Querying Vulnerability Information About an Artifact Scan
Function
This API is used to query vulnerability information about an artifact scan.
Constraints
This API is only supported by SWR Enterprise Edition instances v25.7.20 or later.
Calling Method
For details, see Calling APIs.
Authorization Information
Each account has all the permissions required to call all APIs, but IAM users must be assigned the required permissions.
- If you are using role/policy-based authorization, see Permissions Policies and Supported Actions for details on the required permissions.
- If you are using identity policy-based authorization, no identity policy-based permission required for calling this API.
URI
GET /v2/{project_id}/instances/{instance_id}/namespaces/{namespace_name}/repositories/{repository_name}/artifacts/{reference}/vulnerabilities
| Parameter | Mandatory | Type | Description |
|---|---|---|---|
| project_id | Yes | String | Project ID. |
| instance_id | Yes | String | ID of an SWR Enterprise Edition instance. |
| namespace_name | Yes | String | Namespace name. |
| repository_name | Yes | String | Artifact repository name. If the repository name contains a slash (/), replace the slash (/) with %2F before sending the request. Note: When using the curl command to send a request, replace the slash (/) with %252F (% in %2F is encoded as %25). |
| reference | Yes | String | Artifact digest. |
Request Parameters
| Parameter | Mandatory | Type | Description |
|---|---|---|---|
| X-Auth-Token | Yes | String | User token. The token can be obtained by calling the IAM API. The value of X-Subject-Token in the response header is the user token. |
Response Parameters
Status code: 200
| Parameter | Type | Description |
|---|---|---|
| {User defined key} | Map<String,VulnerabilityReports> | Vulnerability report of the application/vnd.security.vulnerability.report; version=1.1 type. |
| Parameter | Type | Description |
|---|---|---|
| generated_at | String | Time when a vulnerability report was generated. |
| severity | String | Overall severity in the artifact scan report. The options are None (no scores), Low (low risk), Medium (medium risk), High (high risk), Critical (critical), and Security (secure). |
| scanner | Scanner object | Scanner information. |
| vulnerabilities | Array of vulnerability objects | Vulnerability list. |
| Parameter | Type | Description |
|---|---|---|
| name | String | Scanner name. |
| vendor | String | Scanner provider. |
| version | String | Scanner version. |
| Parameter | Type | Description |
|---|---|---|
| id | String | Vulnerability ID. |
| package | String | Name of the software package that contains a vulnerability. |
| version | String | Version of the software package that contains a vulnerability. |
| fix_version | String | Version of the software package that fixes a vulnerability. |
| severity | String | Severity of a vulnerability. The options are Low (low risk), Medium (medium risk), High (high risk), and Critical (critical). |
| description | String | Vulnerability description. |
| links | Array of strings | Vulnerability-related links. |
| artifact_digests | Array of strings | Image layers that contain a vulnerability. |
| preferred_cvss | preferred_cvss object | Vulnerability scores and attack vectors based on CVSS3 and CVSS2. |
| cwe_ids | Array of strings | CWE ID list related to a vulnerability. |
| Parameter | Type | Description |
|---|---|---|
| score_v3 | Number | CVSS3 score of a vulnerability. |
| score_v2 | Number | CVSS2 score of a vulnerability. |
| vector_v3 | String | CVSS3 attack vector of a vulnerability. |
| vector_v2 | String | CVSS2 attack vector of a vulnerability. |
Status code: 400
| Parameter | Type | Description |
|---|---|---|
| error_code | String | Error code. |
| error_msg | String | Error message. |
| encoded_authorization_message | String | Detailed rejection reason after encryption. You can call the API decode-authorization-message of STS to decrypt the reason. |
Status code: 401
| Parameter | Type | Description |
|---|---|---|
| error_code | String | Error code. |
| error_msg | String | Error message. |
| encoded_authorization_message | String | Detailed rejection reason after encryption. You can call the API decode-authorization-message of STS to decrypt the reason. |
Status code: 403
| Parameter | Type | Description |
|---|---|---|
| error_code | String | Error code. |
| error_msg | String | Error message. |
| encoded_authorization_message | String | Detailed rejection reason after encryption. You can call the API decode-authorization-message of STS to decrypt the reason. |
Status code: 404
| Parameter | Type | Description |
|---|---|---|
| error_code | String | Error code. |
| error_msg | String | Error message. |
| encoded_authorization_message | String | Detailed rejection reason after encryption. You can call the API decode-authorization-message of STS to decrypt the reason. |
Status code: 500
| Parameter | Type | Description |
|---|---|---|
| error_code | String | Error code. |
| error_msg | String | Error message. |
| encoded_authorization_message | String | Detailed rejection reason after encryption. You can call the API decode-authorization-message of STS to decrypt the reason. |
Example Requests
GET https://{endpoint}/v2/{project_id}/instances/{instance_id}/namespaces/{namespace_name}/repositories/{repository_name}/artifacts/{reference}/vulnerabilities Example Responses
Status code: 200
The vulnerability information about the artifact is queried successfully.
