Skip to content
qibdo qibdo
v1
API version
  • v1
Theme
Book a demo

Get Scan Report

GET
/registry/v1/workspaces/{workspace}/engines/qibdo/repositories/{repository}/artifacts/{reference}/scan
curl --request GET \
--url https://example.com/registry/v1/workspaces/example/engines/qibdo/repositories/example/artifacts/example/scan

Returns the merged vulnerability report (severity counts + per-CVE findings) for the most recent successful scan of an artifact.

workspace
required
string

The unique identifier of the workspace that the repository belongs to

repository
required
string

The unique identifier of the parent repository

reference
required
string

Digest or tag identifying the artifact whose report to return

OK

Media type application/json
object
digest
stringOutput only
status
string format: enum Output only
Allowed values: ARTIFACT_SCAN_STATUS_UNSPECIFIED ARTIFACT_SCAN_STATUS_NOT_SCANNED ARTIFACT_SCAN_STATUS_SCANNING ARTIFACT_SCAN_STATUS_SCANNED ARTIFACT_SCAN_STATUS_FAILED
scan_time
string format: date-time Output only
critical_count
integer format: int32 Output only
high_count
integer format: int32 Output only
medium_count
integer format: int32 Output only
low_count
integer format: int32 Output only
findings
Array<object>Output only

A single vulnerability reported by the image scanner. Every field is scanner-owned and reproduced verbatim, so all are OUTPUT_ONLY: this message only ever appears inside ScanReport.findings, which is itself OUTPUT_ONLY. A client-facing length or character rule here would publish a constraint the platform cannot honour — a scanner description longer than the cap is still returned, so the contract would contradict the response.

object
cve_id
stringOutput only
severity
stringOutput only
package_name
stringOutput only
affected_version
stringOutput only
fixed_version
stringOutput only
description
stringOutput only
advisory_url
stringOutput only
Example
{
"status": "ARTIFACT_SCAN_STATUS_UNSPECIFIED"
}

Default error response

Media type application/json

The Status type defines a logical error model that is suitable for different programming environments, including REST APIs and RPC APIs. It is used by gRPC. Each Status message contains three pieces of data: error code, error message, and error details. You can find out more about this error model and how to work with it in the API Design Guide.

object
code

The status code, which should be an enum value of [google.rpc.Code][google.rpc.Code].

integer format: int32
message

A developer-facing error message, which should be in English. Any user-facing error message should be localized and sent in the [google.rpc.Status.details][google.rpc.Status.details] field, or localized by the client.

string
details

A list of messages that carry the error details. There is a common set of message types for APIs to use.

Array<object>

Contains an arbitrary serialized message along with a @type that describes the type of the serialized message.

object
@type

The type of the serialized message.

string
key
additional properties
any
Example generated
{
"code": 1,
"message": "example",
"details": [
{
"@type": "example"
}
]
}