---
title: "UploadVulnerabilityScan"
url: "https://us-prod.jeffyongtaotang.com/apis/konnect-service-catalog-1/versions/cdbef9b7-686c-4189-bbc8-55c727a972e8/schemas/CreateVulnerabilityScan"
---

> Full API specification: https://us-prod.jeffyongtaotang.com/apis/konnect-service-catalog-1/versions/cdbef9b7-686c-4189-bbc8-55c727a972e8.md

# UploadVulnerabilityScan

## OpenAPI definition

```yaml
openapi: 3.0.3
info:
  title: Konnect Service Catalog
  version: 1.3.0
servers:
  - url: https://us.api.konghq.com/v1
    description: United-States Production region
  - url: https://eu.api.konghq.com/v1
    description: Europe Production region
  - url: https://au.api.konghq.com/v1
    description: Australia Production region
  - url: https://me.api.konghq.com/v1
    description: Middle-East Production region
  - url: https://in.api.konghq.com/v1
    description: India Production region
  - url: https://sg.api.konghq.com/v1
    description: Singapore Production region
components:
  schemas:
    VulnerabilityScanKey:
      title: VulnerabilityScanKey
      type: string
      description: >
        Machine-usable value to correlate scans (and their vulnerabilities) on a
        given resource. This value is then

        used to determine vulnerabilities resolved/fixed between subsequent
        scans on the same resource.
      example: namespaces/foo:pods/bar-api
    VulnerabilityScanTool:
      type: string
      enum:
        - grype
        - trivy
      example: trivy
    CreateVulnerabilityScanCatalogReference:
      type: object
      oneOf:
        - $ref: "#/components/schemas/CreateServiceVulnerabilityScanCatalogReference"
    CreateServiceVulnerabilityScanCatalogReference:
      type: object
      additionalProperties: false
      properties:
        service:
          type: string
          description: Reference to the service to map the vulnerability scan to. Can be
            either the service name or ID.
          example: user-svc
      required:
        - service
    CreateVulnerabilityScan:
      title: UploadVulnerabilityScan
      type: object
      additionalProperties: false
      properties:
        scan_key:
          $ref: "#/components/schemas/VulnerabilityScanKey"
        tool:
          $ref: "#/components/schemas/VulnerabilityScanTool"
        description:
          type: string
          nullable: true
        raw_scan_report:
          type: object
          additionalProperties: true
        catalog_reference:
          $ref: "#/components/schemas/CreateVulnerabilityScanCatalogReference"
        environment:
          type: string
          nullable: true
          example: prod
        region:
          type: string
          nullable: true
          example: us-east-2
        source_correlation_key:
          type: string
          example: kong/repo-id
          description: >
            Optional key used to correlate vulnerabilities found in this scan
            with the same vulnerabilities found across different sources.

            This allows tracking the same vulnerability in two sources as one
            vulnerability instance.

            When omitted, this will inherit the value of `scan_key`.
        attributes:
          type: object
          additionalProperties:
            type: string
          example:
            org.kong.enterprise.source.version: v1
        ts:
          type: string
          format: date-time
          description: >
            Optional RFC-3339 timestamp indicating when the vulnerability scan
            was run.

            If provided, this value will be used as the authoritative scan time.

            If omitted, the system will attempt to extract a timestamp from the
            uploaded scan report.

            If no timestamp can be extracted, the server's current time at
            ingestion will be used.
          example: 2025-01-01T00:00:00Z
      required:
        - scan_key
        - tool
        - description
        - raw_scan_report
        - catalog_reference
        - environment
        - region
        - attributes
```
