Skip to main content

vulnerabilityDisclosureSubmissions

Lists VDR submissions in the company's inbox

vulnerabilityDisclosureSubmissions(
companyId: Int!
trustCenterId: Int
statuses: [String!]
search: String
limit: Int
): [VulnerabilityDisclosureSubmission!]!

Arguments

vulnerabilityDisclosureSubmissions.companyId ● Int! non-null scalar

vulnerabilityDisclosureSubmissions.trustCenterId ● Int scalar

Restrict the inbox to the reports submitted through one Trust Center page.

vulnerabilityDisclosureSubmissions.statuses ● [String!] list scalar

Filter by status. Accepts: pending_verification, submitted, triaging, accepted, duplicate, invalid, resolved. Default: submitted + triaging.

vulnerabilityDisclosureSubmissions.limit ● Int scalar

Type

VulnerabilityDisclosureSubmission object

A vulnerability disclosure report received from an external researcher. Carries third-party PII (researcherEmail, reporterIp): reading it requires vulnerability_read plus a grant on the owning company or on the FQDN asset of the Trust Center the report came in through. Not gated on an admin flag — see Trust::DisclosureSubmissionPolicy.

Example request

This generated query uses placeholders for required values. Replace them with values available to your API key before running it.

Before you run it

Run the companies query first and use data.companies.collection[].id as companyId.

curl --request POST https://api.convisoappsec.com/graphql \
--header "x-api-key: $CONVISO_API_KEY" \
--header "content-type: application/json" \
--data '{"query":"query GetVulnerabilityDisclosureSubmissions($companyId: Int!) {\n vulnerabilityDisclosureSubmissions(companyId: $companyId) { id title status }\n}","variables":{"companyId":1}}'

Contribute to the Docs

Found something outdated or missing? Help us improve the documentation with a quick suggestion or edit.

How to contribute

Resources

By exploring our content, you'll find resources that will enhance your understanding of the importance of a Security Application Program.

Conviso Blog: Explore our blog, which offers a collection of articles and posts covering a wide range of AppSec topics. The content on the blog is primarily in English.

Conviso's YouTube Channel: Access a wealth of informative videos covering various topics related to AppSec. Please note that the content is primarily in Portuguese.