---
title: "VulnerabilityScan"
url: "https://us-prod.jeffyongtaotang.com/apis/konnect-service-catalog-1/versions/cdbef9b7-686c-4189-bbc8-55c727a972e8/schemas/VulnerabilityScan"
---

> Full API specification: https://us-prod.jeffyongtaotang.com/apis/konnect-service-catalog-1/versions/cdbef9b7-686c-4189-bbc8-55c727a972e8.md

# VulnerabilityScan

## OpenAPI definition

```yaml
openapi: 3.0.3
info:
  title: Konnect Service Catalog
  version: 1.3.0
servers:
  - url: https://us.api.konghq.com/v1
    description: United-States Production region
  - url: https://eu.api.konghq.com/v1
    description: Europe Production region
  - url: https://au.api.konghq.com/v1
    description: Australia Production region
  - url: https://me.api.konghq.com/v1
    description: Middle-East Production region
  - url: https://in.api.konghq.com/v1
    description: India Production region
  - url: https://sg.api.konghq.com/v1
    description: Singapore Production region
components:
  schemas:
    VulnerabilityScanKey:
      title: VulnerabilityScanKey
      type: string
      description: >
        Machine-usable value to correlate scans (and their vulnerabilities) on a
        given resource. This value is then

        used to determine vulnerabilities resolved/fixed between subsequent
        scans on the same resource.
      example: namespaces/foo:pods/bar-api
    VulnerabilityScanTool:
      type: string
      enum:
        - grype
        - trivy
      example: trivy
    VulnerabilityScanToolMetadata:
      type: object
      properties:
        name:
          type: string
          example: Trivy
        version:
          type: string
          nullable: true
          example: 1.0.0
      required:
        - name
        - version
    VulnerabilityScanCatalogReference:
      type: object
      oneOf:
        - $ref: "#/components/schemas/ServiceVulnerabilityScanCatalogReference"
    VulnerabilityScanStatus:
      title: VulnerabilityScanStatus
      type: string
      enum:
        - in_progress
        - completed
        - failed
    CreatedAt:
      type: string
      format: date-time
      example: 2022-11-04T20:10:06.927Z
      description: An ISO-8601 timestamp representation of entity creation date.
      readOnly: true
      x-speakeasy-param-suppress-computed-diff: true
    UpdatedAt:
      type: string
      format: date-time
      example: 2022-11-04T20:10:06.927Z
      description: An ISO-8601 timestamp representation of entity update date.
      readOnly: true
      x-speakeasy-param-suppress-computed-diff: true
    ServiceVulnerabilityScanCatalogReference:
      type: object
      additionalProperties: false
      properties:
        service:
          type: object
          additionalProperties: false
          properties:
            id:
              type: string
              format: uuid
              example: b72008a7-1a8b-42d7-9691-ed88cbc1e61f
            name:
              type: string
              example: user-svc
            display_name:
              type: string
              example: User Service
          required:
            - id
            - name
            - display_name
      required:
        - service
    VulnerabilityScan:
      title: VulnerabilityScan
      type: object
      properties:
        id:
          type: string
          format: uuid
          example: 0ca46543-e6a3-4a8b-8e2c-205935a1bb3a
        scan_key:
          $ref: "#/components/schemas/VulnerabilityScanKey"
        tool:
          $ref: "#/components/schemas/VulnerabilityScanTool"
        tool_metadata:
          $ref: "#/components/schemas/VulnerabilityScanToolMetadata"
        description:
          type: string
          nullable: true
        catalog_reference:
          $ref: "#/components/schemas/VulnerabilityScanCatalogReference"
        environment:
          type: string
          nullable: true
          example: prod
        region:
          type: string
          nullable: true
          example: us-east-2
        source_correlation_key:
          type: string
          nullable: true
          example: kong/repo-id
        attributes:
          type: object
          additionalProperties:
            type: string
          example:
            org.kong.enterprise.source.version: v1
        ts:
          type: string
          format: date-time
          description: Date the vulnerability scan occurred at.
          example: 2025-01-01T00:00:00Z
        status:
          $ref: "#/components/schemas/VulnerabilityScanStatus"
        created_at:
          $ref: "#/components/schemas/CreatedAt"
        updated_at:
          $ref: "#/components/schemas/UpdatedAt"
      required:
        - id
        - scan_key
        - tool
        - tool_metadata
        - description
        - catalog_reference
        - environment
        - region
        - source_correlation_key
        - attributes
        - ts
        - status
        - created_at
        - updated_at
```
