-no-invariants-only
        - GFDL-1.2-no-invariants-or-later
        - GFDL-1.2-only
        - GFDL-1.2-or-later
        - GFDL-1.3
        - GFDL-1.3-invariants-only
        - GFDL-1.3-invariants-or-later
        - GFDL-1.3-no-invariants-only
        - GFDL-1.3-no-invariants-or-later
        - GFDL-1.3-only
        - GFDL-1.3-or-later
        - GL2PS
        - GLWTPL
        - GPL-1.0
        - GPL-1.0+
        - GPL-1.0-only
        - GPL-1.0-or-later
        - GPL-2.0
        - GPL-2.0+
        - GPL-2.0-only
        - GPL-2.0-or-later
        - GPL-2.0-with-GCC-exception
        - GPL-2.0-with-autoconf-exception
        - GPL-2.0-with-bison-exception
        - GPL-2.0-with-classpath-exception
        - GPL-2.0-with-font-exception
        - GPL-3.0
        - GPL-3.0+
        - GPL-3.0-only
        - GPL-3.0-or-later
        - GPL-3.0-with-GCC-exception
        - GPL-3.0-with-autoconf-exception
        - Giftware
        - Glide
        - Glulxe
        - HPND
        - HPND-sell-variant
        - HTMLTIDY
        - HaskellReport
        - Hippocratic-2.1
        - IBM-pibs
        - ICU
        - IJG
        - IPA
        - IPL-1.0
        - ISC
        - ImageMagick
        - Imlib2
        - Info-ZIP
        - Intel
        - Intel-ACPI
        - Interbase-1.0
        - JPNIC
        - JSON
        - JasPer-2.0
        - LAL-1.2
        - LAL-1.3
        - LGPL-2.0
        - LGPL-2.0+
        - LGPL-2.0-only
        - LGPL-2.0-or-later
        - LGPL-2.1
        - LGPL-2.1+
        - LGPL-2.1-only
        - LGPL-2.1-or-later
        - LGPL-3.0
        - LGPL-3.0+
        - LGPL-3.0-only
        - LGPL-3.0-or-later
        - LGPLLR
        - LPL-1.0
        - LPL-1.02
        - LPPL-1.0
        - LPPL-1.1
        - LPPL-1.2
        - LPPL-1.3a
        - LPPL-1.3c
        - Latex2e
        - Leptonica
        - LiLiQ-P-1.1
        - LiLiQ-R-1.1
        - LiLiQ-Rplus-1.1
        - Libpng
        - Linux-OpenIB
        - MIT
        - MIT-0
        - MIT-CMU
        - MIT-advertising
        - MIT-enna
        - MIT-feh
        - MIT-open-group
        - MITNFA
        - MPL-1.0
        - MPL-1.1
        - MPL-2.0
        - MPL-2.0-no-copyleft-exception
        - MS-PL
        - MS-RL
        - MTLL
        - MakeIndex
        - MirOS
        - Motosoto
        - MulanPSL-1.0
        - MulanPSL-2.0
        - Multics
        - Mup
        - NASA-1.3
        - NBPL-1.0
        - NCGL-UK-2.0
        - NCSA
        - NGPL
        - NIST-PD
        - NIST-PD-fallback
        - NLOD-1.0
        - NLPL
        - NOSL
        - NPL-1.0
        - NPL-1.1
        - NPOSL-3.0
        - NRL
        - NTP
        - NTP-0
        - Naumen
        - Net-SNMP
        - NetCDF
        - Newsletr
        - Nokia
        - Noweb
        - Nunit
        - O-UDA-1.0
        - OCCT-PL
        - OCLC-2.0
        - ODC-By-1.0
        - ODbL-1.0
        - OFL-1.0
        - OFL-1.0-RFN
        - OFL-1.0-no-RFN
        - OFL-1.1
        - OFL-1.1-RFN
        - OFL-1.1-no-RFN
        - OGC-1.0
        - OGL-Canada-2.0
        - OGL-UK-1.0
        - OGL-UK-2.0
        - OGL-UK-3.0
        - OGTSL
        - OLDAP-1.1
        - OLDAP-1.2
        - OLDAP-1.3
        - OLDAP-1.4
        - OLDAP-2.0
        - OLDAP-2.0.1
        - OLDAP-2.1
        - OLDAP-2.2
        - OLDAP-2.2.1
        - OLDAP-2.2.2
        - OLDAP-2.3
        - OLDAP-2.4
        - OLDAP-2.5
        - OLDAP-2.6
        - OLDAP-2.7
        - OLDAP-2.8
        - OML
        - OPL-1.0
        - OSET-PL-2.1
        - OSL-1.0
        - OSL-1.1
        - OSL-2.0
        - OSL-2.1
        - OSL-3.0
        - OpenSSL
        - PDDL-1.0
        - PHP-3.0
        - PHP-3.01
        - PSF-2.0
        - Parity-6.0.0
        - Parity-7.0.0
        - Plexus
        - PolyForm-Noncommercial-1.0.0
        - PolyForm-Small-Business-1.0.0
        - PostgreSQL
        - Python-2.0
        - QPL-1.0
        - Qhull
        - RHeCos-1.1
        - RPL-1.1
        - RPL-1.5
        - RPSL-1.0
        - RSA-MD
        - RSCPL
        - Rdisc
        - Ruby
        - SAX-PD
        - SCEA
        - SGI-B-1.0
        - SGI-B-1.1
        - SGI-B-2.0
        - SHL-0.5
        - SHL-0.51
        - SISSL
        - SISSL-1.2
        - SMLNJ
        - SMPPL
        - SNIA
        - SPL-1.0
        - SSH-OpenSSH
        - SSH-short
        - SSPL-1.0
        - SWL
        - Saxpath
        - Sendmail
        - Sendmail-8.23
        - SimPL-2.0
        - Sleepycat
        - Spencer-86
        - Spencer-94
        - Spencer-99
        - StandardML-NJ
        - SugarCRM-1.1.3
        - TAPR-OHL-1.0
        - TCL
        - TCP-wrappers
        - TMate
        - TORQUE-1.1
        - TOSL
        - TU-Berlin-1.0
        - TU-Berlin-2.0
        - UCL-1.0
        - UPL-1.0
        - Unicode-DFS-2015
        - Unicode-DFS-2016
        - Unicode-TOU
        - Unlicense
        - VOSTROM
        - VSL-1.0
        - Vim
        - W3C
        - W3C-19980720
        - W3C-20150513
        - WTFPL
        - Watcom-1.0
        - Wsuipa
        - X11
        - XFree86-1.1
        - XSkat
        - Xerox
        - Xnet
        - YPL-1.0
        - YPL-1.1
        - ZPL-1.1
        - ZPL-2.0
        - ZPL-2.1
        - Zed
        - Zend-2.0
        - Zimbra-1.3
        - Zimbra-1.4
        - Zlib
        - blessing
        - bzip2-1.0.5
        - bzip2-1.0.6
        - copyleft-next-0.3.0
        - copyleft-next-0.3.1
        - curl
        - diffmark
        - dvipdfm
        - eCos-2.0
        - eGenix
        - etalab-2.0
        - gSOAP-1.3b
        - gnuplot
        - iMatix
        - libpng-2.0
        - libselinux-1.0
        - libtiff
        - mpich2
        - psfrag
        - psutils
        - wxWindows
        - xinetd
        - xpp
        - zlib-acknowledgement
      type: string
    shared.ImageTag:
      description: ImageTag represents an image repository and its associated tag or registry digest
      properties:
        digest:
          description: 'Image digest (requires V2 or later registry).

