Skip to content
qibdo qibdo
v1
API version
  • v1
Theme
Book a demo

Get Scan Policy

GET
/registry/v1/workspaces/{workspace}/engines/{engine}/scan-policies/{id}
curl --request GET \
--url https://example.com/registry/v1/workspaces/example/engines/example/scan-policies/example

Returns a scan policy by unique ID.

workspace
required
string
engine
required
string
id
required
string

OK

Media type application/json

A scan policy configures vulnerability-scanning behaviour for a workspace registry. Scanning is project-wide on the backend, so a scan policy is scoped to the whole workspace.

object
id
stringOutput only
workspace_id

The workspace this scan policy applies to.

stringOutput only
engine

The provider this scan policy applies to.

string format: enum Output only
Allowed values: ENGINE_UNSPECIFIED ENGINE_QIBDO
auto_scan_on_push

Whether every artifact is automatically scanned on push.

boolean
block_on_critical_cve

Whether pushes of artifacts carrying an unresolved critical CVE are blocked.

boolean
cve_allowlist

CVE identifiers that are exempt from the block-on-critical rule.

Array<string>
create_time
string format: date-time Output only
update_time
string format: date-time Output only
Example
{
"engine": "ENGINE_UNSPECIFIED"
}

Default error response

Media type application/json

The Status type defines a logical error model that is suitable for different programming environments, including REST APIs and RPC APIs. It is used by gRPC. Each Status message contains three pieces of data: error code, error message, and error details. You can find out more about this error model and how to work with it in the API Design Guide.

object
code

The status code, which should be an enum value of [google.rpc.Code][google.rpc.Code].

integer format: int32
message

A developer-facing error message, which should be in English. Any user-facing error message should be localized and sent in the [google.rpc.Status.details][google.rpc.Status.details] field, or localized by the client.

string
details

A list of messages that carry the error details. There is a common set of message types for APIs to use.

Array<object>

Contains an arbitrary serialized message along with a @type that describes the type of the serialized message.

object
@type

The type of the serialized message.

string
key
additional properties
any
Example generated
{
"code": 1,
"message": "example",
"details": [
{
"@type": "example"
}
]
}