Skip to main content

ScaFinding

No description

type ScaFinding implements BaseFields, FindingInterface, IssueInterface {
aiAgentAnalysis: AiAgentAnalysis
asset: Asset!
assignedTeams: [Team!]
assignedUsers: [PortalUserBasicInfoType!]
author: PortalUser!
branch: Branch
branchName: String
category: String
controlSyncStatus: ControlSyncStatus
createdAt: ISO8601DateTime!
cvssMetric: String
cvssScore: Float
description: String!
detail: ScaFindingDetail!
fingerprint: String!
history: [IssueHistory!]
id: ID
impactLevel: ImpactLevelCategory
lastUpdatedBy: PortalUser
originalIssueIdFromTool: String
patterns: [String!]
permittedStatus: [IssueStatusLabel!]!
probabilityLevel: ProbabilityLevelCategory
project: Project
reference: String
riskAcceptedUntil: ISO8601DateTime
runningRetestProject: Project
scanKind: ToolTypeCategory
scanSource: String
severity: SeverityCategory
sla: IssueSLA!
solution: String
status: IssueStatusLabel!
statusHistory: [IssueStatusHistory!]!
timeline(
pagination: BasePaginationInput
filters: IssueTimelineFiltersInput
): IssueTimelineEventCollection!
title: String!
type: Issue!
updatedAt: ISO8601DateTime!
}

Fields​

ScaFinding.aiAgentAnalysis ● AiAgentAnalysis object​

AI agent analysis information for this issue

ScaFinding.asset ● Asset! non-null object​

The asset associated with the vulnerability

ScaFinding.assignedTeams ● [Team!] list object​

ScaFinding.assignedUsers ● [PortalUserBasicInfoType!] list object​

ScaFinding.author ● PortalUser! non-null object​

The author who created the vulnerability

ScaFinding.branch ● Branch object​

The branch this issue was found on; the asset's default branch for a repository issue predating branch stamping; null for an agnostic/legacy asset

ScaFinding.branchName ● String scalar​

Label of the branch this finding was found on; the asset's default branch for a repository asset whose finding predates branch stamping; null for agnostic/legacy assets

ScaFinding.category ● String scalar​

CWE Categories

ScaFinding.controlSyncStatus ● ControlSyncStatus object​

The scan/sync that brought this vulnerability to Conviso Platform

ScaFinding.createdAt ● ISO8601DateTime! non-null scalar​

The date when record was created

ScaFinding.cvssMetric ● String scalar​

Raw CVSS vector (e.g. 'CVSS:3.1/AV:N/...'); null when the source provided none

ScaFinding.cvssScore ● Float scalar​

CVSS score derived from the CVSS vector: the Environmental score when the vector carries Environmental metrics, the Temporal score when it carries only Temporal ones, the Base score otherwise. Null when no vector is present.

ScaFinding.description ● String! non-null scalar​

A detailed description of the vulnerability

ScaFinding.detail ● ScaFindingDetail! non-null object​

Detailed information about the SCA vulnerability

ScaFinding.fingerprint ● String! non-null scalar​

A unique identifier for the vulnerability

ScaFinding.history ● [IssueHistory!] list object​

ScaFinding.id ● ID scalar​

The ID scalar type represents a unique identifier

ScaFinding.impactLevel ● ImpactLevelCategory enum​

The impact level of the vulnerability

ScaFinding.lastUpdatedBy ● PortalUser object​

The portal user (analyst, integration, or AI agent) who last updated the vulnerability

ScaFinding.originalIssueIdFromTool ● String scalar​

The original vulnerability ID from the tool that detected the vulnerability

ScaFinding.patterns ● [String!] list scalar​

OWASP Patterns

ScaFinding.permittedStatus ● [IssueStatusLabel!]! non-null enum​

List of statuses available for change

ScaFinding.probabilityLevel ● ProbabilityLevelCategory enum​

The probability level of the vulnerability being exploited

ScaFinding.project ● Project object​

Associated project

ScaFinding.reference ● String scalar​

Links for further information

ScaFinding.riskAcceptedUntil ● ISO8601DateTime scalar​

The datetime until which the risk is accepted

ScaFinding.runningRetestProject ● Project object​

Active Vulnerability Retest project associated with this vulnerability

ScaFinding.scanKind ● ToolTypeCategory enum​

Which Conviso AST category (SAST/SCA/IaC/Secrets/Container) produced this finding; null for a finding from any other integration, or one that predates this field

ScaFinding.scanSource ● String scalar​

Source of the vulnerability; Retrieves the name of the source (e.g.: Dependency Track)

ScaFinding.severity ● SeverityCategory enum​

The severity of the vulnerability

ScaFinding.sla ● IssueSLA! non-null object​

Computed SLA view (due_at, state, days_remaining) derived on read from the company's SLA matrix

ScaFinding.solution ● String scalar​

The solution or mitigation for the vulnerability

ScaFinding.status ● IssueStatusLabel! non-null enum​

The current status of the vulnerability

ScaFinding.statusHistory ● [IssueStatusHistory!]! non-null object​

List of previous statuses

ScaFinding.timeline ● IssueTimelineEventCollection! non-null object​

Activity timeline of the issue, newest first

ScaFinding.timeline.pagination ● BasePaginationInput input​
ScaFinding.timeline.filters ● IssueTimelineFiltersInput input​

ScaFinding.title ● String! non-null scalar​

The title of the vulnerability

ScaFinding.type ● Issue! non-null enum​

The type of the vulnerability (e.g., SAST, SCA, Web, Network, etc.)

ScaFinding.updatedAt ● ISO8601DateTime! non-null scalar​

The date when record was updated

Interfaces​

BaseFields interface​

FindingInterface interface​

IssueInterface interface​

Member Of​

CreateScaFindingPayload object

Contribute to the Docs

Found something outdated or missing? Help us improve the documentation with a quick suggestion or edit.

How to contribute

Resources

By exploring our content, you'll find resources that will enhance your understanding of the importance of a Security Application Program.

Conviso Blog: Explore our blog, which offers a collection of articles and posts covering a wide range of AppSec topics. The content on the blog is primarily in English.

Conviso's YouTube Channel: Access a wealth of informative videos covering various topics related to AppSec. Please note that the content is primarily in Portuguese.