            '
          type: string
        id:
          description: 'ID of the image.

            '
          type: string
        registry:
          description: 'Registry name to which the image belongs.

            '
          type: string
        repo:
          description: 'Repository name to which the image belongs.

            '
          type: string
        tag:
          description: 'Image tag.

            '
          type: string
      type: object
    common.CloudMetadata:
      description: CloudMetadata is the metadata for a cloud provider managed asset (e.g., as part of AWS/GCP/Azure/OCI)
      properties:
        accountID:
          description: 'Cloud account ID.

            '
          type: string
        awsExecutionEnv:
          description: 'AWS execution environment (e.g. EC2/Fargate).

            '
          type: string
        azure:
          $ref: '#/components/schemas/common.AzureMetadata'
        gcp:
          $ref: '#/components/schemas/common.GCPCloudMetadata'
        image:
          description: 'The name of the image the cloud managed host or container is based on.

            '
          type: string
        labels:
          description: 'Cloud provider metadata labels.

            '
          items:
            $ref: '#/components/schemas/common.ExternalLabel'
          type: array
        name:
          description: 'Resource name.

            '
          type: string
        ociTenantID:
          description: 'OCI Tenant ID.

            '
          type: string
        provider:
          $ref: '#/components/schemas/common.CloudProvider'
        region:
          description: 'Resource''s region.

