Skip to main content

Asset

No description

type Asset {
activeDevelopers(
lastDays: Int
pagination: BasePaginationInput
): ActiveDeveloperTypeCollection!
applications: [Application!]!
appliedRiskScorePolicy: RiskScorePolicy
architectureType: String
archived: Boolean!
archivedAt: ISO8601DateTime
archivedBy: PortalUserBasicInfoType
assetType: String
assetsTagList: [String!]
assignedTeams: [Team!]
assignedUsers: [PortalUserBasicInfoType!]
astBranchPattern: String
astMatchingBranches: [MatchingBranch!]!
astOnDemandAvailable(
branchId: ID
): Boolean!
astOnDemandUnavailableReason(
branchId: ID
): String
astOnDemandUnavailableReasonCode(
branchId: ID
): AstOnDemandUnavailableReasonEnum
audience: String
branches: [Branch!]!
businessImpact: BusinessImpactLevel
childAssets(
page: Int = 1
perPage: Int = 20
): AssetCollection!
cloudAccount: CloudAccount
cloudProvider: String
company: Company!
createdAt: ISO8601DateTime!
criticity: String
cspmIntegration: CspmIntegration
dataClassification: [DataClassification!]!
defaultBranch: Branch
description: String
developers(
page: Int
perPage: Int
): DeveloperTypeCollection
developmentModel: String
developmentTeam: String
editableBranchName: Boolean
environment: String
environmentCompromised: Boolean!
exploitability: Exploitability
id: ID!
integrationDetails: IntegrationDetailsCollection
integrations: [String!]
latestAstScanRun(
branchId: ID
): ScanRun
lifeCycle: String
name: String
parentAsset: Asset
pendingVulnerabilitiesStats: [IssueSeverityStat!]!
projects(
includeAst: Boolean
): [Project!]
repoUrl: String
repositoryDetail: RepositoryDetail
resourceName: String
resourceType: String
resourceUid: String
riskScore: AssetRiskScoreHistories
sbomComponents(
search: SbomComponentSearchInput
page: Int = 1
limit: Int = 10
): SbomComponentsPaginatedResponse
sbomDependencyGraph(
branchId: ID
rootIds: [ID!]
depth: Int = 3
limit: Int = 500
): SbomDependencyGraph
scanType: [String!]
scannerConfigurations: [ScannerConfigurationInterface!]!
scanners: [String!]
scannersExecutionHistories(
page: Int
perPage: Int
): ScanHistoryCollection!
securityGateConfiguration: SecurityGateConfiguration
serviceName: String
sourceIntegrations: [AssetSourceIntegration!]!
suggestedBranchName: String
teams: [Team!]
technologies: [String!]!
threat: ThreatLevel
updatedAt: ISO8601DateTime!
url: String
users: [UserType!]
vulnerabilities: VulnerabilitiesDetail
}

Fields​

Asset.activeDevelopers ● ActiveDeveloperTypeCollection! non-null object​

List of active developers contributing to the asset

Asset.activeDevelopers.lastDays ● Int scalar​
Asset.activeDevelopers.pagination ● BasePaginationInput input​

Asset.applications ● [Application!]! non-null object​

Applications this asset is part of

Asset.appliedRiskScorePolicy ● RiskScorePolicy object​

The risk-score policy explicitly chosen by an analyst when this asset carried tags from more than one policy

Asset.architectureType ● String scalar​

Asset.archived ● Boolean! non-null scalar​

Indicates if the asset is archived

Asset.archivedAt ● ISO8601DateTime scalar​

Date when the asset was archived; null when the asset is not archived

Asset.archivedBy ● PortalUserBasicInfoType object​

The portal user who archived the asset

Asset.assetType ● String scalar​

Asset.assetsTagList ● [String!] list scalar​

List of tags associated with the asset

Asset.assignedTeams ● [Team!] list object​

Teams assigned to the asset. Access granted elsewhere is not listed here — see teams

Asset.assignedUsers ● [PortalUserBasicInfoType!] list object​

Users assigned to the asset. Access granted elsewhere is not listed here — see users

Asset.astBranchPattern ● String scalar​

The raw configured AST branch pattern, or null when none is configured. Disambiguates astMatchingBranches: null here means every branch scans; a non-null value that still leaves astMatchingBranches empty means the pattern matched nothing.

Asset.astMatchingBranches ● [MatchingBranch!]! non-null object​

The asset's branches the configured AST pattern matches. Empty both when no pattern is configured and when a pattern is configured but matches nothing — use astBranchPattern to tell the two apart.

