Anchore · API Governance Rules
Anchore API Rules
Spectral linting rules defining API design standards and conventions for Anchore.
19 Rules
error 5
warn 12
info 1
Rule Categories
anchore
error
no
operationid
path
query
schema
security
servers
Rules
error
anchore-openapi-info-description
OpenAPI info object must have a description
$.info
error
anchore-openapi-info-version
OpenAPI info object must have a version
$.info
error
anchore-operation-operationId
Every operation must have an operationId
$.paths[*][get,post,put,patch,delete]
warn
anchore-operation-summary
Every operation must have a summary
$.paths[*][get,post,put,patch,delete]
warn
anchore-response-200
Every GET operation must have a 200 response
$.paths[*].get.responses
error
anchore-security-defined
API must define security requirements
$
warn
anchore-schema-type
Schema properties must have a type
$.components.schemas[*].properties[*]
warn
anchore-severity-enum
Vulnerability severity must use standard values
$.components.schemas.Vulnerability.properties.severity
hint
anchore-digest-format
Image digest fields should follow SHA256 format
$.components.schemas[*].properties.imageDigest
error
servers-https-only
Server URLs must use HTTPS.
$.servers[*].url
warn
servers-expected-domain
Server URLs should be on the example.com domain.
$.servers[*].url
warn
path-params-casing
Path parameters should be camelCase (the dominant convention in this API).
$.paths[*].parameters[?(@.in=='path')].name
warn
query-params-casing
Query parameters should be snake_case (the dominant convention in this API).
$.paths[*][get,post,put,patch,delete].parameters[?(@.in=='query')]
warn
operationid-casing
Operation IDs should be camelCase (the dominant convention in this API).
$.paths[*][get,post,put,patch,delete].operationId
warn
schema-names-casing
Component schema names should be PascalCase (the dominant convention in this API).
$.components.schemas
info
schema-properties-casing
Schema properties should be snake_case (the dominant convention in this API).
$.components.schemas[*].properties
warn
security-schemes-defined
Security schemes should be defined in components.
$.components
warn
error-schema-defined
A shared error schema (ErrorResponse) should be defined for error payloads.
$.components.schemas
warn
no-empty-descriptions
Descriptions must not be empty strings.
$..description