            '
          type: string
        resourceID:
          description: 'Unique ID of the resource.

            '
          type: string
        resourceURL:
          description: 'Server-defined URL for the resource.

            '
          type: string
        type:
          description: 'Instance type.

            '
          type: string
        vmID:
          description: 'Azure unique vm ID.

            '
          type: string
        vmImageID:
          description: 'VMImageID holds the VM instance''s image ID.

            '
          type: string
      type: object
    common.NetworkDeviceIP:
      description: NetworkDeviceIP represents a network device name and address pair
      properties:
        ip:
          description: 'Network device IPv4 address.

            '
          type: string
        name:
          description: 'Network device name.

            '
          type: string
      type: object
    common.Color:
      description: Color is a hexadecimal representation of color code value
      type: string
    common.ACIMetadata:
      properties:
        containerGroup:
          description: '.

            '
          type: string
      type: object
    secrets.SecretScanMetrics:
      description: SecretScanMetrics represents metrics collected during secret scan
      properties:
        failedScans:
          description: 'FailedScans represents number of failed scans caused by scanner errors.

            '
          format: int64
          type: integer
        foundSecrets:
          description: 'FoundSecrets represents number of detected secrets.

            '
          type: integer
        scanTime:
          description: 'ScanTime represents cumulative secret scan time in microseconds.

            '
          format: int64
          type: integer
        scanTimeouts:
          description: 'ScanTimeouts represents number of failed scans caused by timeout.

            '
          format: int64
          type: integer
        scannedFileSize:
          description: 'ScannedFileSize represents accumulated size of scanned files.

            '
          format: int64
          type: integer
        scannedFiles:
          description: 'ScannedFiles represents number of text files scanned for secrets.

            '
          format: int64
          type: integer
        totalBytes:
          description: 'TotalBytes represents accumulated file size.

            '
          format: int64
          type: integer
        totalFiles:
          description: 'TotalFiles represents number of files read for secrets.

            '
          format: int64
          type: integer
        totalTime:
          description: 'TotalTime represents the total time in microseconds.

            '
          format: int64
          type: integer
        typesCount:
          additionalProperties:
            $ref: '#/components/schemas/int'
          description: 'TypesCount represents distribution of secrets by its type.

            '
          type: object
      type: object
    shared.Packages:
      description: Packages is a collection of packages
      properties:
        pkgs:
          description: 'List of packages.

            '
          items:
            $ref: '#/components/schemas/shared.Package'
          type: array
        pkgsType:
          $ref: '#/components/schemas/packages.Type'
      type: object
    vuln.ComplianceTemplate:
      description: ComplianceTemplate represents the compliance template
      enum:
      - - PCI
        - HIPAA
        - NIST SP 800-190
        - GDPR
        - DISA STIG
      type: string
    shared.FileDetails:
      description: FileDetails contains file details as the file path, hash checksum
      properties:
        md5:
          description: 'Hash sum of the file using md5.

            '
          type: string
        original_file_location:
          description: 'Path of the original file in a case of archive analysis.

            '
          type: string
        path:
          description: 'Path of the file.

            '
          type: string
        sha1:
          description: 'Hash sum of the file using SHA-1.

            '
          type: string
        sha256:
          description: 'Hash sum of the file using SHA256.

            '
          type: string
      type: object
    vuln.SecretType:
      description: SecretType represents a secret type
      enum:
      - - AWS Access Key ID
        - AWS Secret Key
        - AWS MWS Auth Token
        - Azure Storage Account Access Key
        - Azure Service Principal
        - GCP Service Account Auth Key
        - Private Encryption Key
        - Public Encryption Key
        - PEM X509 Certificate Header
        - SSH Authorized Keys
        - Artifactory API Token
        - Artifactory Password
        - Basic Auth Credentials
        - Mailchimp Access Key
        - NPM Token
        - Slack Token
        - Slack Webhook
        - Square OAuth Secret
        - Notion Integration Token
        - Airtable API Key
        - Atlassian Oauth2 Keys
        - CircleCI Personal Token
        - Databricks Authentication Token
        - GitHub Token
        - GitLab Token
        - Google API key
        - Grafana Token
        - Python Package Index Key (PYPI)
        - Typeform API Token
        - Scalr Token
        - Braintree Access Token
        - Braintree Payments Key
        - Paypal Token Key
        - Braintree Payments ID
        - Datadog Client Token
        - ClickUp Personal API Token
        - OpenAI API Key
        - Java DB Connectivity (JDBC)
        - MongoDB
        - .Net SQL Server
      type: string
    coderepos.PkgDependency:
      description: PkgDependency represents a required package
      properties:
        devDependency:
          description: 'Indicates if this dependency is used only for the development of the package (true) or not (false).

