List security findings
GET
/security/findings
const url = 'https://shoehorn.example.com/api/v1/security/findings?severity=critical&status=open&limit=20';const options = {method: 'GET'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request GET \ --url 'https://shoehorn.example.com/api/v1/security/findings?severity=critical&status=open&limit=20'Returns security findings across all entities.
Parameters
Section titled “ Parameters ”Query Parameters
Section titled “Query Parameters ” severity
string
entity_id
string
type
string
status
string
limit
integer
cursor
string
Responses
Section titled “ Responses ”Paginated security findings
Media type application/json
object
findings
Array<object>
object
id
string format: uuid
entity_id
string
entity_name
string
type
E.g., missing_owner, no_readme, exposed_secret
string
severity
string
status
string
title
string
description
string
remediation
Suggested fix
string
source
E.g., scorecard, scanner, manual
string
created_at
string format: date-time
resolved_at
string format: date-time
pagination
object
total
integer
nextCursor
string
Example
{ "findings": [ { "severity": "critical", "status": "open" } ]}