Skip to main content

SourceCodeVulnerability

No description

type SourceCodeVulnerability implements BaseFields, IssueInterface, VulnerabilityInterface {
aiAgentAnalysis: AiAgentAnalysis
asset: Asset!
assignedTeams: [Team!]
assignedUsers: [PortalUserBasicInfoType!]
author: PortalUser!
branch: Branch
category: String
compromisedEnvironment: Boolean!
createdAt: ISO8601DateTime!
cvssMetric: String
cvssScore: Float
description: String!
detail: SourceCodeVulnerabilityDetail!
history: [IssueHistory!]
id: ID
impactDescription(
blob: Boolean = false
): String!
impactLevel: ImpactLevelCategory
lastUpdatedBy: PortalUser
patterns: [String!]
permittedStatus: [IssueStatusLabel!]!
probabilityLevel: ProbabilityLevelCategory
project: Project
reference: String
riskAcceptedUntil: ISO8601DateTime
runningRetestProject: Project
scanSource: String
severity: SeverityCategory
sla: IssueSLA!
solution: String
status: IssueStatusLabel!
statusHistory: [IssueStatusHistory!]!
stepsToReproduce(
blob: Boolean = false
): String!
summary(
blob: Boolean = false
): String!
timeline(
pagination: BasePaginationInput
filters: IssueTimelineFiltersInput
): IssueTimelineEventCollection!
title: String!
type: Issue!
updatedAt: ISO8601DateTime!
}

Fields​

SourceCodeVulnerability.aiAgentAnalysis ● AiAgentAnalysis object​

AI agent analysis information for this issue

SourceCodeVulnerability.asset ● Asset! non-null object​

The asset associated with the vulnerability

SourceCodeVulnerability.assignedTeams ● [Team!] list object​

SourceCodeVulnerability.assignedUsers ● [PortalUserBasicInfoType!] list object​

SourceCodeVulnerability.author ● PortalUser! non-null object​

The author who created the vulnerability

SourceCodeVulnerability.branch ● Branch object​

The branch this issue was found on; the asset's default branch for a repository issue predating branch stamping; null for an agnostic/legacy asset

SourceCodeVulnerability.category ● String scalar​

CWE Categories

SourceCodeVulnerability.compromisedEnvironment ● Boolean! non-null scalar​

Indicates whether the environment has been compromised due to the vulnerability

SourceCodeVulnerability.createdAt ● ISO8601DateTime! non-null scalar​

The date when record was created

SourceCodeVulnerability.cvssMetric ● String scalar​

Raw CVSS vector (e.g. 'CVSS:3.1/AV:N/...'); null when the source provided none

SourceCodeVulnerability.cvssScore ● Float scalar​

CVSS score derived from the CVSS vector: the Environmental score when the vector carries Environmental metrics, the Temporal score when it carries only Temporal ones, the Base score otherwise. Null when no vector is present.

SourceCodeVulnerability.description ● String! non-null scalar​

A detailed description of the vulnerability

SourceCodeVulnerability.detail ● SourceCodeVulnerabilityDetail! non-null object​

Detailed information about the Source Code vulnerability

SourceCodeVulnerability.history ● [IssueHistory!] list object​

SourceCodeVulnerability.id ● ID scalar​

The ID scalar type represents a unique identifier

SourceCodeVulnerability.impactDescription ● String! non-null scalar​

A detailed description of the impact caused by the vulnerability

SourceCodeVulnerability.impactDescription.blob ● Boolean scalar​

SourceCodeVulnerability.impactLevel ● ImpactLevelCategory enum​

The impact level of the vulnerability

SourceCodeVulnerability.lastUpdatedBy ● PortalUser object​

The portal user (analyst, integration, or AI agent) who last updated the vulnerability

SourceCodeVulnerability.patterns ● [String!] list scalar​

OWASP Patterns

SourceCodeVulnerability.permittedStatus ● [IssueStatusLabel!]! non-null enum​

List of statuses available for change

SourceCodeVulnerability.probabilityLevel ● ProbabilityLevelCategory enum​

The probability level of the vulnerability being exploited

SourceCodeVulnerability.project ● Project object​

Associated project

SourceCodeVulnerability.reference ● String scalar​

Links for further information

SourceCodeVulnerability.riskAcceptedUntil ● ISO8601DateTime scalar​

The datetime until which the risk is accepted

SourceCodeVulnerability.runningRetestProject ● Project object​

Active Vulnerability Retest project associated with this vulnerability

SourceCodeVulnerability.scanSource ● String scalar​

Origin of the vulnerability: the scan/integration that detected it (e.g.: pentest_ai)

SourceCodeVulnerability.severity ● SeverityCategory enum​

The severity of the vulnerability

SourceCodeVulnerability.sla ● IssueSLA! non-null object​

Computed SLA view (due_at, state, days_remaining) derived on read from the company's SLA matrix

SourceCodeVulnerability.solution ● String scalar​

The solution or mitigation for the vulnerability

SourceCodeVulnerability.status ● IssueStatusLabel! non-null enum​

The current status of the vulnerability

SourceCodeVulnerability.statusHistory ● [IssueStatusHistory!]! non-null object​

List of previous statuses

SourceCodeVulnerability.stepsToReproduce ● String! non-null scalar​

Steps to reproduce the vulnerability

SourceCodeVulnerability.stepsToReproduce.blob ● Boolean scalar​

SourceCodeVulnerability.summary ● String! non-null scalar​

A brief summary or description of the vulnerability

SourceCodeVulnerability.summary.blob ● Boolean scalar​

SourceCodeVulnerability.timeline ● IssueTimelineEventCollection! non-null object​

Activity timeline of the issue, newest first

SourceCodeVulnerability.timeline.pagination ● BasePaginationInput input​
SourceCodeVulnerability.timeline.filters ● IssueTimelineFiltersInput input​

SourceCodeVulnerability.title ● String! non-null scalar​

The title of the vulnerability

SourceCodeVulnerability.type ● Issue! non-null enum​

The type of the vulnerability (e.g., SAST, SCA, Web, Network, etc.)

SourceCodeVulnerability.updatedAt ● ISO8601DateTime! non-null scalar​

The date when record was updated

Interfaces​

BaseFields interface​

IssueInterface interface​

VulnerabilityInterface interface​

Member Of​

CreateSourceCodeVulnerabilityPayload object ● UpdateSourceCodeVulnerabilityPayload object

Contribute to the Docs

Found something outdated or missing? Help us improve the documentation with a quick suggestion or edit.

How to contribute

Resources

By exploring our content, you'll find resources that will enhance your understanding of the importance of a Security Application Program.

Conviso Blog: Explore our blog, which offers a collection of articles and posts covering a wide range of AppSec topics. The content on the blog is primarily in English.

Conviso's YouTube Channel: Access a wealth of informative videos covering various topics related to AppSec. Please note that the content is primarily in Portuguese.