---
title: "VulnerabilitiesMetricsQuery"
url: "https://us-prod.jeffyongtaotang.com/apis/konnect-service-catalog-1/versions/cdbef9b7-686c-4189-bbc8-55c727a972e8/schemas/VulnerabilitiesMetricsQuery"
---

> Full API specification: https://us-prod.jeffyongtaotang.com/apis/konnect-service-catalog-1/versions/cdbef9b7-686c-4189-bbc8-55c727a972e8.md

# VulnerabilitiesMetricsQuery

A query against vulnerability metrics.

## OpenAPI definition

```yaml
openapi: 3.0.3
info:
  title: Konnect Service Catalog
  version: 1.3.0
servers:
  - url: https://us.api.konghq.com/v1
    description: United-States Production region
  - url: https://eu.api.konghq.com/v1
    description: Europe Production region
  - url: https://au.api.konghq.com/v1
    description: Australia Production region
  - url: https://me.api.konghq.com/v1
    description: Middle-East Production region
  - url: https://in.api.konghq.com/v1
    description: India Production region
  - url: https://sg.api.konghq.com/v1
    description: Singapore Production region
components:
  schemas:
    VulnerabilitiesMetricsFilterByService:
      type: object
      required:
        - operator
        - value
        - field
      properties:
        operator:
          $ref: "#/components/schemas/MetricsFilterInOperator"
        value:
          type: array
          items:
            type: string
            format: uuid
        field:
          type: string
          enum:
            - service
      description: Filters a metrics query by `service`.
    VulnerabilitiesMetricsFilterBySeverity:
      type: object
      description: Filters a metrics query by `severity`.
      required:
        - field
        - operator
        - value
      properties:
        field:
          type: string
          enum:
            - severity
        operator:
          $ref: "#/components/schemas/MetricsFilterInOperator"
        value:
          type: array
          items:
            $ref: "#/components/schemas/VulnerabilitySeverity"
    VulnerabilitiesMetricsFilterByState:
      type: object
      description: Filters a metrics query by `state`.
      required:
        - field
        - operator
        - value
      properties:
        field:
          type: string
          enum:
            - state
        operator:
          $ref: "#/components/schemas/MetricsFilterInOperator"
        value:
          type: array
          items:
            $ref: "#/components/schemas/VulnerabilityState"
    VulnerabilitiesMetricsFilterByType:
      type: object
      description: Filters a metrics query by `type`.
      required:
        - field
        - operator
        - value
      properties:
        field:
          type: string
          enum:
            - type
        operator:
          $ref: "#/components/schemas/MetricsFilterInOperator"
        value:
          type: array
          items:
            $ref: "#/components/schemas/VulnerabilityType"
    VulnerabilitiesMetricsFilterBySource:
      type: object
      description: Filters a metrics query by `source`.
      required:
        - field
        - operator
        - value
      properties:
        field:
          type: string
          enum:
            - source
        operator:
          $ref: "#/components/schemas/MetricsFilterInOperator"
        value:
          type: array
          items:
            type: string
            example: trivy
    VulnerabilitiesMetricsFilterByEnvironment:
      description: Filters a metrics query by `environment`.
      allOf:
        - type: object
          required:
            - field
          properties:
            field:
              type: string
              enum:
                - environment
        - oneOf:
            - $ref: "#/components/schemas/EmptyValueMetricsFilter"
            - type: object
              required:
                - operator
                - value
              properties:
                operator:
                  $ref: "#/components/schemas/MetricsFilterInOperator"
                value:
                  type: array
                  items:
                    type: string
                    example: prod
    VulnerabilitiesMetricsFilterByRegion:
      description: Filters a metrics query by `region`.
      allOf:
        - type: object
          required:
            - field
          properties:
            field:
              type: string
              enum:
                - region
        - oneOf:
            - $ref: "#/components/schemas/EmptyValueMetricsFilter"
            - type: object
              required:
                - operator
                - value
              properties:
                operator:
                  $ref: "#/components/schemas/MetricsFilterInOperator"
                value:
                  type: array
                  items:
                    type: string
                    example: us-east-1
    VulnerabilitiesMetricsFilterByCVE:
      description: Filters a metrics query by `cve_id`.
      allOf:
        - type: object
          required:
            - field
          properties:
            field:
              type: string
              enum:
                - cve_id
        - oneOf:
            - $ref: "#/components/schemas/EmptyValueMetricsFilter"
            - type: object
              required:
                - operator
                - value
              properties:
                operator:
                  $ref: "#/components/schemas/MetricsFilterInOperator"
                value:
                  type: array
                  items:
                    type: string
                    example: CVE-2025-1000
    VulnerabilitiesMetricsFilterByPackageName:
      description: Filters a metrics query by `package.name`.
      allOf:
        - type: object
          required:
            - field
          properties:
            field:
              type: string
              enum:
                - package.name
        - oneOf:
            - $ref: "#/components/schemas/EmptyValueMetricsFilter"
            - type: object
              required:
                - operator
                - value
              properties:
                operator:
                  $ref: "#/components/schemas/MetricsFilterInOperator"
                value:
                  type: array
                  items:
                    type: string
                    example: log4j
    VulnerabilitiesMetricsFilterByScanAttributes:
      description: >
        Filters a metrics query by `scan_attributes` properties.

        Dot-notation off of `scan_attributes` is used to specify the property to
        filter by.


        Example: `scan_attributes.image_tag`.
      allOf:
        - type: object
          required:
            - field
          properties:
            field:
              type: string
              pattern: ^scan_attributes\.[^.\s]+$
        - oneOf:
            - $ref: "#/components/schemas/EmptyValueMetricsFilter"
            - $ref: "#/components/schemas/StringValueMetricsFilter"
            - $ref: "#/components/schemas/NumericValueMetricsFilter"
      example:
        field: scan_attributes.image_version
        operator: in
        value:
          - 2.0.7
    VulnerabilityMetricsRelativeTimeRange:
      type: object
      description: >
        A duration representing a relative-to-now span of time.

        The start time is floored to the requested granularity.

        The exact start and end timestamps are returned in the result query in
        the meta.start and meta.end fields.

        Example:
          7d from now, with 1day granularity initiated at 2024-01-08T17:11:00+05:00 will query for the time range from 2024-01-01T00:00:00+05:00 to 2024-01-08T17:11:00+05:00.
      additionalProperties: false
      required:
        - type
        - time_range
      properties:
        tz:
          type: string
          description: >
            Time zone in IANA Time Zone Database format (e.g.,
            'America/New_York', 'Europe/London', 'Etc/UTC').

            Optional, defaults to UTC when unspecified.
          default: Etc/UTC
          example: America/Chicago
        type:
          type: string
          enum:
            - relative
        time_range:
          oneOf:
            - title: RelativeDayTimeRange
              type: string
              pattern: ^([1-9]|[1-9][0-9]|1[0-9]{2}|2[0-9]{2}|3[0-5][0-9]|36[0-5])d$
              default: 30d
            - title: RelativeWeekTimeRange
              type: string
              pattern: ^([1-9]|[1-4][0-9]|5[0-2])w$
            - title: RelativeMonthTimeRange
              type: string
              pattern: ^([1-9]|1[0-2])mo$
            - title: RelativeYearTimeRange
              type: string
              enum:
                - 1y
            - title: RelativeReservedRange
              type: string
              enum:
                - current_week
                - current_month
                - previous_week
                - previous_month
    VulnerabilityMetricsAbsoluteTimeRange:
      type: object
      description: A duration representing an exact start and end time.
      additionalProperties: false
      required:
        - type
        - start
        - end
      properties:
        tz:
          type: string
          description: >
            Time zone in IANA Time Zone Database format (e.g.,
            'America/New_York', 'Europe/London', 'Etc/UTC').

            Optional, defaults to UTC when unspecified.
          default: Etc/UTC
          example: America/Chicago
        type:
          type: string
          enum:
            - absolute
        start:
          format: date-time
          type: string
          description: Start of the query time range in RFC-3339 format.
          example: 2025-03-30T07:20:50Z
        end:
          format: date-time
          type: string
          description: Start of the query time range in RFC-3339 format.
          example: 2025-06-30T08:20:50Z
    MetricsFilterInOperator:
      type: string
      description: |
        The type of filter to apply.