            '
          type: boolean
        lastResolved:
          description: 'Date/time of the last version resolution. If the value is zero, it means the version is explicit and does not require resolving.

            '
          format: date-time
          type: string
        licenseSeverity:
          description: 'Maximum severity of the detected licenses according to the compliance policy.

            '
          type: string
        licenses:
          description: 'Detected licenses of the dependant package.

            '
          items:
            $ref: '#/components/schemas/license.SPDXLicense'
          type: array
        name:
          description: 'Package name that the dependency refers to.

            '
          type: string
        rawRequirement:
          description: 'Line in which the package is declared.

            '
          type: string
        unsupported:
          description: 'Indicates if this package is unsupported by the remote package manager DB (e.g., due to a bad name or private package) (true) or not (false).

            '
          type: boolean
        version:
          description: 'Package version, either explicitly specified in a manifest or resolved by the scanner.

            '
          type: string
        vulnerabilities:
          description: 'Vulnerabilities in the package.

            '
          items:
            $ref: '#/components/schemas/vuln.Vulnerability'
          type: array
      type: object
    common.CloudRunMetadata:
      properties:
        revision:
          description: '.

            '
          type: string
        service:
          description: '.

            '
          type: string
      type: object
    vulnerability.RiskFactors:
      additionalProperties:
        $ref: '#/components/schemas/string'
      description: RiskFactors maps the existence of vulnerability risk factors
      type: object
    vulnerability.Type:
      description: Type represents the vulnerability type
      enum:
      - - container
        - image
        - host_config
        - daemon_config
        - daemon_config_files
        - security_operations
        - k8s_master
        - k8s_worker
        - k8s_federation
        - linux
        - windows
        - istio
        - serverless
        - custom
        - docker_stig
        - openshift_master
        - openshift_worker
        - application_control_linux
        - gke_worker
        - image_malware
        - host_malware
        - aks_worker
        - eks_worker
        - image_secret
        - host_secret
      type: string
    common.CloudProvider:
      description: CloudProvider specifies the cloud provider name
      enum:
      - - aws
        - azure
        - gcp
        - alibaba
        - oci
        - others
      type: string
    common.GCPCloudMetadata:
      properties:
        cloudRun:
          $ref: '#/components/schemas/common.CloudRunMetadata'
      type: object
    vuln.AllCompliance:
      description: AllCompliance contains data regarding passed compliance checks
      properties:
        compliance:
          description: 'Compliance are all the passed compliance checks.

            '
          items:
            $ref: '#/components/schemas/vuln.Vulnerability'
          type: array
        enabled:
          description: 'Enabled indicates whether passed compliance checks is enabled by policy.

            '
          type: boolean
      type: object
    shared.PkgsTimes:
      description: PkgsTimes are the compressed layer times for pkgs of the specific type
      properties:
        pkgTimes:
          description: '.

            '
          items:
            $ref: '#/components/schemas/int64'
          type: array
        pkgsType:
          $ref: '#/components/schemas/packages.Type'
      type: object
    vulnerability.ExploitData:
      description: ExploitData holds information about an exploit
      properties:
        kind:
          $ref: '#/components/schemas/vulnerability.ExploitKind'
        link:
          description: 'Link is a link to information about the exploit.

            '
          type: string
        source:
          $ref: '#/components/schemas/vulnerability.ExploitType'
      type: object
    common.ExternalLabel:
      description: ExternalLabel holds an external label with a source and timestamp
      properties:
        key:
          description: 'Label key.

            '
          type: string
        sourceName:
          description: 'Source name (e.g., for a namespace, the source name can be ''twistlock'').

            '
          type: string
        sourceType:
          $ref: '#/components/schemas/common.ExternalLabelSourceType'
        timestamp:
          description: 'Time when the label was fetched.

            '
          format: date-time
          type: string
        value:
          description: 'Value of the label.

            '
          type: string
      type: object
    string:
      type: string
    vuln.WildFireMalware:
      description: WildFireMalware holds the data for WildFire malicious MD5
      properties:
        md5:
          description: 'MD5 is the hash of the malicious binary.

            '
          type: string
        path:
          description: 'Path is the path to malicious binary.

