---
title: "VulnerabilityInstance"
url: "https://us-prod.jeffyongtaotang.com/apis/konnect-service-catalog-1/versions/cdbef9b7-686c-4189-bbc8-55c727a972e8/schemas/VulnerabilityInstance"
---

> Full API specification: https://us-prod.jeffyongtaotang.com/apis/konnect-service-catalog-1/versions/cdbef9b7-686c-4189-bbc8-55c727a972e8.md

# VulnerabilityInstance

## OpenAPI definition

```yaml
openapi: 3.0.3
info:
  title: Konnect Service Catalog
  version: 1.3.0
servers:
  - url: https://us.api.konghq.com/v1
    description: United-States Production region
  - url: https://eu.api.konghq.com/v1
    description: Europe Production region
  - url: https://au.api.konghq.com/v1
    description: Australia Production region
  - url: https://me.api.konghq.com/v1
    description: Middle-East Production region
  - url: https://in.api.konghq.com/v1
    description: India Production region
  - url: https://sg.api.konghq.com/v1
    description: Singapore Production region
components:
  schemas:
    ServiceReference:
      title: ServiceReference
      type: object
      description: Reference object containing information about a related service.
      properties:
        id:
          type: string
          format: uuid
          example: 7f9fd312-a987-4628-b4c5-bb4f4fddd5f7
          description: The service ID.
          readOnly: true
        name:
          type: string
          description: The name of the Service.
          minLength: 1
          maxLength: 120
          pattern: ^[0-9a-z.-]+$
          example: user-svc
        display_name:
          type: string
          description: The display name of the Service.
          minLength: 1
          maxLength: 120
          example: User Service
      required:
        - id
        - name
        - display_name
    VulnerabilityInstanceState:
      type: string
      enum:
        - open
        - fixed
      example: open
    VulnerabilitySource:
      type: object
      oneOf:
        - $ref: "#/components/schemas/ScanVulnerabilitySource"
    ScanVulnerabilitySource:
      type: object
      allOf:
        - $ref: "#/components/schemas/BaseVulnerabilitySource"
        - type: object
          properties:
            scan_key:
              type: string
            scan_tool:
              $ref: "#/components/schemas/VulnerabilityScanToolMetadata"
          required:
            - scan_key
            - scan_tool
    BaseVulnerabilitySource:
      type: object
      properties:
        type:
          type: string
          example: grype
        raw_finding:
          type: object
          nullable: true
          additionalProperties: true
      required:
        - type
        - raw_finding
    VulnerabilityScanToolMetadata:
      type: object
      properties:
        name:
          type: string
          example: Trivy
        version:
          type: string
          nullable: true
          example: 1.0.0
      required:
        - name
        - version
    VulnerabilityInstance:
      title: VulnerabilityInstance
      type: object
      additionalProperties: false
      properties:
        vulnerability_id:
          type: string
          format: uuid
          example: 5c3ddf1c-d34a-4860-83c1-180bc741e8d4
        service:
          $ref: "#/components/schemas/ServiceReference"
        state:
          $ref: "#/components/schemas/VulnerabilityInstanceState"
        sources:
          type: array
          items:
            $ref: "#/components/schemas/VulnerabilitySource"
        opened_at:
          type: string
          format: date-time
          readOnly: true
          example: 2025-01-01T20:41:45.068Z
        reopened_at:
          type: string
          format: date-time
          nullable: true
          readOnly: true
          example: 2025-01-02T20:41:45.068Z
        last_opened_at:
          type: string
          format: date-time
          readOnly: true
          example: 2025-01-02T20:41:45.068Z
        fixed_at:
          type: string
          format: date-time
          nullable: true
          readOnly: true
          example: 2025-01-01T22:41:45.068Z
        environment:
          type: string
          nullable: true
          example: prod
        region:
          type: string
          nullable: true
          example: us-east-2
        source_correlation_key:
          type: string
          nullable: true
          description: >
            Key used to correlate and group activity on this vulnerability
            instance across different sources (e.g. trivy, grype).
          example: kong/repo-id
      required:
        - vulnerability_id
        - service
        - state
        - sources
        - opened_at
        - reopened_at
        - last_opened_at
        - fixed_at
        - environment
        - region
        - source_correlation_key
```