{
"application/vnd.security.vulnerability.report; version=1.1" : {
"generated_at" : "2025-09-12:06:44:31",
"scanner" : {
"name" : "HSS",
"vendor" : "HSS",
"version" : "v5"
},
"severity" : "High",
"vulnerabilities" : [ {
"id" : "CVE-2020-2755",
"package" : "openjdk-8-jre",
"version" : "8u181-b13-2~deb9u1",
"fix_version" : "",
"severity" : "High",
"description" : "Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Scripting). Supported versions that are affected are Java SE: 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).",
"links" : [ "https://security-tracker.debian.org/tracker/DSA-4668-1" ],
"artifact_digests" : [ "sha256:a48d150ffd2faf9ea63217a7774a75cd3b4a252413810c2239d1ee257efc9e13" ],
"preferred_cvss" : {
"score_v3" : 3.700000047683716,
"score_v2" : 3.7,
"vector_v3" : "",
"vector_v2" : ""
},
"cwe_ids" : [ "" ]
} ]
}
} SDK Sample Code
The SDK sample code is as follows.
Java
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 | package com.huaweicloud.sdk.test; import com.huaweicloud.sdk.core.auth.ICredential; import com.huaweicloud.sdk.core.auth.BasicCredentials; import com.huaweicloud.sdk.core.exception.ConnectionException; import com.huaweicloud.sdk.core.exception.RequestTimeoutException; import com.huaweicloud.sdk.core.exception.ServiceResponseException; import com.huaweicloud.sdk.swr.v2.region.SwrRegion; import com.huaweicloud.sdk.swr.v2.*; import com.huaweicloud.sdk.swr.v2.model.*; public class ListInstanceArtifactVulnerabilitiesSolution { public static void main(String[] args) { // The AK and SK used for authentication are hard-coded or stored in plaintext, which has great security risks. It is recommended that the AK and SK be stored in ciphertext in configuration files or environment variables and decrypted during use to ensure security. // In this example, AK and SK are stored in environment variables for authentication. Before running this example, set environment variables CLOUD_SDK_AK and CLOUD_SDK_SK in the local environment String ak = System.getenv("CLOUD_SDK_AK"); String sk = System.getenv("CLOUD_SDK_SK"); String projectId = "{project_id}"; ICredential auth = new BasicCredentials() .withProjectId(projectId) .withAk(ak) .withSk(sk); SwrClient client = SwrClient.newBuilder() .withCredential(auth) .withRegion(SwrRegion.valueOf("<YOUR REGION>")) .build(); ListInstanceArtifactVulnerabilitiesRequest request = new ListInstanceArtifactVulnerabilitiesRequest(); request.withInstanceId("{instance_id}"); request.withNamespaceName("{namespace_name}"); request.withRepositoryName("{repository_name}"); request.withReference("{reference}"); try { ListInstanceArtifactVulnerabilitiesResponse response = client.listInstanceArtifactVulnerabilities(request); System.out.println(response.toString()); } catch (ConnectionException e) { e.printStackTrace(); } catch (RequestTimeoutException e) { e.printStackTrace(); } catch (ServiceResponseException e) { e.printStackTrace(); System.out.println(e.getHttpStatusCode()); System.out.println(e.getRequestId()); System.out.println(e.getErrorCode()); System.out.println(e.getErrorMsg()); } } } |
Python