Asset.astOnDemandAvailable ● Boolean! non-null scalar​

True when "Run AST" can be triggered for this asset right now.

Asset.astOnDemandAvailable.branchId ● ID scalar​

Branch the scan would run on; omit for the configured AST branch.

Asset.astOnDemandUnavailableReason ● String scalar​

Why "Run AST" is unavailable for this asset; null when it is available.

Asset.astOnDemandUnavailableReason.branchId ● ID scalar​

Branch the scan would run on; omit for the configured AST branch.

Asset.astOnDemandUnavailableReasonCode ● AstOnDemandUnavailableReasonEnum enum​

Machine-readable form of astOnDemandUnavailableReason, for a client that has to act on which refusal it got rather than display it; null when available.

Asset.astOnDemandUnavailableReasonCode.branchId ● ID scalar​

Branch the scan would run on; omit for the configured AST branch.

Asset.audience ● String scalar​

Asset.branches ● [Branch!]! non-null object​

Branches of this repository asset

Asset.businessImpact ● BusinessImpactLevel enum​

Business impact level of the asset

Asset.childAssets ● AssetCollection! non-null object​

API (endpoint) child assets of this Domain, ordered by risk score (highest first)

Asset.childAssets.page ● Int scalar​

Page number for paginated results

Asset.childAssets.perPage ● Int scalar​

Number of items per page

Asset.cloudAccount ● CloudAccount object​

Cloud account this asset belongs to

Asset.cloudProvider ● String scalar​

Cloud provider: aws | azure | gcp

Asset.company ● Company! non-null object​

Company associated with the asset

Asset.createdAt ● ISO8601DateTime! non-null scalar​

The date when the asset was created

Asset.criticity ● String scalar​

Asset.cspmIntegration ● CspmIntegration object​

CSPM integration that discovered this asset

Asset.dataClassification ● [DataClassification!]! non-null enum​

Data classification levels associated with the asset

Asset.defaultBranch ● Branch object​

The repository's default branch

Asset.description ● String scalar​

Detailed description of the asset

Asset.developers ● DeveloperTypeCollection object​

Developers associated with the asset

Asset.developers.page ● Int scalar​

Page number for paginated results

Asset.developers.perPage ● Int scalar​

Number of items per page

Asset.developmentModel ● String scalar​

Asset.developmentTeam ● String scalar​

Asset.editableBranchName ● Boolean scalar​

Legacy asset only: true when the UI may let the user change the suggested branch; null when the asset cannot be promoted.

Asset.environment ● String scalar​

Asset.environmentCompromised ● Boolean! non-null scalar​

Indicates if the asset has vulnerabilities that compromise the environment in active status

Asset.exploitability ● Exploitability enum​

Exploitability level of the asset

Asset.id ● ID! non-null scalar​

Asset.integrationDetails ● IntegrationDetailsCollection object​

Details of integration setups for the asset

Asset.integrations ● [String!] list scalar​

List of defect tracker integrations connected to the asset (e.g., Jira, Clickup)

Asset.latestAstScanRun ● ScanRun object​

Most recent AST scan run for this asset. The UI polls its state while a "Run AST" execution is in flight.

Asset.latestAstScanRun.branchId ● ID scalar​

Restrict to runs on this branch; omit for the asset's most recent run.

Asset.lifeCycle ● String scalar​

Asset.name ● String scalar​

The name of the asset

Asset.parentAsset ● Asset object​

Parent (Domain/host) asset when this is an API endpoint child; null for roots

Asset.pendingVulnerabilitiesStats ● [IssueSeverityStat!]! non-null object​

Statistics of pending vulnerabilities related to the asset

Asset.projects ● [Project!] list object​

Projects associated with the asset

Asset.projects.includeAst ● Boolean scalar​

Asset.repoUrl ● String scalar​

Repository URL of the asset's source code

Asset.repositoryDetail ● RepositoryDetail object​

Repository identity (URL, key, subproject, default branch) for a repository-kind asset

Asset.resourceName ● String scalar​

Friendly resource name

Asset.resourceType ● String scalar​

Cloud resource type (e.g. AwsS3Bucket, AwsEc2Instance)

Asset.resourceUid ● String scalar​

Unique resource identifier in the provider (ARN for AWS)

Asset.riskScore ● AssetRiskScoreHistories object​

Risk score history of the asset

Asset.sbomComponents ● SbomComponentsPaginatedResponse object​

SBOM (Software Bill of Materials) components of the asset

Search filter for SBOM components

Asset.sbomComponents.page ● Int scalar​

Page number for paginated results

Asset.sbomComponents.limit ● Int scalar​

Number of items per page

Asset.sbomDependencyGraph ● SbomDependencyGraph object​

Dependency graph of this asset's SBOM for one branch. Empty with dependencyGraphAvailable false when the generating tool supplied no graph

Asset.sbomDependencyGraph.branchId ● ID scalar​

Branch to read. Defaults to the asset's default-branch view

Asset.sbomDependencyGraph.rootIds ● [ID!] list scalar​

Expand from these components instead of the graph's roots. Ids outside this asset and branch are ignored. At most 50

Asset.sbomDependencyGraph.depth ● Int scalar​

Levels to walk below the roots (capped at 12)

Asset.sbomDependencyGraph.limit ● Int scalar​

Maximum nodes to return (capped at 2000)

Asset.scanType ● [String!] list scalar​

Types of scans performed on the asset

Asset.scannerConfigurations ● [ScannerConfigurationInterface!]! non-null interface​

Asset.scanners ● [String!] list scalar​

List of scanners connected to the asset (e.g., Conviso AST, SonarQube)

Asset.scannersExecutionHistories ● ScanHistoryCollection! non-null object​

Scan execution history records for the asset (newest first, max 10 per page)

Asset.scannersExecutionHistories.page ● Int scalar​

Page number for paginated results

Asset.scannersExecutionHistories.perPage ● Int scalar​

Number of items per page (capped at 10)

Asset.securityGateConfiguration ● SecurityGateConfiguration object​

Security gate configuration for the asset

Asset.serviceName ● String scalar​

Cloud service name (e.g. s3, ec2, iam)

Asset.sourceIntegrations ● [AssetSourceIntegration!]! non-null object​

Integration rows that imported this asset, id and name — not just the type. Powers the Environment column: a company can hold several Salt Security environments, and scanners reports the same type for all of them. An API endpoint child reports its parent host's integrations, which is where its sync bridge lives.

Asset.suggestedBranchName ● String scalar​

Legacy asset only: branch name to pre-fill when promoting it to a repository (its deploy/scan history, else "main"); null when the asset cannot be promoted.

Asset.teams ● [Team!] list object​

Teams associated with the asset

Asset.technologies ● [String!]! non-null scalar​

Technologies used in the asset (e.g., languages, frameworks)

Asset.threat ● ThreatLevel enum​

Threat level associated with the asset

Asset.updatedAt ● ISO8601DateTime! non-null scalar​

Date when the asset was last updated

Asset.url ● String scalar​

URL where the asset is accessible

Asset.users ● [UserType!] list object​

Users who have access to the asset (including inherited access from company)

Asset.vulnerabilities ● VulnerabilitiesDetail object​

Vulnerabilities related to the asset

Returned By​

asset query

Member Of​

ApiFinding object ● Application object ● Asset object ● AssetBranch object ● AssetCollection object ● AssetMergeManualPreview object ● AssetMergeNewBranch object ● AssociateProjectData object ● ChangeAssetTypePayload object ● ChangeDefaultBranchPayload object ● CloudFinding object ● Commit object ● ContainerFinding object ● ControlSyncStatus object ● ConvisoDastConfiguration object ● CreateAssetPayload object ● DastFinding object ● DefectTrackerConfiguration object ● FindingInterface interface ● IacFinding object ● ImportedScan object ● Integration object ● IntegrationExternalProject object ● IssueInterface interface ● IssuesAggregation object ● MastFinding object ● NetworkVulnerability object ● ProgramAsset object ● Project object ● PromoteAssetToRepositoryPayload object ● PullRequestScanRun object ● RepositoryConfiguration object ● SastFinding object ● SbomArtifact object ● ScaFinding object ● ScanConfig object ● ScanHistory object ● ScannerConfigurationInterface interface ● ScanRun object ● SecretFinding object ● SecurityGateExecution object ● SourceCodeVulnerability object ● UpdateAssetPayload object ● VulnerabilityInterface interface ● WebVulnerability object

Implemented By​

SecurityGateConfigurationOwnerUnion union

Contribute to the Docs

Found something outdated or missing? Help us improve the documentation with a quick suggestion or edit.

How to contribute

Resources

By exploring our content, you'll find resources that will enhance your understanding of the importance of a Security Application Program.

Conviso Blog: Explore our blog, which offers a collection of articles and posts covering a wide range of AppSec topics. The content on the blog is primarily in English.

Conviso's YouTube Channel: Access a wealth of informative videos covering various topics related to AppSec. Please note that the content is primarily in Portuguese.