Socket Fixes API
The fixes API from Socket — 1 operation(s) for fixes.
The fixes API from Socket — 1 operation(s) for fixes.
Every API here is available over the APIs.io API and to AI agents over MCP.
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
find_apisBrowse and filter every API in the catalog.get_api_artifactsOne API's artifacts, grouped by type.get_openapiThe primary OpenAPI for this API.find_similar_apisAPIs that look like this one.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.curl "https://apis.io/api/v1/apis/socket-fixes-api"
curl "https://apis.io/api/v1/apis?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.
openapi: 3.2.0
info:
description: Specification of the Socket API endpoints
title: Endpoints Fixes API
version: '0'
servers:
- url: https://api.socket.dev/v0
tags:
- name: Fixes
paths:
/orgs/{org_slug}/fixes:
get:
tags:
- Fixes
summary: Fetch fixes for vulnerabilities in a repository, scan, or uploaded manifest
operationId: fetch-fixes
parameters:
- name: org_slug
in: path
required: true
description: The slug of the organization
schema:
type: string
- name: repo_slug
in: query
required: false
description: The slug of the repository to fetch fixes for (e.g. "my-repo" or "my-org/my-repo"). Use the full org/repo path to disambiguate when multiple GitHub orgs share the same repo name. Computes fixes based on the latest scan on the default branch
schema:
type: string
- name: full_scan_id
in: query
required: false
description: The ID of the scan to fetch fixes for
schema:
type: string
- name: tar_hash
in: query
required: false
description: A tarball hash from the upload-manifest-files endpoint. Mutually exclusive with repo_slug and full_scan_id.
schema:
type: string
- name: vulnerability_ids
in: query
required: true
description: Comma-separated list of GHSA or CVE IDs, or "*" for all vulnerabilities
schema:
type: string
- name: allow_major_updates
in: query
required: true
description: Whether to allow major version updates in fixes
schema:
type: boolean
default: false
- name: minimum_release_age
in: query
required: false
description: Minimum release age for fixes packages (e.g., "1h", "2d", "1w"). Higher values reduces risk of installing recently released untested package versions.
schema:
type: string
default: 0d
- name: include_details
in: query
required: false
description: Whether to include advisory details in the response
schema:
type: boolean
default: false
- name: include_responsible_direct_dependencies
in: query
required: false
description: Set to include the direct dependencies responsible for introducing the dependency or dependencies with the vulnerability in the response
schema:
type: boolean
default: false
- name: include_all_detected_ghsas
in: query
required: false
description: Set to include an allDetectedGhsas field listing every GHSA detected in the project, regardless of the vulnerability_ids filter. Useful for CLI clients that request a specific GHSA and want to show the user which GHSAs actually exist when the request has no overlap.
schema:
type: boolean
default: false
- name: include_stateful_alert_ids
in: query
required: false
description: Set to include a statefulAlertIds map (GHSA ID → array of open stateful alert IDs detected in this organization) in the response. Lets callers correlate /fixes results back to the alert IDs surfaced by /v0/orgs/{org_slug}/alerts. Org-scoped only — multiple alerts across repos/branches may share a GHSA. Off by default to avoid an extra ClickHouse round-trip.
schema:
type: boolean
default: false
- name: autofix_run_id
in: query
required: false
description: The id of an autofix-or-upgrade-cli-run record (created via /fixes/register-autofix-or-upgrade-cli-run) to associate this computation with. When set, the server records per-GHSA fix-computation telemetry into autofix_compute_vulnerability and updates the run's autofix_run row, mirroring the legacy /v0/fixes/compute-fixes endpoint. The caller must own the run's organization; foreign-org or unknown ids return 404.
schema:
type: string
security:
- bearerAuth:
- fixes:list
- basicAuth:
- fixes:list
description: Fetches available fixes for vulnerabilities in a repository, scan, or uploaded manifest.
responses:
'200':
content:
application/json:
schema:
type: object
additionalProperties: false
properties:
fixDetails:
type: object
additionalProperties:
type: object
description: ''
default: null
properties: {}
description: ''
allDetectedGhsas:
type: array
items:
type: string
description: ''
default: GHSA ID of a vulnerability detected in the project
description: All vulnerability GHSA IDs detected in the project, regardless of the vulnerability_ids filter. Only present when include_all_detected_ghsas=true is set.
statefulAlertIds:
type: object
additionalProperties:
type: array
items:
type: string
description: ''
default: Stateful alert ID (the human-readable SOCKET-XXX-N identifier from /v0/orgs/{org_slug}/alerts)
description: ''
properties: {}
description: Map of GHSA ID → open stateful alert IDs detected in this organization. Lets callers correlate /fixes results back to the alert IDs they see in /v0/orgs/{org_slug}/alerts. Org-scoped, not repo/branch-scoped — the same GHSA may surface in multiple alerts across repos. Only present when include_stateful_alert_ids=true is set.
required:
- fixDetails
description: Fix details for requested vulnerabilities
'400':
$ref: '#/components/responses/SocketBadRequest'
'401':
$ref: '#/components/responses/SocketUnauthorized'
'403':
$ref: '#/components/responses/SocketForbidden'
'404':
$ref: '#/components/responses/SocketNotFoundResponse'
'429':
$ref: '#/components/responses/SocketTooManyRequestsResponse'
x-readme: {}
components:
responses:
SocketTooManyRequestsResponse:
description: Insufficient quota for API route
headers:
Retry-After:
description: 'Retry contacting the endpoint *at least* after seconds.
See https://tools.ietf.org/html/rfc7231#section-7.1.3'
schema:
format: int32
type: integer
content:
application/json:
schema:
type: object
additionalProperties: false
description: ''
properties:
error:
type: object
additionalProperties: false
description: ''
properties:
message:
type: string
description: ''
default: ''
details:
type:
- object
- 'null'
description: ''
default: null
required:
- details
- message
required:
- error
SocketBadRequest:
content:
application/json:
schema:
type: object
additionalProperties: false
description: ''
properties:
error:
type: object
additionalProperties: false
description: ''
properties:
message:
type: string
description: ''
default: ''
details:
type:
- object
- 'null'
description: ''
default: null
required:
- details
- message
required:
- error
description: Bad request
SocketNotFoundResponse:
content:
application/json:
schema:
type: object
additionalProperties: false
description: ''
properties:
error:
type: object
additionalProperties: false
description: ''
properties:
message:
type: string
description: ''
default: ''
details:
type:
- object
- 'null'
description: ''
default: null
required:
- details
- message
required:
- error
description: Resource not found
SocketUnauthorized:
content:
application/json:
schema:
type: object
additionalProperties: false
description: ''
properties:
error:
type: object
additionalProperties: false
description: ''
properties:
message:
type: string
description: ''
default: ''
details:
type:
- object
- 'null'
description: ''
default: null
required:
- details
- message
required:
- error
description: Unauthorized
SocketForbidden:
content:
application/json:
schema:
type: object
additionalProperties: false
description: ''
properties:
error:
type: object
additionalProperties: false
description: ''
properties:
message:
type: string
description: ''
default: ''
details:
type:
- object
- 'null'
description: ''
default: null
required:
- details
- message
required:
- error
description: Insufficient max_quota for API method
securitySchemes:
bearerAuth:
type: http
scheme: bearer
description: Organization Tokens can be passed as a Bearer token
basicAuth:
type: http
scheme: basic
description: Organization Tokens can be passed as the user field in basic auth