            '
          type: string
        verdict:
          description: 'Verdict is the malicious source like grayware, malware and phishing.

            '
          type: string
      type: object
    vuln.Secret:
      description: Secret represents a secret found on the scanned workload
      properties:
        group:
          description: 'Group is a group name or ID of owner the file metadata containing the secret.

            '
          type: string
        locationInFile:
          description: 'LocationInFile is the line and offset in the file where the secret was found.

            '
          type: string
        metadataModifiedTime:
          description: 'MetadataModifiedTime is the modification time of the file metadata containing the secret.

            '
          format: int64
          type: integer
        modifiedTime:
          description: 'ModifiedTime is the modification time of the file containing the secret.

            '
          format: int64
          type: integer
        originalFileLocation:
          description: '.

            '
          type: string
        path:
          description: 'Path is the path of the file in which the secret was found.

            '
          type: string
        permissions:
          description: 'Permissions are permission bits of the file metadata containing the secret.

            '
          type: string
        secretID:
          description: 'SecretID is the SHA1 of the secret content.

            '
          type: string
        size:
          description: 'Size is the size in bytes of the file in which the secret was found.

            '
          format: int64
          type: integer
        snippet:
          description: 'Snippet is the partial plain secret.

            '
          type: string
        type:
          $ref: '#/components/schemas/vuln.SecretType'
        user:
          description: 'User is a username or ID of owner the file metadata containing the secret.

            '
          type: string
      type: object
    shared.CodeRepoProviderType:
      description: CodeRepoProviderType is the type of provider for the code repository, e.g., GitHub, GitLab etc
      enum:
      - - github
        - CI
      type: string
    coderepos.ManifestFile:
      description: ManifestFile holds the data of a specific manifest file (can also be of a dependency manifest file)
      properties:
        dependencies:
          description: 'Packages listed in the manifest file.

            '
          items:
            $ref: '#/components/schemas/coderepos.PkgDependency'
          type: array
        distribution:
          $ref: '#/components/schemas/vuln.Distribution'
        path:
          description: 'Path to the file.

            '
          type: string
        type:
          $ref: '#/components/schemas/packages.Type'
      type: object
    vuln.Vulnerability:
      description: Vulnerability is a general schema for vulnerabilities (e.g., for compliance or packages)
      properties:
        applicableRules:
          description: 'Rules applied on the package.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
        binaryPkgs:
          description: 'Names of the distro binary package names (packages which are built from the source of the package).

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
        block:
          description: 'Indicates if the vulnerability has a block effect (true) or not (false).

            '
          type: boolean
        cause:
          description: 'Additional information regarding the root cause for the vulnerability.

            '
          type: string
        cri:
          description: 'Indicates if this is a CRI-specific vulnerability (true) or not (false).

            '
          type: boolean
        custom:
          description: 'Indicates if the vulnerability is a custom vulnerability (e.g., openscap, sandbox) (true) or not (false).

            '
          type: boolean
        cve:
          description: 'CVE ID of the vulnerability (if applied).

            '
          type: string
        cvss:
          description: 'CVSS score of the vulnerability.

            '
          format: float
          type: number
        description:
          description: 'Description of the vulnerability.

            '
          type: string
        discovered:
          description: 'Specifies the time of discovery for the vulnerability.

            '
          format: date-time
          type: string
        exploit:
          $ref: '#/components/schemas/vulnerability.ExploitType'
        exploits:
          $ref: '#/components/schemas/vulnerability.Exploits'
        fixDate:
          description: 'Date/time when the vulnerability was fixed (in Unix time).

            '
          format: int64
          type: integer
        fixLink:
          description: 'Link to the vendor''s fixed-version information.

            '
          type: string
        functionLayer:
          description: 'Specifies the serverless layer ID in which the vulnerability was discovered.

            '
          type: string
        gracePeriodDays:
          description: 'Number of grace days left for a vulnerability, based on the configured grace period. Nil if no block vulnerability rule applies.

            '
          type: integer
        id:
          description: 'ID of the violation.

            '
          type: integer
        isRPMModule:
          description: 'IsRPMModule indicates whether this vulnerability is specific to an RPM module.

            '
          type: boolean
        layerTime:
          description: 'Date/time of the image layer to which the CVE belongs.

            '
          format: int64
          type: integer
  

# --- truncated at 32 KB (108 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/palo-alto-networks/refs/heads/main/openapi/palo-alto-networks-coderepos-ci-api-openapi.yml