          - `in` filters will limit results to only the specified values
          - `not_in` filters will exclude the specified values
      enum:
        - in
        - not_in
    VulnerabilitySeverity:
      type: string
      enum:
        - low
        - medium
        - high
        - critical
      example: low
    VulnerabilityState:
      type: string
      enum:
        - open
        - fixed
        - dismissed
      example: dismissed
    VulnerabilityType:
      type: string
      enum:
        - container_image
        - library
      readOnly: true
      example: container_image
    EmptyValueMetricsFilter:
      type: object
      required:
        - operator
      properties:
        operator:
          $ref: "#/components/schemas/MetricsFilterEmptyOperator"
    StringValueMetricsFilter:
      type: object
      required:
        - operator
        - value
      properties:
        operator:
          $ref: "#/components/schemas/MetricsFilterInOperator"
        value:
          type: array
          items:
            type: string
    NumericValueMetricsFilter:
      type: object
      required:
        - operator
        - value
      properties:
        operator:
          $ref: "#/components/schemas/MetricsFilterNumericOperator"
        value:
          type: number
    MetricsFilterEmptyOperator:
      type: string
      description: |
        The type of filter to apply.
        Empty values are `null` or undefined.
      enum:
        - empty
        - not_empty
    MetricsFilterNumericOperator:
      type: string
      description: The type of filter to apply to numeric field values.
      enum:
        - =
        - "!="
        - <
        - ">"
        - <=
        - ">="
    VulnerabilitiesMetricsQuery:
      type: object
      description: A query against vulnerability metrics.
      additionalProperties: false
      required:
        - metrics
        - dimensions
        - filters
        - time_range
      properties:
        metrics:
          type: array
          minItems: 1
          maxItems: 1
          description: List of aggregated metrics to collect across the requested time span.
          items:
            type: string
            enum:
              - vulnerability_count
        dimensions:
          type: array
          description: The list of dimensions to group by.
          maxItems: 2
          example:
            - service
            - state
          items:
            type: string
            enum:
              - time
              - service
              - severity
              - state
              - type
              - source
              - environment
              - region
        filters:
          type: array
          description: A list of filters to apply to the query.
          items:
            oneOf:
              - $ref: "#/components/schemas/VulnerabilitiesMetricsFilterByService"
              - $ref: "#/components/schemas/VulnerabilitiesMetricsFilterBySeverity"
              - $ref: "#/components/schemas/VulnerabilitiesMetricsFilterByState"
              - $ref: "#/components/schemas/VulnerabilitiesMetricsFilterByType"
              - $ref: "#/components/schemas/VulnerabilitiesMetricsFilterBySource"
              - $ref: "#/components/schemas/VulnerabilitiesMetricsFilterByEnvironment"
              - $ref: "#/components/schemas/VulnerabilitiesMetricsFilterByRegion"
              - $ref: "#/components/schemas/VulnerabilitiesMetricsFilterByCVE"
              - $ref: "#/components/schemas/VulnerabilitiesMetricsFilterByPackageName"
              - $ref: "#/components/schemas/VulnerabilitiesMetricsFilterByScanAttributes"
        granularity:
          type: string
          description: >
            Force time grouping into buckets of the specified duration. Only has
            an effect if `time` is in the `dimensions` list.


            The granularity of the result may be coarser than requested.

            The exact result granularity will be reported in the response
            `meta.granularity_ms` field.


            If granularity is not specified and `time` is in the `dimensions`
            list, a default will be chosen based on the time range requested.


            Different relative times support different granularities:
              - 1d  => daily
              - 7d  => daily, weekly
              - 3w  => daily, weekly
              - 30d => daily, weekly
              - 3mo => daily, weekly
              - 1y  => daily, weekly

            For special time ranges:
              - current_week, previous_week   => daily
              - current_month, previous_month => daily, weekly

            For absolute time ranges, daily will be used.
          enum:
            - daily
            - weekly
        time_range:
          description: The time range to query.
          oneOf:
            - $ref: "#/components/schemas/VulnerabilityMetricsRelativeTimeRange"
            - $ref: "#/components/schemas/VulnerabilityMetricsAbsoluteTimeRange"
          discriminator:
            propertyName: type
            mapping:
              relative: "#/components/schemas/VulnerabilityMetricsRelativeTimeRange"
              absolute: "#/components/schemas/VulnerabilityMetricsAbsoluteTimeRange"
```