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 | # coding: utf-8 import os from huaweicloudsdkcore.auth.credentials import BasicCredentials from huaweicloudsdkswr.v2.region.swr_region import SwrRegion from huaweicloudsdkcore.exceptions import exceptions from huaweicloudsdkswr.v2 import * if __name__ == "__main__": # The AK and SK used for authentication are hard-coded or stored in plaintext, which has great security risks. It is recommended that the AK and SK be stored in ciphertext in configuration files or environment variables and decrypted during use to ensure security. # In this example, AK and SK are stored in environment variables for authentication. Before running this example, set environment variables CLOUD_SDK_AK and CLOUD_SDK_SK in the local environment ak = os.environ["CLOUD_SDK_AK"] sk = os.environ["CLOUD_SDK_SK"] projectId = "{project_id}" credentials = BasicCredentials(ak, sk, projectId) client = SwrClient.new_builder() \ .with_credentials(credentials) \ .with_region(SwrRegion.value_of("<YOUR REGION>")) \ .build() try: request = ListInstanceArtifactVulnerabilitiesRequest() request.instance_id = "{instance_id}" request.namespace_name = "{namespace_name}" request.repository_name = "{repository_name}" request.reference = "{reference}" response = client.list_instance_artifact_vulnerabilities(request) print(response) except exceptions.ClientRequestException as e: print(e.status_code) print(e.request_id) print(e.error_code) print(e.error_msg) |
Go
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 | package main import ( "fmt" "github.com/huaweicloud/huaweicloud-sdk-go-v3/core/auth/basic" swr "github.com/huaweicloud/huaweicloud-sdk-go-v3/services/swr/v2" "github.com/huaweicloud/huaweicloud-sdk-go-v3/services/swr/v2/model" region "github.com/huaweicloud/huaweicloud-sdk-go-v3/services/swr/v2/region" ) func main() { // The AK and SK used for authentication are hard-coded or stored in plaintext, which has great security risks. It is recommended that the AK and SK be stored in ciphertext in configuration files or environment variables and decrypted during use to ensure security. // In this example, AK and SK are stored in environment variables for authentication. Before running this example, set environment variables CLOUD_SDK_AK and CLOUD_SDK_SK in the local environment ak := os.Getenv("CLOUD_SDK_AK") sk := os.Getenv("CLOUD_SDK_SK") projectId := "{project_id}" auth, err := basic.NewCredentialsBuilder(). WithAk(ak). WithSk(sk). WithProjectId(projectId). SafeBuild() if err != nil { fmt.Println(err) return } hcClient, err := swr.SwrClientBuilder(). WithRegion(region.ValueOf("<YOUR REGION>")). WithCredential(auth). SafeBuild() if err != nil { fmt.Println(err) return } client := swr.NewSwrClient(hcClient) request := &model.ListInstanceArtifactVulnerabilitiesRequest{} request.InstanceId = "{instance_id}" request.NamespaceName = "{namespace_name}" request.RepositoryName = "{repository_name}" request.Reference = "{reference}" response, err := client.ListInstanceArtifactVulnerabilities(request) if err == nil { fmt.Printf("%+v\n", response) } else { fmt.Println(err) } } |
More
For SDK sample code of more programming languages, see the Sample Code tab in API Explorer. SDK sample code can be automatically generated.
Status Codes
| Status Code | Description |
|---|---|
| 200 | The vulnerability information about the artifact is queried successfully. |
| 400 | Request error. |
| 401 | Authentication failed. |
| 403 | Access denied. |
| 404 | Resource not found. |
| 500 | Internal error. |
Error Codes
See Error Codes.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot